From 2f8ccd3ae56a267fa97a0a8c6782c6a410213c14 Mon Sep 17 00:00:00 2001 From: ematipico Date: Fri, 2 Oct 2026 14:51:46 +0100 Subject: [PATCH 1/2] feat(docs): add support for terraform --- packages/docs-site/package.json | 3 +- .../scripts/generate-terraform-docs.test.mjs | 81 +++++ .../scripts/generate-terraform-docs.ts | 312 ++++++++++++++++++ packages/docs-site/src/api-server.ts | 7 +- .../docs-site/src/components/CodeSample.astro | 71 +++- .../docs-site/src/components/Operation.astro | 176 +++++++--- .../components/TerraformDeclarations.astro | 106 ++++++ .../src/components/TerraformFields.astro | 143 ++++++++ packages/docs-site/src/content.config.ts | 3 +- .../src/generated/terraform-docs.json | 1 + packages/docs-site/src/terraform-extension.ts | 37 +++ packages/docs-site/src/terraform.test.ts | 82 +++++ packages/docs-site/src/terraform.ts | 93 ++++++ 13 files changed, 1060 insertions(+), 55 deletions(-) create mode 100644 packages/docs-site/scripts/generate-terraform-docs.test.mjs create mode 100644 packages/docs-site/scripts/generate-terraform-docs.ts create mode 100644 packages/docs-site/src/components/TerraformDeclarations.astro create mode 100644 packages/docs-site/src/components/TerraformFields.astro create mode 100644 packages/docs-site/src/generated/terraform-docs.json create mode 100644 packages/docs-site/src/terraform-extension.ts create mode 100644 packages/docs-site/src/terraform.test.ts create mode 100644 packages/docs-site/src/terraform.ts diff --git a/packages/docs-site/package.json b/packages/docs-site/package.json index 6277f6b0b..bc6f0c1b2 100644 --- a/packages/docs-site/package.json +++ b/packages/docs-site/package.json @@ -7,7 +7,8 @@ "build": "astro build", "preview": "astro preview", "check": "astro check", - "test": "node --experimental-strip-types --test src/*.test.ts" + "generate:terraform-docs": "node --experimental-strip-types scripts/generate-terraform-docs.ts", + "test": "node --experimental-strip-types --test src/*.test.ts scripts/*.test.mjs" }, "dependencies": { "@astrojs/cloudflare": "^14.2.5", diff --git a/packages/docs-site/scripts/generate-terraform-docs.test.mjs b/packages/docs-site/scripts/generate-terraform-docs.test.mjs new file mode 100644 index 000000000..5a1b6464c --- /dev/null +++ b/packages/docs-site/scripts/generate-terraform-docs.test.mjs @@ -0,0 +1,81 @@ +import assert from 'node:assert/strict'; +import test from 'node:test'; +import { canonicalTerraformEndpoint, extractTerraformDocs } from './generate-terraform-docs.ts'; + +test('canonicalTerraformEndpoint ignores path parameter names', () => { + assert.equal( + canonicalTerraformEndpoint('POST', '/accounts/{account_id}/widgets/{widget_id}'), + 'post /accounts/{}/widgets/{}', + ); +}); + +test('extractTerraformDocs resolves fields and joins declarations to Forge operations', () => { + const servicePath = '(resource) widgets'; + const sourcePath = `${servicePath} > (terraform resource)`; + const namePath = `${sourcePath} > (attribute) name`; + const settingsPath = `${sourcePath} > (attribute) settings`; + const enabledPath = `${settingsPath} > (attribute) enabled`; + const sdkJson = { + resources: { + widgets: { + stainlessPath: servicePath, + methods: { create: { endpoint: 'post /accounts/{account_id}/widgets' } }, + subresources: {}, + }, + }, + decls: { + terraform: { + [servicePath]: { kind: 'TerraformDeclServiceNode', resource: sourcePath }, + [sourcePath]: { + kind: 'TerraformDeclSource', + type: 'resource', + name: 'cloudflare_widget', + methodName: 'create', + required: [namePath], + optional: [settingsPath], + computed: [], + }, + [namePath]: { + kind: 'TerraformDeclAttribute', + name: 'name', + type: { category: 'primitive', type: 'String' }, + children: [], + }, + [settingsPath]: { + kind: 'TerraformDeclAttribute', + name: 'settings', + type: { category: 'nested', type: 'SingleNested' }, + children: [enabledPath], + }, + [enabledPath]: { + kind: 'TerraformDeclAttribute', + name: 'enabled', + type: { category: 'primitive', type: 'Bool' }, + children: [], + }, + }, + }, + snippets: { + 'terraform.default': { + [sourcePath]: { default: { content: 'resource "cloudflare_widget" "example" {}\n' } }, + }, + }, + metadata: { terraform: { version: '1.0.0' } }, + }; + const openapi = { + paths: { + '/accounts/{account}/widgets': { + post: { operationId: 'widgets_create' }, + }, + }, + }; + const result = extractTerraformDocs(sdkJson, openapi); + + assert.deepEqual(result.stats, { operations: 1, declarations: 1, missingSnippets: 0, unmatched: 0 }); + assert.equal(result.operations['post /accounts/{}/widgets'].operationId, 'widgets_create'); + assert.deepEqual(result.operations['post /accounts/{}/widgets'].declarations[0].optional[0], { + name: 'settings', + type: 'Attributes', + children: [{ name: 'enabled', type: 'Bool' }], + }); +}); diff --git a/packages/docs-site/scripts/generate-terraform-docs.ts b/packages/docs-site/scripts/generate-terraform-docs.ts new file mode 100644 index 000000000..98443b4da --- /dev/null +++ b/packages/docs-site/scripts/generate-terraform-docs.ts @@ -0,0 +1,312 @@ +#!/usr/bin/env node + +import { readFile, writeFile } from 'node:fs/promises'; +import path from 'node:path'; +import process from 'node:process'; +import { fileURLToPath, pathToFileURL } from 'node:url'; +import { parseArgs } from 'node:util'; +import { loadForgeOpenApi } from '../src/openapi-source.ts'; + +const HTTP_METHODS = ['get', 'post', 'put', 'patch', 'delete', 'head', 'options', 'trace'] as const; +const OUTPUT_FILE = new URL('../src/generated/terraform-docs.json', import.meta.url); +type TerraformDeclarationKind = 'resource' | 'data-source' | 'list-data-source'; +type TerraformAttributeGroup = 'required' | 'optional' | 'computed'; + +interface TerraformTypeInput { + category?: string; + type?: string; + elementType?: TerraformTypeInput; + allowedSubtypes?: string[]; +} + +interface TerraformAttributeInput { + kind: 'TerraformDeclAttribute'; + name: string; + type: TerraformTypeInput; + description?: string; + deprecated?: string | boolean; + sensitive?: boolean; + requiresReplace?: boolean; + children?: string[]; +} + +interface TerraformSourceInput { + kind: 'TerraformDeclSource'; + name: string; + methodName: string; + required?: string[]; + optional?: string[]; + computed?: string[]; +} + +interface TerraformServiceNodeInput { + kind: 'TerraformDeclServiceNode'; + resource?: string; + dataSource?: string; + listDataSource?: string; +} + +type TerraformDeclarationInput = TerraformAttributeInput | TerraformSourceInput | TerraformServiceNodeInput; + +interface TerraformResourceInput { + stainlessPath?: string; + methods?: Record; + subresources?: Record; +} + +interface TerraformSdkInput { + resources: Record; + decls: { terraform: Record }; + snippets: { + 'terraform.default': Record; + }; + metadata?: { terraform?: unknown }; +} + +interface OpenApiInput { + paths: Record>>; +} + +interface TerraformAttribute { + name: string; + type: string; + description?: string; + deprecated?: string; + sensitive?: boolean; + requiresReplace?: boolean; + children?: TerraformAttribute[]; +} + +interface TerraformDeclaration { + kind: TerraformDeclarationKind; + name: string; + stainlessResource: string; + methodName: string; + snippet?: string; + required: TerraformAttribute[]; + optional: TerraformAttribute[]; + computed: TerraformAttribute[]; +} + +interface OperationEntry { + operationId: string; + declarations: TerraformDeclaration[]; +} + +function usage() { + return 'Usage: node --experimental-strip-types scripts/generate-terraform-docs.ts --sdk-json '; +} + +export function canonicalTerraformEndpoint(method: string, endpointPath: string): string { + return `${method.toLowerCase()} ${endpointPath.replaceAll(/\{[^}]+\}/g, '{}')}`; +} + +function terraformTypeLabel(type: TerraformTypeInput): string { + const name = type.type ?? 'unknown'; + if (type.category === 'collection' && type.elementType) return `${name}[${terraformTypeLabel(type.elementType)}]`; + if (type.category === 'dynamic') { + const variants = type.allowedSubtypes ?? []; + return variants.length > 0 ? `Dynamic ${variants.join(' | ')}` : 'Dynamic'; + } + if (type.category === 'nested') + return name === 'SingleNested' ? 'Attributes' : `${name.replace(/Nested$/, '')}[Attributes]`; + return name; +} + +function deprecatedMessage(value: unknown): string | undefined { + if (typeof value === 'string' && value.trim()) return value.trim(); + return value === true ? 'Deprecated.' : undefined; +} + +function resolveAttribute( + declarations: Record, + reference: string, + ancestors: ReadonlySet = new Set(), +): TerraformAttribute { + if (ancestors.has(reference)) throw new Error(`Terraform declaration cycle at ${reference}`); + const declaration = declarations[reference]; + if (!declaration || declaration.kind !== 'TerraformDeclAttribute') { + throw new Error(`Expected ${reference} to be a TerraformDeclAttribute`); + } + const nextAncestors = new Set(ancestors).add(reference); + const children = (declaration.children ?? []).map((child) => resolveAttribute(declarations, child, nextAncestors)); + return { + name: declaration.name, + type: terraformTypeLabel(declaration.type), + ...(typeof declaration.description === 'string' && declaration.description + ? { description: declaration.description } + : {}), + ...(deprecatedMessage(declaration.deprecated) ? { deprecated: deprecatedMessage(declaration.deprecated) } : {}), + ...(declaration.sensitive === true ? { sensitive: true } : {}), + ...(declaration.requiresReplace === true ? { requiresReplace: true } : {}), + ...(children.length > 0 ? { children } : {}), + }; +} + +function terraformResourceNodes( + resources: Record, +): Map { + const nodes = new Map(); + function visit(entries: Record): void { + for (const resource of Object.values(entries)) { + if (resource.stainlessPath) { + nodes.set(resource.stainlessPath.replace(/^\(resource\) /, ''), resource); + } + if (resource.subresources) visit(resource.subresources); + } + } + visit(resources); + return nodes; +} + +function openApiOperations(document: OpenApiInput): Map { + const operations = new Map(); + for (const [endpointPath, pathItem] of Object.entries(document.paths)) { + for (const method of HTTP_METHODS) { + const operation = pathItem[method]; + if (!operation) continue; + const operationId = operation.operationId; + if (typeof operationId !== 'string' || !operationId) continue; + const key = canonicalTerraformEndpoint(method, endpointPath); + if (operations.has(key)) + throw new Error(`OpenAPI endpoint key ${key} is ambiguous after parameter normalization`); + operations.set(key, operationId); + } + } + return operations; +} + +export function extractTerraformDocs(sdkJson: TerraformSdkInput, openapi: OpenApiInput) { + const declarations = sdkJson.decls.terraform; + const snippets = sdkJson.snippets['terraform.default']; + const resources = terraformResourceNodes(sdkJson.resources); + const operations = openApiOperations(openapi); + const outputOperations = new Map(); + const unmatched: Array<{ kind: TerraformDeclarationKind; name: string; endpoint: string }> = []; + let missingSnippets = 0; + + const serviceNodes = Object.entries(declarations) + .filter((entry): entry is [string, TerraformServiceNodeInput] => entry[1].kind === 'TerraformDeclServiceNode') + .sort(([left], [right]) => left.localeCompare(right)); + + for (const [servicePath, serviceNode] of serviceNodes) { + const stainlessResource = servicePath.replace(/^\(resource\) /, ''); + const resource = resources.get(stainlessResource); + if (!resource) throw new Error(`No Terraform SDK resource found for ${servicePath}`); + const methods = resource.methods ?? {}; + + const sources: Array<[TerraformDeclarationKind, unknown]> = [ + ['resource', serviceNode.resource], + ['data-source', serviceNode.dataSource], + ['list-data-source', serviceNode.listDataSource], + ]; + for (const [kind, sourceReferenceValue] of sources) { + if (typeof sourceReferenceValue !== 'string') continue; + const sourceReference = sourceReferenceValue; + const source = declarations[sourceReference]; + if (source?.kind !== 'TerraformDeclSource') { + throw new Error(`Expected ${sourceReference} to be a TerraformDeclSource`); + } + const methodName = source.methodName; + const method = methods[methodName]; + if (!method?.endpoint) { + throw new Error(`Terraform method ${stainlessResource}.${methodName} has no endpoint`); + } + const separator = method.endpoint.indexOf(' '); + if (separator < 1) throw new Error(`Invalid Terraform endpoint ${method.endpoint}`); + const key = canonicalTerraformEndpoint(method.endpoint.slice(0, separator), method.endpoint.slice(separator + 1)); + const operationId = operations.get(key); + if (!operationId) { + unmatched.push({ kind, name: source.name, endpoint: method.endpoint }); + continue; + } + const snippet = snippets[sourceReference]?.default?.content; + if (typeof snippet !== 'string' || !snippet) missingSnippets += 1; + const resolveGroup = (name: TerraformAttributeGroup): TerraformAttribute[] => { + const references = source[name]; + if (!Array.isArray(references)) throw new Error(`Terraform source ${sourceReference}.${name} is not an array`); + return references.map((reference) => resolveAttribute(declarations, String(reference))); + }; + const declaration: TerraformDeclaration = { + kind, + name: source.name, + stainlessResource, + methodName, + ...(typeof snippet === 'string' && snippet ? { snippet } : {}), + required: resolveGroup('required'), + optional: resolveGroup('optional'), + computed: resolveGroup('computed'), + }; + const entry = outputOperations.get(key) ?? { operationId, declarations: [] }; + if (entry.operationId !== operationId) throw new Error(`Conflicting operation IDs for ${key}`); + entry.declarations.push(declaration); + outputOperations.set(key, entry); + } + } + + const orderedOperations = Object.fromEntries( + [...outputOperations] + .sort(([left], [right]) => left.localeCompare(right)) + .map(([key, entry]) => [ + key, + { + operationId: entry.operationId, + declarations: entry.declarations.sort( + (left, right) => left.kind.localeCompare(right.kind) || left.name.localeCompare(right.name), + ), + }, + ]), + ); + const declarationCount = Object.values(orderedOperations).reduce( + (count, operation) => count + operation.declarations.length, + 0, + ); + return { + format: 1, + source: { + terraform: sdkJson.metadata?.terraform ?? {}, + }, + stats: { + operations: Object.keys(orderedOperations).length, + declarations: declarationCount, + missingSnippets, + unmatched: unmatched.length, + }, + unmatched, + operations: orderedOperations, + }; +} + +async function readJson(filePath: string): Promise { + return JSON.parse(await readFile(filePath, 'utf8')) as T; +} + +async function main() { + const { values } = parseArgs({ + args: process.argv.slice(2), + options: { + 'sdk-json': { type: 'string' }, + }, + strict: true, + allowPositionals: false, + }); + const sdkJsonPath = values['sdk-json']; + if (!sdkJsonPath) throw new Error(`Missing --sdk-json\n\n${usage()}`); + const [sdkJson, openapi] = await Promise.all([ + readJson(sdkJsonPath), + loadForgeOpenApi() as Promise, + ]); + const output = extractTerraformDocs(sdkJson, openapi); + await writeFile(OUTPUT_FILE, `${JSON.stringify(output)}\n`, 'utf8'); + const relativeOutput = path.relative(process.cwd(), fileURLToPath(OUTPUT_FILE)); + console.log( + `generate-terraform-docs: wrote ${relativeOutput} (${output.stats.operations} operations, ${output.stats.declarations} declarations, ${output.stats.unmatched} unmatched, ${output.stats.missingSnippets} missing snippets)`, + ); +} + +if (process.argv[1] && import.meta.url === pathToFileURL(process.argv[1]).href) { + main().catch((error) => { + console.error(error instanceof Error ? error.stack : error); + process.exitCode = 1; + }); +} diff --git a/packages/docs-site/src/api-server.ts b/packages/docs-site/src/api-server.ts index 1a42bc238..b3d35459f 100644 --- a/packages/docs-site/src/api-server.ts +++ b/packages/docs-site/src/api-server.ts @@ -18,6 +18,7 @@ import { } from './api-routing.ts'; import { requireAssetFetcher } from './artifact-fetcher.ts'; import { assertToolingRouteNamespace } from './command-reference/routing.ts'; +import { withTerraformTarget } from './terraform.ts'; export type ResolvedApiPage = | ApiProductSelection @@ -55,7 +56,8 @@ async function operationLoadOptions(request: Request, locals: App.Locals): Promi export async function getApiPage(url: URL, request: Request, locals: App.Locals): Promise { const selection: ApiPageSelection | undefined = (await getApiRouter()).resolvePage(url); if (!selection || selection.kind !== 'operation') return selection; - return { ...selection, page: await getFernPage(selection.pageId, await operationLoadOptions(request, locals)) }; + const page = await getFernPage(selection.pageId, await operationLoadOptions(request, locals)); + return { ...selection, page: withTerraformTarget(page) }; } export async function getApiOperation( @@ -67,7 +69,8 @@ export async function getApiOperation( const router = await getApiRouter(); const selection = router.resolveOperation(url, representation); if (!selection) return undefined; - return { ...selection, page: await getFernPage(selection.pageId, await operationLoadOptions(request, locals)) }; + const page = await getFernPage(selection.pageId, await operationLoadOptions(request, locals)); + return { ...selection, page: withTerraformTarget(page) }; } /** Loads one exact operation snapshot for deferred server-island rendering. */ diff --git a/packages/docs-site/src/components/CodeSample.astro b/packages/docs-site/src/components/CodeSample.astro index f74e9abb2..471d84aa7 100644 --- a/packages/docs-site/src/components/CodeSample.astro +++ b/packages/docs-site/src/components/CodeSample.astro @@ -12,6 +12,8 @@ import { type RenderedResponseExampleSchema, } from 'astro-fern/content'; import { LEGACY_API_VERSION } from '../version.ts'; +import type { TerraformOperationData } from '../terraform.ts'; +import { terraformDeclarationLabel } from '../terraform.ts'; import CopyableCode from './CopyableCode.astro'; interface Props { @@ -22,6 +24,7 @@ interface Props { httpMethod: string; examples: OperationExampleSchema[]; responses: RenderedOperationResponseSchema[]; + terraform?: TerraformOperationData; } type AssociatedRequestPart = [string, JsonValueSchema | undefined, string | undefined]; @@ -35,6 +38,7 @@ const { httpMethod, examples, responses, + terraform, } = Astro.props; const current = targets.find((target) => target.id === selectedTarget) ?? targets[0]; const preferredStatus = preferredResponse(responses); @@ -188,8 +192,14 @@ function codeSampleSyntax(sample: OperationCodeSampleSchema): string {
0 || undefined}>
- {httpMethod} - Request + {current.id === 'terraform' ? ( + Terraform + ) : ( + <> + {httpMethod} + Request + + )}
-
- {current.code ? ( +
+ {current.id === 'terraform' ? ( + terraform ? ( +
+ {terraform.declarations.map((declaration) => ( +
+

{terraformDeclarationLabel(declaration)}

+ {declaration.snippet ? ( + + ) : ( +

No generated HCL example is available for this declaration.

+ )} +
+ ))} +
+ ) : ( +

This operation is not implemented in Terraform.

+ ) + ) : current.code ? ( {current.label} samples are coming soon.

)}
- {snapshotId !== LEGACY_API_VERSION && ( + {current.id !== 'terraform' && snapshotId !== LEGACY_API_VERSION && (

Samples are version-neutral. Version selection currently changes documentation only.

@@ -698,6 +729,36 @@ function codeSampleSyntax(sample: OperationCodeSampleSchema): string { background: var(--cf-surface-sunken); } + .forge-terraform-code { + max-height: none; + overflow: hidden; + } + + .forge-terraform-samples :global(.forge-code) { + min-width: 0; + overflow: hidden; + } + + .forge-terraform-samples :global(.forge-code code) { + white-space: pre-wrap; + overflow-wrap: anywhere; + } + + .forge-terraform-sample + .forge-terraform-sample { + border-top: 1px solid var(--cf-border); + } + + .forge-terraform-sample h3 { + margin: 0; + border-bottom: 1px solid var(--cf-border); + padding: 0.625rem 0.75rem; + color: var(--cf-foreground); + background: var(--cf-muted); + font-family: var(--sl-font-mono); + font-size: 0.6875rem; + font-weight: 600; + } + :global(.forge-code) { min-width: max-content; margin: 0; diff --git a/packages/docs-site/src/components/Operation.astro b/packages/docs-site/src/components/Operation.astro index 8694c3625..9cc6eaf2e 100644 --- a/packages/docs-site/src/components/Operation.astro +++ b/packages/docs-site/src/components/Operation.astro @@ -3,9 +3,11 @@ import AnchorHeading from '@astrojs/starlight/components/AnchorHeading.astro'; import { Aside } from '@astrojs/starlight/components'; import type { FernPageSchema } from 'astro-fern'; import { DEFER_THRESHOLD, nodeCount, operationView, responseSummary, topLevelNodes } from '../operation-sections.ts'; +import { getTerraformOperationData } from '../terraform.ts'; import CodeSample from './CodeSample.astro'; import SchemaSectionIsland from './SchemaSectionIsland.astro'; import SchemaTree from './SchemaTree.astro'; +import TerraformDeclarations from './TerraformDeclarations.astro'; interface Props { page: FernPageSchema; @@ -23,6 +25,8 @@ const requestMediaTypes = op.requestBody?.representations.map(({ mediaType }) => const requestContentTypeLabel = requestMediaTypes.length === 1 ? 'Content type' : 'Content types'; const deprecationMessage = op.deprecated ? op.availability?.message : undefined; const availabilityMessage = !op.deprecated ? op.availability?.message : undefined; +const terraform = getTerraformOperationData(op); +const showTerraform = selectedTarget === 'terraform'; ---
@@ -51,21 +55,67 @@ const availabilityMessage = !op.deprecated ? op.availability?.message : undefine {op.description.html ?
: null}
- - -
- { - view.fieldSections.map((section) => ( + { + showTerraform ? ( +
+ {terraform ? ( + terraform.declarations.map((declaration, declarationIndex) => ( +
+
+ +
+ +
+ )) + ) : ( +
+
+ +
+ +
+ )} +
+ ) : ( + <> + + +
+ {view.fieldSections.map((section) => (
{section.title} @@ -117,39 +167,39 @@ const availabilityMessage = !op.deprecated ? op.availability?.message : undefine )}
- )) - } + ))} - { - view.response ? ( -
- Returns - {returnsSummary ?

{returnsSummary}

: null} - {showResponseSchemaSource && view.responseStatus && view.responseRepresentation ? ( -

- Schema shown for {view.responseStatus.status} ·{' '} - {view.responseRepresentation.mediaType} -

+ {view.response ? ( +
+ Returns + {returnsSummary ?

{returnsSummary}

: null} + {showResponseSchemaSource && view.responseStatus && view.responseRepresentation ? ( +

+ Schema shown for {view.responseStatus.status} ·{' '} + {view.responseRepresentation.mediaType} +

+ ) : null} + {nodeCount(responseNodes) > DEFER_THRESHOLD ? ( + +

+ Loading response fields… +

+
+ ) : ( + + )} +
) : null} - {nodeCount(responseNodes) > DEFER_THRESHOLD ? ( - -

- Loading response fields… -

-
- ) : ( - - )} -
- ) : null - } -
+
+ + ) + }
diff --git a/packages/docs-site/src/components/TerraformDeclarations.astro b/packages/docs-site/src/components/TerraformDeclarations.astro new file mode 100644 index 000000000..f202e3cfe --- /dev/null +++ b/packages/docs-site/src/components/TerraformDeclarations.astro @@ -0,0 +1,106 @@ +--- +import AnchorHeading from '@astrojs/starlight/components/AnchorHeading.astro'; +import type { TerraformOperationData } from '../terraform.ts'; +import TerraformFields from './TerraformFields.astro'; + +interface Props { + operation?: TerraformOperationData; + declarationOffset?: number; +} + +const { operation, declarationOffset = 0 } = Astro.props; +const groups = [ + { id: 'required', label: 'Required', fields: 'required' as const }, + { id: 'optional', label: 'Optional', fields: 'optional' as const }, + { id: 'computed', label: 'Computed', fields: 'computed' as const }, +]; + +const declarationKindLabels = { + resource: 'Resource', + 'data-source': 'Data source', + 'list-data-source': 'List data source', +}; +--- + +{ + operation ? ( + operation.declarations.map((declaration, declarationIndex) => ( +
+
+ {declarationKindLabels[declaration.kind]} +

{declaration.name}

+
+ {groups.map((group) => + declaration[group.fields].length > 0 ? ( +
+

{group.label}

+ +
+ ) : null, + )} +
+ )) + ) : ( +
+ + Terraform + +

This operation is not implemented in Terraform.

+
+ ) +} + + diff --git a/packages/docs-site/src/components/TerraformFields.astro b/packages/docs-site/src/components/TerraformFields.astro new file mode 100644 index 000000000..6c65719e1 --- /dev/null +++ b/packages/docs-site/src/components/TerraformFields.astro @@ -0,0 +1,143 @@ +--- +import type { TerraformAttribute } from '../terraform.ts'; +import TerraformFields from './TerraformFields.astro'; + +interface Props { + fields: TerraformAttribute[]; +} + +const { fields } = Astro.props; +--- + +
    + { + fields.map((field) => ( +
  • +
    + {field.name} + {field.type} + {field.requiresReplace ? forces replacement : null} + {field.sensitive ? sensitive : null} + {field.deprecated ? deprecated : null} +
    + {field.description ?

    {field.description}

    : null} + {field.deprecated && field.deprecated !== 'Deprecated.' ? ( +

    {field.deprecated}

    + ) : null} + {field.children?.length ? ( +
    + + Show {field.children.length} {field.children.length === 1 ? 'attribute' : 'attributes'} + + +
    + ) : null} +
  • + )) + } +
+ + diff --git a/packages/docs-site/src/content.config.ts b/packages/docs-site/src/content.config.ts index acef31534..1079c31be 100644 --- a/packages/docs-site/src/content.config.ts +++ b/packages/docs-site/src/content.config.ts @@ -14,6 +14,7 @@ import { import { cfCommandCatalog } from './command-reference/cf-commands.ts'; import { commandCatalogLoader } from './command-reference/loader.ts'; import { loadForgeOpenApi } from './openapi-source.ts'; +import { cloudflareTerraformExtension } from './terraform-extension.ts'; import { cloudflareApiVersionLabel, cloudflareApiVersionSlug, parseCloudflareApiVersion } from './version.ts'; const source = async () => hoistForgeCommands(await loadForgeOpenApi()); @@ -50,6 +51,6 @@ export const collections = { operationRoutingPreference: cloudflareOperationRoutingPreference, isOperationHidden: hasRemovedForgeOperationFields, snippets: cloudflareSnippets, - extensions: [forgeExtension()], + extensions: [forgeExtension(), cloudflareTerraformExtension], } satisfies FernContentOptions), }; diff --git a/packages/docs-site/src/generated/terraform-docs.json b/packages/docs-site/src/generated/terraform-docs.json new file mode 100644 index 000000000..d3b818deb --- /dev/null +++ b/packages/docs-site/src/generated/terraform-docs.json @@ -0,0 +1 @@ +{"format":1,"source":{"terraform":{"repo_url":"https://www.github.com/cloudflare/terraform-provider-cloudflare","code_url":"https://github.com/cloudflare/terraform-provider-cloudflare/tree/main","package_title":"Cloudflare Terraform","version":"0.0.1","install":"cloudflare = { source = \"cloudflare/cloudflare\" }"}},"stats":{"operations":664,"declarations":673,"missingSnippets":4,"unmatched":48},"unmatched":[{"kind":"resource","name":"cloudflare_account_subscription","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/subscriptions"},{"kind":"data-source","name":"cloudflare_account_subscription","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/subscriptions"},{"kind":"resource","name":"cloudflare_custom_csr","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/custom_csrs"},{"kind":"data-source","name":"cloudflare_custom_csr","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_csrs/{custom_csr_id}"},{"kind":"list-data-source","name":"cloudflare_custom_csrs","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_csrs"},{"kind":"resource","name":"cloudflare_custom_pages","endpoint":"put /{accounts_or_zones}/{account_or_zone_id}/custom_pages/{identifier}"},{"kind":"data-source","name":"cloudflare_custom_pages","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/{identifier}"},{"kind":"list-data-source","name":"cloudflare_custom_pages_list","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages"},{"kind":"resource","name":"cloudflare_custom_page_asset","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets"},{"kind":"data-source","name":"cloudflare_custom_page_asset","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets/{asset_name}"},{"kind":"list-data-source","name":"cloudflare_custom_page_assets","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets"},{"kind":"resource","name":"cloudflare_account_dns_settings","endpoint":"patch /accounts/{account_id}/dns_settings"},{"kind":"data-source","name":"cloudflare_account_dns_settings","endpoint":"get /accounts/{account_id}/dns_settings"},{"kind":"resource","name":"cloudflare_zone_dns_settings","endpoint":"patch /zones/{zone_id}/dns_settings"},{"kind":"data-source","name":"cloudflare_zone_dns_settings","endpoint":"get /zones/{zone_id}/dns_settings"},{"kind":"list-data-source","name":"cloudflare_email_routing_rules","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/email/routing/rules"},{"kind":"resource","name":"cloudflare_access_rule","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules"},{"kind":"data-source","name":"cloudflare_access_rule","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules/{rule_id}"},{"kind":"list-data-source","name":"cloudflare_access_rules","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules"},{"kind":"resource","name":"cloudflare_load_balancer","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/load_balancers"},{"kind":"data-source","name":"cloudflare_load_balancer","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/load_balancers/{load_balancer_id}"},{"kind":"list-data-source","name":"cloudflare_load_balancers","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/load_balancers"},{"kind":"data-source","name":"cloudflare_logpush_dataset_field","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/datasets/{dataset_id}/fields"},{"kind":"data-source","name":"cloudflare_logpush_dataset_job","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/datasets/{dataset_id}/jobs"},{"kind":"resource","name":"cloudflare_logpush_job","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs"},{"kind":"data-source","name":"cloudflare_logpush_job","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs/{job_id}"},{"kind":"list-data-source","name":"cloudflare_logpush_jobs","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs"},{"kind":"resource","name":"cloudflare_logpush_ownership_challenge","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/logpush/ownership"},{"kind":"list-data-source","name":"cloudflare_waiting_rooms","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/waiting_rooms"},{"kind":"resource","name":"cloudflare_zero_trust_access_short_lived_certificate","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}/ca"},{"kind":"data-source","name":"cloudflare_zero_trust_access_short_lived_certificate","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}/ca"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_short_lived_certificates","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/apps/ca"},{"kind":"resource","name":"cloudflare_zero_trust_access_mtls_certificate","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/certificates"},{"kind":"data-source","name":"cloudflare_zero_trust_access_mtls_certificate","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/certificates/{certificate_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_mtls_certificates","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/certificates"},{"kind":"resource","name":"cloudflare_zero_trust_access_mtls_hostname_settings","endpoint":"put /{accounts_or_zones}/{account_or_zone_id}/access/certificates/settings"},{"kind":"data-source","name":"cloudflare_zero_trust_access_mtls_hostname_settings","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/certificates/settings"},{"kind":"resource","name":"cloudflare_zero_trust_access_group","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/groups"},{"kind":"data-source","name":"cloudflare_zero_trust_access_group","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/groups/{group_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_groups","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/groups"},{"kind":"resource","name":"cloudflare_zero_trust_access_service_token","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens"},{"kind":"data-source","name":"cloudflare_zero_trust_access_service_token","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens/{service_token_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_service_tokens","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens"},{"kind":"resource","name":"cloudflare_zero_trust_access_identity_provider","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers"},{"kind":"data-source","name":"cloudflare_zero_trust_access_identity_provider","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers/{identity_provider_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_identity_providers","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers"},{"kind":"resource","name":"cloudflare_zero_trust_organization","endpoint":"put /{accounts_or_zones}/{account_or_zone_id}/access/organizations"},{"kind":"data-source","name":"cloudflare_zero_trust_organization","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/organizations"}],"operations":{"get /accounts":{"operationId":"accounts-list-accounts","declarations":[{"kind":"list-data-source","name":"cloudflare_accounts","stainlessResource":"accounts","methodName":"list","snippet":"data \"cloudflare_accounts\" \"example_accounts\" {\n direction = \"desc\"\n name = \"example.com\"\n}\n","required":[],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"name","type":"String","description":"Name of the account."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Account name"},{"name":"type","type":"String"},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the account"},{"name":"managed_by","type":"Attributes","description":"Parent container details","children":[{"name":"parent_org_id","type":"String","description":"ID of the parent Organization, if one exists"},{"name":"parent_org_name","type":"String","description":"Name of the parent Organization, if one exists"}]},{"name":"settings","type":"Attributes","description":"Account settings","children":[{"name":"abuse_contact_email","type":"String","description":"Sets an abuse contact email to notify for abuse reports."},{"name":"enforce_twofactor","type":"Bool","description":"Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled"}]}]}]}]},"get /accounts/{}":{"operationId":"accounts-account-details","declarations":[{"kind":"data-source","name":"cloudflare_account","stainlessResource":"accounts","methodName":"get","snippet":"data \"cloudflare_account\" \"example_account\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[],"optional":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"name","type":"String","description":"Name of the account."}]}],"computed":[{"name":"id","type":"String","description":"Account identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the account"},{"name":"name","type":"String","description":"Account name"},{"name":"type","type":"String"},{"name":"managed_by","type":"Attributes","description":"Parent container details","children":[{"name":"parent_org_id","type":"String","description":"ID of the parent Organization, if one exists"},{"name":"parent_org_name","type":"String","description":"Name of the parent Organization, if one exists"}]},{"name":"settings","type":"Attributes","description":"Account settings","children":[{"name":"abuse_contact_email","type":"String","description":"Sets an abuse contact email to notify for abuse reports."},{"name":"enforce_twofactor","type":"Bool","description":"Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled"}]}]}]},"get /accounts/{}/access/ai-controls/mcp/portals":{"operationId":"mcp-portals-api-list-portals","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_portals","stainlessResource":"zero_trust.access.ai_controls.mcp.portals","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_portals\" \"example_zero_trust_access_ai_controls_mcp_portals\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search by id, name, hostname"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP portal."},{"name":"hostname","type":"String","description":"Hostname where the MCP portal is available."},{"name":"name","type":"String","description":"Display name for the MCP portal."},{"name":"servers","type":"Set[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"server_id","type":"String","description":"Unique identifier for the MCP server."},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"default_disabled","type":"Bool","description":"Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated_tools or updated_prompts."},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"on_behalf","type":"Bool"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"updated_prompts","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]},{"name":"updated_tools","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]}]},{"name":"allow_code_mode","type":"Bool","description":"Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.","deprecated":"Deprecated."},{"name":"code_mode","type":"String","description":"Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP portal."},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound MCP traffic through Zero Trust Secure Web Gateway."}]}]}]},"get /accounts/{}/access/ai-controls/mcp/portals/{}":{"operationId":"mcp-portals-api-fetch-gateways","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_portal","stainlessResource":"zero_trust.access.ai_controls.mcp.portals","methodName":"read","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_portal\" \"example_zero_trust_access_ai_controls_mcp_portal\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-portal\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String","description":"Unique identifier for the MCP portal."},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Search by id, name, hostname"}]}],"computed":[{"name":"allow_code_mode","type":"Bool","description":"Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.","deprecated":"Deprecated."},{"name":"code_mode","type":"String","description":"Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP portal."},{"name":"hostname","type":"String","description":"Hostname where the MCP portal is available."},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"name","type":"String","description":"Display name for the MCP portal."},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound MCP traffic through Zero Trust Secure Web Gateway."},{"name":"servers","type":"Set[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"server_id","type":"String","description":"Unique identifier for the MCP server."},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"default_disabled","type":"Bool","description":"Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated_tools or updated_prompts."},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"on_behalf","type":"Bool"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"updated_prompts","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]},{"name":"updated_tools","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]}]}]}]},"get /accounts/{}/access/ai-controls/mcp/servers":{"operationId":"mcp-portals-api-list-servers","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_servers","stainlessResource":"zero_trust.access.ai_controls.mcp.servers","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_servers\" \"example_zero_trust_access_ai_controls_mcp_servers\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search by id, name"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"updated_prompts","type":"List[Attributes]","description":"Server-wide prompt capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Server-wide tool capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]}]}]}]},"get /accounts/{}/access/ai-controls/mcp/servers/{}":{"operationId":"mcp-portals-api-fetch-servers","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_server","stainlessResource":"zero_trust.access.ai_controls.mcp.servers","methodName":"read","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_server\" \"example_zero_trust_access_ai_controls_mcp_server\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-server\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Search by id, name"}]}],"computed":[{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"updated_prompts","type":"List[Attributes]","description":"Server-wide prompt capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Server-wide tool capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]}]}]},"get /accounts/{}/access/custom_pages":{"operationId":"access-custom-pages-list-custom-pages","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_custom_pages","stainlessResource":"zero_trust.access.custom_pages","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_custom_pages\" \"example_zero_trust_access_custom_pages\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"name","type":"String","description":"Custom page name."},{"name":"type","type":"String","description":"Custom page type."},{"name":"app_count","type":"Int64","description":"Number of apps the custom page is assigned to."},{"name":"contract_version","type":"Int64","description":"Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim."},{"name":"created_at","type":"Time"},{"name":"uid","type":"String","description":"UUID."},{"name":"updated_at","type":"Time"},{"name":"warnings","type":"List[Attributes]","description":"Advisory validation findings returned when creating or updating a template. Omitted when empty.","children":[{"name":"message","type":"String","description":"Human-readable description of the finding."},{"name":"tier","type":"String","description":"The validation tier that produced the finding (e.g. html, liquid)."},{"name":"ref","type":"String","description":"Optional pointer to the part of the template the finding refers to."}]}]}]}]},"get /accounts/{}/access/custom_pages/{}":{"operationId":"access-custom-pages-get-a-custom-page","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_custom_page","stainlessResource":"zero_trust.access.custom_pages","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_custom_page\" \"example_zero_trust_access_custom_page\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_page_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"custom_page_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"app_count","type":"Int64","description":"Number of apps the custom page is assigned to."},{"name":"contract_version","type":"Int64","description":"Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim."},{"name":"created_at","type":"Time"},{"name":"custom_html","type":"String","description":"Custom page HTML."},{"name":"name","type":"String","description":"Custom page name."},{"name":"type","type":"String","description":"Custom page type."},{"name":"uid","type":"String","description":"UUID."},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/access/keys":{"operationId":"access-key-configuration-get-the-access-key-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_key_configuration","stainlessResource":"zero_trust.access.keys","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_key_configuration\" \"example_zero_trust_access_key_configuration\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"days_until_next_rotation","type":"Float64","description":"The number of days until the next key rotation."},{"name":"key_rotation_interval_days","type":"Float64","description":"The number of days between key rotations."},{"name":"last_key_rotation_at","type":"Time","description":"The timestamp of the previous key rotation."}]}]},"get /accounts/{}/access/policies":{"operationId":"access-policies-list-access-reusable-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_policies","stainlessResource":"zero_trust.access.policies","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_policies\" \"example_zero_trust_access_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The UUID of the policy"},{"name":"account_id","type":"String","description":"Identifier."},{"name":"app_count","type":"Int64","description":"Number of access applications currently using this policy."},{"name":"approval_groups","type":"Set[Attributes]","description":"Administrators who can approve a temporary authentication request.","children":[{"name":"approvals_needed","type":"Float64","description":"The number of approvals needed to obtain access."},{"name":"email_addresses","type":"List[String]","description":"A list of emails that can approve the access request."},{"name":"email_list_uuid","type":"String","description":"The UUID of an re-usable email list."}]},{"name":"approval_required","type":"Bool","description":"Requires the user to request access from an administrator at the start of each session."},{"name":"connection_rules","type":"Attributes","description":"The rules that define how users may connect to targets secured by your application.","children":[{"name":"rdp","type":"Attributes","description":"The RDP-specific rules that define clipboard behavior for RDP connections.","children":[{"name":"allowed_clipboard_local_to_remote_formats","type":"List[String]","description":"Clipboard formats allowed when copying from local machine to remote RDP session."},{"name":"allowed_clipboard_remote_to_local_formats","type":"List[String]","description":"Clipboard formats allowed when copying from remote RDP session to local machine."}]}]},{"name":"created_at","type":"Time"},{"name":"decision","type":"String","description":"The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action."},{"name":"exclude","type":"Set[Attributes]","description":"Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"include","type":"Set[Attributes]","description":"Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"isolation_required","type":"Bool","description":"Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature."},{"name":"mfa_config","type":"Attributes","description":"Configures multi-factor authentication (MFA) settings.","children":[{"name":"allowed_authenticators","type":"List[String]","description":"Lists the MFA methods that users can authenticate with."},{"name":"mfa_disabled","type":"Bool","description":"Indicates whether to disable MFA for this resource. This option is available at the application and policy level."},{"name":"session_duration","type":"String","description":"Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`."}]},{"name":"name","type":"String","description":"The name of the Access policy."},{"name":"purpose_justification_prompt","type":"String","description":"A custom message that will appear on the purpose justification screen."},{"name":"purpose_justification_required","type":"Bool","description":"Require users to enter a justification when they log in to the application."},{"name":"require","type":"Set[Attributes]","description":"Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"reusable","type":"Bool"},{"name":"session_duration","type":"String","description":"The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h."},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/access/policies/{}":{"operationId":"access-policies-get-an-access-reusable-policy","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_policy","stainlessResource":"zero_trust.access.policies","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_policy\" \"example_zero_trust_access_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"policy_id","type":"String","description":"The UUID of the policy"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The UUID of the policy"},{"name":"app_count","type":"Int64","description":"Number of access applications currently using this policy."},{"name":"approval_required","type":"Bool","description":"Requires the user to request access from an administrator at the start of each session."},{"name":"created_at","type":"Time"},{"name":"decision","type":"String","description":"The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action."},{"name":"isolation_required","type":"Bool","description":"Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature."},{"name":"name","type":"String","description":"The name of the Access policy."},{"name":"purpose_justification_prompt","type":"String","description":"A custom message that will appear on the purpose justification screen."},{"name":"purpose_justification_required","type":"Bool","description":"Require users to enter a justification when they log in to the application."},{"name":"reusable","type":"Bool"},{"name":"session_duration","type":"String","description":"The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h."},{"name":"updated_at","type":"Time"},{"name":"approval_groups","type":"Set[Attributes]","description":"Administrators who can approve a temporary authentication request.","children":[{"name":"approvals_needed","type":"Float64","description":"The number of approvals needed to obtain access."},{"name":"email_addresses","type":"List[String]","description":"A list of emails that can approve the access request."},{"name":"email_list_uuid","type":"String","description":"The UUID of an re-usable email list."}]},{"name":"connection_rules","type":"Attributes","description":"The rules that define how users may connect to targets secured by your application.","children":[{"name":"rdp","type":"Attributes","description":"The RDP-specific rules that define clipboard behavior for RDP connections.","children":[{"name":"allowed_clipboard_local_to_remote_formats","type":"List[String]","description":"Clipboard formats allowed when copying from local machine to remote RDP session."},{"name":"allowed_clipboard_remote_to_local_formats","type":"List[String]","description":"Clipboard formats allowed when copying from remote RDP session to local machine."}]}]},{"name":"exclude","type":"Set[Attributes]","description":"Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"include","type":"Set[Attributes]","description":"Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"mfa_config","type":"Attributes","description":"Configures multi-factor authentication (MFA) settings.","children":[{"name":"allowed_authenticators","type":"List[String]","description":"Lists the MFA methods that users can authenticate with."},{"name":"mfa_disabled","type":"Bool","description":"Indicates whether to disable MFA for this resource. This option is available at the application and policy level."},{"name":"session_duration","type":"String","description":"Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`."}]},{"name":"require","type":"Set[Attributes]","description":"Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]}]}]},"get /accounts/{}/access/tags":{"operationId":"access-tags-list-tags","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_tags","stainlessResource":"zero_trust.access.tags","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_tags\" \"example_zero_trust_access_tags\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The name of the tag"},{"name":"name","type":"String","description":"The name of the tag"},{"name":"app_count","type":"Int64","description":"The number of applications that have this tag"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/access/tags/{}":{"operationId":"access-tags-get-a-tag","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_tag","stainlessResource":"zero_trust.access.tags","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_tag\" \"example_zero_trust_access_tag\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tag_name = \"engineers\"\n}\n","required":[{"name":"tag_name","type":"String","description":"The name of the tag"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The name of the tag"},{"name":"app_count","type":"Int64","description":"The number of applications that have this tag"},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"The name of the tag"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/addressing/address_maps":{"operationId":"ip-address-management-address-maps-list-address-maps","declarations":[{"kind":"list-data-source","name":"cloudflare_address_maps","stainlessResource":"addressing.address_maps","methodName":"list","snippet":"data \"cloudflare_address_maps\" \"example_address_maps\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of an Address Map."},{"name":"can_delete","type":"Bool","description":"If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps."},{"name":"can_modify_ips","type":"Bool","description":"If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps."},{"name":"created_at","type":"Time"},{"name":"default_sni","type":"String","description":"If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account."},{"name":"description","type":"String","description":"An optional description field which may be used to describe the types of IPs or zones on the map."},{"name":"enabled","type":"Bool","description":"Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled."},{"name":"modified_at","type":"Time"}]}]}]},"get /accounts/{}/addressing/address_maps/{}":{"operationId":"ip-address-management-address-maps-address-map-details","declarations":[{"kind":"data-source","name":"cloudflare_address_map","stainlessResource":"addressing.address_maps","methodName":"get","snippet":"data \"cloudflare_address_map\" \"example_address_map\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n address_map_id = \"055817b111884e0227e1be16a0be6ee0\"\n}\n","required":[{"name":"address_map_id","type":"String","description":"Identifier of an Address Map."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of an Address Map."},{"name":"can_delete","type":"Bool","description":"If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps."},{"name":"can_modify_ips","type":"Bool","description":"If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps."},{"name":"created_at","type":"Time"},{"name":"default_sni","type":"String","description":"If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account."},{"name":"description","type":"String","description":"An optional description field which may be used to describe the types of IPs or zones on the map."},{"name":"enabled","type":"Bool","description":"Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled."},{"name":"modified_at","type":"Time"},{"name":"ips","type":"List[Attributes]","description":"The set of IPs on the Address Map.","children":[{"name":"created_at","type":"Time"},{"name":"ip","type":"String","description":"An IPv4 or IPv6 address."}]},{"name":"memberships","type":"List[Attributes]","description":"Zones and Accounts which will be assigned IPs on this Address Map. A zone membership will take priority over an account membership.","children":[{"name":"can_delete","type":"Bool","description":"Controls whether the membership can be deleted via the API or not."},{"name":"created_at","type":"Time"},{"name":"identifier","type":"String","description":"The identifier for the membership (eg. a zone or account tag)."},{"name":"kind","type":"String","description":"The type of the membership."}]}]}]},"get /accounts/{}/addressing/prefixes":{"operationId":"ip-address-management-prefixes-list-prefixes","declarations":[{"kind":"list-data-source","name":"cloudflare_byo_ip_prefixes","stainlessResource":"addressing.prefixes","methodName":"list","snippet":"data \"cloudflare_byo_ip_prefixes\" \"example_byo_ip_prefixes\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of an IP Prefix."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."},{"name":"advertised","type":"Bool","description":"Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"advertised_modified_at","type":"Time","description":"Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"approved","type":"String","description":"Approval state of the prefix (P = pending, V = active)."},{"name":"asn","type":"Int64","description":"Autonomous System Number (ASN) the prefix will be advertised under."},{"name":"cidr","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"created_at","type":"Time"},{"name":"delegate_loa_creation","type":"Bool","description":"Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner."},{"name":"description","type":"String","description":"Description of the prefix."},{"name":"irr_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"loa_document_id","type":"String","description":"Identifier for the uploaded LOA document."},{"name":"modified_at","type":"Time"},{"name":"on_demand_enabled","type":"Bool","description":"Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"on_demand_locked","type":"Bool","description":"Whether advertisement status of the prefix is locked, meaning it cannot be changed.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"ownership_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"ownership_validation_token","type":"String","description":"Token provided to demonstrate ownership of the prefix."},{"name":"rpki_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."}]}]}]},"get /accounts/{}/addressing/prefixes/{}":{"operationId":"ip-address-management-prefixes-prefix-details","declarations":[{"kind":"data-source","name":"cloudflare_byo_ip_prefix","stainlessResource":"addressing.prefixes","methodName":"get","snippet":"data \"cloudflare_byo_ip_prefix\" \"example_byo_ip_prefix\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n prefix_id = \"2af39739cc4e3b5910c918468bb89828\"\n}\n","required":[{"name":"prefix_id","type":"String","description":"Identifier of an IP Prefix."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of an IP Prefix."},{"name":"advertised","type":"Bool","description":"Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"advertised_modified_at","type":"Time","description":"Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"approved","type":"String","description":"Approval state of the prefix (P = pending, V = active)."},{"name":"asn","type":"Int64","description":"Autonomous System Number (ASN) the prefix will be advertised under."},{"name":"cidr","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"created_at","type":"Time"},{"name":"delegate_loa_creation","type":"Bool","description":"Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner."},{"name":"description","type":"String","description":"Description of the prefix."},{"name":"irr_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"loa_document_id","type":"String","description":"Identifier for the uploaded LOA document."},{"name":"modified_at","type":"Time"},{"name":"on_demand_enabled","type":"Bool","description":"Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"on_demand_locked","type":"Bool","description":"Whether advertisement status of the prefix is locked, meaning it cannot be changed.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"ownership_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"ownership_validation_token","type":"String","description":"Token provided to demonstrate ownership of the prefix."},{"name":"rpki_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."}]}]},"get /accounts/{}/ai-gateway/gateways":{"operationId":"aig-config-list-gateway","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_gateways","stainlessResource":"ai_gateway","methodName":"list","snippet":"data \"cloudflare_ai_gateways\" \"example_ai_gateways\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search by id"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier of the AI Gateway within the account."},{"name":"cache_invalidate_on_update","type":"Bool"},{"name":"cache_ttl","type":"Int64"},{"name":"collect_logs","type":"Bool"},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"rate_limiting_interval","type":"Int64"},{"name":"rate_limiting_limit","type":"Int64"},{"name":"authentication","type":"Bool"},{"name":"byok_only","type":"Bool","description":"Requires customer-provided provider credentials and prevents fallback to Unified Billing."},{"name":"dlp","type":"Attributes","children":[{"name":"action","type":"String"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"},{"name":"policies","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"action","type":"String"},{"name":"check","type":"List[String]"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"}]}]},{"name":"guardrails","type":"Attributes","children":[{"name":"prompt","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]},{"name":"response","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]}]},{"name":"is_default","type":"Bool"},{"name":"log_classification","type":"Bool"},{"name":"log_management","type":"Int64"},{"name":"log_management_strategy","type":"String"},{"name":"logpush","type":"Bool"},{"name":"logpush_public_key","type":"String"},{"name":"otel","type":"List[Attributes]","children":[{"name":"headers","type":"Map[String]"},{"name":"url","type":"String"},{"name":"authorization","type":"String"},{"name":"content_type","type":"String"}]},{"name":"rate_limiting_technique","type":"String"},{"name":"retry_backoff","type":"String","description":"Backoff strategy for retry delays"},{"name":"retry_delay","type":"Int64","description":"Delay between retry attempts in milliseconds (0-60000)"},{"name":"retry_max_attempts","type":"Int64","description":"Maximum number of retry attempts for failed requests (1-5)"},{"name":"spend_limits","type":"Attributes","children":[{"name":"enabled","type":"Bool"},{"name":"rules","type":"List[Attributes]","children":[{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Int64"},{"name":"id","type":"String"},{"name":"enabled","type":"Bool"},{"name":"metadata","type":"Map[Attributes]","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"model","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"ai_gateway_provider","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"technique","type":"String"}]}]},{"name":"store_id","type":"String"},{"name":"stripe","type":"Attributes","children":[{"name":"authorization","type":"String"},{"name":"usage_events","type":"List[Attributes]","children":[{"name":"payload","type":"String"}]}]},{"name":"workers_ai_billing_mode","type":"String","description":"Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway."},{"name":"zdr","type":"Bool"}]}]}]},"get /accounts/{}/ai-gateway/gateways/{}":{"operationId":"aig-config-fetch-gateway","declarations":[{"kind":"data-source","name":"cloudflare_ai_gateway","stainlessResource":"ai_gateway","methodName":"get","snippet":"data \"cloudflare_ai_gateway\" \"example_ai_gateway\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n id = \"my-gateway\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String","description":"Unique identifier of the AI Gateway within the account."},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Search by id"}]}],"computed":[{"name":"authentication","type":"Bool"},{"name":"byok_only","type":"Bool","description":"Requires customer-provided provider credentials and prevents fallback to Unified Billing."},{"name":"cache_invalidate_on_update","type":"Bool"},{"name":"cache_ttl","type":"Int64"},{"name":"collect_logs","type":"Bool"},{"name":"created_at","type":"Time"},{"name":"is_default","type":"Bool"},{"name":"log_classification","type":"Bool"},{"name":"log_management","type":"Int64"},{"name":"log_management_strategy","type":"String"},{"name":"logpush","type":"Bool"},{"name":"logpush_public_key","type":"String"},{"name":"modified_at","type":"Time"},{"name":"rate_limiting_interval","type":"Int64"},{"name":"rate_limiting_limit","type":"Int64"},{"name":"rate_limiting_technique","type":"String"},{"name":"retry_backoff","type":"String","description":"Backoff strategy for retry delays"},{"name":"retry_delay","type":"Int64","description":"Delay between retry attempts in milliseconds (0-60000)"},{"name":"retry_max_attempts","type":"Int64","description":"Maximum number of retry attempts for failed requests (1-5)"},{"name":"store_id","type":"String"},{"name":"workers_ai_billing_mode","type":"String","description":"Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway."},{"name":"zdr","type":"Bool"},{"name":"dlp","type":"Attributes","children":[{"name":"action","type":"String"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"},{"name":"policies","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"action","type":"String"},{"name":"check","type":"List[String]"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"}]}]},{"name":"guardrails","type":"Attributes","children":[{"name":"prompt","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]},{"name":"response","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]}]},{"name":"otel","type":"List[Attributes]","children":[{"name":"headers","type":"Map[String]"},{"name":"url","type":"String"},{"name":"authorization","type":"String"},{"name":"content_type","type":"String"}]},{"name":"spend_limits","type":"Attributes","children":[{"name":"enabled","type":"Bool"},{"name":"rules","type":"List[Attributes]","children":[{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Int64"},{"name":"id","type":"String"},{"name":"enabled","type":"Bool"},{"name":"metadata","type":"Map[Attributes]","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"model","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"ai_gateway_provider","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"technique","type":"String"}]}]},{"name":"stripe","type":"Attributes","children":[{"name":"authorization","type":"String"},{"name":"usage_events","type":"List[Attributes]","children":[{"name":"payload","type":"String"}]}]}]}]},"get /accounts/{}/ai-gateway/gateways/{}/routes/{}":{"operationId":"aig-config-get-gateway-dynamic-route","declarations":[{"kind":"data-source","name":"cloudflare_ai_gateway_dynamic_routing","stainlessResource":"ai_gateway.dynamic_routing","methodName":"get","snippet":"data \"cloudflare_ai_gateway_dynamic_routing\" \"example_ai_gateway_dynamic_routing\" {\n account_id = \"0d37909e38d3e99c29fa2cd343ac421a\"\n gateway_id = \"54442216\"\n id = \"54442216\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"gateway_id","type":"String"},{"name":"id","type":"String"}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String"},{"name":"deployment","type":"Attributes","children":[{"name":"created_at","type":"String"},{"name":"deployment_id","type":"String"},{"name":"version_id","type":"String"}]},{"name":"elements","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"outputs","type":"Attributes","children":[{"name":"next","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"false","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"true","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"element_id","type":"String"},{"name":"fallback","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"success","type":"Attributes","children":[{"name":"element_id","type":"String"}]}]},{"name":"type","type":"String"},{"name":"properties","type":"Attributes","children":[{"name":"conditions","type":"unknown"},{"name":"key","type":"String"},{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Float64"},{"name":"model","type":"String"},{"name":"ai_gateway_dynamic_routing_provider","type":"String"},{"name":"retries","type":"Float64"},{"name":"timeout","type":"Float64"}]}]},{"name":"version","type":"Attributes","children":[{"name":"active","type":"String"},{"name":"created_at","type":"String"},{"name":"data","type":"String"},{"name":"version_id","type":"String"},{"name":"is_valid","type":"Bool"}]}]}]},"get /accounts/{}/ai-search/instances":{"operationId":"ai-search-list-instances","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_search_instances","stainlessResource":"ai_search.instances","methodName":"list","snippet":"data \"cloudflare_ai_search_instances\" \"example_ai_search_instances\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n hostname = \"x\"\n namespace = \"namespace\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"hostname","type":"String","description":"Filter by exact Search for Agents hostname (case-insensitive)."},{"name":"namespace","type":"String","description":"Filter by namespace."},{"name":"search","type":"String","description":"Filter instances whose id contains this string (case-insensitive)."},{"name":"order_by","type":"String","description":"Field to order results by."},{"name":"order_by_direction","type":"String","description":"Order direction."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"ai_gateway_id","type":"String"},{"name":"aisearch_model","type":"String"},{"name":"cache","type":"Bool"},{"name":"cache_threshold","type":"String"},{"name":"cache_ttl","type":"Float64"},{"name":"chunk","type":"Bool"},{"name":"chunk_overlap","type":"Float64"},{"name":"chunk_size","type":"Float64"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"custom_metadata","type":"List[Attributes]","children":[{"name":"data_type","type":"String"},{"name":"field_name","type":"String"}]},{"name":"embedding_model","type":"String"},{"name":"enable","type":"Bool"},{"name":"engine_version","type":"Float64"},{"name":"fusion_method","type":"String"},{"name":"hybrid_search_enabled","type":"Bool"},{"name":"index_method","type":"Attributes","children":[{"name":"keyword","type":"Bool"},{"name":"vector","type":"Bool"}]},{"name":"indexing_options","type":"Attributes","children":[{"name":"keyword_tokenizer","type":"String"},{"name":"use_ocr","type":"Bool"}]},{"name":"last_activity","type":"Time"},{"name":"max_num_results","type":"Float64"},{"name":"metadata","type":"Attributes","children":[{"name":"created_from_aisearch_wizard","type":"Bool"},{"name":"worker_domain","type":"String"}]},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"namespace","type":"String"},{"name":"paused","type":"Bool"},{"name":"public_endpoint_id","type":"String"},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool"}]},{"name":"custom_domains","type":"List[String]"},{"name":"default_domain_enabled","type":"Bool"},{"name":"enabled","type":"Bool"},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool"}]}]},{"name":"reranking","type":"Bool"},{"name":"reranking_model","type":"String"},{"name":"retrieval_options","type":"Attributes","children":[{"name":"boost_by","type":"List[Attributes]","children":[{"name":"field","type":"String"},{"name":"data_type","type":"String"},{"name":"direction","type":"String"}]},{"name":"keyword_match_mode","type":"String"}]},{"name":"rewrite_model","type":"String"},{"name":"rewrite_query","type":"Bool"},{"name":"score_threshold","type":"Float64"},{"name":"source","type":"String"},{"name":"source_params","type":"Attributes","children":[{"name":"exclude_items","type":"List[String]"},{"name":"include_items","type":"List[String]"},{"name":"prefix","type":"String"},{"name":"r2_jurisdiction","type":"String"},{"name":"web_crawler","type":"Attributes","children":[{"name":"discover_options","type":"Attributes","children":[{"name":"depth","type":"Float64"},{"name":"include_external_links","type":"Bool"},{"name":"include_subdomains","type":"Bool"},{"name":"limit","type":"Float64","description":"Maximum number of pages to crawl. New values are capped at 100000; instances configured before that cap may report a higher stored value, which the crawler clamps at run time."},{"name":"max_age","type":"Float64"},{"name":"source","type":"String"}]},{"name":"parse_options","type":"Attributes","children":[{"name":"content_selector","type":"List[Attributes]","children":[{"name":"path","type":"String"},{"name":"selector","type":"String"}]},{"name":"include_headers","type":"Map[String]"},{"name":"include_images","type":"Bool"},{"name":"specific_sitemaps","type":"List[String]"},{"name":"use_browser_rendering","type":"Bool"}]},{"name":"parse_type","type":"String"}]}]},{"name":"status","type":"String"},{"name":"summarization","type":"Bool"},{"name":"summarization_model","type":"String"},{"name":"sync_interval","type":"Float64"},{"name":"system_prompt_aisearch","type":"String"},{"name":"system_prompt_index_summarization","type":"String"},{"name":"system_prompt_rewrite_query","type":"String"},{"name":"token_id","type":"String"},{"name":"type","type":"String"}]}]}]},"get /accounts/{}/ai-search/instances/{}":{"operationId":"ai-search-fetch-instance","declarations":[{"kind":"data-source","name":"cloudflare_ai_search_instance","stainlessResource":"ai_search.instances","methodName":"read","snippet":"data \"cloudflare_ai_search_instance\" \"example_ai_search_instance\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n id = \"my-ai-search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"hostname","type":"String","description":"Filter by exact Search for Agents hostname (case-insensitive)."},{"name":"namespace","type":"String","description":"Filter by namespace."},{"name":"order_by","type":"String","description":"Field to order results by."},{"name":"order_by_direction","type":"String","description":"Order direction."},{"name":"search","type":"String","description":"Filter instances whose id contains this string (case-insensitive)."}]}],"computed":[{"name":"ai_gateway_id","type":"String"},{"name":"aisearch_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"cache","type":"Bool"},{"name":"cache_threshold","type":"String"},{"name":"cache_ttl","type":"Float64","description":"Cache entry TTL in seconds. Allowed values: 600 (10min), 1800 (30min), 3600 (1h), 7200 (2h), 21600 (6h), 43200 (12h), 86400 (24h), 172800 (48h), 259200 (72h), 518400 (6d)."},{"name":"chunk_overlap","type":"Int64"},{"name":"chunk_size","type":"Int64"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"embedding_model","type":"String"},{"name":"enable","type":"Bool"},{"name":"engine_version","type":"Float64"},{"name":"fusion_method","type":"String"},{"name":"hybrid_search_enabled","type":"Bool","description":"Deprecated — use index_method instead. Defaults to true for new instances; set false to create a vector-only instance.","deprecated":"Deprecated."},{"name":"last_activity","type":"Time"},{"name":"max_num_results","type":"Int64"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"namespace","type":"String"},{"name":"paused","type":"Bool"},{"name":"public_endpoint_id","type":"String"},{"name":"reranking","type":"Bool"},{"name":"reranking_model","type":"String"},{"name":"rewrite_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"rewrite_query","type":"Bool"},{"name":"score_threshold","type":"Float64"},{"name":"source","type":"String"},{"name":"status","type":"String"},{"name":"sync_interval","type":"Float64","description":"Interval between automatic syncs, in seconds. Allowed values: 900 (15min), 1800 (30min), 3600 (1h), 7200 (2h), 14400 (4h), 21600 (6h), 43200 (12h), 86400 (24h)."},{"name":"token_id","type":"String"},{"name":"type","type":"String","description":"Source type. When omitted or null with a non-blank source, HTTP(S) URLs infer web-crawler and existing R2 bucket names infer r2. A missing or blank source without a type uses managed upload-only storage."},{"name":"custom_metadata","type":"List[Attributes]","children":[{"name":"data_type","type":"String"},{"name":"field_name","type":"String"}]},{"name":"index_method","type":"Attributes","description":"Controls which storage backends are used during indexing. Defaults to vector and keyword indexing for new instances.","children":[{"name":"keyword","type":"Bool","description":"Enable keyword (BM25) storage backend."},{"name":"vector","type":"Bool","description":"Enable vector (embedding) storage backend."}]},{"name":"indexing_options","type":"Attributes","children":[{"name":"keyword_tokenizer","type":"String","description":"Tokenizer used for keyword search indexing. porter provides word-level tokenization with Porter stemming (good for natural language queries). trigram enables character-level substring matching (good for partial matches, code, identifiers). Changing this triggers a full re-index. Defaults to porter."},{"name":"use_ocr","type":"Bool","description":"Enables OCR ingestion for PDFs and images. Changing this triggers a full re-index. Defaults to false."}]},{"name":"metadata","type":"Attributes","children":[{"name":"created_from_aisearch_wizard","type":"Bool"},{"name":"worker_domain","type":"String"}]},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]},{"name":"retrieval_options","type":"Attributes","children":[{"name":"boost_by","type":"List[Attributes]","description":"Metadata fields to boost search results by. Each entry specifies a metadata field and an optional direction. Direction defaults to 'asc' for numeric/datetime fields and 'exists' for text/boolean fields. Fields must match 'timestamp' or a defined custom_metadata field.","children":[{"name":"field","type":"String","description":"Metadata field name to boost by. Use 'timestamp' for document freshness, or any custom_metadata field. Numeric and datetime fields support all four directions (asc, desc, exists, not_exists); text/boolean fields only support exists/not_exists."},{"name":"direction","type":"String","description":"Boost direction. 'desc' = higher values rank higher (e.g. newer timestamps). 'asc' = lower values rank higher. 'exists' = boost chunks that have the field. 'not_exists' = boost chunks that lack the field. Optional — defaults to 'asc' for numeric/datetime fields, 'exists' for text/boolean fields."}]},{"name":"keyword_match_mode","type":"String","description":"Controls which documents are candidates for BM25 scoring. 'and' restricts candidates to documents containing all query terms; 'or' includes any document containing at least one term, ranked by BM25 relevance. When omitted on an update, the existing stored value is preserved; when never set, search falls back to 'and'."}]},{"name":"source_params","type":"Attributes","children":[{"name":"exclude_items","type":"List[String]","description":"List of path patterns to exclude. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /admin/** matches /admin/users and /admin/settings/advanced). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"include_items","type":"List[String]","description":"List of path patterns to include. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /blog/** matches /blog/post and /blog/2024/post). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"prefix","type":"String"},{"name":"r2_jurisdiction","type":"String"},{"name":"web_crawler","type":"Attributes","children":[{"name":"discover_options","type":"Attributes","description":"Options for parse_type 'discover', where Browser Run discovers URLs by link following and sitemaps. Ignored for 'sitemap'.","children":[{"name":"depth","type":"Float64","description":"Maximum link-follow depth from the seed URL."},{"name":"include_external_links","type":"Bool","description":"Follow links that point outside the source domain. Must stay `false` — discover crawls are restricted to the zone you own."},{"name":"include_subdomains","type":"Bool","description":"Follow links to subdomains of the source host."},{"name":"limit","type":"Float64","description":"Maximum number of pages to crawl (1-100000)."},{"name":"max_age","type":"Float64","description":"Maximum content age in seconds to accept (0–604800)."},{"name":"source","type":"String","description":"Where the crawler looks for URLs: 'sitemaps' reads sitemap XML only, 'links' follows page links only, 'all' does both."}]},{"name":"parse_options","type":"Attributes","children":[{"name":"content_selector","type":"List[Attributes]","description":"List of path-to-selector mappings for extracting specific content from crawled pages. Each entry pairs a URL glob pattern with a CSS selector. The first matching path wins. Only the matched HTML fragment is stored and indexed. Omit the field to disable content selection — empty arrays are rejected.","children":[{"name":"path","type":"String","description":"Glob pattern to match against the page URL path. Uses standard glob syntax: * matches within a segment, ** crosses directories."},{"name":"selector","type":"String","description":"CSS selector to extract content from pages matching the path pattern. Must not contain disallowed characters (;, `, $, {, }, \\). Must target a single element; if multiple elements match, the selector is ignored and the full page is used."}]},{"name":"include_headers","type":"Map[String]","description":"Up to 5 custom HTTP headers sent with each crawl request. Names must be RFC-7230 token characters (no spaces, colons, or control characters); values must be HTAB + printable ASCII (no CR/LF)."},{"name":"include_images","type":"Bool"},{"name":"specific_sitemaps","type":"List[String]","description":"List of specific sitemap URLs to use for crawling. Only valid when parse_type is 'sitemap'."},{"name":"use_browser_rendering","type":"Bool"}]},{"name":"parse_type","type":"String","description":"How URLs are discovered. 'sitemap' reads XML sitemaps; 'discover' follows links recursively and requires the source to be a Verified zone on this account."}]}]}]}]},"get /accounts/{}/ai-search/namespaces":{"operationId":"ai-search-list-namespaces","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_search_namespaces","stainlessResource":"ai_search.namespaces","methodName":"list","snippet":"data \"cloudflare_ai_search_namespaces\" \"example_ai_search_namespaces\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n search = \"prod\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Filter namespaces whose name or description contains this string (case-insensitive)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"description","type":"String","description":"Optional description for the namespace. Max 256 characters."},{"name":"public_endpoint_id","type":"String"},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"instances_allowed","type":"List[String]","description":"Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit."},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]}]}]}]},"get /accounts/{}/ai-search/namespaces/{}":{"operationId":"ai-search-fetch-namespace","declarations":[{"kind":"data-source","name":"cloudflare_ai_search_namespace","stainlessResource":"ai_search.namespaces","methodName":"read","snippet":"data \"cloudflare_ai_search_namespace\" \"example_ai_search_namespace\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n name = \"production\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"name","type":"String"}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Optional description for the namespace. Max 256 characters."},{"name":"public_endpoint_id","type":"String"},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"instances_allowed","type":"List[String]","description":"Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit."},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]}]}]},"get /accounts/{}/ai-search/tokens":{"operationId":"ai-search-list-tokens","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_search_tokens","stainlessResource":"ai_search.tokens","methodName":"list","snippet":"data \"cloudflare_ai_search_tokens\" \"example_ai_search_tokens\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n search = \"my-token\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Filter tokens whose name contains this string (case-insensitive)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"cf_api_id","type":"String"},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String"},{"name":"created_by","type":"String"},{"name":"enabled","type":"Bool"},{"name":"legacy","type":"Bool"},{"name":"modified_by","type":"String"}]}]}]},"get /accounts/{}/ai-search/tokens/{}":{"operationId":"ai-search-fetch-tokens","declarations":[{"kind":"data-source","name":"cloudflare_ai_search_token","stainlessResource":"ai_search.tokens","methodName":"read","snippet":"data \"cloudflare_ai_search_token\" \"example_ai_search_token\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n id = \"62af0db3-c410-40b2-9ee3-0e93f6dd1de0\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Filter tokens whose name contains this string (case-insensitive)."}]}],"computed":[{"name":"cf_api_id","type":"String"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"enabled","type":"Bool"},{"name":"legacy","type":"Bool"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"name","type":"String"}]}]},"get /accounts/{}/alerting/v3/destinations/webhooks":{"operationId":"notification-webhooks-list-webhooks","declarations":[{"kind":"list-data-source","name":"cloudflare_notification_policy_webhooks_list","stainlessResource":"alerting.destinations.webhooks","methodName":"list","snippet":"data \"cloudflare_notification_policy_webhooks_list\" \"example_notification_policy_webhooks_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account id"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of a webhook"},{"name":"created_at","type":"Time","description":"Timestamp of when the webhook destination was created."},{"name":"last_failure","type":"Time","description":"Timestamp of the last time an attempt to dispatch a notification to this webhook failed."},{"name":"last_success","type":"Time","description":"Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook."},{"name":"name","type":"String","description":"The name of the webhook destination. This will be included in the request body when you receive a webhook notification."},{"name":"secret","type":"String","description":"Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.","sensitive":true},{"name":"type","type":"String","description":"Type of webhook endpoint."},{"name":"url","type":"String","description":"The POST endpoint to call when dispatching a notification."}]}]}]},"get /accounts/{}/alerting/v3/destinations/webhooks/{}":{"operationId":"notification-webhooks-get-a-webhook","declarations":[{"kind":"data-source","name":"cloudflare_notification_policy_webhooks","stainlessResource":"alerting.destinations.webhooks","methodName":"get","snippet":"data \"cloudflare_notification_policy_webhooks\" \"example_notification_policy_webhooks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n webhook_id = \"b115d5ec15c641ee8b7692c449b5227b\"\n}\n","required":[{"name":"webhook_id","type":"String","description":"The unique identifier of a webhook"},{"name":"account_id","type":"String","description":"The account id"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique identifier of a webhook"},{"name":"created_at","type":"Time","description":"Timestamp of when the webhook destination was created."},{"name":"last_failure","type":"Time","description":"Timestamp of the last time an attempt to dispatch a notification to this webhook failed."},{"name":"last_success","type":"Time","description":"Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook."},{"name":"name","type":"String","description":"The name of the webhook destination. This will be included in the request body when you receive a webhook notification."},{"name":"secret","type":"String","description":"Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.","sensitive":true},{"name":"type","type":"String","description":"Type of webhook endpoint."},{"name":"url","type":"String","description":"The POST endpoint to call when dispatching a notification."}]}]},"get /accounts/{}/alerting/v3/policies":{"operationId":"notification-policies-list-notification-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_notification_policies","stainlessResource":"alerting.policies","methodName":"list","snippet":"data \"cloudflare_notification_policies\" \"example_notification_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account id"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of a notification policy"},{"name":"alert_interval","type":"String","description":"Optional specification of how often to re-alert from the same incident, not support on all alert types."},{"name":"alert_type","type":"String","description":"Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values."},{"name":"created","type":"Time"},{"name":"description","type":"String","description":"Optional description for the Notification policy."},{"name":"enabled","type":"Bool","description":"Whether or not the Notification policy is enabled."},{"name":"filters","type":"Attributes","description":"Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.","children":[{"name":"actions","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"affected_asns","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"affected_components","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"affected_locations","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"airport_code","type":"List[String]","description":"Used for configuring maintenance_event_notification"},{"name":"alert_trigger_preferences","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"alert_trigger_preferences_value","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"enabled","type":"List[String]","description":"Used for configuring load_balancing_pool_enablement_alert"},{"name":"environment","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event_source","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"event_type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"group_by","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"health_check_id","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"incident_impact","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"input_id","type":"List[String]","description":"Used for configuring stream_live_notifications"},{"name":"insight_class","type":"List[String]","description":"Used for configuring security_insights_alert"},{"name":"limit","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"logo_tag","type":"List[String]","description":"Used for configuring logo_match_alert"},{"name":"megabits_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"new_health","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"new_status","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"packets_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"pool_id","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"pop_names","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"product","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"project_id","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"protocol","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"query_tag","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"requests_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"selectors","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"services","type":"List[String]","description":"Used for configuring clickhouse_alert_fw_ent_anomaly"},{"name":"slo","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"status","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"target_hostname","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"target_ip","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"target_zone_name","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"token_id","type":"List[String]","description":"Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens."},{"name":"traffic_exclusions","type":"List[String]","description":"Used for configuring traffic_anomalies_alert"},{"name":"tunnel_id","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"tunnel_name","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"where","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"zones","type":"List[String]","description":"Usage depends on specific alert type"}]},{"name":"mechanisms","type":"Attributes","description":"List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.","children":[{"name":"email","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The email address"}]},{"name":"pagerduty","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]},{"name":"webhooks","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]}]},{"name":"modified","type":"Time"},{"name":"name","type":"String","description":"Name of the policy."}]}]}]},"get /accounts/{}/alerting/v3/policies/{}":{"operationId":"notification-policies-get-a-notification-policy","declarations":[{"kind":"data-source","name":"cloudflare_notification_policy","stainlessResource":"alerting.policies","methodName":"get","snippet":"data \"cloudflare_notification_policy\" \"example_notification_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"0da2b59ef118439d8097bdfb215203c9\"\n}\n","required":[{"name":"policy_id","type":"String","description":"The unique identifier of a notification policy"},{"name":"account_id","type":"String","description":"The account id"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique identifier of a notification policy"},{"name":"alert_interval","type":"String","description":"Optional specification of how often to re-alert from the same incident, not support on all alert types."},{"name":"alert_type","type":"String","description":"Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values."},{"name":"created","type":"Time"},{"name":"description","type":"String","description":"Optional description for the Notification policy."},{"name":"enabled","type":"Bool","description":"Whether or not the Notification policy is enabled."},{"name":"modified","type":"Time"},{"name":"name","type":"String","description":"Name of the policy."},{"name":"filters","type":"Attributes","description":"Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.","children":[{"name":"actions","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"affected_asns","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"affected_components","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"affected_locations","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"airport_code","type":"List[String]","description":"Used for configuring maintenance_event_notification"},{"name":"alert_trigger_preferences","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"alert_trigger_preferences_value","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"enabled","type":"List[String]","description":"Used for configuring load_balancing_pool_enablement_alert"},{"name":"environment","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event_source","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"event_type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"group_by","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"health_check_id","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"incident_impact","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"input_id","type":"List[String]","description":"Used for configuring stream_live_notifications"},{"name":"insight_class","type":"List[String]","description":"Used for configuring security_insights_alert"},{"name":"limit","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"logo_tag","type":"List[String]","description":"Used for configuring logo_match_alert"},{"name":"megabits_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"new_health","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"new_status","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"packets_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"pool_id","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"pop_names","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"product","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"project_id","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"protocol","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"query_tag","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"requests_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"selectors","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"services","type":"List[String]","description":"Used for configuring clickhouse_alert_fw_ent_anomaly"},{"name":"slo","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"status","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"target_hostname","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"target_ip","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"target_zone_name","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"token_id","type":"List[String]","description":"Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens."},{"name":"traffic_exclusions","type":"List[String]","description":"Used for configuring traffic_anomalies_alert"},{"name":"tunnel_id","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"tunnel_name","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"where","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"zones","type":"List[String]","description":"Usage depends on specific alert type"}]},{"name":"mechanisms","type":"Attributes","description":"List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.","children":[{"name":"email","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The email address"}]},{"name":"pagerduty","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]},{"name":"webhooks","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]}]}]}]},"get /accounts/{}/botnet_feed/configs/asn":{"operationId":"botnet-threat-feed-list-asn","declarations":[{"kind":"data-source","name":"cloudflare_botnet_feed_config_asn","stainlessResource":"botnet_feed.configs.asn","methodName":"get","snippet":"data \"cloudflare_botnet_feed_config_asn\" \"example_botnet_feed_config_asn\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"asn","type":"Int64"}]}]},"get /accounts/{}/calls/apps":{"operationId":"calls-apps-list","declarations":[{"kind":"list-data-source","name":"cloudflare_calls_sfu_apps","stainlessResource":"calls.sfu","methodName":"list","snippet":"data \"cloudflare_calls_sfu_apps\" \"example_calls_sfu_apps\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]}]},"get /accounts/{}/calls/apps/{}":{"operationId":"calls-apps-retrieve-app-details","declarations":[{"kind":"data-source","name":"cloudflare_calls_sfu_app","stainlessResource":"calls.sfu","methodName":"get","snippet":"data \"cloudflare_calls_sfu_app\" \"example_calls_sfu_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n app_id = \"2a95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"app_id","type":"String","description":"A Cloudflare-generated unique identifier for a item."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"get /accounts/{}/calls/turn_keys":{"operationId":"calls-turn-key-list","declarations":[{"kind":"list-data-source","name":"cloudflare_calls_turn_apps","stainlessResource":"calls.turn","methodName":"list","snippet":"data \"cloudflare_calls_turn_apps\" \"example_calls_turn_apps\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]}]},"get /accounts/{}/calls/turn_keys/{}":{"operationId":"calls-retrieve-turn-key-details","declarations":[{"kind":"data-source","name":"cloudflare_calls_turn_app","stainlessResource":"calls.turn","methodName":"get","snippet":"data \"cloudflare_calls_turn_app\" \"example_calls_turn_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n key_id = \"2a95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"key_id","type":"String","description":"A Cloudflare-generated unique identifier for a item."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"get /accounts/{}/cfd_tunnel":{"operationId":"cloudflare-tunnel-list-cloudflare-tunnels","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_cloudflareds","stainlessResource":"zero_trust.tunnels.cloudflared","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflareds\" \"example_zero_trust_tunnel_cloudflareds\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n exclude_prefix = \"vpc1-\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n include_prefix = \"vpc1-\"\n is_deleted = true\n name = \"blog\"\n status = \"healthy\"\n uuid = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n was_active_at = \"2009-11-10T23:00:00Z\"\n was_inactive_at = \"2009-11-10T23:00:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"config_src","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"remote_config","type":"Bool","description":"If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.","deprecated":"Use the config_src field instead."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."}]}]}]},"get /accounts/{}/cfd_tunnel/{}":{"operationId":"cloudflare-tunnel-get-a-cloudflare-tunnel","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared","stainlessResource":"zero_trust.tunnels.cloudflared","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared\" \"example_zero_trust_tunnel_cloudflared\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"filter","type":"Attributes","children":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"config_src","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard."},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"remote_config","type":"Bool","description":"If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.","deprecated":"Use the config_src field instead."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"get /accounts/{}/cfd_tunnel/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-get-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_config","stainlessResource":"zero_trust.tunnels.cloudflared.configurations","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_config\" \"example_zero_trust_tunnel_cloudflared_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"source","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel's configuration on the Zero Trust dashboard."},{"name":"version","type":"Int64","description":"The version of the Tunnel Configuration."},{"name":"config","type":"Attributes","description":"The tunnel configuration and ingress rules.","children":[{"name":"ingress","type":"List[Attributes]","description":"List of public hostname definitions. At least one ingress rule needs to be defined for the tunnel.","children":[{"name":"hostname","type":"String","description":"Public hostname for this service."},{"name":"service","type":"String","description":"Protocol and address of destination server. Supported protocols: http://, https://, unix://, tcp://, ssh://, rdp://, unix+tls://, smb://. Alternatively can return a HTTP status code http_status:[code] e.g. 'http_status:404'.\n"},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"path","type":"String","description":"Requests with this path route to this public hostname."}]},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"warp_routing","type":"Attributes","description":"Enable private network access from WARP users to private network routes. This is enabled if the tunnel has an assigned route.","deprecated":"This field is ignored by cloudflared since version 2023.10.0.","children":[{"name":"enabled","type":"Bool"}]}]}]}]},"get /accounts/{}/cfd_tunnel/{}/token":{"operationId":"cloudflare-tunnel-get-a-cloudflare-tunnel-token","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_token","stainlessResource":"zero_trust.tunnels.cloudflared.token","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_token\" \"example_zero_trust_tunnel_cloudflared_token\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"token","type":"String","description":"The Tunnel Token is used as a mechanism to authenticate the operation of a tunnel.","sensitive":true}]}]},"get /accounts/{}/challenges/widgets":{"operationId":"accounts-turnstile-widgets-list","declarations":[{"kind":"list-data-source","name":"cloudflare_turnstile_widgets","stainlessResource":"turnstile.widgets","methodName":"list","snippet":"data \"cloudflare_turnstile_widgets\" \"example_turnstile_widgets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n filter = \"name:my-widget\"\n order = \"id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"Direction to order widgets."},{"name":"filter","type":"String","description":"Filter widgets by field. The `name` field uses case-insensitive\nsubstring matching; `sitekey` uses exact matching.\nFormat: `field:value`\n\nSupported fields:\n- `name` - Filter by widget name (e.g., `filter=name:login-form`)\n- `sitekey` - Filter by sitekey (e.g., `filter=sitekey:0x4AAA`)\n\nReturns 400 Bad Request if the field is unsupported or format is invalid.\nAn empty filter value returns all results.\n"},{"name":"order","type":"String","description":"Field to order widgets by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"bot_fight_mode","type":"Bool","description":"If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only).\n"},{"name":"clearance_level","type":"String","description":"If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\n"},{"name":"created_on","type":"Time","description":"When the widget was created."},{"name":"domains","type":"List[String]"},{"name":"ephemeral_id","type":"Bool","description":"Return the Ephemeral ID in /siteverify (ENT only).\n"},{"name":"mode","type":"String","description":"Widget Mode"},{"name":"modified_on","type":"Time","description":"When the widget was modified."},{"name":"name","type":"String","description":"Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used.\n"},{"name":"offlabel","type":"Bool","description":"Do not show any Cloudflare branding on the widget (ENT only).\n"},{"name":"region","type":"String","description":"Region where this widget can be used. This cannot be changed after creation.\n"},{"name":"sitekey","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"deployed_via","type":"String","description":"Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\n"},{"name":"last_modified_via","type":"String","description":"Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\n"}]}]}]},"get /accounts/{}/challenges/widgets/{}":{"operationId":"accounts-turnstile-widget-get","declarations":[{"kind":"data-source","name":"cloudflare_turnstile_widget","stainlessResource":"turnstile.widgets","methodName":"get","snippet":"data \"cloudflare_turnstile_widget\" \"example_turnstile_widget\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n sitekey = \"0x4AAF00AAAABn0R22HWm-YUc\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"sitekey","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order widgets."},{"name":"filter","type":"String","description":"Filter widgets by field. The `name` field uses case-insensitive\nsubstring matching; `sitekey` uses exact matching.\nFormat: `field:value`\n\nSupported fields:\n- `name` - Filter by widget name (e.g., `filter=name:login-form`)\n- `sitekey` - Filter by sitekey (e.g., `filter=sitekey:0x4AAA`)\n\nReturns 400 Bad Request if the field is unsupported or format is invalid.\nAn empty filter value returns all results.\n"},{"name":"order","type":"String","description":"Field to order widgets by."}]}],"computed":[{"name":"id","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"bot_fight_mode","type":"Bool","description":"If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only).\n"},{"name":"clearance_level","type":"String","description":"If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\n"},{"name":"created_on","type":"Time","description":"When the widget was created."},{"name":"deployed_via","type":"String","description":"Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\n"},{"name":"ephemeral_id","type":"Bool","description":"Return the Ephemeral ID in /siteverify (ENT only).\n"},{"name":"last_modified_via","type":"String","description":"Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\n"},{"name":"mode","type":"String","description":"Widget Mode"},{"name":"modified_on","type":"Time","description":"When the widget was modified."},{"name":"name","type":"String","description":"Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used.\n"},{"name":"offlabel","type":"Bool","description":"Do not show any Cloudflare branding on the widget (ENT only).\n"},{"name":"region","type":"String","description":"Region where this widget can be used. This cannot be changed after creation.\n"},{"name":"secret","type":"String","description":"Secret key for this widget.","sensitive":true},{"name":"domains","type":"List[String]"}]}]},"get /accounts/{}/cloudforce-one/requests/{}":{"operationId":"cloudforce-one-request-get","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request","stainlessResource":"cloudforce_one.requests","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request\" \"example_cloudforce_one_request\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"request_id","type":"String","description":"UUID."},{"name":"filter","type":"Attributes","children":[{"name":"page","type":"Int64","description":"Page number of results."},{"name":"per_page","type":"Int64","description":"Number of results per page."},{"name":"completed_after","type":"Time","description":"Retrieve requests completed after this time."},{"name":"completed_before","type":"Time","description":"Retrieve requests completed before this time."},{"name":"created_after","type":"Time","description":"Retrieve requests created after this time."},{"name":"created_before","type":"Time","description":"Retrieve requests created before this time."},{"name":"request_type","type":"String","description":"Requested information from request."},{"name":"sort_by","type":"String","description":"Field to sort results by."},{"name":"sort_order","type":"String","description":"Sort order (asc or desc)."},{"name":"status","type":"String","description":"Request Status."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"content","type":"String","description":"Request content."},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"priority","type":"Time"},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"get /accounts/{}/cloudforce-one/requests/{}/asset/{}":{"operationId":"cloudforce-one-request-asset-get","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request_asset","stainlessResource":"cloudforce_one.requests.assets","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request_asset\" \"example_cloudforce_one_request_asset\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n asset_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"asset_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"request_id","type":"String","description":"UUID."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created","type":"Time","description":"Defines the asset creation time."},{"name":"description","type":"String","description":"Asset description."},{"name":"file_type","type":"String","description":"Asset file type."},{"name":"name","type":"String","description":"Asset name."}]}]},"get /accounts/{}/cloudforce-one/requests/priority/{}":{"operationId":"cloudforce-one-priority-get","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request_priority","stainlessResource":"cloudforce_one.requests.priority","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request_priority\" \"example_cloudforce_one_request_priority\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n priority_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"priority_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"content","type":"String","description":"Request content."},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"priority","type":"Time"},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"get /accounts/{}/connectivity/directory/services":{"operationId":"connectivity-services-list","declarations":[{"kind":"list-data-source","name":"cloudflare_connectivity_directory_services","stainlessResource":"connectivity.directory.services","methodName":"list","snippet":"data \"cloudflare_connectivity_directory_services\" \"example_connectivity_directory_services\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n type = \"tcp\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier"}],"optional":[{"name":"type","type":"String"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"host","type":"Attributes","children":[{"name":"ipv4","type":"String"},{"name":"network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"}]},{"name":"ipv6","type":"String"},{"name":"hostname","type":"String"},{"name":"resolver_network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"},{"name":"resolver_ips","type":"List[String]"}]}]},{"name":"name","type":"String"},{"name":"type","type":"String"},{"name":"created_at","type":"Time"},{"name":"http_port","type":"Int64"},{"name":"https_port","type":"Int64"},{"name":"service_id","type":"String"},{"name":"tls_settings","type":"Attributes","description":"TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.","children":[{"name":"cert_verification_mode","type":"String","description":"TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all"}]},{"name":"updated_at","type":"Time"},{"name":"app_protocol","type":"String"},{"name":"tcp_port","type":"Int64"}]}]}]},"get /accounts/{}/connectivity/directory/services/{}":{"operationId":"connectivity-services-get","declarations":[{"kind":"data-source","name":"cloudflare_connectivity_directory_service","stainlessResource":"connectivity.directory.services","methodName":"get","snippet":"data \"cloudflare_connectivity_directory_service\" \"example_connectivity_directory_service\" {\n account_id = \"account_id\"\n service_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"service_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"type","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"app_protocol","type":"String"},{"name":"created_at","type":"Time"},{"name":"http_port","type":"Int64"},{"name":"https_port","type":"Int64"},{"name":"name","type":"String"},{"name":"tcp_port","type":"Int64"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"host","type":"Attributes","children":[{"name":"ipv4","type":"String"},{"name":"network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"}]},{"name":"ipv6","type":"String"},{"name":"hostname","type":"String"},{"name":"resolver_network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"},{"name":"resolver_ips","type":"List[String]"}]}]},{"name":"tls_settings","type":"Attributes","description":"TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.","children":[{"name":"cert_verification_mode","type":"String","description":"TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all"}]}]}]},"get /accounts/{}/d1/database":{"operationId":"d1-list-databases","declarations":[{"kind":"list-data-source","name":"cloudflare_d1_databases","stainlessResource":"d1.database","methodName":"list","snippet":"data \"cloudflare_d1_databases\" \"example_d1_databases\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"name\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"name","type":"String","description":"a database name to search for."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"D1 database identifier (UUID)."},{"name":"created_at","type":"Time","description":"Specifies the timestamp the resource was created as an ISO8601 string."},{"name":"jurisdiction","type":"String","description":"Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored."},{"name":"name","type":"String","description":"D1 database name."},{"name":"uuid","type":"String","description":"D1 database identifier (UUID)."},{"name":"version","type":"String"}]}]}]},"get /accounts/{}/d1/database/{}":{"operationId":"d1-get-database","declarations":[{"kind":"data-source","name":"cloudflare_d1_database","stainlessResource":"d1.database","methodName":"get","snippet":"data \"cloudflare_d1_database\" \"example_d1_database\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n database_id = \"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx\"\n fields = [\"uuid\"]\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"database_id","type":"String","description":"D1 database identifier (UUID)."},{"name":"fields","type":"List[String]","description":"Comma-separated list of fields to include in the response. When omitted,\nall fields are returned.\n"},{"name":"filter","type":"Attributes","children":[{"name":"name","type":"String","description":"a database name to search for."}]}],"computed":[{"name":"id","type":"String","description":"D1 database identifier (UUID)."},{"name":"created_at","type":"Time","description":"Specifies the timestamp the resource was created as an ISO8601 string."},{"name":"file_size","type":"Float64","description":"The D1 database's size, in bytes."},{"name":"jurisdiction","type":"String","description":"Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored."},{"name":"name","type":"String","description":"D1 database name."},{"name":"num_tables","type":"Float64","description":"The number of tables in the D1 database. This count is no longer accurate and should not be relied upon.","deprecated":"Deprecated."},{"name":"uuid","type":"String","description":"D1 database identifier (UUID)."},{"name":"version","type":"String"},{"name":"read_replication","type":"Attributes","description":"Configuration for D1 read replication.","children":[{"name":"mode","type":"String","description":"The read replication mode for the database. Mode 'auto' denotes that D1 creates replicas and automatically places them around the world. Mode 'disabled' denotes that no database replicas are used."}]}]}]},"get /accounts/{}/data-security/posture/policies":{"operationId":"ListPolicies","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_casb_policies","stainlessResource":"zero_trust.casb.posture.policies","methodName":"list","snippet":"data \"cloudflare_zero_trust_casb_policies\" \"example_zero_trust_casb_policies\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the policy configuration."},{"name":"actions","type":"Attributes","description":"The actions configured for this policy.","children":[{"name":"remediation_types","type":"List[Attributes]","description":"List of remediation types that will be executed.","children":[{"name":"display_name","type":"String","description":"Display name/label of the remediation type."},{"name":"remediation_type","type":"String","description":"The system name of the remediation type."},{"name":"remediation_type_id","type":"String","description":"Unique identifier for the remediation type."}]},{"name":"webhook_configs","type":"List[Attributes]","description":"List of webhook configurations that will be triggered.","children":[{"name":"display_name","type":"String","description":"Display name/label of the webhook configuration."},{"name":"webhook_config_id","type":"String","description":"Unique identifier for the webhook configuration."}]}]},{"name":"applies_to_all_integrations","type":"Bool","description":"When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids."},{"name":"created_at","type":"Time","description":"Timestamp when the policy was created."},{"name":"description","type":"String","description":"User-set description of what this policy does. Limited to 1000 characters."},{"name":"display_name","type":"String","description":"Display name for the policy configuration. Limited to 255 characters."},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset)."},{"name":"finding_type_id","type":"String","description":"The finding type this policy is associated with. Immutable after creation; changing it replaces the policy."},{"name":"integration_ids","type":"List[String]","description":"The integrations this policy applies to."},{"name":"updated_at","type":"Time","description":"Timestamp when the policy was last updated."},{"name":"disabled_at","type":"Time","description":"Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled."},{"name":"last_triggered_at","type":"Time","description":"Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints."}]}]}]},"get /accounts/{}/data-security/posture/policies/{}":{"operationId":"GetPolicyByID","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_casb_policy","stainlessResource":"zero_trust.casb.posture.policies","methodName":"get","snippet":"data \"cloudflare_zero_trust_casb_policy\" \"example_zero_trust_casb_policy\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n policy_id = \"497f6eca-6276-4993-bfeb-53cbbbba6f08\"\n}\n","required":[{"name":"policy_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"applies_to_all_integrations","type":"Bool","description":"When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids."},{"name":"created_at","type":"Time","description":"Timestamp when the policy was created."},{"name":"description","type":"String","description":"User-set description of what this policy does. Limited to 1000 characters."},{"name":"disabled_at","type":"Time","description":"Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled."},{"name":"display_name","type":"String","description":"Display name for the policy configuration. Limited to 255 characters."},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset)."},{"name":"finding_type_id","type":"String","description":"The finding type this policy is associated with. Immutable after creation; changing it replaces the policy."},{"name":"last_triggered_at","type":"Time","description":"Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints."},{"name":"updated_at","type":"Time","description":"Timestamp when the policy was last updated."},{"name":"integration_ids","type":"List[String]","description":"The integrations this policy applies to."},{"name":"actions","type":"Attributes","description":"The actions configured for this policy.","children":[{"name":"remediation_types","type":"List[Attributes]","description":"List of remediation types that will be executed.","children":[{"name":"display_name","type":"String","description":"Display name/label of the remediation type."},{"name":"remediation_type","type":"String","description":"The system name of the remediation type."},{"name":"remediation_type_id","type":"String","description":"Unique identifier for the remediation type."}]},{"name":"webhook_configs","type":"List[Attributes]","description":"List of webhook configurations that will be triggered.","children":[{"name":"display_name","type":"String","description":"Display name/label of the webhook configuration."},{"name":"webhook_config_id","type":"String","description":"Unique identifier for the webhook configuration."}]}]}]}]},"get /accounts/{}/data-security/posture/webhooks":{"operationId":"ListWebhooks","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_casb_webhooks","stainlessResource":"zero_trust.casb.posture.webhooks","methodName":"list","snippet":"data \"cloudflare_zero_trust_casb_webhooks\" \"example_zero_trust_casb_webhooks\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the specific webhook configuration."},{"name":"authentication_type","type":"String","description":"Type of authentication used for the webhook."},{"name":"created_at","type":"Time","description":"Timestamp when the webhook configuration was created."},{"name":"destination_url","type":"String","description":"Target URL for the webhook configuration. Where resulting data will be sent."},{"name":"label","type":"String","description":"Account-specified display label for the webhook configuration."},{"name":"status","type":"String","description":"Current status of the webhook configuration. If disabled, data cannot be sent through this configuration."},{"name":"updated_at","type":"Time","description":"Timestamp when the webhook configuration was last updated."},{"name":"version","type":"Int64","description":"Version number of the configuration."},{"name":"headers","type":"List[Attributes]","description":"List of header keys configured for this webhook. Values are not included for security reasons.","children":[{"name":"key","type":"String","description":"Header key name (lowercase)."},{"name":"value","type":"String","description":"Header value. This field is never returned in API responses for security reasons.","sensitive":true}]}]}]}]},"get /accounts/{}/data-security/posture/webhooks/{}":{"operationId":"GetWebhookConfigByID","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_casb_webhook","stainlessResource":"zero_trust.casb.posture.webhooks","methodName":"get","snippet":"data \"cloudflare_zero_trust_casb_webhook\" \"example_zero_trust_casb_webhook\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n webhook_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"webhook_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"authentication_type","type":"String","description":"Type of authentication used for the webhook."},{"name":"created_at","type":"Time","description":"Timestamp when the webhook configuration was created."},{"name":"destination_url","type":"String","description":"Target URL for the webhook configuration. Where resulting data will be sent."},{"name":"label","type":"String","description":"Account-specified display label for the webhook configuration."},{"name":"status","type":"String","description":"Current status of the webhook configuration. If disabled, data cannot be sent through this configuration."},{"name":"updated_at","type":"Time","description":"Timestamp when the webhook configuration was last updated."},{"name":"version","type":"Int64","description":"Version number of the configuration."},{"name":"headers","type":"List[Attributes]","description":"List of header keys configured for this webhook. Values are not included for security reasons.","children":[{"name":"key","type":"String","description":"Header key name (lowercase)."},{"name":"value","type":"String","description":"Header value. This field is never returned in API responses for security reasons.","sensitive":true}]}]}]},"get /accounts/{}/devices/deployment-groups":{"operationId":"list-deployment-groups","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_deployment_groups_list","stainlessResource":"zero_trust.devices.deployment_groups","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_deployment_groups_list\" \"example_zero_trust_device_deployment_groups_list\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the deployment group."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was created."},{"name":"name","type":"String","description":"A user-friendly name for the deployment group."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was last updated."},{"name":"version_config","type":"List[Attributes]","description":"Contains version configurations for different target environments.","children":[{"name":"target_environment","type":"String","description":"The target environment for the client version (e.g., windows, macos)."},{"name":"version","type":"String","description":"The specific client version to deploy."}]},{"name":"policy_ids","type":"List[String]","description":"Contains a list of policy IDs assigned to this deployment group."}]}]}]},"get /accounts/{}/devices/deployment-groups/{}":{"operationId":"get-deployment-group","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_deployment_groups","stainlessResource":"zero_trust.devices.deployment_groups","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_deployment_groups\" \"example_zero_trust_device_deployment_groups\" {\n account_id = \"account_id\"\n group_id = \"group_id\"\n}\n","required":[{"name":"group_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was created."},{"name":"name","type":"String","description":"A user-friendly name for the deployment group."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was last updated."},{"name":"policy_ids","type":"List[String]","description":"Contains a list of policy IDs assigned to this deployment group."},{"name":"version_config","type":"List[Attributes]","description":"Contains version configurations for different target environments.","children":[{"name":"target_environment","type":"String","description":"The target environment for the client version (e.g., windows, macos)."},{"name":"version","type":"String","description":"The specific client version to deploy."}]}]}]},"get /accounts/{}/devices/ip-profiles":{"operationId":"list-ip-profiles","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_ip_profiles","stainlessResource":"zero_trust.devices.ip_profiles","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_ip_profiles\" \"example_zero_trust_device_ip_profiles\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the Device IP profile."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was created."},{"name":"description","type":"String","description":"An optional description of the Device IP profile."},{"name":"enabled","type":"Bool","description":"Whether the Device IP profile is enabled."},{"name":"match","type":"String","description":"The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"."},{"name":"name","type":"String","description":"A user-friendly name for the Device IP profile."},{"name":"precedence","type":"Int64","description":"The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field."},{"name":"subnet_id","type":"String","description":"The ID of the Subnet."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was last updated."}]}]}]},"get /accounts/{}/devices/ip-profiles/{}":{"operationId":"get-ip-profile","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_ip_profile","stainlessResource":"zero_trust.devices.ip_profiles","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_ip_profile\" \"example_zero_trust_device_ip_profile\" {\n account_id = \"account_id\"\n profile_id = \"profile_id\"\n}\n","required":[{"name":"profile_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was created."},{"name":"description","type":"String","description":"An optional description of the Device IP profile."},{"name":"enabled","type":"Bool","description":"Whether the Device IP profile is enabled."},{"name":"match","type":"String","description":"The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"."},{"name":"name","type":"String","description":"A user-friendly name for the Device IP profile."},{"name":"precedence","type":"Int64","description":"The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field."},{"name":"subnet_id","type":"String","description":"The ID of the Subnet."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was last updated."}]}]},"get /accounts/{}/devices/networks":{"operationId":"device-managed-networks-list-device-managed-networks","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_managed_networks_list","stainlessResource":"zero_trust.devices.networks","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_managed_networks_list\" \"example_zero_trust_device_managed_networks_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"API UUID."},{"name":"config","type":"Attributes","description":"The configuration object containing information for the WARP client to detect the managed network.","children":[{"name":"tls_sockaddr","type":"String","description":"A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host."},{"name":"sha256","type":"String","description":"The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate."}]},{"name":"name","type":"String","description":"The name of the device managed network. This name must be unique."},{"name":"network_id","type":"String","description":"API UUID."},{"name":"type","type":"String","description":"The type of device managed network."}]}]}]},"get /accounts/{}/devices/networks/{}":{"operationId":"device-managed-networks-device-managed-network-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_managed_networks","stainlessResource":"zero_trust.devices.networks","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_managed_networks\" \"example_zero_trust_device_managed_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n network_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"network_id","type":"String","description":"API UUID."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"name","type":"String","description":"The name of the device managed network. This name must be unique."},{"name":"type","type":"String","description":"The type of device managed network."},{"name":"config","type":"Attributes","description":"The configuration object containing information for the WARP client to detect the managed network.","children":[{"name":"tls_sockaddr","type":"String","description":"A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host."},{"name":"sha256","type":"String","description":"The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate."}]}]}]},"get /accounts/{}/devices/policies":{"operationId":"devices-list-device-settings-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_custom_profiles","stainlessResource":"zero_trust.devices.policies.custom","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_custom_profiles\" \"example_zero_trust_device_custom_profiles\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"profile_type","type":"String","description":"Filter profiles by client type. When omitted, only WARP profiles are returned."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"browser_extension_config","type":"Attributes","description":"Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.","children":[{"name":"proxy_control","type":"String","description":"Whether the user may disable the browser extension proxy."},{"name":"proxy_enabled","type":"Bool","description":"Whether the browser extension proxy is active."}]},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy is the account default. WARP group profiles cannot set this field."},{"name":"description","type":"String","description":"A description of the policy."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"gateway_unique_id","type":"String"},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"match","type":"String","description":"The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"."},{"name":"name","type":"String","description":"The name of the device settings profile."},{"name":"policy_id","type":"String"},{"name":"precedence","type":"Float64","description":"The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field."},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"target_tests","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The id of the DEX test targeting this policy."},{"name":"name","type":"String","description":"The name of the DEX test targeting this policy."}]},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]}]}]}]},"get /accounts/{}/devices/policy":{"operationId":"devices-get-default-device-settings-policy","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_default_profile","stainlessResource":"zero_trust.devices.policies.default","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_default_profile\" \"example_zero_trust_device_default_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"gateway_unique_id","type":"String"},{"name":"policy_id","type":"String"},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]}]}]},"get /accounts/{}/devices/policy/{}":{"operationId":"devices-get-device-settings-policy-by-id","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_custom_profile","stainlessResource":"zero_trust.devices.policies.custom","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_custom_profile\" \"example_zero_trust_device_custom_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"policy_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"profile_type","type":"String","description":"Filter profiles by client type. When omitted, only WARP profiles are returned."}]}],"computed":[{"name":"id","type":"String"},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy is the account default. WARP group profiles cannot set this field."},{"name":"description","type":"String","description":"A description of the policy."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"gateway_unique_id","type":"String"},{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"match","type":"String","description":"The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"."},{"name":"name","type":"String","description":"The name of the device settings profile."},{"name":"precedence","type":"Float64","description":"The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field."},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"browser_extension_config","type":"Attributes","description":"Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.","children":[{"name":"proxy_control","type":"String","description":"Whether the user may disable the browser extension proxy."},{"name":"proxy_enabled","type":"Bool","description":"Whether the browser extension proxy is active."}]},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]},{"name":"target_tests","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The id of the DEX test targeting this policy."},{"name":"name","type":"String","description":"The name of the DEX test targeting this policy."}]},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]}]}]},"get /accounts/{}/devices/policy/{}/fallback_domains":{"operationId":"devices-get-local-domain-fallback-list-for-a-device-settings-policy","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_custom_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.custom.fallback_domains","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_custom_profile_local_domain_fallback\" \"example_zero_trust_device_custom_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"policy_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}]},"get /accounts/{}/devices/policy/fallback_domains":{"operationId":"devices-get-local-domain-fallback-list","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_default_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.default.fallback_domains","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_default_profile_local_domain_fallback\" \"example_zero_trust_device_default_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}]},"get /accounts/{}/devices/posture":{"operationId":"device-posture-rules-list-device-posture-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_posture_rules","stainlessResource":"zero_trust.devices.posture","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_posture_rules\" \"example_zero_trust_device_posture_rules\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"API UUID."},{"name":"description","type":"String","description":"The description of the device posture rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise."},{"name":"expiration","type":"String","description":"Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client."},{"name":"input","type":"Attributes","description":"The value to be checked against.","children":[{"name":"operating_system","type":"String","description":"Operating system."},{"name":"path","type":"String","description":"File path."},{"name":"exists","type":"Bool","description":"Whether or not file exists."},{"name":"sha256","type":"String","description":"SHA-256."},{"name":"thumbprint","type":"String","description":"Signing certificate thumbprint."},{"name":"id","type":"String","description":"List ID."},{"name":"domain","type":"String","description":"Domain."},{"name":"operator","type":"String","description":"Operator."},{"name":"version","type":"String","description":"Version of OS."},{"name":"os_distro_name","type":"String","description":"Operating System Distribution Name (linux only)."},{"name":"os_distro_revision","type":"String","description":"Version of OS Distribution (linux only)."},{"name":"os_version_extra","type":"String","description":"Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version."},{"name":"enabled","type":"Bool","description":"Enabled."},{"name":"check_disks","type":"List[String]","description":"List of volume names to be checked for encryption."},{"name":"require_all","type":"Bool","description":"Whether to check all disks for encryption."},{"name":"certificate_id","type":"String","description":"UUID of Cloudflare managed certificate."},{"name":"cn","type":"String","description":"Common Name that is protected by the certificate."},{"name":"check_private_key","type":"Bool","description":"Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key."},{"name":"extended_key_usage","type":"List[String]","description":"List of values indicating purposes for which the certificate public key can be used."},{"name":"locations","type":"Attributes","children":[{"name":"paths","type":"List[String]","description":"List of paths to check for client certificate on linux."},{"name":"trust_stores","type":"List[String]","description":"List of trust stores to check for client certificate."}]},{"name":"subject_alternative_names","type":"List[String]","description":"List of certificate Subject Alternative Names."},{"name":"update_window_days","type":"Float64","description":"Number of days that the antivirus should be updated within."},{"name":"compliance_status","type":"String","description":"Compliance Status."},{"name":"connection_id","type":"String","description":"Posture Integration ID."},{"name":"last_seen","type":"String","description":"For more details on last seen, please refer to the Crowdstrike documentation."},{"name":"os","type":"String","description":"Os Version."},{"name":"overall","type":"String","description":"Overall."},{"name":"sensor_config","type":"String","description":"SensorConfig."},{"name":"state","type":"String","description":"For more details on state, please refer to the Crowdstrike documentation."},{"name":"version_operator","type":"String","description":"Version Operator."},{"name":"auth_state","type":"List[String]","description":"The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states."},{"name":"count_operator","type":"String","description":"Count Operator."},{"name":"issue_count","type":"String","description":"The Number of Issues."},{"name":"eid_last_seen","type":"String","description":"For more details on eid last seen, refer to the Tanium documentation."},{"name":"risk_level","type":"String","description":"For more details on risk level, refer to the Tanium documentation."},{"name":"score_operator","type":"String","description":"Score Operator."},{"name":"total_score","type":"Float64","description":"For more details on total score, refer to the Tanium documentation."},{"name":"active_threats","type":"Float64","description":"The Number of active threats."},{"name":"infected","type":"Bool","description":"Whether device is infected."},{"name":"is_active","type":"Bool","description":"Whether device is active."},{"name":"network_status","type":"String","description":"Network status of device."},{"name":"operational_state","type":"String","description":"Agent operational state."},{"name":"score","type":"Float64","description":"A value between 0-100 assigned to devices set by the 3rd party posture provider."}]},{"name":"match","type":"List[Attributes]","description":"The conditions that the client must match to run the rule.","children":[{"name":"platform","type":"String"}]},{"name":"name","type":"String","description":"The name of the device posture rule."},{"name":"schedule","type":"String","description":"Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`."},{"name":"type","type":"String","description":"The type of device posture rule."}]}]}]},"get /accounts/{}/devices/posture/{}":{"operationId":"device-posture-rules-device-posture-rules-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_posture_rule","stainlessResource":"zero_trust.devices.posture","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_posture_rule\" \"example_zero_trust_device_posture_rule\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"rule_id","type":"String","description":"API UUID."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"description","type":"String","description":"The description of the device posture rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise."},{"name":"expiration","type":"String","description":"Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client."},{"name":"name","type":"String","description":"The name of the device posture rule."},{"name":"schedule","type":"String","description":"Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`."},{"name":"type","type":"String","description":"The type of device posture rule."},{"name":"input","type":"Attributes","description":"The value to be checked against.","children":[{"name":"operating_system","type":"String","description":"Operating system."},{"name":"path","type":"String","description":"File path."},{"name":"exists","type":"Bool","description":"Whether or not file exists."},{"name":"sha256","type":"String","description":"SHA-256."},{"name":"thumbprint","type":"String","description":"Signing certificate thumbprint."},{"name":"id","type":"String","description":"List ID."},{"name":"domain","type":"String","description":"Domain."},{"name":"operator","type":"String","description":"Operator."},{"name":"version","type":"String","description":"Version of OS."},{"name":"os_distro_name","type":"String","description":"Operating System Distribution Name (linux only)."},{"name":"os_distro_revision","type":"String","description":"Version of OS Distribution (linux only)."},{"name":"os_version_extra","type":"String","description":"Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version."},{"name":"enabled","type":"Bool","description":"Enabled."},{"name":"check_disks","type":"List[String]","description":"List of volume names to be checked for encryption."},{"name":"require_all","type":"Bool","description":"Whether to check all disks for encryption."},{"name":"certificate_id","type":"String","description":"UUID of Cloudflare managed certificate."},{"name":"cn","type":"String","description":"Common Name that is protected by the certificate."},{"name":"check_private_key","type":"Bool","description":"Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key."},{"name":"extended_key_usage","type":"List[String]","description":"List of values indicating purposes for which the certificate public key can be used."},{"name":"locations","type":"Attributes","children":[{"name":"paths","type":"List[String]","description":"List of paths to check for client certificate on linux."},{"name":"trust_stores","type":"List[String]","description":"List of trust stores to check for client certificate."}]},{"name":"subject_alternative_names","type":"List[String]","description":"List of certificate Subject Alternative Names."},{"name":"update_window_days","type":"Float64","description":"Number of days that the antivirus should be updated within."},{"name":"compliance_status","type":"String","description":"Compliance Status."},{"name":"connection_id","type":"String","description":"Posture Integration ID."},{"name":"last_seen","type":"String","description":"For more details on last seen, please refer to the Crowdstrike documentation."},{"name":"os","type":"String","description":"Os Version."},{"name":"overall","type":"String","description":"Overall."},{"name":"sensor_config","type":"String","description":"SensorConfig."},{"name":"state","type":"String","description":"For more details on state, please refer to the Crowdstrike documentation."},{"name":"version_operator","type":"String","description":"Version Operator."},{"name":"auth_state","type":"List[String]","description":"The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states."},{"name":"count_operator","type":"String","description":"Count Operator."},{"name":"issue_count","type":"String","description":"The Number of Issues."},{"name":"eid_last_seen","type":"String","description":"For more details on eid last seen, refer to the Tanium documentation."},{"name":"risk_level","type":"String","description":"For more details on risk level, refer to the Tanium documentation."},{"name":"score_operator","type":"String","description":"Score Operator."},{"name":"total_score","type":"Float64","description":"For more details on total score, refer to the Tanium documentation."},{"name":"active_threats","type":"Float64","description":"The Number of active threats."},{"name":"infected","type":"Bool","description":"Whether device is infected."},{"name":"is_active","type":"Bool","description":"Whether device is active."},{"name":"network_status","type":"String","description":"Network status of device."},{"name":"operational_state","type":"String","description":"Agent operational state."},{"name":"score","type":"Float64","description":"A value between 0-100 assigned to devices set by the 3rd party posture provider."}]},{"name":"match","type":"List[Attributes]","description":"The conditions that the client must match to run the rule.","children":[{"name":"platform","type":"String"}]}]}]},"get /accounts/{}/devices/posture/integration":{"operationId":"device-posture-integrations-list-device-posture-integrations","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_posture_integrations","stainlessResource":"zero_trust.devices.posture.integrations","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_posture_integrations\" \"example_zero_trust_device_posture_integrations\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"API UUID."},{"name":"config","type":"Attributes","description":"The configuration object containing third-party integration information.","children":[{"name":"api_url","type":"String","description":"The Workspace One API URL provided in the Workspace One Admin Dashboard."},{"name":"auth_url","type":"String","description":"The Workspace One Authorization URL depending on your region."},{"name":"client_id","type":"String","description":"The Workspace One client ID provided in the Workspace One Admin Dashboard."}]},{"name":"interval","type":"String","description":"The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)."},{"name":"name","type":"String","description":"The name of the device posture integration."},{"name":"type","type":"String","description":"The type of device posture integration."}]}]}]},"get /accounts/{}/devices/posture/integration/{}":{"operationId":"device-posture-integrations-device-posture-integration-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_posture_integration","stainlessResource":"zero_trust.devices.posture.integrations","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_posture_integration\" \"example_zero_trust_device_posture_integration\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n integration_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"integration_id","type":"String","description":"API UUID."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"interval","type":"String","description":"The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)."},{"name":"name","type":"String","description":"The name of the device posture integration."},{"name":"type","type":"String","description":"The type of device posture integration."},{"name":"config","type":"Attributes","description":"The configuration object containing third-party integration information.","children":[{"name":"api_url","type":"String","description":"The Workspace One API URL provided in the Workspace One Admin Dashboard."},{"name":"auth_url","type":"String","description":"The Workspace One Authorization URL depending on your region."},{"name":"client_id","type":"String","description":"The Workspace One client ID provided in the Workspace One Admin Dashboard."}]}]}]},"get /accounts/{}/devices/settings":{"operationId":"zero-trust-accounts-get-device-settings-for-zero-trust-account","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_settings","stainlessResource":"zero_trust.devices.settings","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_settings\" \"example_zero_trust_device_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"disable_for_time","type":"Float64","description":"Sets the time limit, in seconds, that a user can use an override code to bypass WARP."},{"name":"external_emergency_signal_enabled","type":"Bool","description":"Controls whether the external emergency disconnect feature is enabled."},{"name":"external_emergency_signal_fingerprint","type":"String","description":"The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external_emergency_signal_url. If provided, the WARP client will use this value to verify the server's identity. The device will ignore any response if the server's certificate fingerprint does not exactly match this value."},{"name":"external_emergency_signal_interval","type":"String","description":"The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., \"5m\", \"2m30s\", \"1h\"). Minimum 30 seconds."},{"name":"external_emergency_signal_url","type":"String","description":"The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host."},{"name":"gateway_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on TCP."},{"name":"gateway_udp_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on UDP."},{"name":"root_certificate_installation_enabled","type":"Bool","description":"Enable installation of cloudflare managed root certificate."},{"name":"use_zt_virtual_ip","type":"Bool","description":"Enable using CGNAT virtual IPv4."}]}]},"get /accounts/{}/dex/devices/dex_tests":{"operationId":"device-dex-test-details","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dex_tests","stainlessResource":"zero_trust.devices.dex_tests","methodName":"list","snippet":"data \"cloudflare_zero_trust_dex_tests\" \"example_zero_trust_dex_tests\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n kind = \"http\"\n test_name = \"testName\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[{"name":"kind","type":"String","description":"Filter by test type."},{"name":"test_name","type":"String","description":"Filter by test name."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier for the test."},{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool","description":"Determines whether or not the test is active."},{"name":"interval","type":"String","description":"How often the test will run."},{"name":"name","type":"String","description":"The name of the DEX test. Must be unique."},{"name":"created","type":"Time","description":"Date the test was created, in RFC 3339 format."},{"name":"description","type":"String","description":"Additional details about the test."},{"name":"target_policies","type":"List[Attributes]","description":"DEX rules targeted by this test","children":[{"name":"id","type":"String","description":"The id of the DEX rule."},{"name":"default","type":"Bool","description":"Whether the DEX rule is the account default."},{"name":"name","type":"String","description":"The name of the DEX rule."}]},{"name":"targeted","type":"Bool"},{"name":"test_id","type":"String","description":"The unique identifier for the test."},{"name":"updated","type":"Time","description":"Date the test was last updated, in RFC 3339 format."}]}]}]},"get /accounts/{}/dex/devices/dex_tests/{}":{"operationId":"device-dex-test-get-device-dex-test","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dex_test","stainlessResource":"zero_trust.devices.dex_tests","methodName":"get","snippet":"data \"cloudflare_zero_trust_dex_test\" \"example_zero_trust_dex_test\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n dex_test_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[{"name":"dex_test_id","type":"String","description":"The unique identifier for the test."},{"name":"filter","type":"Attributes","children":[{"name":"kind","type":"String","description":"Filter by test type."},{"name":"test_name","type":"String","description":"Filter by test name."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier for the test."},{"name":"created","type":"Time","description":"Date the test was created, in RFC 3339 format."},{"name":"description","type":"String","description":"Additional details about the test."},{"name":"enabled","type":"Bool","description":"Determines whether or not the test is active."},{"name":"interval","type":"String","description":"How often the test will run."},{"name":"name","type":"String","description":"The name of the DEX test. Must be unique."},{"name":"targeted","type":"Bool"},{"name":"test_id","type":"String","description":"The unique identifier for the test."},{"name":"updated","type":"Time","description":"Date the test was last updated, in RFC 3339 format."},{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"target_policies","type":"List[Attributes]","description":"DEX rules targeted by this test","children":[{"name":"id","type":"String","description":"The id of the DEX rule."},{"name":"default","type":"Bool","description":"Whether the DEX rule is the account default."},{"name":"name","type":"String","description":"The name of the DEX rule."}]}]}]},"get /accounts/{}/dex/rules":{"operationId":"list-dex-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dex_rules","stainlessResource":"zero_trust.dex.rules","methodName":"list","snippet":"data \"cloudflare_zero_trust_dex_rules\" \"example_zero_trust_dex_rules\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n name = \"name\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[{"name":"name","type":"String","description":"Filter results by rule name."},{"name":"sort_by","type":"String","description":"Which property to sort results by."},{"name":"sort_order","type":"String","description":"Sort direction for sort_by property."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"API Resource UUID tag."},{"name":"created_at","type":"String"},{"name":"match","type":"String"},{"name":"name","type":"String"},{"name":"description","type":"String"},{"name":"targeted_tests","type":"List[Attributes]","children":[{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"test_id","type":"String"}]},{"name":"updated_at","type":"String"}]}]}]}]},"get /accounts/{}/dex/rules/{}":{"operationId":"get-dex-rule","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dex_rule","stainlessResource":"zero_trust.dex.rules","methodName":"get","snippet":"data \"cloudflare_zero_trust_dex_rule\" \"example_zero_trust_dex_rule\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"rule_id","type":"String","description":"API Resource UUID tag."},{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"API Resource UUID tag."},{"name":"created_at","type":"String"},{"name":"description","type":"String"},{"name":"match","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"String"},{"name":"targeted_tests","type":"List[Attributes]","children":[{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"test_id","type":"String"}]}]}]},"get /accounts/{}/dlp/custom_prompt_topics":{"operationId":"dlp-custom-prompt-topics-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_custom_prompt_topics","stainlessResource":"zero_trust.dlp.custom_prompt_topics","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_custom_prompt_topics\" \"example_zero_trust_dlp_custom_prompt_topics\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool","deprecated":"Deprecated."},{"name":"name","type":"String"},{"name":"topic","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String","deprecated":"Deprecated."}]}]}]},"get /accounts/{}/dlp/custom_prompt_topics/{}":{"operationId":"dlp-custom-prompt-topics-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_custom_prompt_topic","stainlessResource":"zero_trust.dlp.custom_prompt_topics","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_custom_prompt_topic\" \"example_zero_trust_dlp_custom_prompt_topic\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"entry_id","type":"String"}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"enabled","type":"Bool","deprecated":"Deprecated."},{"name":"id","type":"String"},{"name":"name","type":"String"},{"name":"profile_id","type":"String","deprecated":"Deprecated."},{"name":"topic","type":"String"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/dlp/data_classes":{"operationId":"dlp-data-classes-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_data_classes","stainlessResource":"zero_trust.dlp.data_classes","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_data_classes\" \"example_zero_trust_dlp_data_classes\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"data_tags","type":"List[String]"},{"name":"expression","type":"String"},{"name":"name","type":"String"},{"name":"sensitivity_levels","type":"List[Attributes]","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/data_classes/{}":{"operationId":"dlp-data-classes-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_data_class","stainlessResource":"zero_trust.dlp.data_classes","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_data_class\" \"example_zero_trust_dlp_data_class\" {\n account_id = \"account_id\"\n data_class_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"data_class_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"expression","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"data_tags","type":"List[String]"},{"name":"sensitivity_levels","type":"List[Attributes]","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories":{"operationId":"dlp-data-tag-categories-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_data_tag_categories","stainlessResource":"zero_trust.dlp.data_tag_categories","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_data_tag_categories\" \"example_zero_trust_dlp_data_tag_categories\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"tags","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"template_id","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories/{}":{"operationId":"dlp-data-tag-categories-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_data_tag_category","stainlessResource":"zero_trust.dlp.data_tag_categories","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_data_tag_category\" \"example_zero_trust_dlp_data_tag_category\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"category_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"template_id","type":"String"},{"name":"updated_at","type":"Time"},{"name":"tags","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories/{}/data_tags":{"operationId":"dlp-data-tags-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_data_tags","stainlessResource":"zero_trust.dlp.data_tag_categories.data_tags","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_data_tags\" \"example_zero_trust_dlp_data_tags\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"category_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories/{}/data_tags/{}":{"operationId":"dlp-data-tags-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_data_tag","stainlessResource":"zero_trust.dlp.data_tag_categories.data_tags","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_data_tag\" \"example_zero_trust_dlp_data_tag\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n tag_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"tag_id","type":"String"},{"name":"account_id","type":"String"},{"name":"category_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/dlp/datasets":{"operationId":"dlp-datasets-read-all","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_datasets","stainlessResource":"zero_trust.dlp.datasets","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_datasets\" \"example_zero_trust_dlp_datasets\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"created_at","type":"Time"},{"name":"encoding_version","type":"Int64"},{"name":"name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"secret","type":"Bool"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]},{"name":"case_sensitive","type":"Bool"},{"name":"description","type":"String","description":"The description of the dataset."}]}]}]},"get /accounts/{}/dlp/datasets/{}":{"operationId":"dlp-datasets-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_dataset","stainlessResource":"zero_trust.dlp.datasets","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_dataset\" \"example_zero_trust_dlp_dataset\" {\n account_id = \"account_id\"\n dataset_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"dataset_id","type":"String"}],"optional":[],"computed":[{"name":"case_sensitive","type":"Bool"},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"The description of the dataset."},{"name":"encoding_version","type":"Int64"},{"name":"id","type":"String"},{"name":"name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"secret","type":"Bool"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]}]}]},"get /accounts/{}/dlp/entries":{"operationId":"dlp-entries-list-all-entries","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_custom_entries","stainlessResource":"zero_trust.dlp.entries.custom","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_custom_entries\" \"example_zero_trust_dlp_custom_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]},{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_entries","stainlessResource":"zero_trust.dlp.entries","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_entries\" \"example_zero_trust_dlp_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]},{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_integration_entries","stainlessResource":"zero_trust.dlp.entries.integration","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_integration_entries\" \"example_zero_trust_dlp_integration_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]},{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_predefined_entries","stainlessResource":"zero_trust.dlp.entries.predefined","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_predefined_entries\" \"example_zero_trust_dlp_predefined_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]}]},"get /accounts/{}/dlp/entries/{}":{"operationId":"dlp-entries-get-dlp-entry","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_custom_entry","stainlessResource":"zero_trust.dlp.entries.custom","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_custom_entry\" \"example_zero_trust_dlp_custom_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"data-source","name":"cloudflare_zero_trust_dlp_entry","stainlessResource":"zero_trust.dlp.entries","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_entry\" \"example_zero_trust_dlp_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"data-source","name":"cloudflare_zero_trust_dlp_integration_entry","stainlessResource":"zero_trust.dlp.entries.integration","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_integration_entry\" \"example_zero_trust_dlp_integration_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"data-source","name":"cloudflare_zero_trust_dlp_predefined_entry","stainlessResource":"zero_trust.dlp.entries.predefined","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_predefined_entry\" \"example_zero_trust_dlp_predefined_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"get /accounts/{}/dlp/profiles/custom/{}":{"operationId":"dlp-profiles-get-custom-profile","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_custom_profile","stainlessResource":"zero_trust.dlp.profiles.custom","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_custom_profile\" \"example_zero_trust_dlp_custom_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"profile_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64","description":"Related DLP policies will trigger when the match count exceeds the number set."},{"name":"confidence_threshold","type":"String"},{"name":"created_at","type":"Time","description":"When the profile was created."},{"name":"description","type":"String","description":"The description of the profile."},{"name":"integration_id","type":"String"},{"name":"name","type":"String","description":"The name of the profile."},{"name":"ocr_enabled","type":"Bool"},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."},{"name":"type","type":"String"},{"name":"updated_at","type":"Time","description":"When the profile was lasted updated."},{"name":"data_classes","type":"List[String]","description":"Data classes associated with this profile."},{"name":"data_tags","type":"List[String]","description":"Data tags associated with this profile."},{"name":"context_awareness","type":"Attributes","description":"Scan the context of predefined entries to only return matches surrounded by keywords.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"If true, scan the context of predefined entries to only return matches surrounded by keywords."},{"name":"skip","type":"Attributes","description":"Content types to exclude from context analysis and return all matches.","children":[{"name":"files","type":"Bool","description":"If the content type is a file, skip context analysis and return all matches."}]}]},{"name":"entries","type":"List[Attributes]","deprecated":"Deprecated.","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]},{"name":"sensitivity_levels","type":"List[Attributes]","description":"Sensitivity levels associated with this profile.","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]},{"name":"shared_entries","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]}]},"get /accounts/{}/dlp/profiles/predefined/{}/config":{"operationId":"dlp-profiles-get-predefined-profile-config","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_predefined_profile","stainlessResource":"zero_trust.dlp.profiles.predefined","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_predefined_profile\" \"example_zero_trust_dlp_predefined_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"profile_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64"},{"name":"confidence_threshold","type":"String"},{"name":"name","type":"String","description":"The name of the predefined profile."},{"name":"ocr_enabled","type":"Bool"},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."},{"name":"enabled_entries","type":"List[String]","description":"Entries to enable for this predefined profile. Any entries not provided will be disabled."},{"name":"entries","type":"List[Attributes]","description":"This field has been deprecated for `enabled_entries`.","deprecated":"Deprecated.","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups":{"operationId":"dlp-sensitivity-groups-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_sensitivity_groups","stainlessResource":"zero_trust.dlp.sensitivity_groups","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_groups\" \"example_zero_trust_dlp_sensitivity_groups\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"levels","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"template_id","type":"String"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}":{"operationId":"dlp-sensitivity-groups-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_sensitivity_group","stainlessResource":"zero_trust.dlp.sensitivity_groups","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_group\" \"example_zero_trust_dlp_sensitivity_group\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"sensitivity_group_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"template_id","type":"String"},{"name":"updated_at","type":"Time"},{"name":"levels","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}/level_order":{"operationId":"dlp-sensitivity-groups-get-level-order","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_sensitivity_level_order","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels.order","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_level_order\" \"example_zero_trust_dlp_sensitivity_level_order\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"sensitivity_group_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"level_ids","type":"List[String]"}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}/levels":{"operationId":"dlp-sensitivity-levels-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_sensitivity_levels","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_levels\" \"example_zero_trust_dlp_sensitivity_levels\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"sensitivity_group_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}/levels/{}":{"operationId":"dlp-sensitivity-levels-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_sensitivity_level","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_level\" \"example_zero_trust_dlp_sensitivity_level\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n sensitivity_level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"sensitivity_level_id","type":"String"},{"name":"account_id","type":"String"},{"name":"sensitivity_group_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/dlp/settings":{"operationId":"dlp-settings-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_settings","stainlessResource":"zero_trust.dlp.settings","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_settings\" \"example_zero_trust_dlp_settings\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ai_context_analysis","type":"Bool","description":"Whether AI context analysis is enabled at the account level."},{"name":"ocr","type":"Bool","description":"Whether OCR is enabled at the account level."},{"name":"payload_logging","type":"Attributes","children":[{"name":"updated_at","type":"Time"},{"name":"masking_level","type":"String","description":"Masking level for payload logs.\n\n- `full`: The entire payload is masked.\n- `partial`: Only partial payload content is masked.\n- `clear`: No masking is applied to the payload content.\n- `default`: DLP uses its default masking behavior."},{"name":"public_key","type":"String","description":"Base64-encoded public key for encrypting payload logs. Null when payload logging is disabled."}]}]}]},"get /accounts/{}/dls/regional_services/prefix_bindings":{"operationId":"publicListPrefixBindings","declarations":[{"kind":"list-data-source","name":"cloudflare_dls_prefix_bindings","stainlessResource":"dls.regional_services.prefix_bindings","methodName":"list","snippet":"data \"cloudflare_dls_prefix_bindings\" \"example_dls_prefix_bindings\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the binding."},{"name":"cidr","type":"String","description":"The CIDR that is bound."},{"name":"prefix_id","type":"String","description":"The ID of the parent prefix."},{"name":"region_key","type":"String","description":"The region key used for the binding."}]}]}]},"get /accounts/{}/dls/regional_services/prefix_bindings/{}":{"operationId":"publicGetPrefixBinding","declarations":[{"kind":"data-source","name":"cloudflare_dls_prefix_binding","stainlessResource":"dls.regional_services.prefix_bindings","methodName":"get","snippet":"data \"cloudflare_dls_prefix_binding\" \"example_dls_prefix_binding\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n binding_id = \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}\n","required":[{"name":"binding_id","type":"String","description":"Unique identifier for the prefix binding."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Unique identifier for the prefix binding."},{"name":"cidr","type":"String","description":"The CIDR that is bound."},{"name":"prefix_id","type":"String","description":"The ID of the parent prefix."},{"name":"region_key","type":"String","description":"The region key used for the binding."}]}]},"get /accounts/{}/dns_firewall":{"operationId":"dns-firewall-list-dns-firewall-clusters","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_firewalls","stainlessResource":"dns_firewall","methodName":"list","snippet":"data \"cloudflare_dns_firewalls\" \"example_dns_firewalls\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"deprecate_any_requests","type":"Bool","description":"Whether to refuse to answer queries for the ANY type"},{"name":"dns_firewall_ips","type":"Set[String]"},{"name":"ecs_fallback","type":"Bool","description":"Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent"},{"name":"maximum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"minimum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons.\n"},{"name":"modified_on","type":"Time","description":"Last modification of DNS Firewall cluster"},{"name":"name","type":"String","description":"DNS Firewall cluster name"},{"name":"negative_cache_ttl","type":"Float64","description":"This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"ratelimit","type":"Float64","description":"Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting."},{"name":"retries","type":"Float64","description":"Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)"},{"name":"upstream_ips","type":"Set[String]"},{"name":"attack_mitigation","type":"Attributes","description":"Attack mitigation settings","children":[{"name":"enabled","type":"Bool","description":"When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers"},{"name":"only_when_upstream_unhealthy","type":"Bool","description":"Only mitigate attacks when upstream servers seem unhealthy"}]}]}]}]},"get /accounts/{}/dns_firewall/{}":{"operationId":"dns-firewall-dns-firewall-cluster-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_firewall","stainlessResource":"dns_firewall","methodName":"get","snippet":"data \"cloudflare_dns_firewall\" \"example_dns_firewall\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns_firewall_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"dns_firewall_id","type":"String","description":"Identifier."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"deprecate_any_requests","type":"Bool","description":"Whether to refuse to answer queries for the ANY type"},{"name":"ecs_fallback","type":"Bool","description":"Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent"},{"name":"maximum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"minimum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons.\n"},{"name":"modified_on","type":"Time","description":"Last modification of DNS Firewall cluster"},{"name":"name","type":"String","description":"DNS Firewall cluster name"},{"name":"negative_cache_ttl","type":"Float64","description":"This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"ratelimit","type":"Float64","description":"Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting."},{"name":"retries","type":"Float64","description":"Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)"},{"name":"dns_firewall_ips","type":"Set[String]"},{"name":"upstream_ips","type":"Set[String]"},{"name":"attack_mitigation","type":"Attributes","description":"Attack mitigation settings","children":[{"name":"enabled","type":"Bool","description":"When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers"},{"name":"only_when_upstream_unhealthy","type":"Bool","description":"Only mitigate attacks when upstream servers seem unhealthy"}]}]}]},"get /accounts/{}/dns_settings/views":{"operationId":"dns-views-for-an-account-list-internal-dns-views","declarations":[{"kind":"list-data-source","name":"cloudflare_account_dns_settings_internal_views","stainlessResource":"dns.settings.account.views","methodName":"list","snippet":"data \"cloudflare_account_dns_settings_internal_views\" \"example_account_dns_settings_internal_views\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = {\n contains = \"view\"\n endswith = \"ew\"\n exact = \"my view\"\n startswith = \"my\"\n }\n order = \"name\"\n zone_id = \"ae29bea30e2e427ba9cd8d78b628177b\"\n zone_name = \"www.example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"order","type":"String","description":"Field to order DNS views by."},{"name":"zone_id","type":"String","description":"A zone ID that exists in the zones list for the view.\n"},{"name":"zone_name","type":"String","description":"A zone name that exists in the zones list for the view.\n"},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS view name.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS view name.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS view name.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS view name.\n"}]},{"name":"direction","type":"String","description":"Direction to order DNS views in."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_time","type":"Time","description":"When the view was created."},{"name":"modified_time","type":"Time","description":"When the view was last modified."},{"name":"name","type":"String","description":"The name of the view."},{"name":"zones","type":"Set[String]","description":"The list of zones linked to this view."}]}]}]},"get /accounts/{}/dns_settings/views/{}":{"operationId":"dns-views-for-an-account-get-internal-dns-view","declarations":[{"kind":"data-source","name":"cloudflare_account_dns_settings_internal_view","stainlessResource":"dns.settings.account.views","methodName":"get","snippet":"data \"cloudflare_account_dns_settings_internal_view\" \"example_account_dns_settings_internal_view\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n view_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"view_id","type":"String","description":"Identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order DNS views in."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead.\n"},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS view name.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS view name.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS view name.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS view name.\n"}]},{"name":"order","type":"String","description":"Field to order DNS views by."},{"name":"zone_id","type":"String","description":"A zone ID that exists in the zones list for the view.\n"},{"name":"zone_name","type":"String","description":"A zone name that exists in the zones list for the view.\n"}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_time","type":"Time","description":"When the view was created."},{"name":"modified_time","type":"Time","description":"When the view was last modified."},{"name":"name","type":"String","description":"The name of the view."},{"name":"zones","type":"Set[String]","description":"The list of zones linked to this view."}]}]},"get /accounts/{}/email-security/settings/allow_policies":{"operationId":"email_security_list_allow_policies","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_allow_policies","stainlessResource":"email_security.settings.allow_policies","methodName":"list","snippet":"data \"cloudflare_email_security_allow_policies\" \"example_email_security_allow_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n is_acceptable_sender = true\n is_exempt_recipient = true\n is_trusted_sender = true\n order = \"pattern\"\n pattern = \"pattern\"\n pattern_type = \"EMAIL\"\n search = \"search\"\n verify_sender = true\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_acceptable_sender","type":"Bool","description":"Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious)."},{"name":"is_exempt_recipient","type":"Bool","description":"Filter to show only policies where messages to the recipient bypass all detections."},{"name":"is_trusted_sender","type":"Bool","description":"Filter to show only policies where messages from the sender bypass all detections and link following."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by exact pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"verify_sender","type":"Bool","description":"Filter to show only policies that enforce DMARC, SPF, or DKIM authentication."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Allow policy identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"comments","type":"String"},{"name":"is_acceptable_sender","type":"Bool","description":"Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply."},{"name":"is_exempt_recipient","type":"Bool","description":"Bypasses all detections for messages to this recipient."},{"name":"is_recipient","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.","deprecated":"Use `is_exempt_recipient` instead."},{"name":"is_regex","type":"Bool"},{"name":"is_sender","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_trusted_sender` instead."},{"name":"is_spoof","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_acceptable_sender` instead."},{"name":"is_trusted_sender","type":"Bool","description":"Bypasses all detections and link following for messages from this sender."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"},{"name":"verify_sender","type":"Bool","description":"Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication."}]}]}]},"get /accounts/{}/email-security/settings/allow_policies/{}":{"operationId":"email_security_get_allow_policy","declarations":[{"kind":"data-source","name":"cloudflare_email_security_allow_policy","stainlessResource":"email_security.settings.allow_policies","methodName":"get","snippet":"data \"cloudflare_email_security_allow_policy\" \"example_email_security_allow_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"policy_id","type":"String","description":"Allow policy identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_acceptable_sender","type":"Bool","description":"Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious)."},{"name":"is_exempt_recipient","type":"Bool","description":"Filter to show only policies where messages to the recipient bypass all detections."},{"name":"is_trusted_sender","type":"Bool","description":"Filter to show only policies where messages from the sender bypass all detections and link following."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by exact pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"verify_sender","type":"Bool","description":"Filter to show only policies that enforce DMARC, SPF, or DKIM authentication."}]}],"computed":[{"name":"id","type":"String","description":"Allow policy identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_acceptable_sender","type":"Bool","description":"Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply."},{"name":"is_exempt_recipient","type":"Bool","description":"Bypasses all detections for messages to this recipient."},{"name":"is_recipient","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.","deprecated":"Use `is_exempt_recipient` instead."},{"name":"is_regex","type":"Bool"},{"name":"is_sender","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_trusted_sender` instead."},{"name":"is_spoof","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_acceptable_sender` instead."},{"name":"is_trusted_sender","type":"Bool","description":"Bypasses all detections and link following for messages from this sender."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"},{"name":"verify_sender","type":"Bool","description":"Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication."}]}]},"get /accounts/{}/email-security/settings/block_senders":{"operationId":"email_security_list_blocked_senders","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_block_senders","stainlessResource":"email_security.settings.block_senders","methodName":"list","snippet":"data \"cloudflare_email_security_block_senders\" \"example_email_security_block_senders\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"pattern\"\n pattern = \"pattern\"\n pattern_type = \"EMAIL\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Blocked sender pattern identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal value."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"}]}]}]},"get /accounts/{}/email-security/settings/block_senders/{}":{"operationId":"email_security_get_blocked_sender","declarations":[{"kind":"data-source","name":"cloudflare_email_security_block_sender","stainlessResource":"email_security.settings.block_senders","methodName":"get","snippet":"data \"cloudflare_email_security_block_sender\" \"example_email_security_block_sender\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pattern_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"pattern_id","type":"String","description":"Blocked sender pattern identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."}]}],"computed":[{"name":"id","type":"String","description":"Blocked sender pattern identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal value."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"}]}]},"get /accounts/{}/email-security/settings/domains":{"operationId":"email_security_list_domains","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_domains","stainlessResource":"email_security.settings.domains","methodName":"list","snippet":"data \"cloudflare_email_security_domains\" \"example_email_security_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n active_delivery_mode = \"DIRECT\"\n allowed_delivery_mode = \"DIRECT\"\n direction = \"asc\"\n domain = [\"string\"]\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n order = \"domain\"\n search = \"search\"\n status = \"PENDING\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"active_delivery_mode","type":"String","description":"Currently active delivery mode to filter by."},{"name":"allowed_delivery_mode","type":"String","description":"Delivery mode to filter by."},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"integration_id","type":"String","description":"Integration ID to filter by."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"status","type":"String","description":"Filters response to domains with the provided status."},{"name":"domain","type":"List[String]","description":"Domain names to filter by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"allowed_delivery_modes","type":"Set[String]"},{"name":"authorization","type":"Attributes","children":[{"name":"authorized","type":"Bool"},{"name":"timestamp","type":"Time"},{"name":"status_message","type":"String"}]},{"name":"created_at","type":"Time"},{"name":"dmarc_status","type":"String"},{"name":"domain","type":"String"},{"name":"drop_dispositions","type":"Set[String]"},{"name":"emails_processed","type":"Attributes","children":[{"name":"timestamp","type":"Time"},{"name":"total_emails_processed","type":"Int64"},{"name":"total_emails_processed_previous","type":"Int64"}]},{"name":"folder","type":"String","description":"The mailbox folder to scan, for API-scanning domains."},{"name":"inbox_provider","type":"String"},{"name":"integration_id","type":"String"},{"name":"ip_restrictions","type":"Set[String]"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"lookback_hops","type":"Int64"},{"name":"modified_at","type":"Time"},{"name":"o365_tenant_id","type":"String"},{"name":"regions","type":"Set[String]"},{"name":"require_tls_inbound","type":"Bool"},{"name":"require_tls_outbound","type":"Bool"},{"name":"spf_status","type":"String"},{"name":"status","type":"String"},{"name":"transport","type":"String"}]}]}]},"get /accounts/{}/email-security/settings/domains/{}":{"operationId":"email_security_get_domain","declarations":[{"kind":"data-source","name":"cloudflare_email_security_domain","stainlessResource":"email_security.settings.domains","methodName":"get","snippet":"data \"cloudflare_email_security_domain\" \"example_email_security_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"domain_id","type":"String","description":"Domain identifier."},{"name":"filter","type":"Attributes","children":[{"name":"active_delivery_mode","type":"String","description":"Currently active delivery mode to filter by."},{"name":"allowed_delivery_mode","type":"String","description":"Delivery mode to filter by."},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"domain","type":"List[String]","description":"Domain names to filter by."},{"name":"integration_id","type":"String","description":"Integration ID to filter by."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"status","type":"String","description":"Filters response to domains with the provided status."}]}],"computed":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"created_at","type":"Time"},{"name":"dmarc_status","type":"String"},{"name":"domain","type":"String"},{"name":"folder","type":"String","description":"The mailbox folder to scan, for API-scanning domains."},{"name":"inbox_provider","type":"String"},{"name":"integration_id","type":"String"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"lookback_hops","type":"Int64"},{"name":"modified_at","type":"Time"},{"name":"o365_tenant_id","type":"String"},{"name":"require_tls_inbound","type":"Bool"},{"name":"require_tls_outbound","type":"Bool"},{"name":"spf_status","type":"String"},{"name":"status","type":"String"},{"name":"transport","type":"String"},{"name":"allowed_delivery_modes","type":"Set[String]"},{"name":"drop_dispositions","type":"Set[String]"},{"name":"ip_restrictions","type":"Set[String]"},{"name":"regions","type":"Set[String]"},{"name":"authorization","type":"Attributes","children":[{"name":"authorized","type":"Bool"},{"name":"timestamp","type":"Time"},{"name":"status_message","type":"String"}]},{"name":"emails_processed","type":"Attributes","children":[{"name":"timestamp","type":"Time"},{"name":"total_emails_processed","type":"Int64"},{"name":"total_emails_processed_previous","type":"Int64"}]}]}]},"get /accounts/{}/email-security/settings/impersonation_registry":{"operationId":"email_security_list_impersonation_registry","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_impersonation_registries","stainlessResource":"email_security.settings.impersonation_registry","methodName":"list","snippet":"data \"cloudflare_email_security_impersonation_registries\" \"example_email_security_impersonation_registries\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"name\"\n provenance = \"A1S_INTERNAL\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"provenance","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Impersonation registry entry identifier."},{"name":"comments","type":"String","description":"Optional note describing the entry."},{"name":"created_at","type":"Time"},{"name":"directory_id","type":"Int64","description":"Identifier of the directory the entry was synced from, when directory-synced."},{"name":"directory_node_id","type":"Int64","description":"Identifier of the directory node the entry was synced from, when directory-synced."},{"name":"email","type":"String","description":"Email address (or pattern) of the protected identity."},{"name":"external_directory_node_id","type":"String","description":"Deprecated. External identifier of the directory node.","deprecated":"This field is deprecated."},{"name":"is_email_regex","type":"Bool","description":"Whether `email` is a regular expression instead of a literal address."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Display name of the protected identity."},{"name":"provenance","type":"String","description":"Source the entry was created from."}]}]}]},"get /accounts/{}/email-security/settings/impersonation_registry/{}":{"operationId":"email_security_get_impersonation_registry","declarations":[{"kind":"data-source","name":"cloudflare_email_security_impersonation_registry","stainlessResource":"email_security.settings.impersonation_registry","methodName":"get","snippet":"data \"cloudflare_email_security_impersonation_registry\" \"example_email_security_impersonation_registry\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n impersonation_registry_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"impersonation_registry_id","type":"String","description":"Impersonation registry entry identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"provenance","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."}]}],"computed":[{"name":"id","type":"String","description":"Impersonation registry entry identifier."},{"name":"comments","type":"String","description":"Optional note describing the entry."},{"name":"created_at","type":"Time"},{"name":"directory_id","type":"Int64","description":"Identifier of the directory the entry was synced from, when directory-synced."},{"name":"directory_node_id","type":"Int64","description":"Identifier of the directory node the entry was synced from, when directory-synced."},{"name":"email","type":"String","description":"Email address (or pattern) of the protected identity."},{"name":"external_directory_node_id","type":"String","description":"Deprecated. External identifier of the directory node.","deprecated":"This field is deprecated."},{"name":"is_email_regex","type":"Bool","description":"Whether `email` is a regular expression instead of a literal address."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Display name of the protected identity."},{"name":"provenance","type":"String","description":"Source the entry was created from."}]}]},"get /accounts/{}/email-security/settings/trusted_domains":{"operationId":"email_security_list_trusted_domains","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_trusted_domains_list","stainlessResource":"email_security.settings.trusted_domains","methodName":"list","snippet":"data \"cloudflare_email_security_trusted_domains_list\" \"example_email_security_trusted_domains_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n is_recent = true\n is_similarity = true\n order = \"pattern\"\n pattern = \"pattern\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_recent","type":"Bool","description":"Filter to show only recently registered domains that are trusted to prevent triggering Suspicious or Malicious dispositions."},{"name":"is_similarity","type":"Bool","description":"Filter to show only proximity domains (partner or approved domains with similar spelling to connected domains) that prevent Spoof dispositions."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Trusted domain identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_recent","type":"Bool","description":"Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition."},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal domain."},{"name":"is_similarity","type":"Bool","description":"Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The domain pattern to trust, e.g. `example.com`."}]}]}]},"get /accounts/{}/email-security/settings/trusted_domains/{}":{"operationId":"email_security_get_trusted_domain","declarations":[{"kind":"data-source","name":"cloudflare_email_security_trusted_domains","stainlessResource":"email_security.settings.trusted_domains","methodName":"get","snippet":"data \"cloudflare_email_security_trusted_domains\" \"example_email_security_trusted_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n trusted_domain_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"trusted_domain_id","type":"String","description":"Trusted domain identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_recent","type":"Bool","description":"Filter to show only recently registered domains that are trusted to prevent triggering Suspicious or Malicious dispositions."},{"name":"is_similarity","type":"Bool","description":"Filter to show only proximity domains (partner or approved domains with similar spelling to connected domains) that prevent Spoof dispositions."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."}]}],"computed":[{"name":"id","type":"String","description":"Trusted domain identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_recent","type":"Bool","description":"Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition."},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal domain."},{"name":"is_similarity","type":"Bool","description":"Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The domain pattern to trust, e.g. `example.com`."}]}]},"get /accounts/{}/email/routing/addresses":{"operationId":"email-routing-destination-addresses-list-destination-addresses","declarations":[{"kind":"list-data-source","name":"cloudflare_email_routing_addresses","stainlessResource":"email_routing.addresses","methodName":"list","snippet":"data \"cloudflare_email_routing_addresses\" \"example_email_routing_addresses\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"Sorts results in an ascending or descending order."},{"name":"verified","type":"Bool","description":"Filter by verified destination addresses."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Destination address identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"tag","type":"String","description":"Destination address tag. (Deprecated, replaced by destination address identifier)","deprecated":"Deprecated."},{"name":"verified","type":"Time","description":"The date and time the destination address has been verified. Null means not verified yet."}]}]}]},"get /accounts/{}/email/routing/addresses/{}":{"operationId":"email-routing-destination-addresses-get-a-destination-address","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_address","stainlessResource":"email_routing.addresses","methodName":"get","snippet":"data \"cloudflare_email_routing_address\" \"example_email_routing_address\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n destination_address_identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"destination_address_identifier","type":"String","description":"Destination address identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sorts results in an ascending or descending order."},{"name":"verified","type":"Bool","description":"Filter by verified destination addresses."}]}],"computed":[{"name":"id","type":"String","description":"Destination address identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"tag","type":"String","description":"Destination address tag. (Deprecated, replaced by destination address identifier)","deprecated":"Deprecated."},{"name":"verified","type":"Time","description":"The date and time the destination address has been verified. Null means not verified yet."}]}]},"get /accounts/{}/event_notifications/r2/{}/configuration/queues/{}":{"operationId":"r2-get-event-notification-config","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_event_notification","stainlessResource":"r2.buckets.event_notifications","methodName":"get","snippet":"data \"cloudflare_r2_bucket_event_notification\" \"example_r2_bucket_event_notification\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n queue_id = \"queue_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."},{"name":"queue_id","type":"String","description":"ID of the Cloudflare Queue that receives notifications for matching R2 object events."}],"optional":[],"computed":[{"name":"queue_name","type":"String","description":"Name of the queue."},{"name":"rules","type":"List[Attributes]","children":[{"name":"actions","type":"List[String]","description":"Array of R2 object actions that will trigger notifications."},{"name":"created_at","type":"String","description":"Timestamp when the rule was created."},{"name":"description","type":"String","description":"A description that can be used to identify the event notification rule after creation."},{"name":"prefix","type":"String","description":"Notifications will be sent only for objects with this prefix."},{"name":"rule_id","type":"String","description":"Rule ID."},{"name":"suffix","type":"String","description":"Notifications will be sent only for objects with this suffix."}]}]}]},"get /accounts/{}/field_extractors/{}":{"operationId":"getFieldExtractor","declarations":[{"kind":"data-source","name":"cloudflare_field_extractor","stainlessResource":"field_extractors","methodName":"get","snippet":"data \"cloudflare_field_extractor\" \"example_field_extractor\" {\n account_id = \"123456\"\n extractor = \"llm_prompts\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID."},{"name":"extractor","type":"String","description":"Extractor type."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"expression","type":"String","description":"Wirefilter value expression."},{"name":"name","type":"String","description":"Field name."}]},{"name":"ref","type":"String","description":"Stable rule identifier."},{"name":"description","type":"String","description":"Human-readable rule description."}]}]}]},"get /accounts/{}/flagship/apps":{"operationId":"flagship_list_apps","declarations":[{"kind":"list-data-source","name":"cloudflare_flagship_apps","stainlessResource":"flagship.apps","methodName":"list","snippet":"data \"cloudflare_flagship_apps\" \"example_flagship_apps\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String","description":"Email of the actor who last modified the app, or `unknown` when unavailable."}]}]}]},"get /accounts/{}/flagship/apps/{}":{"operationId":"flagship_get_app","declarations":[{"kind":"data-source","name":"cloudflare_flagship_app","stainlessResource":"flagship.apps","methodName":"get","snippet":"data \"cloudflare_flagship_app\" \"example_flagship_app\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n}\n","required":[{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created."},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Flagship app ID returned when the app was created."},{"name":"created_at","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String","description":"Email of the actor who last modified the app, or `unknown` when unavailable."}]}]},"get /accounts/{}/flagship/apps/{}/flags":{"operationId":"flagship_list_flags","declarations":[{"kind":"list-data-source","name":"cloudflare_flagship_flags","stainlessResource":"flagship.apps.flags","methodName":"list","snippet":"data \"cloudflare_flagship_flags\" \"example_flagship_flags\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n limit = 1\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."},{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created."}],"optional":[{"name":"limit","type":"Int64","description":"Max items to return (1–200)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls."},{"name":"default_variation","type":"String","description":"Variation the API serves when the flag is off, or when it's on but no rule matches the context. Must be a key in `variations`."},{"name":"enabled","type":"Bool","description":"When false, the flag bypasses all rules and always serves `default_variation`."},{"name":"key","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls."},{"name":"rules","type":"List[Attributes]","description":"Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.","children":[{"name":"conditions","type":"List[Attributes]","description":"Conditions the context must satisfy for this rule to match. An empty array matches all contexts.","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[String]"},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"priority","type":"Int64","description":"Evaluation order: the API evaluates rules with lower numbers first. Must be unique across the flag's rules."},{"name":"serve_variation","type":"String","description":"Variation the API serves when this rule matches. Must be a key in `variations`."},{"name":"rollout","type":"Attributes","children":[{"name":"percentage","type":"Float64","description":"Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)."},{"name":"attribute","type":"String","description":"Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request."}]}]},{"name":"type","type":"String","description":"Server-inferred value type shared by all of the flag's variations."},{"name":"variations","type":"Map[String]","description":"Map of variation name to value. All values share the same type (boolean, string, number, or JSON object/array), and each serialized value stays within 10KB."},{"name":"description","type":"String","description":"Optional operator-facing description. It does not affect flag evaluation."},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String"}]}]}]},"get /accounts/{}/flagship/apps/{}/flags/{}":{"operationId":"flagship_get_flag","declarations":[{"kind":"data-source","name":"cloudflare_flagship_flag","stainlessResource":"flagship.apps.flags","methodName":"get","snippet":"data \"cloudflare_flagship_flag\" \"example_flagship_flag\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n flag_key = \"flag_key\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."},{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created."}],"optional":[{"name":"flag_key","type":"String","description":"Case-sensitive key identifying the flag within the app."},{"name":"filter","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Max items to return (1–200)."}]}],"computed":[{"name":"id","type":"String","description":"Case-sensitive key identifying the flag within the app."},{"name":"default_variation","type":"String","description":"Variation the API serves when the flag is off, or when it's on but no rule matches the context. Must be a key in `variations`."},{"name":"description","type":"String","description":"Optional operator-facing description. It does not affect flag evaluation."},{"name":"enabled","type":"Bool","description":"When false, the flag bypasses all rules and always serves `default_variation`."},{"name":"key","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls."},{"name":"type","type":"String","description":"Server-inferred value type shared by all of the flag's variations."},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String"},{"name":"variations","type":"Map[String]","description":"Map of variation name to value. All values share the same type (boolean, string, number, or JSON object/array), and each serialized value stays within 10KB."},{"name":"rules","type":"List[Attributes]","description":"Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.","children":[{"name":"conditions","type":"List[Attributes]","description":"Conditions the context must satisfy for this rule to match. An empty array matches all contexts.","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[String]"},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"priority","type":"Int64","description":"Evaluation order: the API evaluates rules with lower numbers first. Must be unique across the flag's rules."},{"name":"serve_variation","type":"String","description":"Variation the API serves when this rule matches. Must be a key in `variations`."},{"name":"rollout","type":"Attributes","children":[{"name":"percentage","type":"Float64","description":"Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)."},{"name":"attribute","type":"String","description":"Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request."}]}]}]}]},"get /accounts/{}/gateway/app_types":{"operationId":"zero-trust-gateway-application-and-application-type-mappings-list-application-and-application-type-mappings","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_app_types_list","stainlessResource":"zero_trust.gateway.app_types","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_app_types_list\" \"example_zero_trust_gateway_app_types_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Provide the identifier string."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Identify this application. Only one application per ID."},{"name":"application_type_id","type":"Int64","description":"Identify the type of this application. Multiple applications can share the same type. Refers to the `id` of a returned application type."},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"Specify the name of the application or application type."},{"name":"description","type":"String","description":"Provide a short summary of applications with this type."}]}]}]},"get /accounts/{}/gateway/categories":{"operationId":"zero-trust-gateway-categories-list-categories","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_categories_list","stainlessResource":"zero_trust.gateway.categories","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_categories_list\" \"example_zero_trust_gateway_categories_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Provide the identifier string."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Identify this category. Only one category per ID."},{"name":"beta","type":"Bool","description":"Indicate whether the category is in beta and subject to change."},{"name":"class","type":"String","description":"Specify which account types can create policies for this category. `blocked` Blocks unconditionally for all accounts. `removalPending` Allows removal from policies but disables addition. `noBlock` Prevents blocking."},{"name":"description","type":"String","description":"Provide a short summary of domains in the category."},{"name":"name","type":"String","description":"Specify the category name."},{"name":"subcategories","type":"List[Attributes]","description":"Provide all subcategories for this category.","children":[{"name":"id","type":"Int64","description":"Identify this category. Only one category per ID."},{"name":"beta","type":"Bool","description":"Indicate whether the category is in beta and subject to change."},{"name":"class","type":"String","description":"Specify which account types can create policies for this category. `blocked` Blocks unconditionally for all accounts. `removalPending` Allows removal from policies but disables addition. `noBlock` Prevents blocking."},{"name":"description","type":"String","description":"Provide a short summary of domains in the category."},{"name":"name","type":"String","description":"Specify the category name."}]}]}]}]},"get /accounts/{}/gateway/certificates":{"operationId":"zero-trust-certificates-list-zero-trust-certificates","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_certificates","stainlessResource":"zero_trust.gateway.certificates","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_certificates\" \"example_zero_trust_gateway_certificates\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identify the certificate with a UUID."},{"name":"binding_status","type":"String","description":"Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state."},{"name":"certificate","type":"String","description":"Provide the CA certificate (read-only)."},{"name":"created_at","type":"Time"},{"name":"expires_on","type":"Time"},{"name":"fingerprint","type":"String","description":"Provide the SHA256 fingerprint of the certificate (read-only)."},{"name":"in_use","type":"Bool","description":"Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)."},{"name":"issuer_org","type":"String","description":"Indicate the organization that issued the certificate (read-only)."},{"name":"issuer_raw","type":"String","description":"Provide the entire issuer field of the certificate (read-only)."},{"name":"type","type":"String","description":"Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed."},{"name":"updated_at","type":"Time"},{"name":"uploaded_on","type":"Time"}]}]}]},"get /accounts/{}/gateway/certificates/{}":{"operationId":"zero-trust-certificates-zero-trust-certificate-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_certificate","stainlessResource":"zero_trust.gateway.certificates","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_certificate\" \"example_zero_trust_gateway_certificate\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n certificate_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"certificate_id","type":"String","description":"Identify the certificate with a UUID."},{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identify the certificate with a UUID."},{"name":"binding_status","type":"String","description":"Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state."},{"name":"certificate","type":"String","description":"Provide the CA certificate (read-only)."},{"name":"created_at","type":"Time"},{"name":"expires_on","type":"Time"},{"name":"fingerprint","type":"String","description":"Provide the SHA256 fingerprint of the certificate (read-only)."},{"name":"in_use","type":"Bool","description":"Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)."},{"name":"issuer_org","type":"String","description":"Indicate the organization that issued the certificate (read-only)."},{"name":"issuer_raw","type":"String","description":"Provide the entire issuer field of the certificate (read-only)."},{"name":"type","type":"String","description":"Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed."},{"name":"updated_at","type":"Time"},{"name":"uploaded_on","type":"Time"}]}]},"get /accounts/{}/gateway/configuration":{"operationId":"zero-trust-accounts-get-zero-trust-account-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_settings","stainlessResource":"zero_trust.gateway.configurations","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_settings\" \"example_zero_trust_gateway_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier."},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"},{"name":"settings","type":"Attributes","description":"Specify account settings.","children":[{"name":"activity_log","type":"Attributes","description":"Specify activity log settings.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to log activity."}]},{"name":"antivirus","type":"Attributes","description":"Specify anti-virus settings.","children":[{"name":"enabled_download_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on downloads."},{"name":"enabled_upload_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on uploads."},{"name":"fail_closed","type":"Bool","description":"Specify whether to block requests for unscannable files."},{"name":"notification_settings","type":"Attributes","description":"Configure the message the user's device shows during an antivirus scan.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable notifications."},{"name":"include_context","type":"Bool","description":"Specify whether to include context information as query parameters."},{"name":"msg","type":"String","description":"Specify the message to show in the notification."},{"name":"support_url","type":"String","description":"Specify a URL that directs users to more information. If unset, the notification opens a block page."}]}]},{"name":"block_page","type":"Attributes","description":"Specify block page layout settings.","children":[{"name":"background_color","type":"String","description":"Specify the block page background color in `#rrggbb` format when the mode is customized_block_page."},{"name":"enabled","type":"Bool","description":"Specify whether to enable the custom block page."},{"name":"footer_text","type":"String","description":"Specify the block page footer text when the mode is customized_block_page."},{"name":"header_text","type":"String","description":"Specify the block page header text when the mode is customized_block_page."},{"name":"include_context","type":"Bool","description":"Specify whether to append context to target_uri as query parameters. This applies only when the mode is redirect_uri."},{"name":"logo_path","type":"String","description":"Specify the full URL to the logo file when the mode is customized_block_page."},{"name":"mailto_address","type":"String","description":"Specify the admin email for users to contact when the mode is customized_block_page."},{"name":"mailto_subject","type":"String","description":"Specify the subject line for emails created from the block page when the mode is customized_block_page."},{"name":"mode","type":"String","description":"Specify whether to redirect users to a Cloudflare-hosted block page or a customer-provided URI."},{"name":"name","type":"String","description":"Specify the block page title when the mode is customized_block_page."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"suppress_footer","type":"Bool","description":"Specify whether to suppress detailed information at the bottom of the block page when the mode is customized_block_page."},{"name":"target_uri","type":"String","description":"Specify the URI to redirect users to when the mode is redirect_uri."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"body_scanning","type":"Attributes","description":"Specify the DLP inspection mode.","children":[{"name":"inspection_mode","type":"String","description":"Specify the inspection mode as either `deep` or `shallow`."}]},{"name":"browser_isolation","type":"Attributes","description":"Specify Clientless Browser Isolation settings.","children":[{"name":"non_identity_enabled","type":"Bool","description":"Specify whether to enable non-identity onramp support for Browser Isolation."},{"name":"url_browser_isolation_enabled","type":"Bool","description":"Specify whether to enable Clientless Browser Isolation."}]},{"name":"certificate","type":"Attributes","description":"Specify certificate settings for Gateway TLS interception. If unset, the Cloudflare Root CA handles interception.","children":[{"name":"id","type":"String","description":"Specify the UUID of the certificate used for interception. Ensure the certificate is available at the edge(previously called 'active'). A nil UUID directs Cloudflare to use the Root CA."}]},{"name":"custom_certificate","type":"Attributes","description":"Specify custom certificate settings for BYO-PKI. This field is deprecated; use `certificate` instead.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable a custom certificate authority for signing Gateway traffic."},{"name":"id","type":"String","description":"Specify the UUID of the certificate (ID from MTLS certificate store)."},{"name":"binding_status","type":"String","description":"Indicate the internal certificate status."},{"name":"updated_at","type":"Time"}]},{"name":"extended_email_matching","type":"Attributes","description":"Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses `.` or `+` modifiers.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to match all variants of user emails (with + or . modifiers) used as criteria in Firewall policies."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"fips","type":"Attributes","description":"Specify FIPS settings.","children":[{"name":"tls","type":"Bool","description":"Enforce cipher suites and TLS versions compliant with FIPS 140-2."}]},{"name":"host_selector","type":"Attributes","description":"Enable host selection in egress policies.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable filtering via hosts for egress policies."}]},{"name":"inspection","type":"Attributes","description":"Define the proxy inspection mode.","children":[{"name":"mode","type":"String","description":"Define the proxy inspection mode. 1. static: Gateway applies static inspection to HTTP on TCP(80). With TLS decryption on, Gateway inspects HTTPS traffic on TCP(443) and UDP(443). 2. dynamic: Gateway applies protocol detection to inspect HTTP and HTTPS traffic on any port. TLS decryption must remain on to inspect HTTPS traffic."}]},{"name":"max_ttl_secs","type":"Int64","description":"Account-level cap on DNS response TTLs, in seconds. Gateway rewrites DNS responses so returned record TTLs do not exceed this value. Null means no cap. Each DNS location can inherit, override, or disable it through the location `max_ttl` setting."},{"name":"protocol_detection","type":"Attributes","description":"Specify whether to detect protocols from the initial bytes of client traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to detect protocols from the initial bytes of client traffic."}]},{"name":"sandbox","type":"Attributes","description":"Specify whether to enable the sandbox.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable the sandbox."},{"name":"fallback_action","type":"String","description":"Specify the action to take when the system cannot scan the file."}]},{"name":"tls_decrypt","type":"Attributes","description":"Specify whether to inspect encrypted HTTP traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to inspect encrypted HTTP traffic."}]}]}]}]},"get /accounts/{}/gateway/lists":{"operationId":"zero-trust-lists-list-zero-trust-lists","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_lists","stainlessResource":"zero_trust.gateway.lists","methodName":"list","snippet":"data \"cloudflare_zero_trust_lists\" \"example_zero_trust_lists\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n type = \"SERIAL\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. Applies to the field named in `order_by`; when `order_by`\nis omitted it applies to the default `created_at` ordering. When\n`direction` is omitted the default is field-specific: explicitly choosing\n`created_at` or `updated_at` defaults to descending (newest first); `name`\nand `item_count` default to ascending; and the default `created_at`\nordering used when `order_by` is omitted is ascending (for backwards\ncompatibility).\n * `asc` — ascending.\n * `desc` — descending."},{"name":"order_by","type":"String","description":"Field to sort the returned lists by. When omitted, results are ordered by\n`created_at` in ascending order (i.e. creation order) for backwards\ncompatibility. Supported values:\n * `name` — sort alphabetically by list name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\n * `item_count` — sort by number of items in the list."},{"name":"search","type":"String","description":"Case-insensitive substring match on the list name or description. When\ncombined with `filter`, both must match (logical AND)."},{"name":"type","type":"String","description":"Specify the list type."},{"name":"filter","type":"List[String]","description":"Filter the returned lists by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a list must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the list name.\n * `id` — substring match on the list ID (UUID), with or without dashes.\n * `type` — exact match on the list type. Supersedes the legacy `type` query\n parameter when both are supplied. Must be one of the valid type values.\n * `item_count` — exact integer match on the number of items in the list.\n\nEach entry must match one of the per-field patterns below: the field must be\none of `name`, `id`, `type`, or `item_count`; `name`/`id` accept any value,\n`type` is restricted to the valid list type values, and `item_count` must be\na non-negative integer."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"list_count","type":"Float64","description":"Indicate the number of items in the list."},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list description."},{"name":"items","type":"Set[Attributes]","description":"Provide the list items.","children":[{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list item description (optional)."},{"name":"value","type":"String","description":"Specify the item value."}]},{"name":"name","type":"String","description":"Specify the list name."},{"name":"type","type":"String","description":"Specify the list type."},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/gateway/lists/{}":{"operationId":"zero-trust-lists-zero-trust-list-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_list","stainlessResource":"zero_trust.gateway.lists","methodName":"get","snippet":"data \"cloudflare_zero_trust_list\" \"example_zero_trust_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n list_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"list_id","type":"String","description":"Identify the API resource with a UUID."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. Applies to the field named in `order_by`; when `order_by`\nis omitted it applies to the default `created_at` ordering. When\n`direction` is omitted the default is field-specific: explicitly choosing\n`created_at` or `updated_at` defaults to descending (newest first); `name`\nand `item_count` default to ascending; and the default `created_at`\nordering used when `order_by` is omitted is ascending (for backwards\ncompatibility).\n * `asc` — ascending.\n * `desc` — descending."},{"name":"filter","type":"List[String]","description":"Filter the returned lists by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a list must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the list name.\n * `id` — substring match on the list ID (UUID), with or without dashes.\n * `type` — exact match on the list type. Supersedes the legacy `type` query\n parameter when both are supplied. Must be one of the valid type values.\n * `item_count` — exact integer match on the number of items in the list.\n\nEach entry must match one of the per-field patterns below: the field must be\none of `name`, `id`, `type`, or `item_count`; `name`/`id` accept any value,\n`type` is restricted to the valid list type values, and `item_count` must be\na non-negative integer."},{"name":"order_by","type":"String","description":"Field to sort the returned lists by. When omitted, results are ordered by\n`created_at` in ascending order (i.e. creation order) for backwards\ncompatibility. Supported values:\n * `name` — sort alphabetically by list name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\n * `item_count` — sort by number of items in the list."},{"name":"search","type":"String","description":"Case-insensitive substring match on the list name or description. When\ncombined with `filter`, both must match (logical AND)."},{"name":"type","type":"String","description":"Specify the list type."}]}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list description."},{"name":"list_count","type":"Float64","description":"Indicate the number of items in the list."},{"name":"name","type":"String","description":"Specify the list name."},{"name":"type","type":"String","description":"Specify the list type."},{"name":"updated_at","type":"Time"},{"name":"items","type":"Set[Attributes]","description":"Provide the list items.","children":[{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list item description (optional)."},{"name":"value","type":"String","description":"Specify the item value."}]}]}]},"get /accounts/{}/gateway/locations":{"operationId":"zero-trust-gateway-locations-list-zero-trust-gateway-locations","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dns_locations","stainlessResource":"zero_trust.gateway.locations","methodName":"list","snippet":"data \"cloudflare_zero_trust_dns_locations\" \"example_zero_trust_dns_locations\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"order_by","type":"String","description":"Field to sort the returned locations by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by location name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the location name. When combined\nwith `filter`, both must match (logical AND)."},{"name":"filter","type":"List[String]","description":"Filter the returned locations by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a location must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the location name.\n * `id` — substring match on the location ID (UUID), with or without dashes.\n * `is_default` — whether it is the default for the account.\n\nEach entry must match one of the per-field patterns below:\n * the field must be one of `name`, `id`, or `is_default`;\n * `name`/`id` accept any value;\n * `is_default` only accepts `true` or `false`; any other value returns `400`"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"client_default","type":"Bool","description":"Indicate whether this location is the default location."},{"name":"created_at","type":"Time"},{"name":"dns_destination_ips_id","type":"String","description":"Indicate the identifier of the pair of IPv4 addresses assigned to this location."},{"name":"dns_destination_ipv6_block_id","type":"String","description":"Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block."},{"name":"doh_subdomain","type":"String","description":"Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value."},{"name":"ecs_support","type":"Bool","description":"Indicate whether the location must resolve EDNS queries."},{"name":"endpoints","type":"Attributes","description":"Configure the destination endpoints for this location.","children":[{"name":"doh","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOH endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]},{"name":"require_token","type":"Bool","description":"Specify whether the DOH endpoint requires user identity authentication."}]},{"name":"dot","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOT endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]}]},{"name":"ipv4","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPv4 endpoint is enabled for this location."}]},{"name":"ipv6","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPV6 endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv6 address or IPv6 CIDR."}]}]}]},{"name":"ip","type":"String","description":"Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location."},{"name":"ipv4_destination","type":"String","description":"Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"ipv4_destination_backup","type":"String","description":"Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"max_ttl","type":"Attributes","description":"Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.","children":[{"name":"mode","type":"String","description":"`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged."},{"name":"ttl_secs","type":"Int64","description":"Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`."}]},{"name":"name","type":"String","description":"Specify the location name."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24."}]},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/gateway/locations/{}":{"operationId":"zero-trust-gateway-locations-zero-trust-gateway-location-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dns_location","stainlessResource":"zero_trust.gateway.locations","methodName":"get","snippet":"data \"cloudflare_zero_trust_dns_location\" \"example_zero_trust_dns_location\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n location_id = \"ed35569b41ce4d1facfe683550f54086\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"location_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"filter","type":"List[String]","description":"Filter the returned locations by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a location must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the location name.\n * `id` — substring match on the location ID (UUID), with or without dashes.\n * `is_default` — whether it is the default for the account.\n\nEach entry must match one of the per-field patterns below:\n * the field must be one of `name`, `id`, or `is_default`;\n * `name`/`id` accept any value;\n * `is_default` only accepts `true` or `false`; any other value returns `400`"},{"name":"order_by","type":"String","description":"Field to sort the returned locations by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by location name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the location name. When combined\nwith `filter`, both must match (logical AND)."}]}],"computed":[{"name":"id","type":"String"},{"name":"client_default","type":"Bool","description":"Indicate whether this location is the default location."},{"name":"created_at","type":"Time"},{"name":"dns_destination_ips_id","type":"String","description":"Indicate the identifier of the pair of IPv4 addresses assigned to this location."},{"name":"dns_destination_ipv6_block_id","type":"String","description":"Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block."},{"name":"doh_subdomain","type":"String","description":"Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value."},{"name":"ecs_support","type":"Bool","description":"Indicate whether the location must resolve EDNS queries."},{"name":"ip","type":"String","description":"Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location."},{"name":"ipv4_destination","type":"String","description":"Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"ipv4_destination_backup","type":"String","description":"Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"name","type":"String","description":"Specify the location name."},{"name":"updated_at","type":"Time"},{"name":"endpoints","type":"Attributes","description":"Configure the destination endpoints for this location.","children":[{"name":"doh","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOH endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]},{"name":"require_token","type":"Bool","description":"Specify whether the DOH endpoint requires user identity authentication."}]},{"name":"dot","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOT endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]}]},{"name":"ipv4","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPv4 endpoint is enabled for this location."}]},{"name":"ipv6","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPV6 endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv6 address or IPv6 CIDR."}]}]}]},{"name":"max_ttl","type":"Attributes","description":"Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.","children":[{"name":"mode","type":"String","description":"`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged."},{"name":"ttl_secs","type":"Int64","description":"Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`."}]},{"name":"networks","type":"List[Attributes]","description":"Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24."}]}]}]},"get /accounts/{}/gateway/logging":{"operationId":"zero-trust-accounts-get-logging-settings-for-the-zero-trust-account","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_logging","stainlessResource":"zero_trust.gateway.logging","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_logging\" \"example_zero_trust_gateway_logging\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier."},{"name":"redact_pii","type":"Bool","description":"Indicate whether to redact personally identifiable information from activity logging (PII fields include source IP, user email, user ID, device ID, URL, referrer, and user agent)."},{"name":"settings_by_rule_type","type":"Attributes","description":"Configure logging settings for each rule type.","children":[{"name":"dns","type":"Attributes","description":"Configure logging settings for DNS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"http","type":"Attributes","description":"Configure logging settings for HTTP/HTTPS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"l4","type":"Attributes","description":"Configure logging settings for Network firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]}]}]}]},"get /accounts/{}/gateway/pacfiles":{"operationId":"zero-trust-gateway-pacfiles-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_pacfiles","stainlessResource":"zero_trust.gateway.pacfiles","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_pacfiles\" \"example_zero_trust_gateway_pacfiles\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Detailed description of the PAC file."},{"name":"name","type":"String","description":"Name of the PAC file."},{"name":"slug","type":"String","description":"URL-friendly version of the PAC file name."},{"name":"updated_at","type":"Time"},{"name":"url","type":"String","description":"Unique URL to download the PAC file."}]}]}]},"get /accounts/{}/gateway/pacfiles/{}":{"operationId":"zero-trust-gateway-pacfiles-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_pacfile","stainlessResource":"zero_trust.gateway.pacfiles","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_pacfile\" \"example_zero_trust_gateway_pacfile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n pacfile_id = \"ed35569b41ce4d1facfe683550f54086\"\n}\n","required":[{"name":"pacfile_id","type":"String"},{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"contents","type":"String","description":"Actual contents of the PAC file"},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Detailed description of the PAC file."},{"name":"name","type":"String","description":"Name of the PAC file."},{"name":"slug","type":"String","description":"URL-friendly version of the PAC file name."},{"name":"updated_at","type":"Time"},{"name":"url","type":"String","description":"Unique URL to download the PAC file."}]}]},"get /accounts/{}/gateway/proxy_endpoints":{"operationId":"zero-trust-gateway-proxy-endpoints-list-proxy-endpoints","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_proxy_endpoints","stainlessResource":"zero_trust.gateway.proxy_endpoints","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_proxy_endpoints\" \"example_zero_trust_gateway_proxy_endpoints\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"order_by","type":"String","description":"Field to sort the returned endpoints by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by endpoint name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the endpoint name. When combined\nwith `filter`, both must match (logical AND)."},{"name":"filter","type":"List[String]","description":"Filter the returned proxy endpoints by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (an endpoint must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the endpoint name.\n * `id` — substring match on the endpoint ID (UUID), with or without dashes.\n * `kind` — exact match on the endpoint kind. The value must be `ip` or `identity`; any other value returns `400`.\n\nEach entry must match one of the per-field patterns below: the field\nmust be one of `name`, `id`, or `kind`; `name`/`id` accept any value,\nwhile `kind` only accepts `ip` or `identity`."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"ips","type":"List[String]","description":"Specify the list of CIDRs to restrict ingress connections."},{"name":"name","type":"String","description":"Specify the name of the proxy endpoint."},{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The proxy endpoint kind"},{"name":"subdomain","type":"String","description":"Specify the subdomain to use as the destination in the proxy client."},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/gateway/proxy_endpoints/{}":{"operationId":"zero-trust-gateway-proxy-endpoints-proxy-endpoint-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_proxy_endpoint","stainlessResource":"zero_trust.gateway.proxy_endpoints","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_proxy_endpoint\" \"example_zero_trust_gateway_proxy_endpoint\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n proxy_endpoint_id = \"ed35569b41ce4d1facfe683550f54086\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"proxy_endpoint_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"filter","type":"List[String]","description":"Filter the returned proxy endpoints by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (an endpoint must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the endpoint name.\n * `id` — substring match on the endpoint ID (UUID), with or without dashes.\n * `kind` — exact match on the endpoint kind. The value must be `ip` or `identity`; any other value returns `400`.\n\nEach entry must match one of the per-field patterns below: the field\nmust be one of `name`, `id`, or `kind`; `name`/`id` accept any value,\nwhile `kind` only accepts `ip` or `identity`."},{"name":"order_by","type":"String","description":"Field to sort the returned endpoints by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by endpoint name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the endpoint name. When combined\nwith `filter`, both must match (logical AND)."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The proxy endpoint kind"},{"name":"name","type":"String","description":"Specify the name of the proxy endpoint."},{"name":"subdomain","type":"String","description":"Specify the subdomain to use as the destination in the proxy client."},{"name":"updated_at","type":"Time"},{"name":"ips","type":"List[String]","description":"Specify the list of CIDRs to restrict ingress connections."}]}]},"get /accounts/{}/gateway/rules":{"operationId":"zero-trust-gateway-rules-list-zero-trust-gateway-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_policies","stainlessResource":"zero_trust.gateway.rules","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_policies\" \"example_zero_trust_gateway_policies\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. When `order_by` is omitted, this controls the direction\nof the existing precedence ordering. Shared rules remain first in either\ndirection. Accepted values are `asc` and `desc`."},{"name":"order_by","type":"String","description":"Field to sort the returned rules by. Supported values are `name`,\n`created_at`, `updated_at`, and `precedence`."},{"name":"search","type":"String","description":"Case-insensitive substring search across rule name and description."},{"name":"filter","type":"List[String]","description":"Filter the returned rules by one or more `field:value` pairs. Repeat the\nparameter to combine filters with logical AND.\n\nSupported fields are `name`, `id`, `action`, `enabled`, `source_account`,\n`is_shared`, `filters`, and `expression` (max 1024 bytes). The `source_account`\nvalue is matched as a normalized UUID substring. The `filters` value must\nbe one of the rule filter names and matches a member of the rule's `filters`\narray. The `expression` filter performs a case-insensitive literal\nsubstring match across traffic, identity, and device posture expressions."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"action","type":"String","description":"Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`."},{"name":"enabled","type":"Bool","description":"Specify whether the rule is enabled."},{"name":"filters","type":"List[String]","description":"Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value."},{"name":"name","type":"String","description":"Specify the rule name."},{"name":"precedence","type":"Int64","description":"Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform."},{"name":"traffic","type":"String","description":"Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"deleted_at","type":"Time","description":"Indicate the date of deletion, if any."},{"name":"description","type":"String","description":"Specify the rule description."},{"name":"device_posture","type":"String","description":"Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"expiration","type":"Attributes","description":"Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.","children":[{"name":"expires_at","type":"Time","description":"Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time."},{"name":"duration","type":"Int64","description":"Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule."},{"name":"expired","type":"Bool","description":"Indicates whether the policy is expired."}]},{"name":"identity","type":"String","description":"Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"read_only","type":"Bool","description":"Indicate that this rule is shared via the Orgs API and read only."},{"name":"rule_settings","type":"Attributes","description":"Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.","children":[{"name":"add_headers","type":"Map[List[String]]","description":"Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"allow_child_bypass","type":"Bool","description":"Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules."},{"name":"audit_ssh","type":"Attributes","description":"Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.","children":[{"name":"command_logging","type":"Bool","description":"Enable SSH command logging."}]},{"name":"biso_admin_controls","type":"Attributes","description":"Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.","children":[{"name":"copy","type":"String","description":"Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\"."},{"name":"dcp","type":"Bool","description":"Set to false to enable copy-pasting. Only applies when `version == \"v1\"`."},{"name":"dd","type":"Bool","description":"Set to false to enable downloading. Only applies when `version == \"v1\"`."},{"name":"dk","type":"Bool","description":"Set to false to enable keyboard usage. Only applies when `version == \"v1\"`."},{"name":"download","type":"String","description":"Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\"."},{"name":"dp","type":"Bool","description":"Set to false to enable printing. Only applies when `version == \"v1\"`."},{"name":"du","type":"Bool","description":"Set to false to enable uploading. Only applies when `version == \"v1\"`."},{"name":"keyboard","type":"String","description":"Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\"."},{"name":"paste","type":"String","description":"Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\"."},{"name":"printing","type":"String","description":"Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\"."},{"name":"upload","type":"String","description":"Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\"."},{"name":"version","type":"String","description":"Indicate which version of the browser isolation controls should apply."},{"name":"wm_id","type":"String","description":"Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser."}]},{"name":"block_page","type":"Attributes","description":"Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."}]},{"name":"block_page_enabled","type":"Bool","description":"Enable the custom block page. Settable only for `dns` rules with action `block`."},{"name":"block_reason","type":"String","description":"Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`."},{"name":"bypass_parent_rule","type":"Bool","description":"Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules."},{"name":"check_session","type":"Attributes","description":"Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.","children":[{"name":"duration","type":"String","description":"Sets the required session freshness threshold. The API returns a normalized version of this value."},{"name":"enforce","type":"Bool","description":"Enable session enforcement."}]},{"name":"delete_headers","type":"List[String]","description":"Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`."},{"name":"dns_resolvers","type":"Attributes","description":"Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"ipv4","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv4 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]},{"name":"ipv6","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv6 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]}]},{"name":"egress","type":"Attributes","description":"Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.","children":[{"name":"ipv4","type":"String","description":"Specify the IPv4 address to use for egress."},{"name":"ipv4_fallback","type":"String","description":"Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs."},{"name":"ipv6","type":"String","description":"Specify the IPv6 range to use for egress."}]},{"name":"forensic_copy","type":"Attributes","description":"Configure whether a copy of the HTTP request will be sent to storage when the rule matches.","children":[{"name":"enabled","type":"Bool","description":"Enable sending the copy to storage."}]},{"name":"ignore_cname_category_matches","type":"Bool","description":"Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules."},{"name":"insecure_disable_dnssec_validation","type":"Bool","description":"Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules."},{"name":"ip_categories","type":"Bool","description":"Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules."},{"name":"ip_indicator_feeds","type":"Bool","description":"Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules."},{"name":"l4override","type":"Attributes","description":"Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.","children":[{"name":"ip","type":"String","description":"Defines the IPv4 or IPv6 address."},{"name":"port","type":"Int64","description":"Defines a port number to use for TCP/UDP overrides."}]},{"name":"notification_settings","type":"Attributes","description":"Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.","children":[{"name":"enabled","type":"Bool","description":"Enable notification."},{"name":"include_context","type":"Bool","description":"Indicates whether to pass the context information as query parameters."},{"name":"msg","type":"String","description":"Customize the message shown in the notification."},{"name":"support_url","type":"String","description":"Defines an optional URL to direct users to additional information. If unset, the notification opens a block page."}]},{"name":"override_host","type":"String","description":"Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"override_ips","type":"List[String]","description":"Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"payload_log","type":"Attributes","description":"Configure DLP payload logging. Settable only for `http` rules.","children":[{"name":"enabled","type":"Bool","description":"Enable DLP payload logging for this rule."}]},{"name":"quarantine","type":"Attributes","description":"Configure settings that apply to quarantine rules. Settable only for `http` rules.","children":[{"name":"file_types","type":"List[String]","description":"Specify the types of files to sandbox."}]},{"name":"redirect","type":"Attributes","description":"Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."},{"name":"preserve_path_and_query","type":"Bool","description":"Specify whether to append the path and query parameters from the original request to target_uri."}]},{"name":"resolve_dns_internally","type":"Attributes","description":"Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"fallback","type":"String","description":"Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries."},{"name":"view_id","type":"String","description":"Specify the internal DNS view identifier to pass to the internal DNS service."}]},{"name":"resolve_dns_through_cloudflare","type":"Bool","description":"Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules."},{"name":"set_headers","type":"Map[List[String]]","description":"Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"untrusted_cert","type":"Attributes","description":"Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.","children":[{"name":"action","type":"String","description":"Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526."}]}]},{"name":"schedule","type":"Attributes","description":"Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.","children":[{"name":"fri","type":"String","description":"Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"mon","type":"String","description":"Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sat","type":"String","description":"Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sun","type":"String","description":"Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"thu","type":"String","description":"Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"time_zone","type":"String","description":"Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location."},{"name":"tue","type":"String","description":"Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"wed","type":"String","description":"Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."}]},{"name":"sharable","type":"Bool","description":"Indicate that this rule is sharable via the Orgs API."},{"name":"source_account","type":"String","description":"Provide the account tag of the account that created the rule."},{"name":"updated_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicate the version number of the rule(read-only)."},{"name":"warning_status","type":"String","description":"Indicate a warning for a misconfigured rule, if any."}]}]}]},"get /accounts/{}/gateway/rules/{}":{"operationId":"zero-trust-gateway-rules-zero-trust-gateway-rule-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_policy","stainlessResource":"zero_trust.gateway.rules","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_policy\" \"example_zero_trust_gateway_policy\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"rule_id","type":"String","description":"Identify the API resource with a UUID."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. When `order_by` is omitted, this controls the direction\nof the existing precedence ordering. Shared rules remain first in either\ndirection. Accepted values are `asc` and `desc`."},{"name":"filter","type":"List[String]","description":"Filter the returned rules by one or more `field:value` pairs. Repeat the\nparameter to combine filters with logical AND.\n\nSupported fields are `name`, `id`, `action`, `enabled`, `source_account`,\n`is_shared`, `filters`, and `expression` (max 1024 bytes). The `source_account`\nvalue is matched as a normalized UUID substring. The `filters` value must\nbe one of the rule filter names and matches a member of the rule's `filters`\narray. The `expression` filter performs a case-insensitive literal\nsubstring match across traffic, identity, and device posture expressions."},{"name":"order_by","type":"String","description":"Field to sort the returned rules by. Supported values are `name`,\n`created_at`, `updated_at`, and `precedence`."},{"name":"search","type":"String","description":"Case-insensitive substring search across rule name and description."}]}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"action","type":"String","description":"Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`."},{"name":"created_at","type":"Time"},{"name":"deleted_at","type":"Time","description":"Indicate the date of deletion, if any."},{"name":"description","type":"String","description":"Specify the rule description."},{"name":"device_posture","type":"String","description":"Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"enabled","type":"Bool","description":"Specify whether the rule is enabled."},{"name":"identity","type":"String","description":"Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"name","type":"String","description":"Specify the rule name."},{"name":"precedence","type":"Int64","description":"Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform."},{"name":"read_only","type":"Bool","description":"Indicate that this rule is shared via the Orgs API and read only."},{"name":"sharable","type":"Bool","description":"Indicate that this rule is sharable via the Orgs API."},{"name":"source_account","type":"String","description":"Provide the account tag of the account that created the rule."},{"name":"traffic","type":"String","description":"Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"updated_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicate the version number of the rule(read-only)."},{"name":"warning_status","type":"String","description":"Indicate a warning for a misconfigured rule, if any."},{"name":"filters","type":"List[String]","description":"Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value."},{"name":"expiration","type":"Attributes","description":"Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.","children":[{"name":"expires_at","type":"Time","description":"Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time."},{"name":"duration","type":"Int64","description":"Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule."},{"name":"expired","type":"Bool","description":"Indicates whether the policy is expired."}]},{"name":"rule_settings","type":"Attributes","description":"Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.","children":[{"name":"add_headers","type":"Map[List[String]]","description":"Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"allow_child_bypass","type":"Bool","description":"Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules."},{"name":"audit_ssh","type":"Attributes","description":"Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.","children":[{"name":"command_logging","type":"Bool","description":"Enable SSH command logging."}]},{"name":"biso_admin_controls","type":"Attributes","description":"Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.","children":[{"name":"copy","type":"String","description":"Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\"."},{"name":"dcp","type":"Bool","description":"Set to false to enable copy-pasting. Only applies when `version == \"v1\"`."},{"name":"dd","type":"Bool","description":"Set to false to enable downloading. Only applies when `version == \"v1\"`."},{"name":"dk","type":"Bool","description":"Set to false to enable keyboard usage. Only applies when `version == \"v1\"`."},{"name":"download","type":"String","description":"Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\"."},{"name":"dp","type":"Bool","description":"Set to false to enable printing. Only applies when `version == \"v1\"`."},{"name":"du","type":"Bool","description":"Set to false to enable uploading. Only applies when `version == \"v1\"`."},{"name":"keyboard","type":"String","description":"Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\"."},{"name":"paste","type":"String","description":"Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\"."},{"name":"printing","type":"String","description":"Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\"."},{"name":"upload","type":"String","description":"Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\"."},{"name":"version","type":"String","description":"Indicate which version of the browser isolation controls should apply."},{"name":"wm_id","type":"String","description":"Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser."}]},{"name":"block_page","type":"Attributes","description":"Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."}]},{"name":"block_page_enabled","type":"Bool","description":"Enable the custom block page. Settable only for `dns` rules with action `block`."},{"name":"block_reason","type":"String","description":"Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`."},{"name":"bypass_parent_rule","type":"Bool","description":"Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules."},{"name":"check_session","type":"Attributes","description":"Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.","children":[{"name":"duration","type":"String","description":"Sets the required session freshness threshold. The API returns a normalized version of this value."},{"name":"enforce","type":"Bool","description":"Enable session enforcement."}]},{"name":"delete_headers","type":"List[String]","description":"Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`."},{"name":"dns_resolvers","type":"Attributes","description":"Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"ipv4","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv4 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]},{"name":"ipv6","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv6 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]}]},{"name":"egress","type":"Attributes","description":"Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.","children":[{"name":"ipv4","type":"String","description":"Specify the IPv4 address to use for egress."},{"name":"ipv4_fallback","type":"String","description":"Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs."},{"name":"ipv6","type":"String","description":"Specify the IPv6 range to use for egress."}]},{"name":"forensic_copy","type":"Attributes","description":"Configure whether a copy of the HTTP request will be sent to storage when the rule matches.","children":[{"name":"enabled","type":"Bool","description":"Enable sending the copy to storage."}]},{"name":"ignore_cname_category_matches","type":"Bool","description":"Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules."},{"name":"insecure_disable_dnssec_validation","type":"Bool","description":"Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules."},{"name":"ip_categories","type":"Bool","description":"Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules."},{"name":"ip_indicator_feeds","type":"Bool","description":"Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules."},{"name":"l4override","type":"Attributes","description":"Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.","children":[{"name":"ip","type":"String","description":"Defines the IPv4 or IPv6 address."},{"name":"port","type":"Int64","description":"Defines a port number to use for TCP/UDP overrides."}]},{"name":"notification_settings","type":"Attributes","description":"Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.","children":[{"name":"enabled","type":"Bool","description":"Enable notification."},{"name":"include_context","type":"Bool","description":"Indicates whether to pass the context information as query parameters."},{"name":"msg","type":"String","description":"Customize the message shown in the notification."},{"name":"support_url","type":"String","description":"Defines an optional URL to direct users to additional information. If unset, the notification opens a block page."}]},{"name":"override_host","type":"String","description":"Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"override_ips","type":"List[String]","description":"Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"payload_log","type":"Attributes","description":"Configure DLP payload logging. Settable only for `http` rules.","children":[{"name":"enabled","type":"Bool","description":"Enable DLP payload logging for this rule."}]},{"name":"quarantine","type":"Attributes","description":"Configure settings that apply to quarantine rules. Settable only for `http` rules.","children":[{"name":"file_types","type":"List[String]","description":"Specify the types of files to sandbox."}]},{"name":"redirect","type":"Attributes","description":"Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."},{"name":"preserve_path_and_query","type":"Bool","description":"Specify whether to append the path and query parameters from the original request to target_uri."}]},{"name":"resolve_dns_internally","type":"Attributes","description":"Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"fallback","type":"String","description":"Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries."},{"name":"view_id","type":"String","description":"Specify the internal DNS view identifier to pass to the internal DNS service."}]},{"name":"resolve_dns_through_cloudflare","type":"Bool","description":"Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules."},{"name":"set_headers","type":"Map[List[String]]","description":"Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"untrusted_cert","type":"Attributes","description":"Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.","children":[{"name":"action","type":"String","description":"Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526."}]}]},{"name":"schedule","type":"Attributes","description":"Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.","children":[{"name":"fri","type":"String","description":"Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"mon","type":"String","description":"Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sat","type":"String","description":"Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sun","type":"String","description":"Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"thu","type":"String","description":"Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"time_zone","type":"String","description":"Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location."},{"name":"tue","type":"String","description":"Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"wed","type":"String","description":"Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."}]}]}]},"get /accounts/{}/hyperdrive/configs":{"operationId":"list-hyperdrive","declarations":[{"kind":"list-data-source","name":"cloudflare_hyperdrive_configs","stainlessResource":"hyperdrive.configs","methodName":"list","snippet":"data \"cloudflare_hyperdrive_configs\" \"example_hyperdrive_configs\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Define configurations using a unique string identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"caching","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Defines whether caching is disabled."},{"name":"max_age","type":"Int64","description":"Defines the maximum duration (in seconds) items persist in the cache."},{"name":"stale_while_revalidate","type":"Int64","description":"Defines the number of seconds the cache may serve a stale response."}]},{"name":"name","type":"String","description":"The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API."},{"name":"origin","type":"Attributes","description":"Combines database connection fields with exactly one supported network location.","children":[{"name":"database","type":"String","description":"Set the name of your origin database."},{"name":"host","type":"String","description":"Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed."},{"name":"password","type":"String","description":"Set the password needed to access your origin database. The API never returns this write-only value.","sensitive":true},{"name":"port","type":"Int64","description":"Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"user","type":"String","description":"Set the user of your origin database."},{"name":"access_client_id","type":"String","description":"Defines the Client ID of the Access token to use when connecting to the origin database."},{"name":"access_client_secret","type":"String","description":"Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.","sensitive":true},{"name":"service_id","type":"String","description":"The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database."}]},{"name":"created_on","type":"Time","description":"Defines the creation time of the Hyperdrive configuration."},{"name":"integration","type":"Attributes","description":"Connects to a PlanetScale database using credentials managed by Cloudflare. The Cloudflare account must already be linked to PlanetScale in the Hyperdrive dashboard.","children":[{"name":"database_branch_name","type":"String","description":"The name of the PlanetScale database branch."},{"name":"database_name","type":"String","description":"The name of the PlanetScale database."},{"name":"organization_name","type":"String","description":"The name of the PlanetScale organization."},{"name":"hyperdrive_config_provider","type":"String","description":"The database integration provider used by this operation."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"custom_database_name","type":"String","description":"The database name to use when connecting. Defaults to `postgres` for PostgreSQL and `mysql` for MySQL."}]},{"name":"modified_on","type":"Time","description":"Defines the last modified time of the Hyperdrive configuration."},{"name":"mtls","type":"Attributes","description":"mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.","children":[{"name":"ca_certificate_id","type":"String","description":"Define CA certificate ID obtained after uploading CA cert."},{"name":"mtls_certificate_id","type":"String","description":"Define mTLS certificate ID obtained after uploading client cert."},{"name":"sslmode","type":"String","description":"PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate."}]},{"name":"origin_connection_limit","type":"Int64","description":"The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit.\n"},{"name":"restarted_on","type":"Time","description":"Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted."}]}]}]},"get /accounts/{}/hyperdrive/configs/{}":{"operationId":"get-hyperdrive","declarations":[{"kind":"data-source","name":"cloudflare_hyperdrive_config","stainlessResource":"hyperdrive.configs","methodName":"get","snippet":"data \"cloudflare_hyperdrive_config\" \"example_hyperdrive_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hyperdrive_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"hyperdrive_id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"account_id","type":"String","description":"Define configurations using a unique string identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"created_on","type":"Time","description":"Defines the creation time of the Hyperdrive configuration."},{"name":"modified_on","type":"Time","description":"Defines the last modified time of the Hyperdrive configuration."},{"name":"name","type":"String","description":"The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API."},{"name":"origin_connection_limit","type":"Int64","description":"The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit.\n"},{"name":"restarted_on","type":"Time","description":"Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted."},{"name":"caching","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Defines whether caching is disabled."},{"name":"max_age","type":"Int64","description":"Defines the maximum duration (in seconds) items persist in the cache."},{"name":"stale_while_revalidate","type":"Int64","description":"Defines the number of seconds the cache may serve a stale response."}]},{"name":"integration","type":"Attributes","description":"Connects to a PlanetScale database using credentials managed by Cloudflare. The Cloudflare account must already be linked to PlanetScale in the Hyperdrive dashboard.","children":[{"name":"database_branch_name","type":"String","description":"The name of the PlanetScale database branch."},{"name":"database_name","type":"String","description":"The name of the PlanetScale database."},{"name":"organization_name","type":"String","description":"The name of the PlanetScale organization."},{"name":"hyperdrive_config_provider","type":"String","description":"The database integration provider used by this operation."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"custom_database_name","type":"String","description":"The database name to use when connecting. Defaults to `postgres` for PostgreSQL and `mysql` for MySQL."}]},{"name":"mtls","type":"Attributes","description":"mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.","children":[{"name":"ca_certificate_id","type":"String","description":"Define CA certificate ID obtained after uploading CA cert."},{"name":"mtls_certificate_id","type":"String","description":"Define mTLS certificate ID obtained after uploading client cert."},{"name":"sslmode","type":"String","description":"PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate."}]},{"name":"origin","type":"Attributes","description":"Combines database connection fields with exactly one supported network location.","children":[{"name":"database","type":"String","description":"Set the name of your origin database."},{"name":"host","type":"String","description":"Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed."},{"name":"password","type":"String","description":"Set the password needed to access your origin database. The API never returns this write-only value.","sensitive":true},{"name":"port","type":"Int64","description":"Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"user","type":"String","description":"Set the user of your origin database."},{"name":"access_client_id","type":"String","description":"Defines the Client ID of the Access token to use when connecting to the origin database."},{"name":"access_client_secret","type":"String","description":"Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.","sensitive":true},{"name":"service_id","type":"String","description":"The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database."}]}]}]},"get /accounts/{}/iam/permission_groups":{"operationId":"account-permission-group-list","declarations":[{"kind":"list-data-source","name":"cloudflare_account_permission_groups","stainlessResource":"iam.permission_groups","methodName":"list","snippet":"data \"cloudflare_account_permission_groups\" \"example_account_permission_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"6d7f2f5f5b1d4a0e9081fdc98d432fd1\"\n label = \"labelOfThePermissionGroup\"\n name = \"NameOfThePermissionGroup\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"id","type":"String","description":"ID of the permission group to be fetched."},{"name":"label","type":"String","description":"Label of the permission group to be fetched."},{"name":"name","type":"String","description":"Name of the permission group to be fetched."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]}]}]},"get /accounts/{}/iam/permission_groups/{}":{"operationId":"account-permission-group-details","declarations":[{"kind":"data-source","name":"cloudflare_account_permission_group","stainlessResource":"iam.permission_groups","methodName":"get","snippet":"data \"cloudflare_account_permission_group\" \"example_account_permission_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n permission_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"permission_group_id","type":"String","description":"Permission Group identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"name","type":"String","description":"Name of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]}]}]},"get /accounts/{}/iam/resource_groups":{"operationId":"account-resource-group-list","declarations":[{"kind":"list-data-source","name":"cloudflare_resource_groups","stainlessResource":"iam.resource_groups","methodName":"list","snippet":"data \"cloudflare_resource_groups\" \"example_resource_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"NameOfTheResourceGroup\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"id","type":"String","description":"ID of the resource group to be fetched."},{"name":"name","type":"String","description":"Name of the resource group to be fetched."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]}]},"get /accounts/{}/iam/resource_groups/{}":{"operationId":"account-resource-group-details","declarations":[{"kind":"data-source","name":"cloudflare_resource_group","stainlessResource":"iam.resource_groups","methodName":"get","snippet":"data \"cloudflare_resource_group\" \"example_resource_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"resource_group_id","type":"String","description":"Resource Group identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"name","type":"String","description":"Name of the resource group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]}]}]},"get /accounts/{}/iam/user_groups":{"operationId":"account-user-group-list","declarations":[{"kind":"list-data-source","name":"cloudflare_user_groups","stainlessResource":"iam.user_groups","methodName":"list","snippet":"data \"cloudflare_user_groups\" \"example_user_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n fuzzy_name = \"Foo\"\n name = \"NameOfTheUserGroup\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"fuzzy_name","type":"String","description":"A string used for searching for user groups containing that substring."},{"name":"id","type":"String","description":"ID of the user group to be fetched."},{"name":"name","type":"String","description":"Name of the user group to be fetched."},{"name":"direction","type":"String","description":"The sort order of returned user groups by name (ascending or descending)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the user group"},{"name":"modified_on","type":"Time","description":"Last time the user group was modified."},{"name":"name","type":"String","description":"Name of the user group."},{"name":"policies","type":"List[Attributes]","description":"Policies attached to the User group","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]}]}]}]},"get /accounts/{}/iam/user_groups/{}":{"operationId":"account-user-group-details","declarations":[{"kind":"data-source","name":"cloudflare_user_group","stainlessResource":"iam.user_groups","methodName":"get","snippet":"data \"cloudflare_user_group\" \"example_user_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"user_group_id","type":"String","description":"User Group identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"ID of the user group to be fetched."},{"name":"direction","type":"String","description":"The sort order of returned user groups by name (ascending or descending)."},{"name":"fuzzy_name","type":"String","description":"A string used for searching for user groups containing that substring."},{"name":"name","type":"String","description":"Name of the user group to be fetched."}]}],"computed":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the user group"},{"name":"modified_on","type":"Time","description":"Last time the user group was modified."},{"name":"name","type":"String","description":"Name of the user group."},{"name":"policies","type":"List[Attributes]","description":"Policies attached to the User group","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]}]}]},"get /accounts/{}/iam/user_groups/{}/members":{"operationId":"account-user-group-member-list","declarations":[{"kind":"data-source","name":"cloudflare_user_group_members","stainlessResource":"iam.user_groups.members","methodName":"list","snippet":"data \"cloudflare_user_group_members\" \"example_user_group_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n fuzzy_email = \"user@\"\n}\n","required":[{"name":"user_group_id","type":"String","description":"User Group identifier tag."},{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"fuzzy_email","type":"String","description":"A string used for filtering members by partial email match."},{"name":"direction","type":"String","description":"The sort order of returned user group members by email."}],"computed":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"status","type":"String","description":"The member's status in the account."}]}]},"get /accounts/{}/images/v1":{"operationId":"cloudflare-images-list-images","declarations":[{"kind":"list-data-source","name":"cloudflare_images","stainlessResource":"images.v1","methodName":"list","snippet":"data \"cloudflare_images\" \"example_images\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n creator = \"creator\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"creator","type":"String","description":"Internal user ID set within the creator field. Setting to empty string \"\" will return images where creator field is not set"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"images","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Image unique identifier."},{"name":"creator","type":"String","description":"Can set the creator field with an internal user ID."},{"name":"filename","type":"String","description":"Image file name."},{"name":"meta","type":"unknown","description":"User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the image can be a accessed only using it's UID. If set to true, a signed token needs to be generated with a signing key to view the image."},{"name":"uploaded","type":"Time","description":"When the media item was uploaded."},{"name":"variants","type":"List[String]","description":"Object specifying available variants for an image."}]}]}]}]},"get /accounts/{}/images/v1/{}":{"operationId":"cloudflare-images-image-details","declarations":[{"kind":"data-source","name":"cloudflare_image","stainlessResource":"images.v1","methodName":"get","snippet":"data \"cloudflare_image\" \"example_image\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n image_id = \"image_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"image_id","type":"String","description":"Image unique identifier."}],"optional":[],"computed":[{"name":"creator","type":"String","description":"Can set the creator field with an internal user ID."},{"name":"filename","type":"String","description":"Image file name."},{"name":"id","type":"String","description":"Image unique identifier."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the image can be a accessed only using it's UID. If set to true, a signed token needs to be generated with a signing key to view the image."},{"name":"uploaded","type":"Time","description":"When the media item was uploaded."},{"name":"variants","type":"List[String]","description":"Object specifying available variants for an image."},{"name":"meta","type":"unknown","description":"User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes."}]}]},"get /accounts/{}/images/v1/variants/{}":{"operationId":"cloudflare-images-variants-variant-details","declarations":[{"kind":"data-source","name":"cloudflare_image_variant","stainlessResource":"images.v1.variants","methodName":"get","snippet":"data \"cloudflare_image_variant\" \"example_image_variant\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n variant_id = \"hero\"\n}\n","required":[{"name":"variant_id","type":"String"},{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"variant","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"options","type":"Attributes","description":"Allows you to define image resizing sizes for different use cases.","children":[{"name":"fit","type":"String","description":"The fit property describes how the width and height dimensions should be interpreted."},{"name":"height","type":"Float64","description":"Maximum height in image pixels."},{"name":"metadata","type":"String","description":"What EXIF data should be preserved in the output image."},{"name":"width","type":"Float64","description":"Maximum width in image pixels."}]},{"name":"never_require_signed_urls","type":"Bool","description":"Indicates whether the variant can access an image without a signature, regardless of image access control."}]}]}]},"get /accounts/{}/infrastructure/targets":{"operationId":"infra-targets-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_infrastructure_targets","stainlessResource":"zero_trust.access.infrastructure.targets","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_infrastructure_targets\" \"example_zero_trust_access_infrastructure_targets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_after = \"2019-12-27T18:11:19.117Z\"\n created_before = \"2019-12-27T18:11:19.117Z\"\n direction = \"asc\"\n hostname = \"hostname\"\n hostname_contains = \"hostname_contains\"\n ip_like = \"ip_like\"\n ip_v4 = \"ip_v4\"\n ip_v6 = \"ip_v6\"\n ips = [\"string\"]\n ipv4_end = \"ipv4_end\"\n ipv4_start = \"ipv4_start\"\n ipv6_end = \"ipv6_end\"\n ipv6_start = \"ipv6_start\"\n modified_after = \"2019-12-27T18:11:19.117Z\"\n modified_before = \"2019-12-27T18:11:19.117Z\"\n order = \"hostname\"\n tag = [\"string\"]\n target_ids = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n virtual_network_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier"}],"optional":[{"name":"created_after","type":"Time","description":"Date and time at which the target was created after (inclusive)"},{"name":"created_before","type":"Time","description":"Date and time at which the target was created before (inclusive)"},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"hostname","type":"String","description":"Hostname of a target"},{"name":"hostname_contains","type":"String","description":"Partial match to the hostname of a target"},{"name":"ip_like","type":"String","description":"Filters for targets whose IP addresses look like the specified string.\nSupports `*` as a wildcard character"},{"name":"ip_v4","type":"String","description":"IPv4 address of the target"},{"name":"ip_v6","type":"String","description":"IPv6 address of the target"},{"name":"ipv4_end","type":"String","description":"Defines an IPv4 filter range's ending value (inclusive). Requires\n`ipv4_start` to be specified as well."},{"name":"ipv4_start","type":"String","description":"Defines an IPv4 filter range's starting value (inclusive). Requires\n`ipv4_end` to be specified as well."},{"name":"ipv6_end","type":"String","description":"Defines an IPv6 filter range's ending value (inclusive). Requires\n`ipv6_start` to be specified as well."},{"name":"ipv6_start","type":"String","description":"Defines an IPv6 filter range's starting value (inclusive). Requires\n`ipv6_end` to be specified as well."},{"name":"modified_after","type":"Time","description":"Date and time at which the target was modified after (inclusive)"},{"name":"modified_before","type":"Time","description":"Date and time at which the target was modified before (inclusive)"},{"name":"order","type":"String","description":"The field to sort by."},{"name":"virtual_network_id","type":"String","description":"Private virtual network identifier of the target"},{"name":"ips","type":"List[String]","description":"Filters for targets that have any of the following IP addresses. Specify\n`ips` multiple times in query parameter to build list of candidates."},{"name":"tag","type":"List[String]","description":"Filter by tag key:value pairs. Multiple `tag` params are AND'd.\nFormat: `tag=key:value` (e.g., `tag=environment:production`).\nKey and value must both be non-empty; `tag=:value` and `tag=key:` return 400."},{"name":"target_ids","type":"List[String]","description":"Filters for targets that have any of the following UUIDs. Specify\n`target_ids` multiple times in query parameter to build list of\ncandidates."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Target identifier"},{"name":"created_at","type":"Time","description":"Date and time at which the target was created"},{"name":"hostname","type":"String","description":"A non-unique field that refers to a target"},{"name":"ip","type":"Attributes","description":"The IPv4/IPv6 address that identifies where to reach a target","children":[{"name":"ipv4","type":"Attributes","description":"The target's IPv4 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]},{"name":"ipv6","type":"Attributes","description":"The target's IPv6 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]}]},{"name":"modified_at","type":"Time","description":"Date and time at which the target was modified"},{"name":"tags","type":"Map[String]","description":"Tags assigned to the target. Empty when no tags are assigned."}]}]}]},"get /accounts/{}/infrastructure/targets/{}":{"operationId":"infra-targets-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_infrastructure_target","stainlessResource":"zero_trust.access.infrastructure.targets","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_infrastructure_target\" \"example_zero_trust_access_infrastructure_target\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n target_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier"}],"optional":[{"name":"target_id","type":"String","description":"Target identifier"},{"name":"filter","type":"Attributes","children":[{"name":"created_after","type":"Time","description":"Date and time at which the target was created after (inclusive)"},{"name":"created_before","type":"Time","description":"Date and time at which the target was created before (inclusive)"},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"hostname","type":"String","description":"Hostname of a target"},{"name":"hostname_contains","type":"String","description":"Partial match to the hostname of a target"},{"name":"ip_like","type":"String","description":"Filters for targets whose IP addresses look like the specified string.\nSupports `*` as a wildcard character"},{"name":"ip_v4","type":"String","description":"IPv4 address of the target"},{"name":"ip_v6","type":"String","description":"IPv6 address of the target"},{"name":"ips","type":"List[String]","description":"Filters for targets that have any of the following IP addresses. Specify\n`ips` multiple times in query parameter to build list of candidates."},{"name":"ipv4_end","type":"String","description":"Defines an IPv4 filter range's ending value (inclusive). Requires\n`ipv4_start` to be specified as well."},{"name":"ipv4_start","type":"String","description":"Defines an IPv4 filter range's starting value (inclusive). Requires\n`ipv4_end` to be specified as well."},{"name":"ipv6_end","type":"String","description":"Defines an IPv6 filter range's ending value (inclusive). Requires\n`ipv6_start` to be specified as well."},{"name":"ipv6_start","type":"String","description":"Defines an IPv6 filter range's starting value (inclusive). Requires\n`ipv6_end` to be specified as well."},{"name":"modified_after","type":"Time","description":"Date and time at which the target was modified after (inclusive)"},{"name":"modified_before","type":"Time","description":"Date and time at which the target was modified before (inclusive)"},{"name":"order","type":"String","description":"The field to sort by."},{"name":"tag","type":"List[String]","description":"Filter by tag key:value pairs. Multiple `tag` params are AND'd.\nFormat: `tag=key:value` (e.g., `tag=environment:production`).\nKey and value must both be non-empty; `tag=:value` and `tag=key:` return 400."},{"name":"target_ids","type":"List[String]","description":"Filters for targets that have any of the following UUIDs. Specify\n`target_ids` multiple times in query parameter to build list of\ncandidates."},{"name":"virtual_network_id","type":"String","description":"Private virtual network identifier of the target"}]}],"computed":[{"name":"id","type":"String","description":"Target identifier"},{"name":"created_at","type":"Time","description":"Date and time at which the target was created"},{"name":"hostname","type":"String","description":"A non-unique field that refers to a target"},{"name":"modified_at","type":"Time","description":"Date and time at which the target was modified"},{"name":"tags","type":"Map[String]","description":"Tags assigned to the target. Empty when no tags are assigned."},{"name":"ip","type":"Attributes","description":"The IPv4/IPv6 address that identifies where to reach a target","children":[{"name":"ipv4","type":"Attributes","description":"The target's IPv4 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]},{"name":"ipv6","type":"Attributes","description":"The target's IPv6 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]}]}]}]},"get /accounts/{}/load_balancers/monitor_groups":{"operationId":"account-load-balancer-monitor-groups-list-monitor-groups","declarations":[{"kind":"list-data-source","name":"cloudflare_load_balancer_monitor_groups","stainlessResource":"load_balancers.monitor_groups","methodName":"list","snippet":"data \"cloudflare_load_balancer_monitor_groups\" \"example_load_balancer_monitor_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"description","type":"String","description":"A short description of the monitor group"},{"name":"members","type":"Set[Attributes]","description":"List of monitors in this group","children":[{"name":"enabled","type":"Bool","description":"Whether this monitor is enabled in the group"},{"name":"monitor_id","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitoring_only","type":"Bool","description":"Whether this monitor is used for monitoring only (does not affect pool health)"},{"name":"must_be_healthy","type":"Bool","description":"Whether this monitor must be healthy for the pool to be considered healthy"},{"name":"created_at","type":"Time","description":"The timestamp of when the monitor was added to the group"},{"name":"updated_at","type":"Time","description":"The timestamp of when the monitor group member was last updated"}]},{"name":"created_on","type":"Time","description":"The timestamp of when the monitor group was created"},{"name":"modified_on","type":"Time","description":"The timestamp of when the monitor group was last updated"}]}]}]},"get /accounts/{}/load_balancers/monitor_groups/{}":{"operationId":"account-load-balancer-monitor-groups-monitor-group-details","declarations":[{"kind":"data-source","name":"cloudflare_load_balancer_monitor_group","stainlessResource":"load_balancers.monitor_groups","methodName":"get","snippet":"data \"cloudflare_load_balancer_monitor_group\" \"example_load_balancer_monitor_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor_group_id = \"17b5962d775c646f3f9725cbc7a53df4\"\n}\n","required":[{"name":"monitor_group_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time","description":"The timestamp of when the monitor group was created"},{"name":"description","type":"String","description":"A short description of the monitor group"},{"name":"modified_on","type":"Time","description":"The timestamp of when the monitor group was last updated"},{"name":"members","type":"Set[Attributes]","description":"List of monitors in this group","children":[{"name":"enabled","type":"Bool","description":"Whether this monitor is enabled in the group"},{"name":"monitor_id","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitoring_only","type":"Bool","description":"Whether this monitor is used for monitoring only (does not affect pool health)"},{"name":"must_be_healthy","type":"Bool","description":"Whether this monitor must be healthy for the pool to be considered healthy"},{"name":"created_at","type":"Time","description":"The timestamp of when the monitor was added to the group"},{"name":"updated_at","type":"Time","description":"The timestamp of when the monitor group member was last updated"}]}]}]},"get /accounts/{}/load_balancers/monitors":{"operationId":"account-load-balancer-monitors-list-monitors","declarations":[{"kind":"list-data-source","name":"cloudflare_load_balancer_monitors","stainlessResource":"load_balancers.monitors","methodName":"list","snippet":"data \"cloudflare_load_balancer_monitors\" \"example_load_balancer_monitors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors."},{"name":"consecutive_down","type":"Int64","description":"To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times."},{"name":"consecutive_up","type":"Int64","description":"To be marked healthy the monitored origin must pass this healthcheck N consecutive times."},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"Object description."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"expected_codes","type":"String","description":"The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations."},{"name":"method","type":"String","description":"The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks."},{"name":"modified_on","type":"String"},{"name":"path","type":"String","description":"The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"port","type":"Int64","description":"The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)."},{"name":"probe_zone","type":"String","description":"Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'."}]}]}]},"get /accounts/{}/load_balancers/monitors/{}":{"operationId":"account-load-balancer-monitors-monitor-details","declarations":[{"kind":"data-source","name":"cloudflare_load_balancer_monitor","stainlessResource":"load_balancers.monitors","methodName":"get","snippet":"data \"cloudflare_load_balancer_monitor\" \"example_load_balancer_monitor\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor_id = \"f1aba936b94213e5b8dca0c0dbf1f9cc\"\n}\n","required":[{"name":"monitor_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors."},{"name":"consecutive_down","type":"Int64","description":"To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times."},{"name":"consecutive_up","type":"Int64","description":"To be marked healthy the monitored origin must pass this healthcheck N consecutive times."},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"Object description."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"expected_codes","type":"String","description":"The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations."},{"name":"method","type":"String","description":"The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks."},{"name":"modified_on","type":"String"},{"name":"path","type":"String","description":"The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"port","type":"Int64","description":"The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)."},{"name":"probe_zone","type":"String","description":"Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors."}]}]},"get /accounts/{}/load_balancers/pools":{"operationId":"account-load-balancer-pools-list-pools","declarations":[{"kind":"list-data-source","name":"cloudflare_load_balancer_pools","stainlessResource":"load_balancers.pools","methodName":"list","snippet":"data \"cloudflare_load_balancer_pools\" \"example_load_balancer_pools\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor = \"monitor\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means every Cloudflare data center."},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"A human-readable description of the pool."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)."},{"name":"health_sources","type":"List[String]","description":"A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions."},{"name":"latitude","type":"Float64","description":"The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set."},{"name":"load_shedding","type":"Attributes","description":"Configures load shedding policies and percentages for the pool.","children":[{"name":"default_percent","type":"Float64","description":"The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity."},{"name":"default_policy","type":"String","description":"The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs."},{"name":"session_percent","type":"Float64","description":"The percent of existing sessions to shed from the pool, according to the session policy."},{"name":"session_policy","type":"String","description":"Only the hash policy is supported for existing sessions (to avoid exponential decay)."}]},{"name":"longitude","type":"Float64","description":"The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set."},{"name":"minimum_origins","type":"Int64","description":"The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool."},{"name":"modified_on","type":"String"},{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitor_group","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"name","type":"String","description":"A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed."},{"name":"networks","type":"List[String]","description":"List of networks where Load Balancer or Pool is enabled."},{"name":"notification_email","type":"String","description":"This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list."},{"name":"notification_filter","type":"Attributes","description":"Filter pool and origin health notifications by resource type or health status. Use null to reset.","children":[{"name":"origin","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]},{"name":"pool","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]}]},{"name":"origin_steering","type":"Attributes","description":"Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.","children":[{"name":"policy","type":"String","description":"The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections."}]},{"name":"origins","type":"Set[Attributes]","description":"The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.","children":[{"name":"address","type":"String","description":"The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the origin is disabled. This field is set with the time the origin was disabled."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool."},{"name":"flatten_cname","type":"Bool","description":"Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting."},{"name":"header","type":"Attributes","description":"The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.","children":[{"name":"host","type":"List[String]","description":"The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin."}]},{"name":"name","type":"String","description":"A human-identifiable name for the origin."},{"name":"port","type":"Int64","description":"The port for upstream connections. A value of 0 means the default port for the protocol will be used."},{"name":"virtual_network_id","type":"String","description":"The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account."},{"name":"weight","type":"Float64","description":"The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections."}]}]}]}]},"get /accounts/{}/load_balancers/pools/{}":{"operationId":"account-load-balancer-pools-pool-details","declarations":[{"kind":"data-source","name":"cloudflare_load_balancer_pool","stainlessResource":"load_balancers.pools","methodName":"get","snippet":"data \"cloudflare_load_balancer_pool\" \"example_load_balancer_pool\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pool_id = \"17b5962d775c646f3f9725cbc7a53df4\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"pool_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"A human-readable description of the pool."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)."},{"name":"latitude","type":"Float64","description":"The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set."},{"name":"longitude","type":"Float64","description":"The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set."},{"name":"minimum_origins","type":"Int64","description":"The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool."},{"name":"modified_on","type":"String"},{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitor_group","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"name","type":"String","description":"A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed."},{"name":"notification_email","type":"String","description":"This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means every Cloudflare data center."},{"name":"health_sources","type":"List[String]","description":"A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions."},{"name":"networks","type":"List[String]","description":"List of networks where Load Balancer or Pool is enabled."},{"name":"load_shedding","type":"Attributes","description":"Configures load shedding policies and percentages for the pool.","children":[{"name":"default_percent","type":"Float64","description":"The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity."},{"name":"default_policy","type":"String","description":"The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs."},{"name":"session_percent","type":"Float64","description":"The percent of existing sessions to shed from the pool, according to the session policy."},{"name":"session_policy","type":"String","description":"Only the hash policy is supported for existing sessions (to avoid exponential decay)."}]},{"name":"notification_filter","type":"Attributes","description":"Filter pool and origin health notifications by resource type or health status. Use null to reset.","children":[{"name":"origin","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]},{"name":"pool","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]}]},{"name":"origin_steering","type":"Attributes","description":"Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.","children":[{"name":"policy","type":"String","description":"The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections."}]},{"name":"origins","type":"Set[Attributes]","description":"The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.","children":[{"name":"address","type":"String","description":"The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the origin is disabled. This field is set with the time the origin was disabled."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool."},{"name":"flatten_cname","type":"Bool","description":"Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting."},{"name":"header","type":"Attributes","description":"The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.","children":[{"name":"host","type":"List[String]","description":"The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin."}]},{"name":"name","type":"String","description":"A human-identifiable name for the origin."},{"name":"port","type":"Int64","description":"The port for upstream connections. A value of 0 means the default port for the protocol will be used."},{"name":"virtual_network_id","type":"String","description":"The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account."},{"name":"weight","type":"Float64","description":"The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections."}]}]}]},"get /accounts/{}/magic/bgp/filter_profiles":{"operationId":"magic-bgp-list-filter-profiles","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_wan_bgp_filter_profiles","stainlessResource":"magic_transit.bgp_filter_profiles","methodName":"list","snippet":"data \"cloudflare_magic_wan_bgp_filter_profiles\" \"example_magic_wan_bgp_filter_profiles\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"description","type":"String","description":"Description of the filter profile"},{"name":"match_action","type":"String","description":"Action to take when a route matches one of the targets in this profile"},{"name":"name","type":"String","description":"Friendly name for the filter profile"},{"name":"targets","type":"List[String]","description":"List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N."},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]}]},"get /accounts/{}/magic/bgp/filter_profiles/{}":{"operationId":"magic-bgp-get-filter-profile","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_bgp_filter_profile","stainlessResource":"magic_transit.bgp_filter_profiles","methodName":"get","snippet":"data \"cloudflare_magic_wan_bgp_filter_profile\" \"example_magic_wan_bgp_filter_profile\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n profile_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"profile_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"Description of the filter profile"},{"name":"match_action","type":"String","description":"Action to take when a route matches one of the targets in this profile"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"Friendly name for the filter profile"},{"name":"targets","type":"List[String]","description":"List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N."}]}]},"get /accounts/{}/magic/cf1_sites":{"operationId":"magic-cf1-sites-list-cf1-sites","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_cf1_sites","stainlessResource":"magic_transit.cf1_sites","methodName":"list","snippet":"data \"cloudflare_magic_transit_cf1_sites\" \"example_magic_transit_cf1_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]},{"name":"modified_on","type":"Time"}]}]}]},"get /accounts/{}/magic/cf1_sites/{}":{"operationId":"magic-cf1-sites-get-cf1-site","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_cf1_site","stainlessResource":"magic_transit.cf1_sites","methodName":"get","snippet":"data \"cloudflare_magic_transit_cf1_site\" \"example_magic_transit_cf1_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cf1_site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"cf1_site_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]}]}]},"get /accounts/{}/magic/connectors":{"operationId":"mconn-connectors-list","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_connectors","stainlessResource":"magic_transit.connectors","methodName":"list","snippet":"data \"cloudflare_magic_transit_connectors\" \"example_magic_transit_connectors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n device_type = \"MANAGED\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"device_type","type":"String","description":"Filter connectors by device type."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"activated","type":"Bool"},{"name":"interrupt_window_days_of_week","type":"List[String]","description":"Allowed days of the week for upgrades. Default is all days."},{"name":"interrupt_window_duration_hours","type":"Float64"},{"name":"interrupt_window_embargo_dates","type":"List[String]","description":"List of dates (YYYY-MM-DD) when upgrades are blocked."},{"name":"interrupt_window_hour_of_day","type":"Float64"},{"name":"last_updated","type":"String"},{"name":"notes","type":"String"},{"name":"timezone","type":"String"},{"name":"device","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"serial_number","type":"String"},{"name":"type","type":"String"}]},{"name":"last_heartbeat","type":"String"},{"name":"last_seen_version","type":"String"},{"name":"license_key","type":"String"}]}]}]},"get /accounts/{}/magic/connectors/{}":{"operationId":"mconn-connectors-get","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_connector","stainlessResource":"magic_transit.connectors","methodName":"get","snippet":"data \"cloudflare_magic_transit_connector\" \"example_magic_transit_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connector_id = \"connector_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"connector_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"device_type","type":"String","description":"Filter connectors by device type."}]}],"computed":[{"name":"id","type":"String"},{"name":"activated","type":"Bool"},{"name":"interrupt_window_duration_hours","type":"Float64"},{"name":"interrupt_window_hour_of_day","type":"Float64"},{"name":"last_heartbeat","type":"String"},{"name":"last_seen_version","type":"String"},{"name":"last_updated","type":"String"},{"name":"license_key","type":"String"},{"name":"notes","type":"String"},{"name":"timezone","type":"String"},{"name":"interrupt_window_days_of_week","type":"List[String]","description":"Allowed days of the week for upgrades. Default is all days."},{"name":"interrupt_window_embargo_dates","type":"List[String]","description":"List of dates (YYYY-MM-DD) when upgrades are blocked."},{"name":"device","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"serial_number","type":"String"},{"name":"type","type":"String"}]}]}]},"get /accounts/{}/magic/gre_tunnels/{}":{"operationId":"magic-gre-tunnels-list-gre-tunnel-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_gre_tunnel","stainlessResource":"magic_transit.gre_tunnels","methodName":"get","snippet":"data \"cloudflare_magic_wan_gre_tunnel\" \"example_magic_wan_gre_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n gre_tunnel_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"gre_tunnel_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"gre_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."}]}]}]},"get /accounts/{}/magic/ipsec_tunnels/{}":{"operationId":"magic-ipsec-tunnels-list-ipsec-tunnel-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_ipsec_tunnel","stainlessResource":"magic_transit.ipsec_tunnels","methodName":"get","snippet":"data \"cloudflare_magic_wan_ipsec_tunnel\" \"example_magic_wan_ipsec_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ipsec_tunnel_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"ipsec_tunnel_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"ipsec_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."}]}]}]},"get /accounts/{}/magic/routes/{}":{"operationId":"magic-static-routes-route-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_static_route","stainlessResource":"magic_transit.routes","methodName":"get","snippet":"data \"cloudflare_magic_wan_static_route\" \"example_magic_wan_static_route\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n route_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"route_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"route","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."}]}]}]},"get /accounts/{}/magic/sites":{"operationId":"magic-sites-list-sites","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_sites","stainlessResource":"magic_transit.sites","methodName":"list","snippet":"data \"cloudflare_magic_transit_sites\" \"example_magic_transit_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connectorid = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"connectorid","type":"String","description":"Identifier"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"connector_id","type":"String","description":"Magic Connector identifier tag."},{"name":"description","type":"String"},{"name":"ha_mode","type":"Bool","description":"Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode."},{"name":"location","type":"Attributes","description":"Location of site in latitude and longitude.","children":[{"name":"lat","type":"String","description":"Latitude"},{"name":"lon","type":"String","description":"Longitude"}]},{"name":"name","type":"String","description":"The name of the site."},{"name":"secondary_connector_id","type":"String","description":"Magic Connector identifier tag. Used when high availability mode is on."}]}]}]},"get /accounts/{}/magic/sites/{}":{"operationId":"magic-sites-site-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site","stainlessResource":"magic_transit.sites","methodName":"get","snippet":"data \"cloudflare_magic_transit_site\" \"example_magic_transit_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"site_id","type":"String","description":"Identifier"},{"name":"filter","type":"Attributes","children":[{"name":"connectorid","type":"String","description":"Identifier"}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"connector_id","type":"String","description":"Magic Connector identifier tag."},{"name":"description","type":"String"},{"name":"ha_mode","type":"Bool","description":"Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode."},{"name":"name","type":"String","description":"The name of the site."},{"name":"secondary_connector_id","type":"String","description":"Magic Connector identifier tag. Used when high availability mode is on."},{"name":"location","type":"Attributes","description":"Location of site in latitude and longitude.","children":[{"name":"lat","type":"String","description":"Latitude"},{"name":"lon","type":"String","description":"Longitude"}]}]}]},"get /accounts/{}/magic/sites/{}/acls":{"operationId":"magic-site-acls-list-acls","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_site_acls","stainlessResource":"magic_transit.sites.acls","methodName":"list","snippet":"data \"cloudflare_magic_transit_site_acls\" \"example_magic_transit_site_acls\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"description","type":"String","description":"Description for the ACL."},{"name":"forward_locally","type":"Bool","description":"The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false."},{"name":"lan_1","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"lan_2","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"name","type":"String","description":"The name of the ACL."},{"name":"protocols","type":"List[String]"},{"name":"unidirectional","type":"Bool","description":"The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false."}]}]}]},"get /accounts/{}/magic/sites/{}/acls/{}":{"operationId":"magic-site-acls-acl-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site_acl","stainlessResource":"magic_transit.sites.acls","methodName":"get","snippet":"data \"cloudflare_magic_transit_site_acl\" \"example_magic_transit_site_acl\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n acl_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"acl_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"description","type":"String","description":"Description for the ACL."},{"name":"forward_locally","type":"Bool","description":"The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false."},{"name":"name","type":"String","description":"The name of the ACL."},{"name":"unidirectional","type":"Bool","description":"The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false."},{"name":"protocols","type":"List[String]"},{"name":"lan_1","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"lan_2","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]}]}]},"get /accounts/{}/magic/sites/{}/lans":{"operationId":"magic-site-lans-list-lans","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_site_lans","stainlessResource":"magic_transit.sites.lans","methodName":"list","snippet":"data \"cloudflare_magic_transit_site_lans\" \"example_magic_transit_site_lans\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"bond_id","type":"Int64"},{"name":"ha_link","type":"Bool","description":"mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link."},{"name":"is_breakout","type":"Bool","description":"mark true to use this LAN for source-based breakout traffic"},{"name":"is_prioritized","type":"Bool","description":"mark true to use this LAN for source-based prioritized traffic"},{"name":"name","type":"String"},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"physport","type":"Int64"},{"name":"routed_subnets","type":"List[Attributes]","children":[{"name":"next_hop","type":"String","description":"A valid IPv4 address."},{"name":"prefix","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]}]},{"name":"site_id","type":"String","description":"Identifier"},{"name":"static_addressing","type":"Attributes","description":"If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"dhcp_relay","type":"Attributes","children":[{"name":"server_addresses","type":"List[String]","description":"List of DHCP server IPs."}]},{"name":"dhcp_server","type":"Attributes","children":[{"name":"dhcp_options","type":"List[Attributes]","description":"Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.","children":[{"name":"code","type":"Int64","description":"DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration."},{"name":"type","type":"String","description":"The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\n"},{"name":"value","type":"String","description":"The option value, interpreted according to the type field."}]},{"name":"dhcp_pool_end","type":"String","description":"A valid IPv4 address."},{"name":"dhcp_pool_start","type":"String","description":"A valid IPv4 address."},{"name":"dns_server","type":"String","description":"A valid IPv4 address.","deprecated":"Deprecated."},{"name":"dns_servers","type":"List[String]"},{"name":"reservations","type":"Map[String]","description":"Mapping of MAC addresses to IP addresses"}]},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"virtual_address","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."}]}]}]},"get /accounts/{}/magic/sites/{}/lans/{}":{"operationId":"magic-site-lans-lan-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site_lan","stainlessResource":"magic_transit.sites.lans","methodName":"get","snippet":"data \"cloudflare_magic_transit_site_lan\" \"example_magic_transit_site_lan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lan_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"lan_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"bond_id","type":"Int64"},{"name":"ha_link","type":"Bool","description":"mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link."},{"name":"is_breakout","type":"Bool","description":"mark true to use this LAN for source-based breakout traffic"},{"name":"is_prioritized","type":"Bool","description":"mark true to use this LAN for source-based prioritized traffic"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"routed_subnets","type":"List[Attributes]","children":[{"name":"next_hop","type":"String","description":"A valid IPv4 address."},{"name":"prefix","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]}]},{"name":"static_addressing","type":"Attributes","description":"If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"dhcp_relay","type":"Attributes","children":[{"name":"server_addresses","type":"List[String]","description":"List of DHCP server IPs."}]},{"name":"dhcp_server","type":"Attributes","children":[{"name":"dhcp_options","type":"List[Attributes]","description":"Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.","children":[{"name":"code","type":"Int64","description":"DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration."},{"name":"type","type":"String","description":"The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\n"},{"name":"value","type":"String","description":"The option value, interpreted according to the type field."}]},{"name":"dhcp_pool_end","type":"String","description":"A valid IPv4 address."},{"name":"dhcp_pool_start","type":"String","description":"A valid IPv4 address."},{"name":"dns_server","type":"String","description":"A valid IPv4 address.","deprecated":"Deprecated."},{"name":"dns_servers","type":"List[String]"},{"name":"reservations","type":"Map[String]","description":"Mapping of MAC addresses to IP addresses"}]},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"virtual_address","type":"String","description":"A valid CIDR notation representing an IP range."}]}]}]},"get /accounts/{}/magic/sites/{}/wans":{"operationId":"magic-site-wans-list-wans","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_site_wans","stainlessResource":"magic_transit.sites.wans","methodName":"list","snippet":"data \"cloudflare_magic_transit_site_wans\" \"example_magic_transit_site_wans\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"health_check_rate","type":"String","description":"Magic WAN health check rate for tunnels created on this link. The default value is `mid`."},{"name":"load_balance_inner_flows","type":"Bool"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"priority","type":"Int64","description":"Priority of WAN for traffic loadbalancing."},{"name":"site_id","type":"String","description":"Identifier"},{"name":"static_addressing","type":"Attributes","description":"(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"gateway_address","type":"String","description":"A valid IPv4 address."},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."}]}]}]},"get /accounts/{}/magic/sites/{}/wans/{}":{"operationId":"magic-site-wans-wan-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site_wan","stainlessResource":"magic_transit.sites.wans","methodName":"get","snippet":"data \"cloudflare_magic_transit_site_wan\" \"example_magic_transit_site_wan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n wan_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"wan_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"health_check_rate","type":"String","description":"Magic WAN health check rate for tunnels created on this link. The default value is `mid`."},{"name":"load_balance_inner_flows","type":"Bool"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"priority","type":"Int64","description":"Priority of WAN for traffic loadbalancing."},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"static_addressing","type":"Attributes","description":"(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"gateway_address","type":"String","description":"A valid IPv4 address."},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."}]}]}]},"get /accounts/{}/members":{"operationId":"account-members-list-members","declarations":[{"kind":"list-data-source","name":"cloudflare_account_members","stainlessResource":"accounts.members","methodName":"list","snippet":"data \"cloudflare_account_members\" \"example_account_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n order = \"status\"\n status = \"accepted\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"order","type":"String","description":"Field to order results by."},{"name":"status","type":"String","description":"A member's status in the account."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Membership identifier tag."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"policies","type":"List[Attributes]","description":"Access policy for the membership","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]},{"name":"roles","type":"List[Attributes]","description":"Roles assigned to this Member.","children":[{"name":"id","type":"String","description":"Role identifier tag."},{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]},{"name":"status","type":"String","description":"A member's status in the account."},{"name":"user","type":"Attributes","description":"Details of the user associated to the membership.","children":[{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"id","type":"String","description":"Identifier"},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."}]}]}]}]},"get /accounts/{}/members/{}":{"operationId":"account-members-member-details","declarations":[{"kind":"data-source","name":"cloudflare_account_member","stainlessResource":"accounts.members","methodName":"get","snippet":"data \"cloudflare_account_member\" \"example_account_member\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n member_id = \"4536bcfad5faccb111b47003c79917fa\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"member_id","type":"String","description":"Membership identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"order","type":"String","description":"Field to order results by."},{"name":"status","type":"String","description":"A member's status in the account."}]}],"computed":[{"name":"id","type":"String","description":"Membership identifier tag."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"status","type":"String","description":"A member's status in the account."},{"name":"policies","type":"List[Attributes]","description":"Access policy for the membership","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]},{"name":"roles","type":"List[Attributes]","description":"Roles assigned to this Member.","children":[{"name":"id","type":"String","description":"Role identifier tag."},{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]},{"name":"user","type":"Attributes","description":"Details of the user associated to the membership.","children":[{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"id","type":"String","description":"Identifier"},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."}]}]}]},"get /accounts/{}/mnm/config":{"operationId":"magic-network-monitoring-configuration-list-account-configuration","declarations":[{"kind":"data-source","name":"cloudflare_magic_network_monitoring_configuration","stainlessResource":"magic_network_monitoring.configs","methodName":"get","snippet":"data \"cloudflare_magic_network_monitoring_configuration\" \"example_magic_network_monitoring_configuration\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"default_sampling","type":"Float64","description":"Fallback sampling rate of flow messages being sent in packets per second. This should match the packet sampling rate configured on the router."},{"name":"name","type":"String","description":"The account name."},{"name":"router_ips","type":"List[String]"},{"name":"warp_devices","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the warp device."},{"name":"name","type":"String","description":"Name of the warp device."},{"name":"router_ip","type":"String","description":"IPv4 CIDR of the router sourcing flow data associated with this warp device. Only /32 addresses are currently supported."}]}]}]},"get /accounts/{}/mnm/rules":{"operationId":"magic-network-monitoring-rules-list-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_network_monitoring_rules","stainlessResource":"magic_network_monitoring.rules","methodName":"list","snippet":"data \"cloudflare_magic_network_monitoring_rules\" \"example_magic_network_monitoring_rules\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The id of the rule. Must be unique."},{"name":"automatic_advertisement","type":"Bool","description":"Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit."},{"name":"name","type":"String","description":"The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters."},{"name":"prefixes","type":"List[String]"},{"name":"type","type":"String","description":"MNM rule type."},{"name":"bandwidth_threshold","type":"Float64","description":"The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"duration","type":"String","description":"The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"]."},{"name":"packet_threshold","type":"Float64","description":"The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"prefix_match","type":"String","description":"Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule."},{"name":"zscore_sensitivity","type":"String","description":"Level of sensitivity set for zscore rules."},{"name":"zscore_target","type":"String","description":"Target of the zscore rule analysis."}]}]}]},"get /accounts/{}/mnm/rules/{}":{"operationId":"magic-network-monitoring-rules-get-rule","declarations":[{"kind":"data-source","name":"cloudflare_magic_network_monitoring_rule","stainlessResource":"magic_network_monitoring.rules","methodName":"get","snippet":"data \"cloudflare_magic_network_monitoring_rule\" \"example_magic_network_monitoring_rule\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n rule_id = \"2890e6fa406311ed9b5a23f70f6fb8cf\"\n}\n","required":[{"name":"rule_id","type":"String","description":"The id of the rule. Must be unique."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The id of the rule. Must be unique."},{"name":"automatic_advertisement","type":"Bool","description":"Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit."},{"name":"bandwidth_threshold","type":"Float64","description":"The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"duration","type":"String","description":"The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"]."},{"name":"name","type":"String","description":"The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters."},{"name":"packet_threshold","type":"Float64","description":"The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"prefix_match","type":"String","description":"Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule."},{"name":"type","type":"String","description":"MNM rule type."},{"name":"zscore_sensitivity","type":"String","description":"Level of sensitivity set for zscore rules."},{"name":"zscore_target","type":"String","description":"Target of the zscore rule analysis."},{"name":"prefixes","type":"List[String]"}]}]},"get /accounts/{}/moq/relays":{"operationId":"moq-relays-list","declarations":[{"kind":"list-data-source","name":"cloudflare_moq_relays","stainlessResource":"moq.relays","methodName":"list","snippet":"data \"cloudflare_moq_relays\" \"example_moq_relays\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_after = \"2026-03-27T15:00:00Z\"\n created_before = \"2026-03-27T15:00:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account identifier."}],"optional":[{"name":"created_after","type":"Time","description":"Cursor for pagination. Returns relays created strictly after this\nRFC 3339 timestamp (typically the `created` value of the last item\non the current page, to fetch the next page).\n"},{"name":"created_before","type":"Time","description":"Cursor for pagination. Returns relays created strictly before this\nRFC 3339 timestamp (typically the `created` value of the first item\non the current page, to fetch the previous page).\n"},{"name":"asc","type":"Bool","description":"Sort order by `created`. When true, results are returned oldest-first\n(ascending); otherwise newest-first (descending, the default).\n"},{"name":"per_page","type":"Int64","description":"Maximum number of relays to return per page. Values above the maximum are\nclamped to it rather than rejected.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created","type":"Time"},{"name":"modified","type":"Time"},{"name":"name","type":"String"},{"name":"uid","type":"String"}]}]}]},"get /accounts/{}/moq/relays/{}":{"operationId":"moq-relays-get","declarations":[{"kind":"data-source","name":"cloudflare_moq_relay","stainlessResource":"moq.relays","methodName":"get","snippet":"data \"cloudflare_moq_relay\" \"example_moq_relay\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n relay_id = \"a1b2c3d4e5f67890a1b2c3d4e5f67890\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account identifier."}],"optional":[{"name":"relay_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"asc","type":"Bool","description":"Sort order by `created`. When true, results are returned oldest-first\n(ascending); otherwise newest-first (descending, the default).\n"},{"name":"created_after","type":"Time","description":"Cursor for pagination. Returns relays created strictly after this\nRFC 3339 timestamp (typically the `created` value of the last item\non the current page, to fetch the next page).\n"},{"name":"created_before","type":"Time","description":"Cursor for pagination. Returns relays created strictly before this\nRFC 3339 timestamp (typically the `created` value of the first item\non the current page, to fetch the previous page).\n"},{"name":"per_page","type":"Int64","description":"Maximum number of relays to return per page. Values above the maximum are\nclamped to it rather than rejected.\n"}]}],"computed":[{"name":"id","type":"String"},{"name":"created","type":"Time"},{"name":"modified","type":"Time"},{"name":"name","type":"String"},{"name":"status","type":"String","description":"\"connected\" when active, omitted otherwise."},{"name":"uid","type":"String"},{"name":"config","type":"Attributes","children":[{"name":"upstreams","type":"Attributes","description":"Upstreams are external MOQT server publishers that a relay falls back\nto when it has no local publisher for a requested namespace/track.\n","children":[{"name":"enabled","type":"Bool"},{"name":"upstreams","type":"List[Attributes]","description":"Ordered list of upstream MOQT server publishers. Each entry is an\nobject (not a bare string) so per-upstream configuration can be\nadded in the future without another breaking change.\n","children":[{"name":"url","type":"String","description":"Upstream MOQT server publisher URL. Must be an absolute URL with a\nhost and a scheme the relay can dial: moqt:// (raw QUIC) or https://\n(WebTransport). Validated on update (PUT); rejected with 21013.\n"}]}]}]}]}]},"get /accounts/{}/mtls_certificates/{}/associations":{"operationId":"m-tls-certificate-management-list-m-tls-certificate-associations","declarations":[{"kind":"data-source","name":"cloudflare_mtls_certificate_associations","stainlessResource":"mtls_certificates.associations","methodName":"get","snippet":"data \"cloudflare_mtls_certificate_associations\" \"example_mtls_certificate_associations\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n mtls_certificate_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"mtls_certificate_id","type":"String","description":"Certificate identifier tag."}],"optional":[],"computed":[{"name":"service","type":"String","description":"The service using the certificate."},{"name":"status","type":"String","description":"Certificate deployment status for the given service."}]}]},"get /accounts/{}/oauth_clients":{"operationId":"oauth-clients-list","declarations":[{"kind":"list-data-source","name":"cloudflare_oauth_clients","stainlessResource":"iam.oauth_clients","methodName":"list","snippet":"data \"cloudflare_oauth_clients\" \"example_oauth_clients\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"client_id","type":"String","description":"The unique identifier for an OAuth client."},{"name":"visibility","type":"String","description":"Visibility of the OAuth client."},{"name":"allowed_cors_origins","type":"List[String]","description":"Array of allowed CORS origins."},{"name":"client_name","type":"String","description":"Human-readable name of the OAuth client."},{"name":"client_uri","type":"String","description":"URL of the home page of the client."},{"name":"client_uri_verification","type":"Attributes","description":"Client URI domain control verification state.","children":[{"name":"status","type":"String","description":"Current verification status for the client URI host."},{"name":"text","type":"String","description":"Exact TXT record value that must be added to DNS to prove ownership of the client URI host."}]},{"name":"created_at","type":"Time","description":"Timestamp when the OAuth client was created."},{"name":"grant_types","type":"List[String]","description":"Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally."},{"name":"has_rotated_secret","type":"Bool","description":"Indicates whether the client has a rotated secret that has not yet been deleted."},{"name":"logo_uri","type":"String","description":"URL of the client's logo."},{"name":"optional_scopes","type":"List[String]","description":"Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional."},{"name":"policy_uri","type":"String","description":"URL that points to a privacy policy document."},{"name":"post_logout_redirect_uris","type":"List[String]","description":"Array of allowed post-logout redirect URIs."},{"name":"promoted_at","type":"Time","description":"Timestamp when the OAuth client was promoted to public visibility."},{"name":"redirect_uris","type":"List[String]","description":"Array of allowed redirect URIs for the client."},{"name":"response_types","type":"List[String]","description":"Array of OAuth response types the client is allowed to use."},{"name":"scopes","type":"List[String]","description":"Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`."},{"name":"token_endpoint_auth_method","type":"String","description":"The authentication method the client uses at the token endpoint."},{"name":"tos_uri","type":"String","description":"URL that points to a terms of service document."},{"name":"updated_at","type":"Time","description":"Timestamp when the OAuth client was last updated."}]}]}]},"get /accounts/{}/oauth_clients/{}":{"operationId":"oauth-clients-get","declarations":[{"kind":"data-source","name":"cloudflare_oauth_client","stainlessResource":"iam.oauth_clients","methodName":"get","snippet":"data \"cloudflare_oauth_client\" \"example_oauth_client\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n oauth_client_id = \"a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"oauth_client_id","type":"String","description":"The unique identifier for an OAuth client."}],"optional":[],"computed":[{"name":"client_id","type":"String","description":"The unique identifier for an OAuth client."},{"name":"client_name","type":"String","description":"Human-readable name of the OAuth client."},{"name":"client_uri","type":"String","description":"URL of the home page of the client."},{"name":"created_at","type":"Time","description":"Timestamp when the OAuth client was created."},{"name":"has_rotated_secret","type":"Bool","description":"Indicates whether the client has a rotated secret that has not yet been deleted."},{"name":"logo_uri","type":"String","description":"URL of the client's logo."},{"name":"policy_uri","type":"String","description":"URL that points to a privacy policy document."},{"name":"promoted_at","type":"Time","description":"Timestamp when the OAuth client was promoted to public visibility."},{"name":"token_endpoint_auth_method","type":"String","description":"The authentication method the client uses at the token endpoint."},{"name":"tos_uri","type":"String","description":"URL that points to a terms of service document."},{"name":"updated_at","type":"Time","description":"Timestamp when the OAuth client was last updated."},{"name":"visibility","type":"String","description":"Visibility of the OAuth client."},{"name":"allowed_cors_origins","type":"List[String]","description":"Array of allowed CORS origins."},{"name":"grant_types","type":"List[String]","description":"Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally."},{"name":"optional_scopes","type":"List[String]","description":"Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional."},{"name":"post_logout_redirect_uris","type":"List[String]","description":"Array of allowed post-logout redirect URIs."},{"name":"redirect_uris","type":"List[String]","description":"Array of allowed redirect URIs for the client."},{"name":"response_types","type":"List[String]","description":"Array of OAuth response types the client is allowed to use."},{"name":"scopes","type":"List[String]","description":"Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`."},{"name":"client_uri_verification","type":"Attributes","description":"Client URI domain control verification state.","children":[{"name":"status","type":"String","description":"Current verification status for the client URI host."},{"name":"text","type":"String","description":"Exact TXT record value that must be added to DNS to prove ownership of the client URI host."}]}]}]},"get /accounts/{}/pages/projects":{"operationId":"pages-project-get-projects","declarations":[{"kind":"list-data-source","name":"cloudflare_pages_projects","stainlessResource":"pages.projects","methodName":"list","snippet":"data \"cloudflare_pages_projects\" \"example_pages_projects\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"ID of the project."},{"name":"canonical_deployment","type":"Attributes","description":"Most recent production deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"created_on","type":"Time","description":"When the project was created."},{"name":"deployment_configs","type":"Attributes","description":"Configs for deployments in a project.","children":[{"name":"preview","type":"Attributes","description":"Configs for preview deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]},{"name":"production","type":"Attributes","description":"Configs for production deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]}]},{"name":"framework","type":"String","description":"Framework the project is using."},{"name":"framework_version","type":"String","description":"Version of the framework the project is using."},{"name":"latest_deployment","type":"Attributes","description":"Most recent deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"preview_script_name","type":"String","description":"Name of the preview script."},{"name":"production_branch","type":"String","description":"Production branch of the project. Used to identify production deployments."},{"name":"production_script_name","type":"String","description":"Name of the production script."},{"name":"uses_functions","type":"Bool","description":"Whether the project uses functions."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"domains","type":"List[String]","description":"A list of associated custom domains for the project."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"subdomain","type":"String","description":"The Cloudflare subdomain associated with the project."}]}]}]},"get /accounts/{}/pages/projects/{}":{"operationId":"pages-project-get-project","declarations":[{"kind":"data-source","name":"cloudflare_pages_project","stainlessResource":"pages.projects","methodName":"get","snippet":"data \"cloudflare_pages_project\" \"example_pages_project\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n}\n","required":[{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"created_on","type":"Time","description":"When the project was created."},{"name":"framework","type":"String","description":"Framework the project is using."},{"name":"framework_version","type":"String","description":"Version of the framework the project is using."},{"name":"name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"preview_script_name","type":"String","description":"Name of the preview script."},{"name":"production_branch","type":"String","description":"Production branch of the project. Used to identify production deployments."},{"name":"production_script_name","type":"String","description":"Name of the production script."},{"name":"subdomain","type":"String","description":"The Cloudflare subdomain associated with the project."},{"name":"uses_functions","type":"Bool","description":"Whether the project uses functions."},{"name":"domains","type":"List[String]","description":"A list of associated custom domains for the project."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"canonical_deployment","type":"Attributes","description":"Most recent production deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"deployment_configs","type":"Attributes","description":"Configs for deployments in a project.","children":[{"name":"preview","type":"Attributes","description":"Configs for preview deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]},{"name":"production","type":"Attributes","description":"Configs for production deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]}]},{"name":"latest_deployment","type":"Attributes","description":"Most recent deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]}]}]},"get /accounts/{}/pages/projects/{}/domains":{"operationId":"pages-domains-get-domains","declarations":[{"kind":"list-data-source","name":"cloudflare_pages_domains","stainlessResource":"pages.projects.domains","methodName":"list","snippet":"data \"cloudflare_pages_domains\" \"example_pages_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"certificate_authority","type":"String"},{"name":"created_on","type":"String"},{"name":"domain_id","type":"String"},{"name":"name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"status","type":"String"},{"name":"validation_data","type":"Attributes","children":[{"name":"method","type":"String"},{"name":"status","type":"String"},{"name":"error_message","type":"String"},{"name":"txt_name","type":"String"},{"name":"txt_value","type":"String"}]},{"name":"verification_data","type":"Attributes","children":[{"name":"status","type":"String"},{"name":"error_message","type":"String"}]},{"name":"zone_tag","type":"String"}]}]}]},"get /accounts/{}/pages/projects/{}/domains/{}":{"operationId":"pages-domains-get-domain","declarations":[{"kind":"data-source","name":"cloudflare_pages_domain","stainlessResource":"pages.projects.domains","methodName":"get","snippet":"data \"cloudflare_pages_domain\" \"example_pages_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n domain_name = \"example.com\"\n}\n","required":[{"name":"domain_name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"certificate_authority","type":"String"},{"name":"created_on","type":"String"},{"name":"domain_id","type":"String"},{"name":"name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"status","type":"String"},{"name":"zone_tag","type":"String"},{"name":"validation_data","type":"Attributes","children":[{"name":"method","type":"String"},{"name":"status","type":"String"},{"name":"error_message","type":"String"},{"name":"txt_name","type":"String"},{"name":"txt_value","type":"String"}]},{"name":"verification_data","type":"Attributes","children":[{"name":"status","type":"String"},{"name":"error_message","type":"String"}]}]}]},"get /accounts/{}/pipelines/v1/pipelines/{}":{"operationId":"getV4AccountsByAccount_idPipelinesV1PipelinesByPipeline_id","declarations":[{"kind":"data-source","name":"cloudflare_pipeline","stainlessResource":"pipelines","methodName":"get_v1","snippet":"data \"cloudflare_pipeline\" \"example_pipeline\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n pipeline_id = \"043e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"pipeline_id","type":"String","description":"Specifies the public ID of the pipeline."},{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the public ID of the pipeline."},{"name":"created_at","type":"String"},{"name":"failure_reason","type":"String","description":"Indicates the reason for the failure of the Pipeline."},{"name":"modified_at","type":"String"},{"name":"name","type":"String","description":"Indicates the name of the Pipeline."},{"name":"sql","type":"String","description":"Specifies SQL for the Pipeline processing flow."},{"name":"status","type":"String","description":"Indicates the current status of the Pipeline."},{"name":"tables","type":"List[Attributes]","description":"List of streams and sinks used by this pipeline.","children":[{"name":"id","type":"String","description":"Unique identifier for the connection (stream or sink)."},{"name":"latest","type":"Int64","description":"Latest available version of the connection."},{"name":"name","type":"String","description":"Name of the connection."},{"name":"type","type":"String","description":"Type of the connection."},{"name":"version","type":"Int64","description":"Current version of the connection used by this pipeline."}]}]}]},"get /accounts/{}/pipelines/v1/sinks":{"operationId":"getV4AccountsByAccount_idPipelinesV1Sinks","declarations":[{"kind":"list-data-source","name":"cloudflare_pipeline_sinks","stainlessResource":"pipelines.sinks","methodName":"list","snippet":"data \"cloudflare_pipeline_sinks\" \"example_pipeline_sinks\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"x\"\n pipeline_id = \"pipeline_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"name","type":"String","description":"Filters sinks by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Indicates a unique identifier for this sink."},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Defines the name of the Sink."},{"name":"type","type":"String","description":"Specifies the type of sink."},{"name":"config","type":"Attributes","description":"Defines the configuration of the R2 Sink.","children":[{"name":"account_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"bucket","type":"String","description":"R2 Bucket to write to"},{"name":"file_naming","type":"Attributes","description":"Controls filename prefix/suffix and strategy.","children":[{"name":"prefix","type":"String","description":"The prefix to use in file name. i.e prefix-.parquet"},{"name":"strategy","type":"String","description":"Filename generation strategy."},{"name":"suffix","type":"String","description":"This will overwrite the default file suffix. i.e .parquet, use with caution"}]},{"name":"jurisdiction","type":"String","description":"Jurisdiction this bucket is hosted in"},{"name":"partitioning","type":"Attributes","description":"Data-layout partitioning for sinks.","children":[{"name":"time_pattern","type":"String","description":"The pattern of the date string"}]},{"name":"path","type":"String","description":"Subpath within the bucket to write to"},{"name":"rolling_policy","type":"Attributes","description":"Rolling policy for file sinks (when & why to close a file and open a new one).","children":[{"name":"file_size_bytes","type":"Int64","description":"Files will be rolled after reaching this number of bytes"},{"name":"inactivity_seconds","type":"Int64","description":"Number of seconds of inactivity to wait before rolling over to a new file"},{"name":"interval_seconds","type":"Int64","description":"Number of seconds to wait before rolling over to a new file"}]},{"name":"table_name","type":"String","description":"Table name"},{"name":"namespace","type":"String","description":"Table namespace"}]},{"name":"format","type":"Attributes","description":"Defines the output data format of a sink.","children":[{"name":"type","type":"String"},{"name":"compression","type":"String","description":"Specifies the compression applied to JSON sink output."},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}]}]}]},"get /accounts/{}/pipelines/v1/sinks/{}":{"operationId":"getV4AccountsByAccount_idPipelinesV1SinksBySink_id","declarations":[{"kind":"data-source","name":"cloudflare_pipeline_sink","stainlessResource":"pipelines.sinks","methodName":"get","snippet":"data \"cloudflare_pipeline_sink\" \"example_pipeline_sink\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n sink_id = \"0223105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"sink_id","type":"String","description":"Specifies the publid ID of the sink."},{"name":"filter","type":"Attributes","children":[{"name":"name","type":"String","description":"Filters sinks by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String"}]}],"computed":[{"name":"id","type":"String","description":"Specifies the publid ID of the sink."},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Defines the name of the Sink."},{"name":"type","type":"String","description":"Specifies the type of sink."},{"name":"config","type":"Attributes","description":"Defines the configuration of the R2 Sink.","children":[{"name":"account_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"bucket","type":"String","description":"R2 Bucket to write to"},{"name":"file_naming","type":"Attributes","description":"Controls filename prefix/suffix and strategy.","children":[{"name":"prefix","type":"String","description":"The prefix to use in file name. i.e prefix-.parquet"},{"name":"strategy","type":"String","description":"Filename generation strategy."},{"name":"suffix","type":"String","description":"This will overwrite the default file suffix. i.e .parquet, use with caution"}]},{"name":"jurisdiction","type":"String","description":"Jurisdiction this bucket is hosted in"},{"name":"partitioning","type":"Attributes","description":"Data-layout partitioning for sinks.","children":[{"name":"time_pattern","type":"String","description":"The pattern of the date string"}]},{"name":"path","type":"String","description":"Subpath within the bucket to write to"},{"name":"rolling_policy","type":"Attributes","description":"Rolling policy for file sinks (when & why to close a file and open a new one).","children":[{"name":"file_size_bytes","type":"Int64","description":"Files will be rolled after reaching this number of bytes"},{"name":"inactivity_seconds","type":"Int64","description":"Number of seconds of inactivity to wait before rolling over to a new file"},{"name":"interval_seconds","type":"Int64","description":"Number of seconds to wait before rolling over to a new file"}]},{"name":"table_name","type":"String","description":"Table name"},{"name":"namespace","type":"String","description":"Table namespace"}]},{"name":"format","type":"Attributes","description":"Defines the output data format of a sink.","children":[{"name":"type","type":"String"},{"name":"compression","type":"String","description":"Specifies the compression applied to JSON sink output."},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}]}]},"get /accounts/{}/pipelines/v1/streams":{"operationId":"getV4AccountsByAccount_idPipelinesV1Streams","declarations":[{"kind":"list-data-source","name":"cloudflare_pipeline_streams","stainlessResource":"pipelines.streams","methodName":"list","snippet":"data \"cloudflare_pipeline_streams\" \"example_pipeline_streams\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"x\"\n pipeline_id = \"043e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"name","type":"String","description":"Filters streams by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String","description":"Specifies the public ID of the pipeline."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Indicates a unique identifier for this stream."},{"name":"created_at","type":"Time"},{"name":"http","type":"Attributes","children":[{"name":"authentication","type":"Bool","description":"Indicates that authentication is required for the HTTP endpoint."},{"name":"enabled","type":"Bool","description":"Indicates that the HTTP endpoint is enabled."},{"name":"cors","type":"Attributes","description":"Specifies the CORS options for the HTTP endpoint.","children":[{"name":"origins","type":"List[String]"}]}]},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Indicates the name of the Stream."},{"name":"version","type":"Int64","description":"Indicates the current version of this stream."},{"name":"worker_binding","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicates that the worker binding is enabled."}]},{"name":"endpoint","type":"String","description":"Indicates the endpoint URL of this stream."},{"name":"format","type":"Attributes","description":"Defines the data format of the events.","children":[{"name":"type","type":"String"},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"compression","type":"String"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}]}]}]},"get /accounts/{}/pipelines/v1/streams/{}":{"operationId":"getV4AccountsByAccount_idPipelinesV1StreamsByStream_id","declarations":[{"kind":"data-source","name":"cloudflare_pipeline_stream","stainlessResource":"pipelines.streams","methodName":"get","snippet":"data \"cloudflare_pipeline_stream\" \"example_pipeline_stream\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n stream_id = \"033e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"stream_id","type":"String","description":"Specifies the public ID of the stream."},{"name":"filter","type":"Attributes","children":[{"name":"name","type":"String","description":"Filters streams by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String","description":"Specifies the public ID of the pipeline."}]}],"computed":[{"name":"id","type":"String","description":"Specifies the public ID of the stream."},{"name":"created_at","type":"Time"},{"name":"endpoint","type":"String","description":"Indicates the endpoint URL of this stream."},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Indicates the name of the Stream."},{"name":"version","type":"Int64","description":"Indicates the current version of this stream."},{"name":"format","type":"Attributes","description":"Defines the data format of the events.","children":[{"name":"type","type":"String"},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"compression","type":"String"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"http","type":"Attributes","children":[{"name":"authentication","type":"Bool","description":"Indicates that authentication is required for the HTTP endpoint."},{"name":"enabled","type":"Bool","description":"Indicates that the HTTP endpoint is enabled."},{"name":"cors","type":"Attributes","description":"Specifies the CORS options for the HTTP endpoint.","children":[{"name":"origins","type":"List[String]"}]}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]},{"name":"worker_binding","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicates that the worker binding is enabled."}]}]}]},"get /accounts/{}/queues":{"operationId":"queues-list","declarations":[{"kind":"list-data-source","name":"cloudflare_queues","stainlessResource":"queues","methodName":"list","snippet":"data \"cloudflare_queues\" \"example_queues\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"consumers","type":"List[Attributes]","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]},{"name":"consumers_total_count","type":"Float64"},{"name":"created_on","type":"String"},{"name":"jurisdiction","type":"String"},{"name":"modified_on","type":"String"},{"name":"producers","type":"List[Attributes]","children":[{"name":"script","type":"String"},{"name":"type","type":"String"},{"name":"bucket_name","type":"String"}]},{"name":"producers_total_count","type":"Float64"},{"name":"queue_id","type":"String"},{"name":"queue_name","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"delivery_delay","type":"Float64","description":"Number of seconds to delay delivery of all messages to consumers."},{"name":"delivery_paused","type":"Bool","description":"Indicates if message delivery to consumers is currently paused."},{"name":"message_retention_period","type":"Float64","description":"Number of seconds after which an unconsumed message will be delayed."}]}]}]}]},"get /accounts/{}/queues/{}":{"operationId":"queues-get","declarations":[{"kind":"data-source","name":"cloudflare_queue","stainlessResource":"queues","methodName":"get","snippet":"data \"cloudflare_queue\" \"example_queue\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"queue_id","type":"String","description":"A Resource identifier."},{"name":"account_id","type":"String","description":"A Resource identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"A Resource identifier."},{"name":"consumers_total_count","type":"Float64"},{"name":"created_on","type":"String"},{"name":"jurisdiction","type":"String"},{"name":"modified_on","type":"String"},{"name":"producers_total_count","type":"Float64"},{"name":"queue_name","type":"String"},{"name":"consumers","type":"List[Attributes]","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]},{"name":"producers","type":"List[Attributes]","children":[{"name":"script","type":"String"},{"name":"type","type":"String"},{"name":"bucket_name","type":"String"}]},{"name":"settings","type":"Attributes","children":[{"name":"delivery_delay","type":"Float64","description":"Number of seconds to delay delivery of all messages to consumers."},{"name":"delivery_paused","type":"Bool","description":"Indicates if message delivery to consumers is currently paused."},{"name":"message_retention_period","type":"Float64","description":"Number of seconds after which an unconsumed message will be delayed."}]}]}]},"get /accounts/{}/queues/{}/consumers":{"operationId":"queues-list-consumers","declarations":[{"kind":"list-data-source","name":"cloudflare_queue_consumers","stainlessResource":"queues.consumers","methodName":"list","snippet":"data \"cloudflare_queue_consumers\" \"example_queue_consumers\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier."},{"name":"queue_id","type":"String","description":"A Resource identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]}]}]},"get /accounts/{}/queues/{}/consumers/{}":{"operationId":"queues-get-consumer","declarations":[{"kind":"data-source","name":"cloudflare_queue_consumer","stainlessResource":"queues.consumers","methodName":"get","snippet":"data \"cloudflare_queue_consumer\" \"example_queue_consumer\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n consumer_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier."},{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"queue_id","type":"String","description":"A Resource identifier."}],"optional":[],"computed":[{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"type","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]}]}]},"get /accounts/{}/r2-catalog/{}":{"operationId":"get-catalog-details","declarations":[{"kind":"data-source","name":"cloudflare_r2_data_catalog","stainlessResource":"r2_data_catalog","methodName":"get","snippet":"data \"cloudflare_r2_data_catalog\" \"example_r2_data_catalog\" {\n account_id = \"0123456789abcdef0123456789abcdef\"\n bucket_name = \"my-data-bucket\"\n}\n","required":[{"name":"bucket_name","type":"String","description":"Specifies the R2 bucket name."},{"name":"account_id","type":"String","description":"Use this to identify the account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the R2 bucket name."},{"name":"bucket","type":"String","description":"Specifies the associated R2 bucket name."},{"name":"credential_status","type":"String","description":"Shows the credential configuration status."},{"name":"name","type":"String","description":"Specifies the catalog name (generated from account and bucket name)."},{"name":"status","type":"String","description":"Indicates the status of the catalog."},{"name":"maintenance_config","type":"Attributes","description":"Configures maintenance for the catalog.","children":[{"name":"compaction","type":"Attributes","description":"Configures compaction for catalog maintenance.","children":[{"name":"state","type":"String","description":"Specifies the state of maintenance operations."},{"name":"target_size_mb","type":"String","description":"Sets the target file size for compaction in megabytes. Defaults to \"128\"."}]},{"name":"interval","type":"String","description":"Scheduling interval between normal table maintenance runs."},{"name":"snapshot_expiration","type":"Attributes","description":"Configures snapshot expiration settings.","children":[{"name":"max_snapshot_age","type":"String","description":"Specifies the maximum age for snapshots. The system deletes snapshots older than this age.\nFormat: where unit is d (days), h (hours), m (minutes), or s (seconds).\nExamples: \"7d\" (7 days), \"48h\" (48 hours), \"2880m\" (2,880 minutes).\nDefaults to \"7d\".\n"},{"name":"min_snapshots_to_keep","type":"Int64","description":"Specifies the minimum number of snapshots to retain. Defaults to 100."},{"name":"state","type":"String","description":"Specifies the state of maintenance operations."}]}]}]}]},"get /accounts/{}/r2/buckets/{}":{"operationId":"r2-get-bucket","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket","stainlessResource":"r2.buckets","methodName":"get","snippet":"data \"cloudflare_r2_bucket\" \"example_r2_bucket\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"bucket_name","type":"String","description":"Name of the bucket."},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the bucket."},{"name":"creation_date","type":"String","description":"Creation timestamp."},{"name":"jurisdiction","type":"String","description":"Jurisdiction where objects in this bucket are guaranteed to be stored."},{"name":"location","type":"String","description":"Location of the bucket."},{"name":"name","type":"String","description":"Name of the bucket."},{"name":"storage_class","type":"String","description":"Storage class for newly uploaded objects, unless specified otherwise."}]}]},"get /accounts/{}/r2/buckets/{}/cors":{"operationId":"r2-get-bucket-cors-policy","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_cors","stainlessResource":"r2.buckets.cors","methodName":"get","snippet":"data \"cloudflare_r2_bucket_cors\" \"example_r2_bucket_cors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"allowed","type":"Attributes","description":"Object specifying allowed origins, methods and headers for this CORS rule.","children":[{"name":"methods","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Methods header R2 sets when requesting objects in a bucket from a browser."},{"name":"origins","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Origin header R2 sets when requesting objects in a bucket from a browser."},{"name":"headers","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Headers header R2 sets when requesting objects in this bucket from a browser. Cross-origin requests that include custom headers (e.g. x-user-id) should specify these headers as AllowedHeaders."}]},{"name":"id","type":"String","description":"Identifier for this rule."},{"name":"expose_headers","type":"List[String]","description":"Specifies the headers that can be exposed back, and accessed by, the JavaScript making the cross-origin request. If you need to access headers beyond the safelisted response headers, such as Content-Encoding or cf-cache-status, you must specify it here."},{"name":"max_age_seconds","type":"Float64","description":"Specifies the amount of time (in seconds) browsers are allowed to cache CORS preflight responses. Browsers may limit this to 2 hours or less, even if the maximum value (86400) is specified."}]}]}]},"get /accounts/{}/r2/buckets/{}/domains/custom/{}":{"operationId":"r2-get-custom-domain-settings","declarations":[{"kind":"data-source","name":"cloudflare_r2_custom_domain","stainlessResource":"r2.buckets.domains.custom","methodName":"get","snippet":"data \"cloudflare_r2_custom_domain\" \"example_r2_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n domain = \"example-domain/custom-domain.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."},{"name":"domain","type":"String","description":"Name of the custom domain."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"Whether this bucket is publicly accessible at the specified custom domain."},{"name":"min_tls","type":"String","description":"Minimum TLS Version the custom domain will accept for incoming connections. If not set, defaults to 1.0."},{"name":"zone_id","type":"String","description":"Zone ID of the custom domain resides in."},{"name":"zone_name","type":"String","description":"Zone that the custom domain resides in."},{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."},{"name":"status","type":"Attributes","children":[{"name":"ownership","type":"String","description":"Ownership status of the domain."},{"name":"ssl","type":"String","description":"SSL certificate status."}]}]}]},"get /accounts/{}/r2/buckets/{}/lifecycle":{"operationId":"r2-get-bucket-lifecycle-configuration","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_lifecycle","stainlessResource":"r2.buckets.lifecycle","methodName":"get","snippet":"data \"cloudflare_r2_bucket_lifecycle\" \"example_r2_bucket_lifecycle\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"conditions","type":"Attributes","description":"Conditions that apply to all transitions of this rule.","children":[{"name":"prefix","type":"String","description":"Transitions will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"abort_multipart_uploads_transition","type":"Attributes","description":"Transition to abort ongoing multipart uploads.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"}]}]},{"name":"delete_objects_transition","type":"Attributes","description":"Transition to delete objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]}]},{"name":"storage_class_transitions","type":"List[Attributes]","description":"Transitions to change the storage class of objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"storage_class","type":"String"}]}]}]}]},"get /accounts/{}/r2/buckets/{}/lock":{"operationId":"r2-get-bucket-lock-configuration","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_lock","stainlessResource":"r2.buckets.locks","methodName":"get","snippet":"data \"cloudflare_r2_bucket_lock\" \"example_r2_bucket_lock\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"condition","type":"Attributes","description":"Condition to apply a lock rule to an object for how long in seconds.","children":[{"name":"max_age_seconds","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"prefix","type":"String","description":"Rule will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]}]}]},"get /accounts/{}/r2/buckets/{}/sippy":{"operationId":"r2-get-bucket-sippy-config","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_sippy","stainlessResource":"r2.buckets.sippy","methodName":"get","snippet":"data \"cloudflare_r2_bucket_sippy\" \"example_r2_bucket_sippy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"State of Sippy for this bucket."},{"name":"destination","type":"Attributes","description":"Details about the configured destination bucket.","children":[{"name":"access_key_id","type":"String","description":"ID of the Cloudflare API token used when writing objects to this\nbucket.\n"},{"name":"account","type":"String"},{"name":"bucket","type":"String","description":"Name of the bucket on the provider."},{"name":"r2_bucket_sippy_provider","type":"String"}]},{"name":"source","type":"Attributes","description":"Details about the configured source bucket.","children":[{"name":"bucket","type":"String","description":"Name of the bucket on the provider (AWS, GCS only)."},{"name":"bucket_url","type":"String","description":"S3-compatible URL (Generic S3-compatible providers only)."},{"name":"container","type":"String","description":"Name of the Azure Blob Storage container (Azure only)."},{"name":"r2_bucket_sippy_provider","type":"String"},{"name":"region","type":"String","description":"Region where the bucket resides (AWS only)."}]}]}]},"get /accounts/{}/registrar/domains":{"operationId":"registrar-domains-list-domains","declarations":[{"kind":"list-data-source","name":"cloudflare_registrar_domains","stainlessResource":"registrar.domains","methodName":"list","snippet":"data \"cloudflare_registrar_domains\" \"example_registrar_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"available","type":"Bool","description":"Shows if a domain is available for transferring into Cloudflare Registrar."},{"name":"can_register","type":"Bool","description":"Indicates eligibility to register the domain as a new domain."},{"name":"created_at","type":"Time","description":"Shows time of creation."},{"name":"current_registrar","type":"String","description":"Shows name of current registrar."},{"name":"expires_at","type":"Time","description":"Shows when domain name registration expires."},{"name":"locked","type":"Bool","description":"Shows whether a registrar lock is in place for a domain."},{"name":"registrant_contact","type":"Attributes","description":"Shows contact information for domain registrant.","children":[{"name":"address","type":"String","description":"Address."},{"name":"city","type":"String","description":"City."},{"name":"country","type":"String","description":"The country in which the user lives."},{"name":"first_name","type":"String","description":"User's first name."},{"name":"last_name","type":"String","description":"User's last name."},{"name":"organization","type":"String","description":"Name of organization."},{"name":"phone","type":"String","description":"User's telephone number."},{"name":"state","type":"String","description":"State."},{"name":"zip","type":"String","description":"The zipcode or postal code where the user lives."},{"name":"id","type":"String","description":"Contact Identifier."},{"name":"address2","type":"String","description":"Optional address line for unit, floor, suite, etc."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"fax","type":"String","description":"Contact fax number."}]},{"name":"registry_statuses","type":"String","description":"A comma-separated list of registry status codes. Refer to [EPP Status Codes](https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en) for the full list."},{"name":"supported_tld","type":"Bool","description":"Indicates whether Cloudflare Registrar currently supports a particular TLD. Refer to [TLD Policies](https://www.cloudflare.com/tld-policies/) for a list of supported TLDs."},{"name":"transfer_in","type":"Attributes","description":"Statuses for domain transfers into Cloudflare Registrar.","children":[{"name":"accept_foa","type":"String","description":"Status of the registrant authorization step."},{"name":"approve_transfer","type":"String","description":"Status of the registry transfer-approval step."},{"name":"can_cancel_transfer","type":"Bool","description":"Indicates if cancellation is still possible."},{"name":"disable_privacy","type":"String","description":"Status of the privacy-guard disabling step at the foreign registrar."},{"name":"enter_auth_code","type":"String","description":"Status of the auth-code entry and verification step."},{"name":"unlock_domain","type":"String","description":"Status of the domain-unlock step at the foreign registrar."}]},{"name":"updated_at","type":"Time","description":"Last updated."}]}]}]},"get /accounts/{}/registrar/domains/{}":{"operationId":"registrar-domains-get-domain","declarations":[{"kind":"data-source","name":"cloudflare_registrar_domain","stainlessResource":"registrar.domains","methodName":"get","snippet":"data \"cloudflare_registrar_domain\" \"example_registrar_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_name = \"example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"domain_name","type":"String","description":"Provides a fully qualified domain name (FQDN), including the extension\n(e.g., `example.com`, `mybrand.app`). The domain name uniquely identifies\na registration. Cloudflare permits only one registration per domain, making\nthe domain name a natural idempotency key for registration requests.\n"}],"optional":[],"computed":[]}]},"get /accounts/{}/resource-library/applications":{"operationId":"getResourceLibraryApplications","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_resource_library_applications","stainlessResource":"zero_trust.resource_library.applications","methodName":"list","snippet":"data \"cloudflare_zero_trust_resource_library_applications\" \"example_zero_trust_resource_library_applications\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n fields = \"fields\"\n filter = \"filter\"\n order_by = \"order_by\"\n search = \"xx\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"fields","type":"String","description":"Return only the listed properties on each application, as a comma-separated list.\nUse this to keep responses small when you only need part of each application — for\nexample populating a picker with `fields=id,name` instead of downloading every\nhostname and IP subnet.\n\nOmit this parameter to receive the full application object.\n\n`id` is always returned.\n\nSelectable properties: `id`, `name`, `human_id`, `version`, `hostnames`,\n`support_domains`, `ip_subnets`, `port_protocols`, `supported`, `gen_ai_score`,\n`application_confidence_score`, `created_at`, `updated_at`, `review_status`.\n\nUnknown or empty property names return `400`.\n"},{"name":"filter","type":"String","description":"Filter applications using key:value format. Supported filter keys:\n- name: Filter by application name (e.g., name:HR)\n- id: Filter by application ID (e.g., id:498)\n- human_id: Filter by human-readable ID (e.g., human_id:HR)\n- hostname: Filter by hostname or support domain (e.g., hostname:portal.example.com)\n- source: Filter by application source name (e.g., source:cloudflare)\n- ip_subnet: Filter by IP subnet using CIDR containment — returns applications where any stored subnet contains the search value (e.g., ip_subnet:10.0.1.5/32 matches apps with 10.0.0.0/16)\n- category_id: Filter by category ID (e.g., category_id:12).\n- category_name: Filter by category name (e.g., category_name:HR).\n- supported: Filter by supported Cloudflare product (e.g., supported:ACCESS). Values: GATEWAY, ACCESS, CASB.\n- review_status: Filter by the account's Gateway review status. Values: approved, unapproved, in_review, unreviewed.\n.\n"},{"name":"order_by","type":"String","description":"Order results using field:direction format. Supported fields are name, id, human_id,\ncategory_id, application_type, application_confidence_score, and gen_ai_score.\nSupported directions are asc and desc. Ignored when search is provided; results are\nranked by relevance instead.\n"},{"name":"search","type":"String","description":"Fuzzy search across application name and hostnames. Results are ranked by relevance. Must be between 2 and 200 characters. Can be combined with filter parameters."},{"name":"limit","type":"Int64","description":"Limit of number of results to return (max 250)."},{"name":"offset","type":"Int64","description":"Offset of results to return."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Returns the application ID."},{"name":"application_confidence_score","type":"Float64","description":"Confidence score for the application. Returns -1 when no score is available."},{"name":"application_score_composition","type":"unknown","description":"Returns the score composition breakdown for the application."},{"name":"application_source","type":"String","description":"Returns the application source."},{"name":"application_type","type":"String","description":"Returns the application type."},{"name":"application_type_description","type":"String","description":"Returns the application type description."},{"name":"category_id","type":"Int64","description":"Returns the category ID."},{"name":"created_at","type":"String","description":"Returns the application creation time."},{"name":"gen_ai_score","type":"Float64","description":"GenAI score for the application. Returns -1 when no score is available."},{"name":"hostnames","type":"Set[String]","description":"Hostnames matched by the application."},{"name":"human_id","type":"String","description":"Returns the human readable ID."},{"name":"ip_subnets","type":"Set[String]","description":"IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128."},{"name":"name","type":"String","description":"Returns the application name."},{"name":"port_protocols","type":"Set[String]","description":"Port and protocol pairs matched by the application."},{"name":"review_status","type":"String","description":"The account-specific Gateway review status. Applications with no assigned review status are returned as `unreviewed`."},{"name":"support_domains","type":"Set[String]","description":"Support domains matched by the application."},{"name":"supported","type":"Set[String]","description":"Cloudflare products that support this application."},{"name":"updated_at","type":"String","description":"Returns the application update time."},{"name":"version","type":"String","description":"Returns the application version."}]}]}]},"get /accounts/{}/resource-library/applications/{}":{"operationId":"getResourceLibraryApplicationById","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_resource_library_application","stainlessResource":"zero_trust.resource_library.applications","methodName":"get","snippet":"data \"cloudflare_zero_trust_resource_library_application\" \"example_zero_trust_resource_library_application\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = 498\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"Int64","description":"Returns the application ID."},{"name":"filter","type":"Attributes","children":[{"name":"fields","type":"String","description":"Return only the listed properties on each application, as a comma-separated list.\nUse this to keep responses small when you only need part of each application — for\nexample populating a picker with `fields=id,name` instead of downloading every\nhostname and IP subnet.\n\nOmit this parameter to receive the full application object.\n\n`id` is always returned.\n\nSelectable properties: `id`, `name`, `human_id`, `version`, `hostnames`,\n`support_domains`, `ip_subnets`, `port_protocols`, `supported`, `gen_ai_score`,\n`application_confidence_score`, `created_at`, `updated_at`, `review_status`.\n\nUnknown or empty property names return `400`.\n"},{"name":"filter","type":"String","description":"Filter applications using key:value format. Supported filter keys:\n- name: Filter by application name (e.g., name:HR)\n- id: Filter by application ID (e.g., id:498)\n- human_id: Filter by human-readable ID (e.g., human_id:HR)\n- hostname: Filter by hostname or support domain (e.g., hostname:portal.example.com)\n- source: Filter by application source name (e.g., source:cloudflare)\n- ip_subnet: Filter by IP subnet using CIDR containment — returns applications where any stored subnet contains the search value (e.g., ip_subnet:10.0.1.5/32 matches apps with 10.0.0.0/16)\n- category_id: Filter by category ID (e.g., category_id:12).\n- category_name: Filter by category name (e.g., category_name:HR).\n- supported: Filter by supported Cloudflare product (e.g., supported:ACCESS). Values: GATEWAY, ACCESS, CASB.\n- review_status: Filter by the account's Gateway review status. Values: approved, unapproved, in_review, unreviewed.\n.\n"},{"name":"limit","type":"Int64","description":"Limit of number of results to return (max 250)."},{"name":"offset","type":"Int64","description":"Offset of results to return."},{"name":"order_by","type":"String","description":"Order results using field:direction format. Supported fields are name, id, human_id,\ncategory_id, application_type, application_confidence_score, and gen_ai_score.\nSupported directions are asc and desc. Ignored when search is provided; results are\nranked by relevance instead.\n"},{"name":"search","type":"String","description":"Fuzzy search across application name and hostnames. Results are ranked by relevance. Must be between 2 and 200 characters. Can be combined with filter parameters."}]}],"computed":[{"name":"application_confidence_score","type":"Float64","description":"Confidence score for the application. Returns -1 when no score is available."},{"name":"application_source","type":"String","description":"Returns the application source."},{"name":"application_type","type":"String","description":"Returns the application type."},{"name":"application_type_description","type":"String","description":"Returns the application type description."},{"name":"category_id","type":"Int64","description":"Returns the category ID."},{"name":"created_at","type":"String","description":"Returns the application creation time."},{"name":"gen_ai_score","type":"Float64","description":"GenAI score for the application. Returns -1 when no score is available."},{"name":"human_id","type":"String","description":"Returns the human readable ID."},{"name":"name","type":"String","description":"Returns the application name."},{"name":"updated_at","type":"String","description":"Returns the application update time."},{"name":"version","type":"String","description":"Returns the application version."},{"name":"hostnames","type":"Set[String]","description":"Hostnames matched by the application."},{"name":"ip_subnets","type":"Set[String]","description":"IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128."},{"name":"port_protocols","type":"Set[String]","description":"Port and protocol pairs matched by the application."},{"name":"support_domains","type":"Set[String]","description":"Support domains matched by the application."},{"name":"supported","type":"Set[String]","description":"Cloudflare products that support this application."},{"name":"application_score_composition","type":"unknown","description":"Returns the score composition breakdown for the application."}]}]},"get /accounts/{}/resource-library/categories":{"operationId":"getResourceLibraryCategories","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_resource_library_categories","stainlessResource":"zero_trust.resource_library.categories","methodName":"list","snippet":"data \"cloudflare_zero_trust_resource_library_categories\" \"example_zero_trust_resource_library_categories\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"limit","type":"Int64","description":"Limit of number of results to return."},{"name":"offset","type":"Int64","description":"Offset of results to return."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Returns the category ID."},{"name":"created_at","type":"String","description":"Returns the category creation time."},{"name":"description","type":"String","description":"Returns the category description."},{"name":"name","type":"String","description":"Returns the category name."}]}]}]},"get /accounts/{}/resource-library/categories/{}":{"operationId":"getResourceLibraryCategoryById","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_resource_library_category","stainlessResource":"zero_trust.resource_library.categories","methodName":"get","snippet":"data \"cloudflare_zero_trust_resource_library_category\" \"example_zero_trust_resource_library_category\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = 12\n}\n","required":[{"name":"account_id","type":"String"},{"name":"id","type":"Int64","description":"Returns the category ID."}],"optional":[],"computed":[{"name":"created_at","type":"String","description":"Returns the category creation time."},{"name":"description","type":"String","description":"Returns the category description."},{"name":"name","type":"String","description":"Returns the category name."}]}]},"get /accounts/{}/roles":{"operationId":"account-roles-list-roles","declarations":[{"kind":"list-data-source","name":"cloudflare_account_roles","stainlessResource":"accounts.roles","methodName":"list","snippet":"data \"cloudflare_account_roles\" \"example_account_roles\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Role identifier tag."},{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]}]}]},"get /accounts/{}/roles/{}":{"operationId":"account-roles-role-details","declarations":[{"kind":"data-source","name":"cloudflare_account_role","stainlessResource":"accounts.roles","methodName":"get","snippet":"data \"cloudflare_account_role\" \"example_account_role\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n role_id = \"3536bcfad5faccb999b47003c79917fb\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"role_id","type":"String","description":"Role identifier tag."}],"optional":[],"computed":[{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"id","type":"String","description":"Role identifier tag."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]}]},"get /accounts/{}/rules/lists":{"operationId":"lists-get-lists","declarations":[{"kind":"list-data-source","name":"cloudflare_lists","stainlessResource":"rules.lists","methodName":"list","snippet":"data \"cloudflare_lists\" \"example_lists\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique ID of the list."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"kind","type":"String","description":"The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects)."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"name","type":"String","description":"An informative name for the list. Use this name in filter and rule expressions."},{"name":"num_items","type":"Float64","description":"The number of items in the list."},{"name":"num_referencing_filters","type":"Float64","description":"The number of [filters](/api/resources/filters/) referencing the list."},{"name":"description","type":"String","description":"An informative summary of the list."}]}]}]},"get /accounts/{}/rules/lists/{}":{"operationId":"lists-get-a-list","declarations":[{"kind":"data-source","name":"cloudflare_list","stainlessResource":"rules.lists","methodName":"get","snippet":"data \"cloudflare_list\" \"example_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n}\n","required":[{"name":"list_id","type":"String","description":"The unique ID of the list."},{"name":"account_id","type":"String","description":"The Account ID for this resource."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the list."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"description","type":"String","description":"An informative summary of the list."},{"name":"kind","type":"String","description":"The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects)."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"name","type":"String","description":"An informative name for the list. Use this name in filter and rule expressions."},{"name":"num_items","type":"Float64","description":"The number of items in the list."},{"name":"num_referencing_filters","type":"Float64","description":"The number of [filters](/api/resources/filters/) referencing the list."}]}]},"get /accounts/{}/rules/lists/{}/items":{"operationId":"lists-get-list-items","declarations":[{"kind":"list-data-source","name":"cloudflare_list_items","stainlessResource":"rules.lists.items","methodName":"list","snippet":"data \"cloudflare_list_items\" \"example_list_items\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n per_page = 1\n search = \"1.1.1.\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource."},{"name":"list_id","type":"String","description":"The unique ID of the list."}],"optional":[{"name":"per_page","type":"Int64","description":"Amount of results to include in each paginated response. A non-negative 32 bit integer."},{"name":"search","type":"String","description":"A search query to filter returned items. Its meaning depends on the list type: IP addresses must start with the provided string, hostnames and bulk redirects must contain the string, and ASNs must match the string exactly."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]},{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."}]}]}]},"get /accounts/{}/rules/lists/{}/items/{}":{"operationId":"lists-get-a-list-item","declarations":[{"kind":"data-source","name":"cloudflare_list_item","stainlessResource":"rules.lists.items","methodName":"get","snippet":"data \"cloudflare_list_item\" \"example_list_item\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n item_id = \"34b12448945f11eaa1b71c4d701ab86e\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource."},{"name":"item_id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"list_id","type":"String","description":"The unique ID of the list."}],"optional":[],"computed":[{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]}]}]},"get /accounts/{}/rum/site_info/{}":{"operationId":"web-analytics-get-site","declarations":[{"kind":"data-source","name":"cloudflare_web_analytics_site","stainlessResource":"rum.site_info","methodName":"get","snippet":"data \"cloudflare_web_analytics_site\" \"example_web_analytics_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"site_id","type":"String","description":"Identifier."},{"name":"filter","type":"Attributes","children":[{"name":"order_by","type":"String","description":"The property used to sort the list of results."}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"auto_install","type":"Bool","description":"If enabled, the JavaScript snippet is automatically injected for orange-clouded sites."},{"name":"created","type":"Time"},{"name":"site_tag","type":"String","description":"The Web Analytics site identifier."},{"name":"site_token","type":"String","description":"The Web Analytics site token."},{"name":"snippet","type":"String","description":"Encoded JavaScript snippet."},{"name":"rules","type":"List[Attributes]","description":"A list of rules.","children":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"host","type":"String","description":"The hostname the rule will be applied to."},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]","description":"The paths the rule will be applied to."},{"name":"priority","type":"Float64"}]},{"name":"ruleset","type":"Attributes","children":[{"name":"id","type":"String","description":"The Web Analytics ruleset identifier."},{"name":"enabled","type":"Bool","description":"Whether the ruleset is enabled."},{"name":"zone_name","type":"String"},{"name":"zone_tag","type":"String","description":"The zone identifier."}]}]}]},"get /accounts/{}/rum/site_info/list":{"operationId":"web-analytics-list-sites","declarations":[{"kind":"list-data-source","name":"cloudflare_web_analytics_sites","stainlessResource":"rum.site_info","methodName":"list","snippet":"data \"cloudflare_web_analytics_sites\" \"example_web_analytics_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n order_by = \"host\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"order_by","type":"String","description":"The property used to sort the list of results."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The Web Analytics site identifier."},{"name":"auto_install","type":"Bool","description":"If enabled, the JavaScript snippet is automatically injected for orange-clouded sites."},{"name":"created","type":"Time"},{"name":"rules","type":"List[Attributes]","description":"A list of rules.","children":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"host","type":"String","description":"The hostname the rule will be applied to."},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]","description":"The paths the rule will be applied to."},{"name":"priority","type":"Float64"}]},{"name":"ruleset","type":"Attributes","children":[{"name":"id","type":"String","description":"The Web Analytics ruleset identifier."},{"name":"enabled","type":"Bool","description":"Whether the ruleset is enabled."},{"name":"zone_name","type":"String"},{"name":"zone_tag","type":"String","description":"The zone identifier."}]},{"name":"site_tag","type":"String","description":"The Web Analytics site identifier."},{"name":"site_token","type":"String","description":"The Web Analytics site token."},{"name":"snippet","type":"String","description":"Encoded JavaScript snippet."}]}]}]},"get /accounts/{}/secondary_dns/acls":{"operationId":"secondary-dns-(-acl)-list-ac-ls","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_zone_transfers_acls","stainlessResource":"dns.zone_transfers.acls","methodName":"list","snippet":"data \"cloudflare_dns_zone_transfers_acls\" \"example_dns_zone_transfers_acls\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"ip_range","type":"String","description":"Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively."},{"name":"name","type":"String","description":"The name of the acl."}]}]}]},"get /accounts/{}/secondary_dns/acls/{}":{"operationId":"secondary-dns-(-acl)-acl-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_acl","stainlessResource":"dns.zone_transfers.acls","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_acl\" \"example_dns_zone_transfers_acl\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n acl_id = \"23ff594956f20c2a721606e94745a8aa\"\n}\n","required":[{"name":"acl_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ip_range","type":"String","description":"Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively."},{"name":"name","type":"String","description":"The name of the acl."}]}]},"get /accounts/{}/secondary_dns/peers":{"operationId":"secondary-dns-(-peer)-list-peers","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_zone_transfers_peers","stainlessResource":"dns.zone_transfers.peers","methodName":"list","snippet":"data \"cloudflare_dns_zone_transfers_peers\" \"example_dns_zone_transfers_peers\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"name","type":"String","description":"The name of the peer."},{"name":"ip","type":"String","description":"IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to."},{"name":"ixfr_enable","type":"Bool","description":"Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones."},{"name":"port","type":"Float64","description":"DNS port of primary or secondary nameserver, depending on what zone this peer is linked to."},{"name":"tsig_id","type":"String","description":"TSIG authentication will be used for zone transfer if configured."}]}]}]},"get /accounts/{}/secondary_dns/peers/{}":{"operationId":"secondary-dns-(-peer)-peer-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_peer","stainlessResource":"dns.zone_transfers.peers","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_peer\" \"example_dns_zone_transfers_peer\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n peer_id = \"23ff594956f20c2a721606e94745a8aa\"\n}\n","required":[{"name":"peer_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ip","type":"String","description":"IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to."},{"name":"ixfr_enable","type":"Bool","description":"Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones."},{"name":"name","type":"String","description":"The name of the peer."},{"name":"port","type":"Float64","description":"DNS port of primary or secondary nameserver, depending on what zone this peer is linked to."},{"name":"tsig_id","type":"String","description":"TSIG authentication will be used for zone transfer if configured."}]}]},"get /accounts/{}/secondary_dns/tsigs":{"operationId":"secondary-dns-(-tsig)-list-tsi-gs","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_zone_transfers_tsigs","stainlessResource":"dns.zone_transfers.tsigs","methodName":"list","snippet":"data \"cloudflare_dns_zone_transfers_tsigs\" \"example_dns_zone_transfers_tsigs\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"algo","type":"String","description":"TSIG algorithm."},{"name":"name","type":"String","description":"TSIG key name."},{"name":"secret","type":"String","description":"TSIG secret.","sensitive":true}]}]}]},"get /accounts/{}/secondary_dns/tsigs/{}":{"operationId":"secondary-dns-(-tsig)-tsig-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_tsig","stainlessResource":"dns.zone_transfers.tsigs","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_tsig\" \"example_dns_zone_transfers_tsig\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n tsig_id = \"69cd1e104af3e6ed3cb344f263fd0d5a\"\n}\n","required":[{"name":"tsig_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"algo","type":"String","description":"TSIG algorithm."},{"name":"name","type":"String","description":"TSIG key name."},{"name":"secret","type":"String","description":"TSIG secret.","sensitive":true}]}]},"get /accounts/{}/secrets_store/stores":{"operationId":"secrets-store-list","declarations":[{"kind":"list-data-source","name":"cloudflare_secrets_stores","stainlessResource":"secrets_store.stores","methodName":"list","snippet":"data \"cloudflare_secrets_stores\" \"example_secrets_stores\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order stores by values in the given field."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Store Identifier."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the store."},{"name":"account_id","type":"String","description":"Account Identifier."}]}]}]},"get /accounts/{}/secrets_store/stores/{}":{"operationId":"secrets-store-get-store-by-id","declarations":[{"kind":"data-source","name":"cloudflare_secrets_store","stainlessResource":"secrets_store.stores","methodName":"get","snippet":"data \"cloudflare_secrets_store\" \"example_secrets_store\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"store_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order stores by values in the given field."}]}],"computed":[{"name":"id","type":"String"},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the store."}]}]},"get /accounts/{}/secrets_store/stores/{}/secrets":{"operationId":"secrets-store-secrets-list","declarations":[{"kind":"list-data-source","name":"cloudflare_secrets_store_secrets","stainlessResource":"secrets_store.stores.secrets","methodName":"list","snippet":"data \"cloudflare_secrets_store_secrets\" \"example_secrets_store_secrets\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n scopes = [\"workers\"]\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"store_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search secrets using a filter string, filtering across name and comment."},{"name":"scopes","type":"List[String]","description":"Only secrets with the given scopes will be returned."},{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order secrets by values in the given field."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Secret identifier tag."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the secret."},{"name":"status","type":"String"},{"name":"store_id","type":"String","description":"Store Identifier."},{"name":"comment","type":"String","description":"Freeform text describing the secret."},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."}]}]}]},"get /accounts/{}/secrets_store/stores/{}/secrets/{}":{"operationId":"secrets-store-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_secrets_store_secret","stainlessResource":"secrets_store.stores.secrets","methodName":"get","snippet":"data \"cloudflare_secrets_store_secret\" \"example_secrets_store_secret\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n secret_id = \"3fd85f74b32742f1bff64a85009dda07\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"store_id","type":"String"}],"optional":[{"name":"secret_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order secrets by values in the given field."},{"name":"scopes","type":"List[String]","description":"Only secrets with the given scopes will be returned."},{"name":"search","type":"String","description":"Search secrets using a filter string, filtering across name and comment."}]}],"computed":[{"name":"id","type":"String"},{"name":"comment","type":"String","description":"Freeform text describing the secret."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the secret."},{"name":"status","type":"String"},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."}]}]},"get /accounts/{}/shares":{"operationId":"shares-list","declarations":[{"kind":"list-data-source","name":"cloudflare_shares","stainlessResource":"resource_sharing","methodName":"list","snippet":"data \"cloudflare_shares\" \"example_shares\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n include_recipient_counts = true\n include_resources = true\n kind = \"sent\"\n resource_types = [\"custom-ruleset\"]\n status = \"active\"\n tag = [\"env=production\"]\n target_type = \"account\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."}],"optional":[{"name":"include_recipient_counts","type":"Bool","description":"Include recipient counts in the response."},{"name":"include_resources","type":"Bool","description":"Include resources in the response."},{"name":"kind","type":"String","description":"Filter shares by kind."},{"name":"status","type":"String","description":"Filter shares by status."},{"name":"target_type","type":"String","description":"Filter shares by target_type."},{"name":"resource_types","type":"List[String]","description":"Filter share resources by resource_types."},{"name":"tag","type":"List[String]","description":"Filter shares by tag. Each value is either `key=value` (matches shares whose tags contain that key/value pair) or `key` alone (matches shares that have any value for that key). May be repeated; multiple `tag` parameters are ANDed together. Maximum 20 `tag` parameters per request."},{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order shares by values in the given field."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Share identifier tag."},{"name":"account_id","type":"String","description":"Account identifier."},{"name":"account_name","type":"String","description":"The display name of an account."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"name","type":"String","description":"The name of the share."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"status","type":"String"},{"name":"target_type","type":"String"},{"name":"associated_recipient_count","type":"Int64","description":"The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"associating_recipient_count","type":"Int64","description":"The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociated_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociating_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"kind","type":"String"},{"name":"resources","type":"List[Attributes]","description":"A list of resources that are part of the share. This field is only included when requested via the 'include_resources' parameter.","children":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]}]}]},"get /accounts/{}/shares/{}":{"operationId":"shares-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_share","stainlessResource":"resource_sharing","methodName":"get","snippet":"data \"cloudflare_share\" \"example_share\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_recipient_counts = true\n include_resources = true\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."}],"optional":[{"name":"share_id","type":"String","description":"Share identifier tag."},{"name":"include_recipient_counts","type":"Bool","description":"Include recipient counts in the response."},{"name":"include_resources","type":"Bool","description":"Include resources in the response."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"kind","type":"String","description":"Filter shares by kind."},{"name":"order","type":"String","description":"Order shares by values in the given field."},{"name":"resource_types","type":"List[String]","description":"Filter share resources by resource_types."},{"name":"status","type":"String","description":"Filter shares by status."},{"name":"tag","type":"List[String]","description":"Filter shares by tag. Each value is either `key=value` (matches shares whose tags contain that key/value pair) or `key` alone (matches shares that have any value for that key). May be repeated; multiple `tag` parameters are ANDed together. Maximum 20 `tag` parameters per request."},{"name":"target_type","type":"String","description":"Filter shares by target_type."}]}],"computed":[{"name":"id","type":"String","description":"Share identifier tag."},{"name":"account_name","type":"String","description":"The display name of an account."},{"name":"associated_recipient_count","type":"Int64","description":"The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"associating_recipient_count","type":"Int64","description":"The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"disassociated_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociating_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"kind","type":"String"},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"name","type":"String","description":"The name of the share."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"status","type":"String"},{"name":"target_type","type":"String"},{"name":"resources","type":"List[Attributes]","description":"A list of resources that are part of the share. This field is only included when requested via the 'include_resources' parameter.","children":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]}]},"get /accounts/{}/shares/{}/recipients":{"operationId":"share-recipients-list","declarations":[{"kind":"list-data-source","name":"cloudflare_share_recipients","stainlessResource":"resource_sharing.recipients","methodName":"list","snippet":"data \"cloudflare_share_recipients\" \"example_share_recipients\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_resources = true\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"include_resources","type":"Bool","description":"Include resources in the response."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Share Recipient identifier tag."},{"name":"account_id","type":"String","description":"Account identifier."},{"name":"association_status","type":"String","description":"The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\n"},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resources","type":"List[Attributes]","children":[{"name":"error","type":"String","description":"Share Recipient error message."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"terminal","type":"Bool","description":"Whether the error is terminal or will be continually retried."}]}]}]}]},"get /accounts/{}/shares/{}/recipients/{}":{"operationId":"share-recipients-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_share_recipient","stainlessResource":"resource_sharing.recipients","methodName":"get","snippet":"data \"cloudflare_share_recipient\" \"example_share_recipient\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n recipient_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_resources = true\n}\n","required":[{"name":"recipient_id","type":"String","description":"Share Recipient identifier tag."},{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"include_resources","type":"Bool","description":"Include resources in the response."}],"computed":[{"name":"id","type":"String","description":"Share Recipient identifier tag."},{"name":"association_status","type":"String","description":"The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\n"},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resources","type":"List[Attributes]","children":[{"name":"error","type":"String","description":"Share Recipient error message."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"terminal","type":"Bool","description":"Whether the error is terminal or will be continually retried."}]}]}]},"get /accounts/{}/shares/{}/resources":{"operationId":"share-resources-list","declarations":[{"kind":"list-data-source","name":"cloudflare_share_resources","stainlessResource":"resource_sharing.resources","methodName":"list","snippet":"data \"cloudflare_share_resources\" \"example_share_resources\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n resource_type = \"custom-ruleset\"\n status = \"active\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"resource_type","type":"String","description":"Filter share resources by resource_type."},{"name":"status","type":"String","description":"Filter share resources by status."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]}]},"get /accounts/{}/shares/{}/resources/{}":{"operationId":"share-resources-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_share_resource","stainlessResource":"resource_sharing.resources","methodName":"get","snippet":"data \"cloudflare_share_resource\" \"example_share_resource\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n share_resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"share_resource_id","type":"String","description":"Share Resource identifier."},{"name":"filter","type":"Attributes","children":[{"name":"resource_type","type":"String","description":"Filter share resources by resource_type."},{"name":"status","type":"String","description":"Filter share resources by status."}]}],"computed":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."},{"name":"meta","type":"unknown","description":"Resource Metadata."}]}]},"get /accounts/{}/sso_connectors":{"operationId":"get-all-sso-connectors","declarations":[{"kind":"list-data-source","name":"cloudflare_sso_connectors","stainlessResource":"iam.sso","methodName":"list","snippet":"data \"cloudflare_sso_connectors\" \"example_sso_connectors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"SSO Connector identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the SSO connector"},{"name":"email_domain","type":"String"},{"name":"enabled","type":"Bool"},{"name":"updated_on","type":"Time","description":"Timestamp for the last update of the SSO connector"},{"name":"use_fedramp_language","type":"Bool","description":"Controls the display of FedRAMP language to the user during SSO login"},{"name":"verification","type":"Attributes","children":[{"name":"code","type":"String","description":"DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership."},{"name":"status","type":"String","description":"The status of the verification code from the verification process."}]}]}]}]},"get /accounts/{}/sso_connectors/{}":{"operationId":"get-sso-connector","declarations":[{"kind":"data-source","name":"cloudflare_sso_connector","stainlessResource":"iam.sso","methodName":"get","snippet":"data \"cloudflare_sso_connector\" \"example_sso_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n sso_connector_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"sso_connector_id","type":"String","description":"SSO Connector identifier tag."},{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String","description":"SSO Connector identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the SSO connector"},{"name":"email_domain","type":"String"},{"name":"enabled","type":"Bool"},{"name":"updated_on","type":"Time","description":"Timestamp for the last update of the SSO connector"},{"name":"use_fedramp_language","type":"Bool","description":"Controls the display of FedRAMP language to the user during SSO login"},{"name":"verification","type":"Attributes","children":[{"name":"code","type":"String","description":"DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership."},{"name":"status","type":"String","description":"The status of the verification code from the verification process."}]}]}]},"get /accounts/{}/storage/kv/namespaces":{"operationId":"workers-kv-namespace-list-namespaces","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_kv_namespaces","stainlessResource":"kv.namespaces","methodName":"list","snippet":"data \"cloudflare_workers_kv_namespaces\" \"example_workers_kv_namespaces\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"id\"\n}\n","required":[{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces."}],"optional":[{"name":"direction","type":"String","description":"Sort namespaces in ascending (`asc`) or descending (`desc`) order."},{"name":"order","type":"String","description":"Namespace field to sort by (`id` or `title`)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"ID of the Workers KV namespace."},{"name":"title","type":"String","description":"Human-readable string name for a Workers KV namespace."},{"name":"jurisdiction","type":"String","description":"Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time."},{"name":"supports_url_encoding","type":"Bool","description":"True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"."}]}]}]},"get /accounts/{}/storage/kv/namespaces/{}":{"operationId":"workers-kv-namespace-get-a-namespace","declarations":[{"kind":"data-source","name":"cloudflare_workers_kv_namespace","stainlessResource":"kv.namespaces","methodName":"get","snippet":"data \"cloudflare_workers_kv_namespace\" \"example_workers_kv_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n}\n","required":[{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces."}],"optional":[{"name":"namespace_id","type":"String","description":"ID of the Workers KV namespace."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort namespaces in ascending (`asc`) or descending (`desc`) order."},{"name":"order","type":"String","description":"Namespace field to sort by (`id` or `title`)."}]}],"computed":[{"name":"id","type":"String","description":"ID of the Workers KV namespace."},{"name":"jurisdiction","type":"String","description":"Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time."},{"name":"supports_url_encoding","type":"Bool","description":"True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"."},{"name":"title","type":"String","description":"Human-readable string name for a Workers KV namespace."}]}]},"get /accounts/{}/storage/kv/namespaces/{}/values/{}":{"operationId":"workers-kv-namespace-read-key-value-pair","declarations":[{"kind":"data-source","name":"cloudflare_workers_kv","stainlessResource":"kv.namespaces.values","methodName":"get","snippet":"data \"cloudflare_workers_kv\" \"example_workers_kv\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n key_name = \"My-Key\"\n}\n","required":[{"name":"key_name","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL."},{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces."},{"name":"namespace_id","type":"String","description":"ID of the Workers KV namespace."}],"optional":[],"computed":[{"name":"id","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL."},{"name":"value","type":"unknown"}]}]},"get /accounts/{}/stream":{"operationId":"stream-videos-list-videos","declarations":[{"kind":"list-data-source","name":"cloudflare_streams","stainlessResource":"stream","methodName":"list","snippet":"data \"cloudflare_streams\" \"example_streams\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"ea95132c15732412d22c1476fa83f27a\"\n after = \"2019-12-27T18:11:19.117Z\"\n before = \"2019-12-27T18:11:19.117Z\"\n creator = \"creator-id_abcde12345\"\n end = \"2014-01-02T02:20:00Z\"\n limit = 1\n live_input_id = \"live_input_id\"\n name = \"name\"\n search = \"puppy.mp4\"\n start = \"2014-01-02T02:20:00Z\"\n status = \"inprogress\"\n type = \"live\"\n video_name = \"puppy.mp4\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"after","type":"Time","description":"Alias for 'start'. Returns videos created after this date/time (RFC 3339 format)."},{"name":"before","type":"Time","description":"Alias for 'end'. Returns videos created before this date/time (RFC 3339 format)."},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"end","type":"Time","description":"Lists videos created before the specified date."},{"name":"id","type":"String","description":"Filter by video ID(s). Can be a single ID or a comma-separated list of IDs."},{"name":"limit","type":"Int64","description":"Maximum number of videos to return (default 1000, max 1000)."},{"name":"live_input_id","type":"String","description":"Filter by live input ID to find videos associated with a specific live stream."},{"name":"name","type":"String","description":"Filter by video name/UID(s). Can be a single name or a comma-separated list."},{"name":"search","type":"String","description":"Provides a partial word match of the `name` key in the `meta` field. Slow for medium to large video libraries. May be unavailable for very large libraries."},{"name":"start","type":"Time","description":"Lists videos created after the specified date."},{"name":"status","type":"String","description":"Specifies the processing status for all quality levels for a video."},{"name":"type","type":"String","description":"Specifies whether the video is `vod` or `live`."},{"name":"video_name","type":"String","description":"Provides a fast, exact string match on the `name` key in the `meta` field."},{"name":"asc","type":"Bool","description":"Lists videos in ascending order of creation."},{"name":"include_counts","type":"Bool","description":"Includes the total number of videos associated with the submitted query parameters."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin."},{"name":"clipped_from","type":"String","description":"The unique identifier of the source video this video was clipped from."},{"name":"created","type":"Time","description":"The date and time the media item was created."},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"duration","type":"Float64","description":"The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready."},{"name":"input","type":"Attributes","children":[{"name":"height","type":"Int64","description":"The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready."},{"name":"width","type":"Int64","description":"The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready."}]},{"name":"live_input","type":"String","description":"The live input ID used to upload a video with Stream Live."},{"name":"max_duration_seconds","type":"Int64","description":"The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown."},{"name":"max_size_bytes","type":"Int64","description":"The maximum size in bytes for the video upload."},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing videos."},{"name":"modified","type":"Time","description":"The date and time the media item was last modified."},{"name":"playback","type":"Attributes","children":[{"name":"dash","type":"String","description":"DASH Media Presentation Description for the video."},{"name":"hls","type":"String","description":"The HLS manifest for the video."}]},{"name":"preview","type":"String","description":"The video's preview page URI. This field is omitted until encoding is complete."},{"name":"public_details","type":"Attributes","description":"Public details for the video including title, share link, channel link, and logo.","children":[{"name":"channel_link","type":"String"},{"name":"logo","type":"String"},{"name":"media_id","type":"Int64"},{"name":"share_link","type":"String"},{"name":"title","type":"String"}]},{"name":"ready_to_stream","type":"Bool","description":"Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"ready_to_stream_at","type":"Time","description":"Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video."},{"name":"scheduled_deletion","type":"Time","description":"Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time."},{"name":"size","type":"Float64","description":"The size of the media item in bytes."},{"name":"status","type":"Attributes","description":"Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.","children":[{"name":"error_reason_code","type":"String","description":"Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use."},{"name":"error_reason_text","type":"String","description":"Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state."},{"name":"pct_complete","type":"String","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"state","type":"String","description":"Specifies the processing status for all quality levels for a video."}]},{"name":"thumbnail","type":"String","description":"The media item's thumbnail URI. This field is omitted until encoding is complete."},{"name":"thumbnail_timestamp_pct","type":"Float64","description":"The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"uploaded","type":"Time","description":"The date and time the media item was uploaded."},{"name":"upload_expiry","type":"Time","description":"The date and time when the video upload URL is no longer valid for direct user uploads."},{"name":"watermark","type":"Attributes","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]}]}]},"get /accounts/{}/stream/{}":{"operationId":"stream-videos-retrieve-video-details","declarations":[{"kind":"data-source","name":"cloudflare_stream","stainlessResource":"stream","methodName":"get","snippet":"data \"cloudflare_stream\" \"example_stream\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}],"optional":[],"computed":[{"name":"clipped_from","type":"String","description":"The unique identifier of the source video this video was clipped from."},{"name":"created","type":"Time","description":"The date and time the media item was created."},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"duration","type":"Float64","description":"The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready."},{"name":"live_input","type":"String","description":"The live input ID used to upload a video with Stream Live."},{"name":"max_duration_seconds","type":"Int64","description":"The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown."},{"name":"max_size_bytes","type":"Int64","description":"The maximum size in bytes for the video upload."},{"name":"modified","type":"Time","description":"The date and time the media item was last modified."},{"name":"preview","type":"String","description":"The video's preview page URI. This field is omitted until encoding is complete."},{"name":"ready_to_stream","type":"Bool","description":"Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"ready_to_stream_at","type":"Time","description":"Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video."},{"name":"scheduled_deletion","type":"Time","description":"Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time."},{"name":"size","type":"Float64","description":"The size of the media item in bytes."},{"name":"thumbnail","type":"String","description":"The media item's thumbnail URI. This field is omitted until encoding is complete."},{"name":"thumbnail_timestamp_pct","type":"Float64","description":"The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"upload_expiry","type":"Time","description":"The date and time when the video upload URL is no longer valid for direct user uploads."},{"name":"uploaded","type":"Time","description":"The date and time the media item was uploaded."},{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin."},{"name":"input","type":"Attributes","children":[{"name":"height","type":"Int64","description":"The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready."},{"name":"width","type":"Int64","description":"The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready."}]},{"name":"playback","type":"Attributes","children":[{"name":"dash","type":"String","description":"DASH Media Presentation Description for the video."},{"name":"hls","type":"String","description":"The HLS manifest for the video."}]},{"name":"public_details","type":"Attributes","description":"Public details for the video including title, share link, channel link, and logo.","children":[{"name":"channel_link","type":"String"},{"name":"logo","type":"String"},{"name":"media_id","type":"Int64"},{"name":"share_link","type":"String"},{"name":"title","type":"String"}]},{"name":"status","type":"Attributes","description":"Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.","children":[{"name":"error_reason_code","type":"String","description":"Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use."},{"name":"error_reason_text","type":"String","description":"Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state."},{"name":"pct_complete","type":"String","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"state","type":"String","description":"Specifies the processing status for all quality levels for a video."}]},{"name":"watermark","type":"Attributes","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing videos."}]}]},"get /accounts/{}/stream/{}/audio":{"operationId":"list-audio-tracks","declarations":[{"kind":"data-source","name":"cloudflare_stream_audio_track","stainlessResource":"stream.audio_tracks","methodName":"get","snippet":"data \"cloudflare_stream_audio_track\" \"example_stream_audio_track\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}],"optional":[],"computed":[{"name":"audio","type":"List[Attributes]","description":"Array of audio tracks for the video.","children":[{"name":"default","type":"Bool","description":"Denotes whether the audio track will be played by default in a player."},{"name":"label","type":"String","description":"A string to uniquely identify the track amongst other audio track labels for the specified video."},{"name":"status","type":"String","description":"Specifies the processing status of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}]}]}]},"get /accounts/{}/stream/{}/captions/{}":{"operationId":"stream-subtitles/-captions-get-caption-or-subtitle-for-language","declarations":[{"kind":"data-source","name":"cloudflare_stream_caption_language","stainlessResource":"stream.captions.language","methodName":"get","snippet":"data \"cloudflare_stream_caption_language\" \"example_stream_caption_language\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n language = \"tr\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"language","type":"String","description":"The language tag in BCP 47 format."}],"optional":[],"computed":[{"name":"generated","type":"Bool","description":"Whether the caption was generated via AI."},{"name":"label","type":"String","description":"The language label displayed in the native language to users."},{"name":"status","type":"String","description":"The status of a generated caption."}]}]},"get /accounts/{}/stream/{}/downloads":{"operationId":"stream-mp4-downloads-list-downloads","declarations":[{"kind":"data-source","name":"cloudflare_stream_download","stainlessResource":"stream.downloads","methodName":"get","snippet":"data \"cloudflare_stream_download\" \"example_stream_download\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}],"optional":[],"computed":[{"name":"audio","type":"Attributes","description":"The audio-only download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]},{"name":"default","type":"Attributes","description":"The default video download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]}]}]},"get /accounts/{}/stream/keys":{"operationId":"stream-signing-keys-list-signing-keys","declarations":[{"kind":"data-source","name":"cloudflare_stream_key","stainlessResource":"stream.keys","methodName":"get","snippet":"data \"cloudflare_stream_key\" \"example_stream_key\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created","type":"Time","description":"The date and time a signing key was created."},{"name":"key_id","type":"String","description":"The unique identifier for the signing key."}]}]},"get /accounts/{}/stream/live_inputs/{}":{"operationId":"stream-live-inputs-retrieve-a-live-input","declarations":[{"kind":"data-source","name":"cloudflare_stream_live_input","stainlessResource":"stream.live_inputs","methodName":"get","snippet":"data \"cloudflare_stream_live_input\" \"example_stream_live_input\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n live_input_identifier = \"66be4bf738797e01e1fca35a7bdecdcd\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"live_input_identifier","type":"String","description":"A unique identifier for a live input."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and time the live input was created."},{"name":"delete_recording_after_days","type":"Float64","description":"Indicates the number of days after which the live inputs recordings will be deleted. When a stream completes and the recording is ready, the value is used to calculate a scheduled deletion date for that recording. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion."},{"name":"enabled","type":"Bool","description":"Indicates whether the live input is enabled and can accept streams."},{"name":"keys_rotated_at","type":"Time","description":"The date and time the live input keys were last rotated. Omitted for live inputs that have never had their keys rotated."},{"name":"modified","type":"Time","description":"The date and time the live input was last modified."},{"name":"prefer_low_latency","type":"Bool","description":"When enabled, the live stream is delivered using Low-Latency HLS (LL-HLS), reducing glass-to-glass latency for viewers at the cost of reduced player compatibility."},{"name":"status","type":"String","description":"The connection status of a live input."},{"name":"uid","type":"String","description":"A unique identifier for a live input."},{"name":"playback","type":"Attributes","description":"Details for playing a live input's broadcast using the HLS or DASH manifests. URLs reference the live input ID.","children":[{"name":"dash","type":"String","description":"The DASH manifest URL used to play live video, referencing the live input ID."},{"name":"hls","type":"String","description":"The HLS manifest URL used to play live video, referencing the live input ID."}]},{"name":"recording","type":"Attributes","description":"Records the input to a Cloudflare Stream video. Behavior depends on the mode. In most cases, the video will initially be viewable as a live video and transition to on-demand after a condition is satisfied.","children":[{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display videos created with this input. Enter allowed origin domains in an array and use `*` for wildcard subdomains. An empty array allows videos to be viewed on any origin."},{"name":"hide_live_viewer_count","type":"Bool","description":"Disables reporting the number of live viewers when this property is set to `true`."},{"name":"mode","type":"String","description":"Specifies the recording behavior for the live input. Set this value to `off` to prevent a recording. Set the value to `automatic` to begin a recording and transition to on-demand after Stream Live stops receiving input."},{"name":"require_signed_urls","type":"Bool","description":"Indicates if a video using the live input has the `requireSignedURLs` property set. Also enforces access controls on any video recording of the livestream with the live input."},{"name":"timeout_seconds","type":"Int64","description":"Determines the amount of time a live input configured in `automatic` mode should wait before a recording transitions from live to on-demand. `0` is recommended for most use cases and indicates the platform default should be used."}]},{"name":"rtmps","type":"Attributes","description":"Details for streaming to an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use when streaming via RTMPS to a live input.","sensitive":true},{"name":"url","type":"String","description":"The RTMPS URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"rtmps_playback","type":"Attributes","description":"Details for playback from an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use for playback via RTMPS.","sensitive":true},{"name":"url","type":"String","description":"The URL used to play live video over RTMPS.","sensitive":true}]},{"name":"srt","type":"Attributes","description":"Details for streaming to a live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use when streaming via SRT to a live input.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use when streaming via SRT."},{"name":"url","type":"String","description":"The SRT URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"srt_playback","type":"Attributes","description":"Details for playback from an live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use for playback via SRT.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use for playback via SRT."},{"name":"url","type":"String","description":"The URL used to play live video over SRT.","sensitive":true}]},{"name":"web_rtc","type":"Attributes","description":"Details for streaming to a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The WebRTC URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"web_rtc_playback","type":"Attributes","description":"Details for playback from a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The URL used to play live video over WebRTC.","sensitive":true}]},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing live inputs."}]}]},"get /accounts/{}/stream/watermarks":{"operationId":"stream-watermark-profile-list-watermark-profiles","declarations":[{"kind":"list-data-source","name":"cloudflare_stream_watermarks","stainlessResource":"stream.watermarks","methodName":"list","snippet":"data \"cloudflare_stream_watermarks\" \"example_stream_watermarks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]}]},"get /accounts/{}/stream/watermarks/{}":{"operationId":"stream-watermark-profile-watermark-profile-details","declarations":[{"kind":"data-source","name":"cloudflare_stream_watermark","stainlessResource":"stream.watermarks","methodName":"get","snippet":"data \"cloudflare_stream_watermark\" \"example_stream_watermark\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"identifier","type":"String","description":"The unique identifier for a watermark profile."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]},"get /accounts/{}/stream/webhook":{"operationId":"stream-webhook-view-webhooks","declarations":[{"kind":"data-source","name":"cloudflare_stream_webhook","stainlessResource":"stream.webhooks","methodName":"get","snippet":"data \"cloudflare_stream_webhook\" \"example_stream_webhook\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[],"computed":[{"name":"modified","type":"Time","description":"The date and time the webhook was last modified."},{"name":"notification_url","type":"String","description":"The URL where webhooks will be sent."},{"name":"secret","type":"String","description":"The secret used to verify webhook signatures.","sensitive":true}]}]},"get /accounts/{}/teamnet/routes":{"operationId":"tunnel-route-list-tunnel-routes","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_routes","stainlessResource":"zero_trust.networks.routes","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_routes\" \"example_zero_trust_tunnel_cloudflared_routes\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n is_deleted = true\n network_subset = \"172.16.0.0/16\"\n network_superset = \"172.16.0.0/16\"\n route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n tun_types = [\"cfd_tunnel\"]\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted routes. If `false`, exclude deleted routes. If empty, all routes will be included."},{"name":"network_subset","type":"String","description":"If set, only list routes that are contained within this IP range."},{"name":"network_superset","type":"String","description":"If set, only list routes that contain this IP range."},{"name":"route_id","type":"String","description":"UUID of the route."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."},{"name":"tun_types","type":"List[String]","description":"The types of tunnels to filter by, separated by commas."},{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the route."},{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range connected by the route, in CIDR notation."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."},{"name":"virtual_network_name","type":"String","description":"A user-friendly name for the virtual network."}]}]}]},"get /accounts/{}/teamnet/routes/{}":{"operationId":"tunnel-route-get-tunnel-route","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_route","stainlessResource":"zero_trust.networks.routes","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_route\" \"example_zero_trust_tunnel_cloudflared_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"route_id","type":"String","description":"UUID of the route."},{"name":"filter","type":"Attributes","children":[{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted routes. If `false`, exclude deleted routes. If empty, all routes will be included."},{"name":"network_subset","type":"String","description":"If set, only list routes that are contained within this IP range."},{"name":"network_superset","type":"String","description":"If set, only list routes that contain this IP range."},{"name":"tun_types","type":"List[String]","description":"The types of tunnels to filter by, separated by commas."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."}]}],"computed":[{"name":"id","type":"String","description":"UUID of the route."},{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range connected by the route, in CIDR notation."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."}]}]},"get /accounts/{}/teamnet/virtual_networks":{"operationId":"tunnel-virtual-network-list-virtual-networks","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_virtual_networks","stainlessResource":"zero_trust.networks.virtual_networks","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_virtual_networks\" \"example_zero_trust_tunnel_cloudflared_virtual_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n is_default = true\n is_default_network = true\n is_deleted = true\n name = \"us-east-1-vpc\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"is_default","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_default_network","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted virtual networks. If `false`, exclude deleted virtual networks. If empty, all virtual networks will be included."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"comment","type":"String","description":"Optional remark describing the virtual network."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"is_default_network","type":"Bool","description":"If `true`, this virtual network is the default for the account."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."}]}]}]},"get /accounts/{}/teamnet/virtual_networks/{}":{"operationId":"tunnel-virtual-network-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_virtual_network","stainlessResource":"zero_trust.networks.virtual_networks","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_virtual_network\" \"example_zero_trust_tunnel_cloudflared_virtual_network\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"is_default","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_default_network","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted virtual networks. If `false`, exclude deleted virtual networks. If empty, all virtual networks will be included."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."}]}],"computed":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"comment","type":"String","description":"Optional remark describing the virtual network."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"is_default_network","type":"Bool","description":"If `true`, this virtual network is the default for the account."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."}]}]},"get /accounts/{}/tokens":{"operationId":"account-api-tokens-list-tokens","declarations":[{"kind":"list-data-source","name":"cloudflare_account_tokens","stainlessResource":"accounts.tokens","methodName":"list","snippet":"data \"cloudflare_account_tokens\" \"example_account_tokens\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."}]}]}]},"get /accounts/{}/tokens/{}":{"operationId":"account-api-tokens-token-details","declarations":[{"kind":"data-source","name":"cloudflare_account_token","stainlessResource":"accounts.tokens","methodName":"get","snippet":"data \"cloudflare_account_token\" \"example_account_token\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n token_id = \"ed17574386854bf78a67040be0a770b0\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"token_id","type":"String","description":"Token identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."}]}],"computed":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]}]}]},"get /accounts/{}/tokens/permission_groups":{"operationId":"account-api-tokens-list-permission-groups","declarations":[{"kind":"data-source","name":"cloudflare_account_api_token_permission_groups","stainlessResource":"accounts.tokens.permission_groups","methodName":"get","snippet":"data \"cloudflare_account_api_token_permission_groups\" \"example_account_api_token_permission_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"name","type":"String","description":"Filter by the name of the permission group.\nThe value must be URL-encoded."},{"name":"scope","type":"String","description":"Filter by the scope of the permission group.\nThe value must be URL-encoded."}],"computed":[{"name":"permission_groups","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Public ID."},{"name":"category","type":"String","description":"Product category that this permission group belongs to."},{"name":"is_selectable","type":"Bool","description":"Whether the caller can select this permission group when creating a token."},{"name":"name","type":"String","description":"Permission Group Name"},{"name":"scopes","type":"List[String]","description":"Resources to which the Permission Group is scoped"}]}]},{"kind":"list-data-source","name":"cloudflare_account_api_token_permission_groups_list","stainlessResource":"accounts.tokens.permission_groups","methodName":"list","snippet":"data \"cloudflare_account_api_token_permission_groups_list\" \"example_account_api_token_permission_groups_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"name","type":"String","description":"Filter by the name of the permission group.\nThe value must be URL-encoded."},{"name":"scope","type":"String","description":"Filter by the scope of the permission group.\nThe value must be URL-encoded."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Public ID."},{"name":"category","type":"String","description":"Product category that this permission group belongs to."},{"name":"is_selectable","type":"Bool","description":"Whether the caller can select this permission group when creating a token."},{"name":"name","type":"String","description":"Permission Group Name"},{"name":"scopes","type":"List[String]","description":"Resources to which the Permission Group is scoped"}]}]}]},"get /accounts/{}/vuln_scanner/credential_sets":{"operationId":"list-credential-sets","declarations":[{"kind":"list-data-source","name":"cloudflare_vulnerability_scanner_credential_sets","stainlessResource":"vulnerability_scanner.credential_sets","methodName":"list","snippet":"data \"cloudflare_vulnerability_scanner_credential_sets\" \"example_vulnerability_scanner_credential_sets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Credential set identifier."},{"name":"name","type":"String","description":"Human-readable name."}]}]}]},"get /accounts/{}/vuln_scanner/credential_sets/{}":{"operationId":"get-credential-set","declarations":[{"kind":"data-source","name":"cloudflare_vulnerability_scanner_credential_set","stainlessResource":"vulnerability_scanner.credential_sets","methodName":"get","snippet":"data \"cloudflare_vulnerability_scanner_credential_set\" \"example_vulnerability_scanner_credential_set\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"credential_set_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"name","type":"String","description":"Human-readable name."}]}]},"get /accounts/{}/vuln_scanner/credential_sets/{}/credentials":{"operationId":"list-credentials","declarations":[{"kind":"list-data-source","name":"cloudflare_vulnerability_scanner_credentials","stainlessResource":"vulnerability_scanner.credential_sets.credentials","methodName":"list","snippet":"data \"cloudflare_vulnerability_scanner_credentials\" \"example_vulnerability_scanner_credentials\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"credential_set_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Credential identifier."},{"name":"credential_set_id","type":"String","description":"Parent credential set identifier."},{"name":"location","type":"String","description":"Where the credential is attached in outgoing requests."},{"name":"location_name","type":"String","description":"Name of the header or cookie where the credential is attached.\n"},{"name":"name","type":"String","description":"Human-readable name."}]}]}]},"get /accounts/{}/vuln_scanner/credential_sets/{}/credentials/{}":{"operationId":"get-credential","declarations":[{"kind":"data-source","name":"cloudflare_vulnerability_scanner_credential","stainlessResource":"vulnerability_scanner.credential_sets.credentials","methodName":"get","snippet":"data \"cloudflare_vulnerability_scanner_credential\" \"example_vulnerability_scanner_credential\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n credential_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"credential_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."},{"name":"credential_set_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"location","type":"String","description":"Where the credential is attached in outgoing requests."},{"name":"location_name","type":"String","description":"Name of the header or cookie where the credential is attached.\n"},{"name":"name","type":"String","description":"Human-readable name."}]}]},"get /accounts/{}/vuln_scanner/target_environments":{"operationId":"list-target-environments","declarations":[{"kind":"list-data-source","name":"cloudflare_vulnerability_scanner_target_environments","stainlessResource":"vulnerability_scanner.target_environments","methodName":"list","snippet":"data \"cloudflare_vulnerability_scanner_target_environments\" \"example_vulnerability_scanner_target_environments\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Target environment identifier."},{"name":"name","type":"String","description":"Human-readable name."},{"name":"target","type":"Attributes","description":"Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.\n","children":[{"name":"type","type":"String"},{"name":"zone_tag","type":"String","description":"Cloudflare zone tag. The zone must belong to the account.\n"}]},{"name":"description","type":"String","description":"Optional description providing additional context."}]}]}]},"get /accounts/{}/vuln_scanner/target_environments/{}":{"operationId":"get-target-environment","declarations":[{"kind":"data-source","name":"cloudflare_vulnerability_scanner_target_environment","stainlessResource":"vulnerability_scanner.target_environments","methodName":"get","snippet":"data \"cloudflare_vulnerability_scanner_target_environment\" \"example_vulnerability_scanner_target_environment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n target_environment_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"target_environment_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"description","type":"String","description":"Optional description providing additional context."},{"name":"name","type":"String","description":"Human-readable name."},{"name":"target","type":"Attributes","description":"Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.\n","children":[{"name":"type","type":"String"},{"name":"zone_tag","type":"String","description":"Cloudflare zone tag. The zone must belong to the account.\n"}]}]}]},"get /accounts/{}/warp_connector":{"operationId":"cloudflare-tunnel-list-warp-connector-tunnels","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_warp_connectors","stainlessResource":"zero_trust.tunnels.warp_connector","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connectors\" \"example_zero_trust_tunnel_warp_connectors\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n exclude_prefix = \"vpc1-\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n include_prefix = \"vpc1-\"\n is_deleted = true\n name = \"blog\"\n status = \"healthy\"\n uuid = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n was_active_at = \"2009-11-10T23:00:00Z\"\n was_inactive_at = \"2009-11-10T23:00:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for the tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."}]}]}]},"get /accounts/{}/warp_connector/{}":{"operationId":"cloudflare-tunnel-get-a-warp-connector-tunnel","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_warp_connector","stainlessResource":"zero_trust.tunnels.warp_connector","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connector\" \"example_zero_trust_tunnel_warp_connector\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"filter","type":"Attributes","children":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for the tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"get /accounts/{}/warp_connector/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-get-warp-connector-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_warp_connector_config","stainlessResource":"zero_trust.tunnels.warp_connector.configurations","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connector_config\" \"example_zero_trust_tunnel_warp_connector_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"configuration_version","type":"Int64","description":"Monotonically increasing configuration version, incremented on each PUT."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"ha_mode","type":"String","description":"High-availability mode for the Mesh node. `none` means HA is enabled but no provider is configured yet (newly created nodes default to this). `disabled` means HA is explicitly turned off. `aws` uses AWS ENI move for failover. `local` uses virtual IPs (VIPs) on the local interface."},{"name":"updated_at","type":"Time","description":"Timestamp of the last update. Null if never updated."},{"name":"config","type":"Attributes","description":"Provider-specific configuration. Present for `aws` and `local` modes.","children":[{"name":"fnr_id","type":"String","description":"Floating Network Resource ID — the secondary ENI that is moved between nodes on failover."},{"name":"vips","type":"List[Attributes]","description":"VIPs to assign on the CloudflareWARP interface.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]},{"name":"vips_previous","type":"List[Attributes]","description":"VIPs to clean up on demotion or version drift.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]}]}]}]},"get /accounts/{}/warp_connector/{}/token":{"operationId":"cloudflare-tunnel-get-a-warp-connector-tunnel-token","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_warp_connector_token","stainlessResource":"zero_trust.tunnels.warp_connector.token","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connector_token\" \"example_zero_trust_tunnel_warp_connector_token\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"token","type":"String","description":"The Tunnel Token is used as a mechanism to authenticate the operation of a tunnel.","sensitive":true}]}]},"get /accounts/{}/workers/dispatch/namespaces":{"operationId":"namespace-worker-list","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_for_platforms_dispatch_namespaces","stainlessResource":"workers_for_platforms.dispatch.namespaces","methodName":"list","snippet":"data \"cloudflare_workers_for_platforms_dispatch_namespaces\" \"example_workers_for_platforms_dispatch_namespaces\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"created_by","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"modified_by","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"namespace_id","type":"String","description":"API Resource UUID tag."},{"name":"namespace_name","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"script_count","type":"Int64","description":"The current number of scripts in this Dispatch Namespace."},{"name":"trusted_workers","type":"Bool","description":"Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"."}]}]}]},"get /accounts/{}/workers/dispatch/namespaces/{}":{"operationId":"namespace-worker-get-namespace","declarations":[{"kind":"data-source","name":"cloudflare_workers_for_platforms_dispatch_namespace","stainlessResource":"workers_for_platforms.dispatch.namespaces","methodName":"get","snippet":"data \"cloudflare_workers_for_platforms_dispatch_namespace\" \"example_workers_for_platforms_dispatch_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dispatch_namespace = \"my-dispatch-namespace\"\n}\n","required":[{"name":"dispatch_namespace","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"created_by","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"modified_by","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"namespace_id","type":"String","description":"API Resource UUID tag."},{"name":"namespace_name","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"script_count","type":"Int64","description":"The current number of scripts in this Dispatch Namespace."},{"name":"trusted_workers","type":"Bool","description":"Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"."}]}]},"get /accounts/{}/workers/domains":{"operationId":"workers.domains.list","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_custom_domains","stainlessResource":"workers.domains","methodName":"list","snippet":"data \"cloudflare_workers_custom_domains\" \"example_workers_custom_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n environment = \"production\"\n hostname = \"app.example.com\"\n service = \"my-worker\"\n zone_id = \"593c9c94de529bbbfaac7c53ced0447d\"\n zone_name = \"example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"environment","type":"String","description":"Worker environment associated with the domain."},{"name":"hostname","type":"String","description":"Hostname of the domain."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Immutable ID of the domain."},{"name":"cert_id","type":"String","description":"ID of the TLS certificate issued for the domain."},{"name":"environment","type":"String","description":"Worker environment associated with the domain.","deprecated":"Deprecated."},{"name":"hostname","type":"String","description":"Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."}]}]}]},"get /accounts/{}/workers/domains/{}":{"operationId":"workers.domains.get","declarations":[{"kind":"data-source","name":"cloudflare_workers_custom_domain","stainlessResource":"workers.domains","methodName":"get","snippet":"data \"cloudflare_workers_custom_domain\" \"example_workers_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_id = \"dbe10b4bc17c295377eabd600e1787fd\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"domain_id","type":"String","description":"ID of the domain."},{"name":"filter","type":"Attributes","children":[{"name":"environment","type":"String","description":"Worker environment associated with the domain."},{"name":"hostname","type":"String","description":"Hostname of the domain."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."}]}],"computed":[{"name":"id","type":"String","description":"ID of the domain."},{"name":"cert_id","type":"String","description":"ID of the TLS certificate issued for the domain."},{"name":"environment","type":"String","description":"Worker environment associated with the domain.","deprecated":"Deprecated."},{"name":"hostname","type":"String","description":"Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."}]}]},"get /accounts/{}/workers/scripts":{"operationId":"worker-script-list-workers","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_scripts","stainlessResource":"workers.scripts","methodName":"list","snippet":"data \"cloudflare_workers_scripts\" \"example_workers_scripts\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tags = \"production:yes,staging:no\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"tags","type":"String","description":"Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The name used to identify the script."},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"etag","type":"String","description":"Hashed script content, can be used in a If-None-Match header when updating."},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the Worker's most recent version,\nincluding Durable Object classes (with their `storage`\nbackend) and named Worker entrypoints. Tombstoned lifecycle\nentries are omitted, so only live exports (`created` and\n`expecting-transfer`) are returned.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the default export."},{"name":"has_assets","type":"Bool","description":"Whether a Worker contains assets."},{"name":"has_modules","type":"Bool","description":"Whether a Worker contains modules."},{"name":"last_deployed_from","type":"String","description":"The client most recently used to deploy this Worker."},{"name":"logpush","type":"Bool","description":"Whether Logpush is turned on for the Worker."},{"name":"migration_tag","type":"String","description":"The tag of the Durable Object migration that was most recently applied for this Worker."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"named_handlers","type":"List[Attributes]","description":"Named exports, such as Durable Object class implementations and named entrypoints.","children":[{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the named export."},{"name":"name","type":"String","description":"The name of the export."}]},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for incoming requests. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"last_analyzed_at","type":"Time","description":"The last time the script was analyzed for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"status","type":"String","description":"Status of [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"placement_mode","type":"String","deprecated":"Deprecated."},{"name":"placement_status","type":"String","deprecated":"Deprecated."},{"name":"routes","type":"List[Attributes]","description":"Routes associated with the Worker.","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."},{"name":"script","type":"String","description":"Name of the script to run if the route matches."}]},{"name":"tag","type":"String","description":"The immutable ID of the script."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"tail_consumers","type":"Set[Attributes]","description":"List of Workers that will consume logs from the attached Worker.","children":[{"name":"service","type":"String","description":"Name of Worker that is to be the consumer."},{"name":"environment","type":"String","description":"Optional environment if the Worker utilizes one."},{"name":"namespace","type":"String","description":"Optional dispatch namespace the script belongs to."}]},{"name":"usage_model","type":"String","description":"Usage model for the Worker invocations."}]}]}]},"get /accounts/{}/workers/scripts/{}":{"operationId":"worker-script-download-worker","declarations":[{"kind":"data-source","name":"cloudflare_workers_script","stainlessResource":"workers.scripts","methodName":"get","snippet":"data \"cloudflare_workers_script\" \"example_workers_script\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"script_name","type":"String","description":"Name of the script."},{"name":"filter","type":"Attributes","children":[{"name":"tags","type":"String","description":"Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'."}]}],"computed":[{"name":"id","type":"String","description":"Name of the script."},{"name":"script","type":"String"}]}]},"get /accounts/{}/workers/scripts/{}/deployments":{"operationId":"worker-deployments-list-deployments","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_deployments","stainlessResource":"workers.scripts.deployments","methodName":"list","snippet":"data \"cloudflare_workers_deployments\" \"example_workers_deployments\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n since = \"2019-12-27T18:11:19.117Z\"\n until = \"2019-12-27T18:11:19.117Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"script_name","type":"String","description":"Name of the script."}],"optional":[{"name":"since","type":"Time","description":"Start of the deployment creation time range, inclusive."},{"name":"until","type":"Time","description":"End of the deployment creation time range, inclusive."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"deployments","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"source","type":"String"},{"name":"strategy","type":"String"},{"name":"versions","type":"List[Attributes]","description":"Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.","children":[{"name":"percentage","type":"Float64","description":"Percentage of traffic served by this version."},{"name":"version_id","type":"String","description":"Identifier of the Worker Version."}]},{"name":"annotations","type":"Attributes","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the deployment. Truncated to 1000 bytes if longer."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the deployment."}]},{"name":"author_email","type":"String"}]}]}]}]},"get /accounts/{}/workers/scripts/{}/deployments/{}":{"operationId":"worker-deployments-get-deployment","declarations":[{"kind":"data-source","name":"cloudflare_workers_deployment","stainlessResource":"workers.scripts.deployments","methodName":"get","snippet":"data \"cloudflare_workers_deployment\" \"example_workers_deployment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n deployment_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"deployment_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."},{"name":"script_name","type":"String","description":"Name of the script."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"author_email","type":"String"},{"name":"created_on","type":"Time"},{"name":"source","type":"String"},{"name":"strategy","type":"String"},{"name":"annotations","type":"Attributes","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the deployment. Truncated to 1000 bytes if longer."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the deployment."}]},{"name":"versions","type":"List[Attributes]","description":"Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.","children":[{"name":"percentage","type":"Float64","description":"Percentage of traffic served by this version."},{"name":"version_id","type":"String","description":"Identifier of the Worker Version."}]}]}]},"get /accounts/{}/workers/scripts/{}/schedules":{"operationId":"worker-cron-trigger-get-cron-triggers","declarations":[{"kind":"data-source","name":"cloudflare_workers_cron_trigger","stainlessResource":"workers.scripts.schedules","methodName":"get","snippet":"data \"cloudflare_workers_cron_trigger\" \"example_workers_cron_trigger\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}\n","required":[{"name":"script_name","type":"String","description":"Name of the script."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the script."},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}]}]},"get /accounts/{}/workers/scripts/{}/subdomain":{"operationId":"worker-script-get-subdomain","declarations":[{"kind":"data-source","name":"cloudflare_workers_script_subdomain","stainlessResource":"workers.scripts.subdomain","methodName":"get","snippet":"data \"cloudflare_workers_script_subdomain\" \"example_workers_script_subdomain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"script_name","type":"String","description":"Name of the script."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"Whether the Worker is available on the workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether the Worker's Preview URLs are available on the workers.dev subdomain."}]}]},"get /accounts/{}/workers/workers":{"operationId":"listWorkers","declarations":[{"kind":"list-data-source","name":"cloudflare_workers","stainlessResource":"workers.beta.workers","methodName":"list","snippet":"data \"cloudflare_workers\" \"example_workers\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"order","type":"String","description":"Sort direction."},{"name":"order_by","type":"String","description":"Property to sort results by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Immutable ID of the Worker."},{"name":"created_on","type":"Time","description":"When the Worker was created."},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled for the Worker."},{"name":"name","type":"String","description":"Name of the Worker."},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"references","type":"Attributes","description":"Other resources that reference the Worker and depend on it existing.","children":[{"name":"dispatch_namespace_outbounds","type":"List[Attributes]","description":"Other Workers that reference the Worker as an outbound for a dispatch namespace.","children":[{"name":"namespace_id","type":"String","description":"ID of the dispatch namespace."},{"name":"namespace_name","type":"String","description":"Name of the dispatch namespace."},{"name":"worker_id","type":"String","description":"ID of the Worker using the dispatch namespace."},{"name":"worker_name","type":"String","description":"Name of the Worker using the dispatch namespace."}]},{"name":"domains","type":"List[Attributes]","description":"Custom domains connected to the Worker.","children":[{"name":"id","type":"String","description":"ID of the custom domain."},{"name":"certificate_id","type":"String","description":"ID of the TLS certificate issued for the custom domain."},{"name":"hostname","type":"String","description":"Full hostname of the custom domain, including the zone name."},{"name":"zone_id","type":"String","description":"ID of the zone."},{"name":"zone_name","type":"String","description":"Name of the zone."}]},{"name":"durable_objects","type":"List[Attributes]","description":"Other Workers that reference Durable Object classes implemented by the Worker.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace being used."},{"name":"namespace_name","type":"String","description":"Name of the Durable Object namespace being used."},{"name":"worker_id","type":"String","description":"ID of the Worker using the Durable Object implementation."},{"name":"worker_name","type":"String","description":"Name of the Worker using the Durable Object implementation."}]},{"name":"queues","type":"List[Attributes]","description":"Queues that send messages to the Worker.","children":[{"name":"queue_consumer_id","type":"String","description":"ID of the queue consumer configuration."},{"name":"queue_id","type":"String","description":"ID of the queue."},{"name":"queue_name","type":"String","description":"Name of the queue."}]},{"name":"workers","type":"List[Attributes]","description":"Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).","children":[{"name":"id","type":"String","description":"ID of the referencing Worker."},{"name":"name","type":"String","description":"Name of the referencing Worker."}]}]},{"name":"subdomain","type":"Attributes","description":"Subdomain settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether the *.workers.dev subdomain is enabled for the Worker."},{"name":"preview_url_suffix","type":"String","description":"Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker."},{"name":"url","type":"String","description":"The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain."}]},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from the Worker.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]},{"name":"updated_on","type":"Time","description":"When the Worker was most recently updated."},{"name":"deployed_on","type":"Time","description":"When the Worker's most recent deployment was created. `null` if the Worker has never been deployed."},{"name":"previews_base_config","type":"Attributes","description":"Template configuration used when creating new Previews for this Worker.","children":[{"name":"cache_options","type":"Attributes","description":"Cache options used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"env","type":"Map[Attributes]","description":"Bindings used when creating new Previews, keyed by binding name.","children":[{"name":"type","type":"String","description":"The kind of resource that the binding provides."}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime for newly created Previews.","children":[{"name":"cpu_ms","type":"Int64","description":"The amount of CPU time this Worker can use in milliseconds."},{"name":"subrequests","type":"Int64","description":"The number of subrequests this Worker can make per request."}]},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled when creating new Previews."},{"name":"observability","type":"Attributes","description":"Observability settings used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Placement configuration used when creating new Previews.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from newly created Previews.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]}]}]}]},"get /accounts/{}/workers/workers/{}":{"operationId":"getWorker","declarations":[{"kind":"data-source","name":"cloudflare_worker","stainlessResource":"workers.beta.workers","methodName":"get","snippet":"data \"cloudflare_worker\" \"example_worker\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name."},{"name":"filter","type":"Attributes","children":[{"name":"order","type":"String","description":"Sort direction."},{"name":"order_by","type":"String","description":"Property to sort results by."}]}],"computed":[{"name":"id","type":"String","description":"Identifier for the Worker, which can be ID or name."},{"name":"created_on","type":"Time","description":"When the Worker was created."},{"name":"deployed_on","type":"Time","description":"When the Worker's most recent deployment was created. `null` if the Worker has never been deployed."},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled for the Worker."},{"name":"name","type":"String","description":"Name of the Worker."},{"name":"updated_on","type":"Time","description":"When the Worker was most recently updated."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"previews_base_config","type":"Attributes","description":"Template configuration used when creating new Previews for this Worker.","children":[{"name":"cache_options","type":"Attributes","description":"Cache options used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"env","type":"Map[Attributes]","description":"Bindings used when creating new Previews, keyed by binding name.","children":[{"name":"type","type":"String","description":"The kind of resource that the binding provides."}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime for newly created Previews.","children":[{"name":"cpu_ms","type":"Int64","description":"The amount of CPU time this Worker can use in milliseconds."},{"name":"subrequests","type":"Int64","description":"The number of subrequests this Worker can make per request."}]},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled when creating new Previews."},{"name":"observability","type":"Attributes","description":"Observability settings used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Placement configuration used when creating new Previews.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from newly created Previews.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]},{"name":"references","type":"Attributes","description":"Other resources that reference the Worker and depend on it existing.","children":[{"name":"dispatch_namespace_outbounds","type":"List[Attributes]","description":"Other Workers that reference the Worker as an outbound for a dispatch namespace.","children":[{"name":"namespace_id","type":"String","description":"ID of the dispatch namespace."},{"name":"namespace_name","type":"String","description":"Name of the dispatch namespace."},{"name":"worker_id","type":"String","description":"ID of the Worker using the dispatch namespace."},{"name":"worker_name","type":"String","description":"Name of the Worker using the dispatch namespace."}]},{"name":"domains","type":"List[Attributes]","description":"Custom domains connected to the Worker.","children":[{"name":"id","type":"String","description":"ID of the custom domain."},{"name":"certificate_id","type":"String","description":"ID of the TLS certificate issued for the custom domain."},{"name":"hostname","type":"String","description":"Full hostname of the custom domain, including the zone name."},{"name":"zone_id","type":"String","description":"ID of the zone."},{"name":"zone_name","type":"String","description":"Name of the zone."}]},{"name":"durable_objects","type":"List[Attributes]","description":"Other Workers that reference Durable Object classes implemented by the Worker.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace being used."},{"name":"namespace_name","type":"String","description":"Name of the Durable Object namespace being used."},{"name":"worker_id","type":"String","description":"ID of the Worker using the Durable Object implementation."},{"name":"worker_name","type":"String","description":"Name of the Worker using the Durable Object implementation."}]},{"name":"queues","type":"List[Attributes]","description":"Queues that send messages to the Worker.","children":[{"name":"queue_consumer_id","type":"String","description":"ID of the queue consumer configuration."},{"name":"queue_id","type":"String","description":"ID of the queue."},{"name":"queue_name","type":"String","description":"Name of the queue."}]},{"name":"workers","type":"List[Attributes]","description":"Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).","children":[{"name":"id","type":"String","description":"ID of the referencing Worker."},{"name":"name","type":"String","description":"Name of the referencing Worker."}]}]},{"name":"subdomain","type":"Attributes","description":"Subdomain settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether the *.workers.dev subdomain is enabled for the Worker."},{"name":"preview_url_suffix","type":"String","description":"Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker."},{"name":"url","type":"String","description":"The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain."}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from the Worker.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]}]},"get /accounts/{}/workers/workers/{}/versions":{"operationId":"listWorkerVersions","declarations":[{"kind":"list-data-source","name":"cloudflare_worker_versions","stainlessResource":"workers.beta.workers.versions","methodName":"list","snippet":"data \"cloudflare_worker_versions\" \"example_worker_versions\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Version identifier."},{"name":"created_on","type":"Time","description":"When the version was created."},{"name":"number","type":"Int64","description":"The integer version number, starting from one."},{"name":"urls","type":"List[String]","description":"All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version."},{"name":"annotations","type":"Attributes","description":"Metadata about the version.","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the version. Truncated to 1000 bytes if longer."},{"name":"workers_tag","type":"String","description":"User-provided identifier for the version. Maximum 100 bytes."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the version."}]},{"name":"assets","type":"Attributes","description":"Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"config","type":"Attributes","description":"Configuration for assets within a Worker.","children":[{"name":"base_path","type":"String","description":"The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%."},{"name":"html_handling","type":"String","description":"Determines the redirects and rewrites of requests for HTML content."},{"name":"not_found_handling","type":"String","description":"Determines the response when a request does not match a static asset, and there is no Worker script."},{"name":"run_worker_first","type":"List[String]","description":"Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules."}]},{"name":"jwt","type":"String","description":"Token provided upon successful upload of all files from a registered manifest.","sensitive":true}]},{"name":"author_email","type":"String","description":"Email of the user who created the version."},{"name":"author_id","type":"String","description":"Identifier of the user who created the version."},{"name":"bindings","type":"List[Attributes]","description":"List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.","children":[{"name":"name","type":"String","description":"A JavaScript variable name for the binding."},{"name":"type","type":"String","description":"The kind of resource that the binding provides."},{"name":"instance_name","type":"String","description":"The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance."},{"name":"namespace","type":"String","description":"The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field."},{"name":"dataset","type":"String","description":"The name of the dataset to bind to."},{"name":"database_id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"part","type":"String","description":"The name of the file containing the data content. Only accepted for `service worker syntax` Workers."},{"name":"outbound","type":"Attributes","description":"Outbound worker.","children":[{"name":"params","type":"List[Attributes]","description":"Pass information from the Dispatch Worker to the Outbound Worker through the parameters.","children":[{"name":"name","type":"String","description":"Name of the parameter."}]},{"name":"worker","type":"Attributes","description":"Outbound worker.","children":[{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the outbound worker."},{"name":"environment","type":"String","description":"Environment of the outbound worker."},{"name":"service","type":"String","description":"Name of the outbound worker."}]}]},{"name":"class_name","type":"String","description":"The exported class name of the Durable Object."},{"name":"dispatch_namespace","type":"String","description":"The dispatch namespace the Durable Object script belongs to."},{"name":"environment","type":"String","description":"The environment of the script_name to bind to."},{"name":"namespace_id","type":"String","description":"Namespace identifier tag."},{"name":"script_name","type":"String","description":"The script where the Durable Object is defined, if it is external to this Worker."},{"name":"old_name","type":"String","description":"The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions."},{"name":"version_id","type":"String","description":"Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version."},{"name":"json","type":"unknown","description":"JSON data to use."},{"name":"certificate_id","type":"String","description":"Identifier of the certificate to bind to."},{"name":"text","type":"String","description":"The text value to use.","sensitive":true},{"name":"pipeline","type":"String","description":"Name of the Pipeline to bind to."},{"name":"stream","type":"String","description":"ID of a K2 stream owned by the account deploying the Worker."},{"name":"queue_name","type":"String","description":"Name of the Queue to bind to."},{"name":"simple","type":"Attributes","description":"The rate limit configuration.","children":[{"name":"limit","type":"Float64","description":"The limit (requests per period)."},{"name":"period","type":"Int64","description":"The period in seconds."},{"name":"mitigation_timeout","type":"Int64","description":"Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero.\n"}]},{"name":"bucket_name","type":"String","description":"R2 bucket to bind to."},{"name":"jurisdiction","type":"String","description":"The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket."},{"name":"allowed_destination_addresses","type":"List[String]","description":"List of allowed destination addresses."},{"name":"allowed_sender_addresses","type":"List[String]","description":"List of allowed sender addresses."},{"name":"destination_address","type":"String","description":"Destination address for the email."},{"name":"service","type":"String","description":"Name of Worker to bind to."},{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the target Worker."},{"name":"index_name","type":"String","description":"Name of the Vectorize index to bind to."},{"name":"secret_name","type":"String","description":"Name of the secret in the store."},{"name":"store_id","type":"String","description":"ID of the store containing the secret."},{"name":"app_id","type":"String","description":"ID of the Flagship app to bind to for feature flag evaluation."},{"name":"algorithm","type":"unknown","description":"Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)."},{"name":"format","type":"String","description":"Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format)."},{"name":"usages","type":"Set[String]","description":"Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)."},{"name":"key_base64","type":"String","description":"Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".","sensitive":true},{"name":"key_jwk","type":"unknown","description":"Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".","sensitive":true},{"name":"workflow_name","type":"String","description":"Name of the Workflow to bind to."},{"name":"service_id","type":"String","description":"Identifier of the VPC service to bind to."},{"name":"identity","type":"String","description":"Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\n"},{"name":"network_id","type":"String","description":"Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id.\n"},{"name":"tunnel_id","type":"String","description":"UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id.\n"}]},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"containers","type":"Set[Attributes]","description":"List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.","children":[{"name":"class_name","type":"String","description":"Select which Durable Object class should get this container attached."}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"exports_reconciliation","type":"Attributes","description":"Summary of the declarative exports reconciliation that ran on\nthis upload. Populated only when the uploaded metadata included\nan `exports` block. Durable Object entries drive reconciliation;\n`type: worker` entries do not contribute to this summary.\n","children":[{"name":"created","type":"List[String]","description":"Class names for which a new namespace was provisioned."},{"name":"deleted","type":"List[String]","description":"Class names whose namespace was deleted by a `deleted` tombstone."},{"name":"info","type":"List[Attributes]","description":"Non-blocking info entries (stale tombstones, tombstone applied\nwith class still in code). See `exports_reconciliation_info`.\n","children":[{"name":"class","type":"String","description":"The class name the info entry is about."},{"name":"message","type":"String","description":"Human-readable explanation."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the entry relates to, when applicable."},{"name":"referencing_scripts","type":"List[String]","description":"Other Workers in the account that still bind to the affected\nclass. Advisory: while non-empty the tombstone is not yet safe\nto remove — redeploy these Workers with bindings re-pointed\nfirst.\n"}]},{"name":"removable_entries","type":"List[String]","description":"Source class names whose tombstone entry is now stale and safe\nto delete from `exports` (no remaining referencing scripts).\n"},{"name":"renamed","type":"List[Attributes]","description":"Applied `renamed` tombstones.","children":[{"name":"from","type":"String","description":"The original (source) class name."},{"name":"to","type":"String","description":"The new class name (`renamed_to`)."}]},{"name":"transfer_pending","type":"List[Attributes]","description":"Phase-1 transfer hints recorded on the target side.","children":[{"name":"class","type":"String","description":"The target-side class name awaiting transfer."},{"name":"from","type":"String","description":"The source script the namespace will be transferred from."}]},{"name":"transferred","type":"List[Attributes]","description":"Committed `transferred` tombstones (phase-2).","children":[{"name":"class","type":"String","description":"The source class name that was transferred."},{"name":"phase","type":"String","description":"The transfer phase. Currently always `committed`."},{"name":"to","type":"String","description":"The destination script that now owns the namespace."}]},{"name":"updated","type":"List[String]","description":"Class names whose provisioned namespace was mutated in place."},{"name":"warnings","type":"List[Attributes]","description":"Non-blocking warnings. See `exports_reconciliation_warning`.","children":[{"name":"class","type":"String","description":"The class name the warning is about."},{"name":"message","type":"String","description":"Human-readable explanation of the warning."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the warning relates to, when applicable."}]}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."},{"name":"subrequests","type":"Int64","description":"Subrequest limit per request."}]},{"name":"main_module","type":"String","description":"The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler)."},{"name":"migration_tag","type":"String","description":"Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects."},{"name":"migrations","type":"Attributes","description":"Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"new_tag","type":"String","description":"Tag to set as the latest migration tag."},{"name":"old_tag","type":"String","description":"Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]},{"name":"steps","type":"List[Attributes]","description":"Migrations to apply in order.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]}]}]},{"name":"modules","type":"Set[Attributes]","description":"Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"content_base64","type":"String","description":"The base64-encoded module content."},{"name":"content_type","type":"String","description":"The content type of the module."},{"name":"name","type":"String","description":"The name of the module."}]},{"name":"package_dependencies","type":"List[Attributes]","description":"The list of npm packages that were installed and used when this Worker\nversion was built.\n","children":[{"name":"installed_version","type":"String","description":"The exact version that was resolved and installed by the package manager."},{"name":"name","type":"String","description":"The npm package name."},{"name":"package_json_version","type":"String","description":"The version constraint as written in package.json."}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"source","type":"String","description":"The client used to create the version."},{"name":"startup_time_ms","type":"Int64","description":"Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)."},{"name":"usage_model","type":"String","description":"Usage model for the version.","deprecated":"Deprecated."}]}]}]},"get /accounts/{}/workers/workers/{}/versions/{}":{"operationId":"getWorkerVersion","declarations":[{"kind":"data-source","name":"cloudflare_worker_version","stainlessResource":"workers.beta.workers.versions","methodName":"get","snippet":"data \"cloudflare_worker_version\" \"example_worker_version\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n version_id = \"version_id\"\n include = \"modules\"\n}\n","required":[{"name":"version_id","type":"String","description":"Identifier for the version, which can be a UUID, a UUID prefix (minimum length 8), or the literal \"latest\" to operate on the most recently created version."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name."}],"optional":[{"name":"include","type":"String","description":"Whether to include the `modules` property of the version in the response, which contains code and sourcemap content and may add several megabytes to the response size."}],"computed":[{"name":"id","type":"String","description":"Identifier for the version, which can be a UUID, a UUID prefix (minimum length 8), or the literal \"latest\" to operate on the most recently created version."},{"name":"author_email","type":"String","description":"Email of the user who created the version."},{"name":"author_id","type":"String","description":"Identifier of the user who created the version."},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"created_on","type":"Time","description":"When the version was created."},{"name":"main_module","type":"String","description":"The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler)."},{"name":"migration_tag","type":"String","description":"Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects."},{"name":"number","type":"Int64","description":"The integer version number, starting from one."},{"name":"source","type":"String","description":"The client used to create the version."},{"name":"startup_time_ms","type":"Int64","description":"Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)."},{"name":"usage_model","type":"String","description":"Usage model for the version.","deprecated":"Deprecated."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"urls","type":"List[String]","description":"All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version."},{"name":"annotations","type":"Attributes","description":"Metadata about the version.","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the version. Truncated to 1000 bytes if longer."},{"name":"workers_tag","type":"String","description":"User-provided identifier for the version. Maximum 100 bytes."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the version."}]},{"name":"assets","type":"Attributes","description":"Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"config","type":"Attributes","description":"Configuration for assets within a Worker.","children":[{"name":"base_path","type":"String","description":"The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%."},{"name":"html_handling","type":"String","description":"Determines the redirects and rewrites of requests for HTML content."},{"name":"not_found_handling","type":"String","description":"Determines the response when a request does not match a static asset, and there is no Worker script."},{"name":"run_worker_first","type":"List[String]","description":"Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules."}]},{"name":"jwt","type":"String","description":"Token provided upon successful upload of all files from a registered manifest.","sensitive":true}]},{"name":"bindings","type":"List[Attributes]","description":"List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.","children":[{"name":"name","type":"String","description":"A JavaScript variable name for the binding."},{"name":"type","type":"String","description":"The kind of resource that the binding provides."},{"name":"instance_name","type":"String","description":"The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance."},{"name":"namespace","type":"String","description":"The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field."},{"name":"dataset","type":"String","description":"The name of the dataset to bind to."},{"name":"database_id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"part","type":"String","description":"The name of the file containing the data content. Only accepted for `service worker syntax` Workers."},{"name":"outbound","type":"Attributes","description":"Outbound worker.","children":[{"name":"params","type":"List[Attributes]","description":"Pass information from the Dispatch Worker to the Outbound Worker through the parameters.","children":[{"name":"name","type":"String","description":"Name of the parameter."}]},{"name":"worker","type":"Attributes","description":"Outbound worker.","children":[{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the outbound worker."},{"name":"environment","type":"String","description":"Environment of the outbound worker."},{"name":"service","type":"String","description":"Name of the outbound worker."}]}]},{"name":"class_name","type":"String","description":"The exported class name of the Durable Object."},{"name":"dispatch_namespace","type":"String","description":"The dispatch namespace the Durable Object script belongs to."},{"name":"environment","type":"String","description":"The environment of the script_name to bind to."},{"name":"namespace_id","type":"String","description":"Namespace identifier tag."},{"name":"script_name","type":"String","description":"The script where the Durable Object is defined, if it is external to this Worker."},{"name":"old_name","type":"String","description":"The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions."},{"name":"version_id","type":"String","description":"Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version."},{"name":"json","type":"unknown","description":"JSON data to use."},{"name":"certificate_id","type":"String","description":"Identifier of the certificate to bind to."},{"name":"text","type":"String","description":"The text value to use.","sensitive":true},{"name":"pipeline","type":"String","description":"Name of the Pipeline to bind to."},{"name":"stream","type":"String","description":"ID of a K2 stream owned by the account deploying the Worker."},{"name":"queue_name","type":"String","description":"Name of the Queue to bind to."},{"name":"simple","type":"Attributes","description":"The rate limit configuration.","children":[{"name":"limit","type":"Float64","description":"The limit (requests per period)."},{"name":"period","type":"Int64","description":"The period in seconds."},{"name":"mitigation_timeout","type":"Int64","description":"Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero.\n"}]},{"name":"bucket_name","type":"String","description":"R2 bucket to bind to."},{"name":"jurisdiction","type":"String","description":"The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket."},{"name":"allowed_destination_addresses","type":"List[String]","description":"List of allowed destination addresses."},{"name":"allowed_sender_addresses","type":"List[String]","description":"List of allowed sender addresses."},{"name":"destination_address","type":"String","description":"Destination address for the email."},{"name":"service","type":"String","description":"Name of Worker to bind to."},{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the target Worker."},{"name":"index_name","type":"String","description":"Name of the Vectorize index to bind to."},{"name":"secret_name","type":"String","description":"Name of the secret in the store."},{"name":"store_id","type":"String","description":"ID of the store containing the secret."},{"name":"app_id","type":"String","description":"ID of the Flagship app to bind to for feature flag evaluation."},{"name":"algorithm","type":"unknown","description":"Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)."},{"name":"format","type":"String","description":"Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format)."},{"name":"usages","type":"Set[String]","description":"Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)."},{"name":"key_base64","type":"String","description":"Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".","sensitive":true},{"name":"key_jwk","type":"unknown","description":"Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".","sensitive":true},{"name":"workflow_name","type":"String","description":"Name of the Workflow to bind to."},{"name":"service_id","type":"String","description":"Identifier of the VPC service to bind to."},{"name":"identity","type":"String","description":"Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\n"},{"name":"network_id","type":"String","description":"Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id.\n"},{"name":"tunnel_id","type":"String","description":"UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id.\n"}]},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"containers","type":"Set[Attributes]","description":"List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.","children":[{"name":"class_name","type":"String","description":"Select which Durable Object class should get this container attached."}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"exports_reconciliation","type":"Attributes","description":"Summary of the declarative exports reconciliation that ran on\nthis upload. Populated only when the uploaded metadata included\nan `exports` block. Durable Object entries drive reconciliation;\n`type: worker` entries do not contribute to this summary.\n","children":[{"name":"created","type":"List[String]","description":"Class names for which a new namespace was provisioned."},{"name":"deleted","type":"List[String]","description":"Class names whose namespace was deleted by a `deleted` tombstone."},{"name":"info","type":"List[Attributes]","description":"Non-blocking info entries (stale tombstones, tombstone applied\nwith class still in code). See `exports_reconciliation_info`.\n","children":[{"name":"class","type":"String","description":"The class name the info entry is about."},{"name":"message","type":"String","description":"Human-readable explanation."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the entry relates to, when applicable."},{"name":"referencing_scripts","type":"List[String]","description":"Other Workers in the account that still bind to the affected\nclass. Advisory: while non-empty the tombstone is not yet safe\nto remove — redeploy these Workers with bindings re-pointed\nfirst.\n"}]},{"name":"removable_entries","type":"List[String]","description":"Source class names whose tombstone entry is now stale and safe\nto delete from `exports` (no remaining referencing scripts).\n"},{"name":"renamed","type":"List[Attributes]","description":"Applied `renamed` tombstones.","children":[{"name":"from","type":"String","description":"The original (source) class name."},{"name":"to","type":"String","description":"The new class name (`renamed_to`)."}]},{"name":"transfer_pending","type":"List[Attributes]","description":"Phase-1 transfer hints recorded on the target side.","children":[{"name":"class","type":"String","description":"The target-side class name awaiting transfer."},{"name":"from","type":"String","description":"The source script the namespace will be transferred from."}]},{"name":"transferred","type":"List[Attributes]","description":"Committed `transferred` tombstones (phase-2).","children":[{"name":"class","type":"String","description":"The source class name that was transferred."},{"name":"phase","type":"String","description":"The transfer phase. Currently always `committed`."},{"name":"to","type":"String","description":"The destination script that now owns the namespace."}]},{"name":"updated","type":"List[String]","description":"Class names whose provisioned namespace was mutated in place."},{"name":"warnings","type":"List[Attributes]","description":"Non-blocking warnings. See `exports_reconciliation_warning`.","children":[{"name":"class","type":"String","description":"The class name the warning is about."},{"name":"message","type":"String","description":"Human-readable explanation of the warning."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the warning relates to, when applicable."}]}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."},{"name":"subrequests","type":"Int64","description":"Subrequest limit per request."}]},{"name":"migrations","type":"Attributes","description":"Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"new_tag","type":"String","description":"Tag to set as the latest migration tag."},{"name":"old_tag","type":"String","description":"Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]},{"name":"steps","type":"List[Attributes]","description":"Migrations to apply in order.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]}]}]},{"name":"modules","type":"Set[Attributes]","description":"Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"content_base64","type":"String","description":"The base64-encoded module content."},{"name":"content_type","type":"String","description":"The content type of the module."},{"name":"name","type":"String","description":"The name of the module."}]},{"name":"package_dependencies","type":"List[Attributes]","description":"The list of npm packages that were installed and used when this Worker\nversion was built.\n","children":[{"name":"installed_version","type":"String","description":"The exact version that was resolved and installed by the package manager."},{"name":"name","type":"String","description":"The npm package name."},{"name":"package_json_version","type":"String","description":"The version constraint as written in package.json."}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]}]}]},"get /accounts/{}/workflows":{"operationId":"wor-list-workflows","declarations":[{"kind":"list-data-source","name":"cloudflare_workflows","stainlessResource":"workflows","methodName":"list","snippet":"data \"cloudflare_workflows\" \"example_workflows\" {\n account_id = \"account_id\"\n search = \"x\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Allows filtering workflows` name."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"class_name","type":"String"},{"name":"created_on","type":"Time"},{"name":"instances","type":"Map[Float64]"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String"},{"name":"script_name","type":"String"},{"name":"triggered_on","type":"Time"},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"next_instance","type":"String"}]},{"name":"script_deleted","type":"Bool","description":"Whether the bound Worker was deleted, leaving this Workflow inactive."}]}]}]},"get /accounts/{}/workflows/{}":{"operationId":"wor-get-workflow-details","declarations":[{"kind":"data-source","name":"cloudflare_workflow","stainlessResource":"workflows","methodName":"get","snippet":"data \"cloudflare_workflow\" \"example_workflow\" {\n account_id = \"account_id\"\n workflow_name = \"x\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"workflow_name","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Allows filtering workflows` name."}]}],"computed":[{"name":"id","type":"String"},{"name":"class_name","type":"String"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String"},{"name":"script_deleted","type":"Bool","description":"Whether the bound Worker was deleted, leaving this Workflow inactive."},{"name":"script_name","type":"String"},{"name":"triggered_on","type":"Time"},{"name":"instances","type":"Map[Float64]"},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"next_instance","type":"String"}]}]}]},"get /accounts/{}/zerotrust/connectivity_settings":{"operationId":"zero-trust-accounts-get-connectivity-settings","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_connectivity_settings","stainlessResource":"zero_trust.connectivity_settings","methodName":"get","snippet":"data \"cloudflare_zero_trust_connectivity_settings\" \"example_zero_trust_connectivity_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Cloudflare account ID"},{"name":"icmp_proxy_enabled","type":"Bool","description":"A flag to enable the ICMP proxy for the account network."},{"name":"offramp_warp_enabled","type":"Bool","description":"A flag to enable WARP to WARP traffic."}]}]},"get /accounts/{}/zerotrust/routes/hostname":{"operationId":"zero-trust-networks-route-hostname-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_network_hostname_routes","stainlessResource":"zero_trust.networks.hostname_routes","methodName":"list","snippet":"data \"cloudflare_zero_trust_network_hostname_routes\" \"example_zero_trust_network_hostname_routes\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n comment = \"example%20comment\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n hostname = \"office-1.local\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"comment","type":"String","description":"If set, only list hostname routes with the given comment."},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"hostname","type":"String","description":"If set, only list hostname routes that contain a substring of the given value, the filter is case-insensitive."},{"name":"id","type":"String","description":"The hostname route ID."},{"name":"tunnel_id","type":"String","description":"If set, only list hostname routes that point to a specific tunnel."},{"name":"is_deleted","type":"Bool","description":"If `true`, only return deleted hostname routes. If `false`, exclude deleted hostname routes."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"comment","type":"String","description":"An optional description of the hostname route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"hostname","type":"String","description":"The hostname of the route."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."}]}]}]},"get /accounts/{}/zerotrust/routes/hostname/{}":{"operationId":"zero-trust-networks-route-hostname-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_network_hostname_route","stainlessResource":"zero_trust.networks.hostname_routes","methodName":"get","snippet":"data \"cloudflare_zero_trust_network_hostname_route\" \"example_zero_trust_network_hostname_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n hostname_route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"hostname_route_id","type":"String","description":"The hostname route ID."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"comment","type":"String","description":"If set, only list hostname routes with the given comment."},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"hostname","type":"String","description":"If set, only list hostname routes that contain a substring of the given value, the filter is case-insensitive."},{"name":"is_deleted","type":"Bool","description":"If `true`, only return deleted hostname routes. If `false`, exclude deleted hostname routes."},{"name":"tunnel_id","type":"String","description":"If set, only list hostname routes that point to a specific tunnel."}]}],"computed":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"comment","type":"String","description":"An optional description of the hostname route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"hostname","type":"String","description":"The hostname of the route."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."}]}]},"get /accounts/{}/zerotrust/subnets/warp/{}":{"operationId":"zero-trust-networks-subnet-get-warp","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_subnet","stainlessResource":"zero_trust.networks.subnets.warp","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_subnet\" \"example_zero_trust_device_subnet\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n subnet_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"subnet_id","type":"String","description":"The UUID of the subnet."},{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The UUID of the subnet."},{"name":"comment","type":"String","description":"An optional description of the subnet."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"is_default_network","type":"Bool","description":"If `true`, this is the default subnet for the account. There can only be one default subnet per account."},{"name":"name","type":"String","description":"A user-friendly name for the subnet."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range defining the subnet, in CIDR notation."},{"name":"subnet_type","type":"String","description":"The type of subnet."},{"name":"capacity","type":"Attributes","description":"IP capacity information for the subnet.","children":[{"name":"total","type":"Int64","description":"Total number of assignable IPs in the subnet."},{"name":"used","type":"Int64","description":"Number of assigned IPs in the subnet."}]}]}]},"get /accounts/{}/zt_risk_scoring/behaviors":{"operationId":"dlp-risk-score-behaviors-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_risk_behavior","stainlessResource":"zero_trust.risk_scoring.behaviours","methodName":"get","snippet":"data \"cloudflare_zero_trust_risk_behavior\" \"example_zero_trust_risk_behavior\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"behaviors","type":"Map[Attributes]","children":[{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"risk_level","type":"String"}]}]}]},"get /accounts/{}/zt_risk_scoring/integrations":{"operationId":"dlp-zt-risk-score-integration-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_risk_scoring_integrations","stainlessResource":"zero_trust.risk_scoring.integrations","methodName":"list","snippet":"data \"cloudflare_zero_trust_risk_scoring_integrations\" \"example_zero_trust_risk_scoring_integrations\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The id of the integration, a UUIDv4."},{"name":"account_tag","type":"String","description":"The Cloudflare account tag."},{"name":"active","type":"Bool","description":"Whether this integration is enabled and should export changes in risk score."},{"name":"created_at","type":"Time","description":"When the integration was created in RFC3339 format."},{"name":"integration_type","type":"String"},{"name":"reference_id","type":"String","description":"A reference ID defined by the client.\nShould be set to the Access-Okta IDP integration ID.\nUseful when the risk-score integration needs to be associated with a secondary asset and recalled using that ID."},{"name":"tenant_url","type":"String","description":"The base URL for the tenant. E.g. \"https://tenant.okta.com\"."},{"name":"well_known_url","type":"String","description":"The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1."}]}]}]},"get /accounts/{}/zt_risk_scoring/integrations/{}":{"operationId":"dlp-zt-risk-score-integration-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_risk_scoring_integration","stainlessResource":"zero_trust.risk_scoring.integrations","methodName":"get","snippet":"data \"cloudflare_zero_trust_risk_scoring_integration\" \"example_zero_trust_risk_scoring_integration\" {\n account_id = \"account_id\"\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"integration_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"account_tag","type":"String","description":"The Cloudflare account tag."},{"name":"active","type":"Bool","description":"Whether this integration is enabled and should export changes in risk score."},{"name":"created_at","type":"Time","description":"When the integration was created in RFC3339 format."},{"name":"integration_type","type":"String"},{"name":"reference_id","type":"String","description":"A reference ID defined by the client.\nShould be set to the Access-Okta IDP integration ID.\nUseful when the risk-score integration needs to be associated with a secondary asset and recalled using that ID."},{"name":"tenant_url","type":"String","description":"The base URL for the tenant. E.g. \"https://tenant.okta.com\"."},{"name":"well_known_url","type":"String","description":"The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1."}]}]},"get /certificates":{"operationId":"origin-ca-list-certificates","declarations":[{"kind":"list-data-source","name":"cloudflare_origin_ca_certificates","stainlessResource":"origin_ca_certificates","methodName":"list","snippet":"data \"cloudflare_origin_ca_certificates\" \"example_origin_ca_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"hostnames","type":"List[String]","description":"Array of hostnames or wildcard names bound to the certificate.\nHostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode."},{"name":"request_type","type":"String","description":"Signature type desired on certificate (\"origin-rsa\" (rsa), \"origin-ecc\" (ecdsa), or \"keyless-certificate\" (for Keyless SSL servers)."},{"name":"requested_validity","type":"Float64","description":"The number of days for which the certificate should be valid."},{"name":"id","type":"String","description":"The x509 serial number of the Origin CA certificate."},{"name":"certificate","type":"String","description":"The Origin CA certificate. Will be newline-encoded."},{"name":"expires_on","type":"String","description":"When the certificate will expire."}]}]}]},"get /certificates/{}":{"operationId":"origin-ca-get-certificate","declarations":[{"kind":"data-source","name":"cloudflare_origin_ca_certificate","stainlessResource":"origin_ca_certificates","methodName":"get","snippet":"data \"cloudflare_origin_ca_certificate\" \"example_origin_ca_certificate\" {\n certificate_id = \"328578533902268680212849205732770752308931942346\"\n}\n","required":[],"optional":[{"name":"certificate_id","type":"String","description":"The x509 serial number of the Origin CA certificate."},{"name":"filter","type":"Attributes","children":[{"name":"zone_id","type":"String","description":"Identifier."},{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."}]}],"computed":[{"name":"id","type":"String","description":"The x509 serial number of the Origin CA certificate."},{"name":"certificate","type":"String","description":"The Origin CA certificate. Will be newline-encoded."},{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"expires_on","type":"String","description":"When the certificate will expire."},{"name":"request_type","type":"String","description":"Signature type desired on certificate (\"origin-rsa\" (rsa), \"origin-ecc\" (ecdsa), or \"keyless-certificate\" (for Keyless SSL servers)."},{"name":"requested_validity","type":"Float64","description":"The number of days for which the certificate should be valid."},{"name":"hostnames","type":"List[String]","description":"Array of hostnames or wildcard names bound to the certificate.\nHostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode."}]}]},"get /ips":{"operationId":"cloudflare-ips-cloudflare-ip-details","declarations":[{"kind":"data-source","name":"cloudflare_ip_ranges","stainlessResource":"ips","methodName":"list","snippet":"data \"cloudflare_ip_ranges\" \"example_ip_ranges\" {\n networks = \"networks\"\n}\n","required":[],"optional":[{"name":"networks","type":"String","description":"Specified as `jdcloud` to list IPs used by JD Cloud data centers."}],"computed":[{"name":"etag","type":"String","description":"A digest of the IP data. Useful for determining if the data has changed."},{"name":"ipv4_cidrs","type":"List[String]","description":"List of Cloudflare IPv4 CIDR addresses."},{"name":"ipv6_cidrs","type":"List[String]","description":"List of Cloudflare IPv6 CIDR addresses."},{"name":"jdcloud_cidrs","type":"List[String]","description":"List IPv4 and IPv6 CIDRs, only populated if `?networks=jdcloud` is used."}]}]},"get /oauth/scopes":{"operationId":"oauth-scopes-list","declarations":[{"kind":"list-data-source","name":"cloudflare_oauth_scopes","stainlessResource":"iam.oauth_scopes","methodName":"list","snippet":"data \"cloudflare_oauth_scopes\" \"example_oauth_scopes\" {\n\n}\n","required":[],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The scope label to use in the scopes array when creating or updating an OAuth client."},{"name":"name","type":"String","description":"Human-readable name of the OAuth scope."},{"name":"category","type":"String","description":"Category for grouping scopes in the UI."},{"name":"scopes","type":"List[String]","description":"The underlying resource scopes (Bach scopes) that define which resources this OAuth scope can act upon."}]}]}]},"get /organizations":{"operationId":"Organization_listOrganizations","declarations":[{"kind":"list-data-source","name":"cloudflare_organizations","stainlessResource":"organizations","methodName":"list","snippet":"data \"cloudflare_organizations\" \"example_organizations\" {\n id = [\"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"]\n containing = {\n account = \"account\"\n organization = \"organization\"\n user = \"user\"\n }\n name = {\n contains = \"contains\"\n ends_with = \"endsWith\"\n starts_with = \"startsWith\"\n }\n page_size = 0\n page_token = \"page_token\"\n parent = {\n id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n }\n}\n","required":[],"optional":[{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"id","type":"List[String]","description":"Only return organizations with the specified IDs (ex. id=foo&id=bar). Send multiple elements\nby repeating the query value."},{"name":"containing","type":"Attributes","children":[{"name":"account","type":"String","description":"Filter the list of organizations to the ones that contain this particular\naccount."},{"name":"organization","type":"String","description":"Filter the list of organizations to the ones that contain this particular\norganization."},{"name":"user","type":"String","description":"Filter the list of organizations to the ones that contain this particular\nuser.\n\nIMPORTANT: Just because an organization \"contains\" a user is not a\nrepresentation of any authorization or privilege to manage any resources\ntherein. An organization \"containing\" a user simply means the user is managed by\nthat organization."}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name contains a particular\nstring."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name ends with a particular\nstring."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name starts with a\nparticular string."}]},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter the list of organizations to the ones that are a sub-organization\nof the specified organization.\n\n\"null\" is a valid value to provide for this parameter. It means \"where\nan organization has no parent (i.e. it is a 'root' organization).\""}]},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"create_time","type":"Time"},{"name":"meta","type":"Attributes","children":[{"name":"hierarchy_tags","type":"List[String]","description":"Ordered chain of organization tags from the root organization down to\n(and including) this organization itself. Root organizations return a\nsingle-element array containing their own tag; sub-organizations return\n`[rootTag, ...intermediateTags, parentTag, selfTag]`. Useful for\nconstructing authorization scopes that need to cover every ancestor\nin the hierarchy."},{"name":"managed_by","type":"String"},{"name":"tenant_flags","type":"Attributes","description":"Enable features for Organizations.","children":[{"name":"account_creation","type":"String"},{"name":"account_creation_applies_tenant_defaults","type":"String"},{"name":"account_deletion","type":"String"},{"name":"account_migration","type":"String"},{"name":"account_mobility","type":"String"},{"name":"enterprise_capability","type":"String"},{"name":"member_management","type":"String"},{"name":"sub_org_creation","type":"String"}]}]},{"name":"name","type":"String"},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"profile","type":"Attributes","children":[{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}]}]}]}]},"get /organizations/{}":{"operationId":"Organizations_retrieve","declarations":[{"kind":"data-source","name":"cloudflare_organization","stainlessResource":"organizations","methodName":"get","snippet":"data \"cloudflare_organization\" \"example_organization\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n}\n","required":[],"optional":[{"name":"organization_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"List[String]","description":"Only return organizations with the specified IDs (ex. id=foo&id=bar). Send multiple elements\nby repeating the query value."},{"name":"containing","type":"Attributes","children":[{"name":"account","type":"String","description":"Filter the list of organizations to the ones that contain this particular\naccount."},{"name":"organization","type":"String","description":"Filter the list of organizations to the ones that contain this particular\norganization."},{"name":"user","type":"String","description":"Filter the list of organizations to the ones that contain this particular\nuser.\n\nIMPORTANT: Just because an organization \"contains\" a user is not a\nrepresentation of any authorization or privilege to manage any resources\ntherein. An organization \"containing\" a user simply means the user is managed by\nthat organization."}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name contains a particular\nstring."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name ends with a particular\nstring."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name starts with a\nparticular string."}]},{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter the list of organizations to the ones that are a sub-organization\nof the specified organization.\n\n\"null\" is a valid value to provide for this parameter. It means \"where\nan organization has no parent (i.e. it is a 'root' organization).\""}]}]}],"computed":[{"name":"id","type":"String"},{"name":"create_time","type":"Time"},{"name":"name","type":"String"},{"name":"meta","type":"Attributes","children":[{"name":"hierarchy_tags","type":"List[String]","description":"Ordered chain of organization tags from the root organization down to\n(and including) this organization itself. Root organizations return a\nsingle-element array containing their own tag; sub-organizations return\n`[rootTag, ...intermediateTags, parentTag, selfTag]`. Useful for\nconstructing authorization scopes that need to cover every ancestor\nin the hierarchy."},{"name":"managed_by","type":"String"},{"name":"tenant_flags","type":"Attributes","description":"Enable features for Organizations.","children":[{"name":"account_creation","type":"String"},{"name":"account_creation_applies_tenant_defaults","type":"String"},{"name":"account_deletion","type":"String"},{"name":"account_migration","type":"String"},{"name":"account_mobility","type":"String"},{"name":"enterprise_capability","type":"String"},{"name":"member_management","type":"String"},{"name":"sub_org_creation","type":"String"}]}]},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"profile","type":"Attributes","children":[{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}]}]}]},"get /organizations/{}/accounts":{"operationId":"Organizations_getAccounts","declarations":[{"kind":"data-source","name":"cloudflare_organization_accounts","stainlessResource":"organizations.organization_accounts","methodName":"get","required":[{"name":"organization_id","type":"String"}],"optional":[{"name":"direction","type":"String","description":"Sort direction for the order_by field. Valid values: `asc`, `desc`.\nDefaults to `asc` when order_by is specified."},{"name":"include_tags","type":"Bool","description":"Include Account tags from the resource tag mirror. Omit this parameter to preserve the existing Account response shape."},{"name":"order_by","type":"String","description":"Field to order results by. Currently supported values: `account_name`.\nWhen not specified, results are ordered by internal account ID."},{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"account_pubname","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of accounts to where the account_pubname contains\na particular string."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the account_pubname ends with\na particular string."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the account_pubname starts with\na particular string."}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of accounts to where the name contains a particular\nstring."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the name ends with a particular\nstring."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the name starts with a\nparticular string."}]},{"name":"include_total","type":"Bool","description":"Whether to calculate and return the exact result_info.total_size for cursor\npagination. Defaults to true. When false, total_size is omitted. page_size and\ninclude_total may change between pages; next_page_token remains the authoritative\ncontinuation signal.\nLegacy page/per_page requests always calculate total_count."}],"computed":[{"name":"organization_accounts","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"name","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"abuse_contact_email","type":"String"},{"name":"access_approval_expiry","type":"Time"},{"name":"api_access_enabled","type":"Bool"},{"name":"default_nameservers","type":"String","description":"Use [DNS Settings](https://developers.cloudflare.com/api/operations/dns-settings-for-an-account-list-dns-settings) instead. Deprecated.","deprecated":"Deprecated."},{"name":"enforce_twofactor","type":"Bool"},{"name":"use_account_custom_ns_by_default","type":"Bool","description":"Use [DNS Settings](https://developers.cloudflare.com/api/operations/dns-settings-for-an-account-list-dns-settings) instead. Deprecated.","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"tags","type":"Map[String]","description":"Account tags, present only when `include_tags=true` is requested."}]}]}]},"get /organizations/{}/members":{"operationId":"Members_list","declarations":[{"kind":"list-data-source","name":"cloudflare_organization_members","stainlessResource":"organizations.members","methodName":"list","required":[{"name":"organization_id","type":"String"}],"optional":[{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"status","type":"List[String]","description":"Filter the list of memberships by membership status."},{"name":"user","type":"Attributes","children":[{"name":"email","type":"String","description":"Filter the list of memberships for a specific email that ends with a substring."}]},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Organization Member ID"},{"name":"create_time","type":"Time"},{"name":"meta","type":"Map[unknown]"},{"name":"status","type":"String"},{"name":"update_time","type":"Time"},{"name":"user","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"email","type":"String"},{"name":"name","type":"String"},{"name":"two_factor_authentication_enabled","type":"Bool"}]}]}]}]},"get /organizations/{}/members/{}":{"operationId":"Members_retrieve","declarations":[{"kind":"data-source","name":"cloudflare_organization_member","stainlessResource":"organizations.members","methodName":"get","required":[{"name":"organization_id","type":"String"}],"optional":[{"name":"member_id","type":"String","description":"Organization Member ID"},{"name":"filter","type":"Attributes","children":[{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"status","type":"List[String]","description":"Filter the list of memberships by membership status."},{"name":"user","type":"Attributes","children":[{"name":"email","type":"String","description":"Filter the list of memberships for a specific email that ends with a substring."}]}]}],"computed":[{"name":"id","type":"String","description":"Organization Member ID"},{"name":"create_time","type":"Time"},{"name":"status","type":"String"},{"name":"update_time","type":"Time"},{"name":"meta","type":"Map[unknown]"},{"name":"user","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"email","type":"String"},{"name":"name","type":"String"},{"name":"two_factor_authentication_enabled","type":"Bool"}]}]}]},"get /organizations/{}/profile":{"operationId":"Organizations_getProfile","declarations":[{"kind":"data-source","name":"cloudflare_organization_profile","stainlessResource":"organizations.organization_profile","methodName":"get","snippet":"data \"cloudflare_organization_profile\" \"example_organization_profile\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n}\n","required":[{"name":"organization_id","type":"String"}],"optional":[],"computed":[{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}]}]},"get /user":{"operationId":"user-user-details","declarations":[{"kind":"data-source","name":"cloudflare_user","stainlessResource":"user","methodName":"get","snippet":"data \"cloudflare_user\" \"example_user\" {\n\n}\n","required":[],"optional":[],"computed":[{"name":"country","type":"String","description":"The country in which the user lives."},{"name":"email","type":"String","description":"Current email address of the user."},{"name":"first_name","type":"String","description":"User's first name"},{"name":"has_business_zones","type":"Bool","description":"Indicates whether user has any business zones"},{"name":"has_enterprise_zones","type":"Bool","description":"Indicates whether user has any enterprise zones"},{"name":"has_pro_zones","type":"Bool","description":"Indicates whether user has any pro zones"},{"name":"id","type":"String","description":"Identifier of the user."},{"name":"last_name","type":"String","description":"User's last name"},{"name":"suspended","type":"Bool","description":"Indicates whether user has been suspended"},{"name":"telephone","type":"String","description":"User's telephone number"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."},{"name":"two_factor_authentication_locked","type":"Bool","description":"Indicates whether two-factor authentication is required by one of the accounts that the user is a member of."},{"name":"zipcode","type":"String","description":"The zipcode or postal code where the user lives."},{"name":"betas","type":"List[String]","description":"Lists the betas that the user is participating in."},{"name":"organizations","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Organization name."},{"name":"permissions","type":"List[String]","description":"Access permissions for this User."},{"name":"roles","type":"List[String]","description":"List of roles that a user has within an organization."},{"name":"status","type":"String","description":"Whether the user is a member of the organization or has an invitation pending."}]}]}]},"get /user/tokens":{"operationId":"user-api-tokens-list-tokens","declarations":[{"kind":"list-data-source","name":"cloudflare_api_tokens","stainlessResource":"user.tokens","methodName":"list","snippet":"data \"cloudflare_api_tokens\" \"example_api_tokens\" {\n direction = \"desc\"\n}\n","required":[],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."}]}]}]},"get /user/tokens/{}":{"operationId":"user-api-tokens-token-details","declarations":[{"kind":"data-source","name":"cloudflare_api_token","stainlessResource":"user.tokens","methodName":"get","snippet":"data \"cloudflare_api_token\" \"example_api_token\" {\n token_id = \"ed17574386854bf78a67040be0a770b0\"\n}\n","required":[],"optional":[{"name":"token_id","type":"String","description":"Token identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."}]}],"computed":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]}]}]},"get /user/tokens/permission_groups":{"operationId":"permission-groups-list-permission-groups","declarations":[{"kind":"list-data-source","name":"cloudflare_api_token_permission_groups_list","stainlessResource":"user.tokens.permission_groups","methodName":"list","snippet":"data \"cloudflare_api_token_permission_groups_list\" \"example_api_token_permission_groups_list\" {\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}\n","required":[],"optional":[{"name":"name","type":"String","description":"Filter by the name of the permission group.\nThe value must be URL-encoded."},{"name":"scope","type":"String","description":"Filter by the scope of the permission group.\nThe value must be URL-encoded."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Public ID."},{"name":"category","type":"String","description":"Product category that this permission group belongs to."},{"name":"is_selectable","type":"Bool","description":"Whether the caller can select this permission group when creating a token."},{"name":"name","type":"String","description":"Permission Group Name"},{"name":"scopes","type":"List[String]","description":"Resources to which the Permission Group is scoped"}]}]}]},"get /zones":{"operationId":"zones-get","declarations":[{"kind":"list-data-source","name":"cloudflare_zones","stainlessResource":"zones","methodName":"list","snippet":"data \"cloudflare_zones\" \"example_zones\" {\n account = {\n id = \"id\"\n name = \"name\"\n }\n direction = \"desc\"\n name = \"name\"\n order = \"status\"\n status = \"initializing\"\n type = [\"full\"]\n}\n","required":[],"optional":[{"name":"direction","type":"String","description":"Direction to order zones."},{"name":"name","type":"String","description":"A domain name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"},{"name":"order","type":"String","description":"Field to order zones by."},{"name":"status","type":"String","description":"Specify a zone status to filter by."},{"name":"type","type":"List[String]","description":"Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type \"internal\" are excluded from the results."},{"name":"account","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter by an account ID."},{"name":"name","type":"String","description":"An account Name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"}]},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"account","type":"Attributes","description":"The account the zone belongs to.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the account."}]},{"name":"activated_on","type":"Time","description":"The last time proof of ownership was detected and the zone was made\nactive."},{"name":"created_on","type":"Time","description":"When the zone was created."},{"name":"development_mode","type":"Float64","description":"The interval (in seconds) from when development mode expires\n(positive integer) or last expired (negative integer) for the\ndomain. If development mode has never been enabled, this value is 0."},{"name":"meta","type":"Attributes","description":"Metadata about the zone.","children":[{"name":"cdn_only","type":"Bool","description":"The zone is only configured for CDN."},{"name":"custom_certificate_quota","type":"Int64","description":"Number of Custom Certificates the zone can have."},{"name":"dns_only","type":"Bool","description":"The zone is only configured for DNS."},{"name":"foundation_dns","type":"Bool","description":"The zone is setup with Foundation DNS."},{"name":"page_rule_quota","type":"Int64","description":"Number of Page Rules a zone can have."},{"name":"phishing_detected","type":"Bool","description":"The zone has been flagged for phishing."},{"name":"step","type":"Int64"}]},{"name":"modified_on","type":"Time","description":"When the zone was last modified."},{"name":"name","type":"String","description":"The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment (\"label\") not exceeding 63 characters."},{"name":"name_servers","type":"List[String]","description":"The name servers Cloudflare assigns to a zone."},{"name":"original_dnshost","type":"String","description":"DNS host at the time of switching to Cloudflare."},{"name":"original_name_servers","type":"List[String]","description":"Original name servers before moving to Cloudflare."},{"name":"original_registrar","type":"String","description":"Registrar for the domain at the time of switching to Cloudflare."},{"name":"owner","type":"Attributes","description":"The owner of the zone.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Name of the owner."},{"name":"type","type":"String","description":"The type of owner."}]},{"name":"plan","type":"Attributes","description":"A Zones subscription information.","deprecated":"Please use the `/zones/{zone_id}/subscription` API\nto update a zone's plan. Changing this value will create/cancel\nassociated subscriptions. To view available plans for this zone,\nsee [Zone Plans](https://developers.cloudflare.com/api/resources/zones/subresources/plans/).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"can_subscribe","type":"Bool","description":"States if the subscription can be activated."},{"name":"currency","type":"String","description":"The denomination of the customer."},{"name":"externally_managed","type":"Bool","description":"If this Zone is managed by another company."},{"name":"frequency","type":"String","description":"How often the customer is billed."},{"name":"is_subscribed","type":"Bool","description":"States if the subscription active."},{"name":"legacy_discount","type":"Bool","description":"If the legacy discount applies to this Zone."},{"name":"legacy_id","type":"String","description":"The legacy name of the plan."},{"name":"name","type":"String","description":"Name of the owner."},{"name":"price","type":"Float64","description":"How much the customer is paying."}]},{"name":"cname_suffix","type":"String","description":"Allows the customer to use a custom apex.\n*Tenants Only Configuration*."},{"name":"paused","type":"Bool","description":"Indicates whether the zone is only using Cloudflare DNS services. A\ntrue value means the zone will not receive security or performance\nbenefits.\n"},{"name":"permissions","type":"List[String]","description":"Legacy permissions based on legacy user membership information.","deprecated":"This has been replaced by Account memberships."},{"name":"status","type":"String","description":"The zone status on Cloudflare."},{"name":"tenant","type":"Attributes","description":"The root organizational unit that this zone belongs to (such as a tenant or organization).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the Tenant account."}]},{"name":"tenant_unit","type":"Attributes","description":"The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization).","children":[{"name":"id","type":"String","description":"Identifier"}]},{"name":"type","type":"String","description":"A full zone implies that DNS is hosted with Cloudflare. A partial zone is\ntypically a partner-hosted zone or a CNAME setup.\n"},{"name":"vanity_name_servers","type":"List[String]","description":"An array of domains used for custom name servers. This is only available for Business and Enterprise plans."},{"name":"verification_key","type":"String","description":"Verification key for partial zone setup."}]}]}]},"get /zones/{}":{"operationId":"zones-0-get","declarations":[{"kind":"data-source","name":"cloudflare_zone","stainlessResource":"zones","methodName":"get","snippet":"data \"cloudflare_zone\" \"example_zone\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[],"optional":[{"name":"zone_id","type":"String","description":"Identifier"},{"name":"filter","type":"Attributes","children":[{"name":"account","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter by an account ID."},{"name":"name","type":"String","description":"An account Name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"}]},{"name":"direction","type":"String","description":"Direction to order zones."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"name","type":"String","description":"A domain name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"},{"name":"order","type":"String","description":"Field to order zones by."},{"name":"status","type":"String","description":"Specify a zone status to filter by."},{"name":"type","type":"List[String]","description":"Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type \"internal\" are excluded from the results."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"activated_on","type":"Time","description":"The last time proof of ownership was detected and the zone was made\nactive."},{"name":"cname_suffix","type":"String","description":"Allows the customer to use a custom apex.\n*Tenants Only Configuration*."},{"name":"created_on","type":"Time","description":"When the zone was created."},{"name":"development_mode","type":"Float64","description":"The interval (in seconds) from when development mode expires\n(positive integer) or last expired (negative integer) for the\ndomain. If development mode has never been enabled, this value is 0."},{"name":"modified_on","type":"Time","description":"When the zone was last modified."},{"name":"name","type":"String","description":"The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment (\"label\") not exceeding 63 characters."},{"name":"original_dnshost","type":"String","description":"DNS host at the time of switching to Cloudflare."},{"name":"original_registrar","type":"String","description":"Registrar for the domain at the time of switching to Cloudflare."},{"name":"paused","type":"Bool","description":"Indicates whether the zone is only using Cloudflare DNS services. A\ntrue value means the zone will not receive security or performance\nbenefits.\n"},{"name":"status","type":"String","description":"The zone status on Cloudflare."},{"name":"type","type":"String","description":"A full zone implies that DNS is hosted with Cloudflare. A partial zone is\ntypically a partner-hosted zone or a CNAME setup.\n"},{"name":"verification_key","type":"String","description":"Verification key for partial zone setup."},{"name":"name_servers","type":"List[String]","description":"The name servers Cloudflare assigns to a zone."},{"name":"original_name_servers","type":"List[String]","description":"Original name servers before moving to Cloudflare."},{"name":"permissions","type":"List[String]","description":"Legacy permissions based on legacy user membership information.","deprecated":"This has been replaced by Account memberships."},{"name":"vanity_name_servers","type":"List[String]","description":"An array of domains used for custom name servers. This is only available for Business and Enterprise plans."},{"name":"account","type":"Attributes","description":"The account the zone belongs to.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the account."}]},{"name":"meta","type":"Attributes","description":"Metadata about the zone.","children":[{"name":"cdn_only","type":"Bool","description":"The zone is only configured for CDN."},{"name":"custom_certificate_quota","type":"Int64","description":"Number of Custom Certificates the zone can have."},{"name":"dns_only","type":"Bool","description":"The zone is only configured for DNS."},{"name":"foundation_dns","type":"Bool","description":"The zone is setup with Foundation DNS."},{"name":"page_rule_quota","type":"Int64","description":"Number of Page Rules a zone can have."},{"name":"phishing_detected","type":"Bool","description":"The zone has been flagged for phishing."},{"name":"step","type":"Int64"}]},{"name":"owner","type":"Attributes","description":"The owner of the zone.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Name of the owner."},{"name":"type","type":"String","description":"The type of owner."}]},{"name":"plan","type":"Attributes","description":"A Zones subscription information.","deprecated":"Please use the `/zones/{zone_id}/subscription` API\nto update a zone's plan. Changing this value will create/cancel\nassociated subscriptions. To view available plans for this zone,\nsee [Zone Plans](https://developers.cloudflare.com/api/resources/zones/subresources/plans/).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"can_subscribe","type":"Bool","description":"States if the subscription can be activated."},{"name":"currency","type":"String","description":"The denomination of the customer."},{"name":"externally_managed","type":"Bool","description":"If this Zone is managed by another company."},{"name":"frequency","type":"String","description":"How often the customer is billed."},{"name":"is_subscribed","type":"Bool","description":"States if the subscription active."},{"name":"legacy_discount","type":"Bool","description":"If the legacy discount applies to this Zone."},{"name":"legacy_id","type":"String","description":"The legacy name of the plan."},{"name":"name","type":"String","description":"Name of the owner."},{"name":"price","type":"Float64","description":"How much the customer is paying."}]},{"name":"tenant","type":"Attributes","description":"The root organizational unit that this zone belongs to (such as a tenant or organization).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the Tenant account."}]},{"name":"tenant_unit","type":"Attributes","description":"The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization).","children":[{"name":"id","type":"String","description":"Identifier"}]}]}]},"get /zones/{}/acm/custom_trust_store":{"operationId":"custom-origin-trust-store-list-details","declarations":[{"kind":"list-data-source","name":"cloudflare_custom_origin_trust_stores","stainlessResource":"acm.custom_trust_store","methodName":"list","snippet":"data \"cloudflare_custom_origin_trust_stores\" \"example_custom_origin_trust_stores\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Certificate identifier tag."},{"name":"certificate","type":"String","description":"The root CA certificate in PEM format. Only root CA certificates are accepted; intermediate and leaf certificates are not supported."},{"name":"expires_on","type":"Time","description":"When the certificate expires."},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"updated_at","type":"Time","description":"When the certificate was last modified."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."}]}]}]},"get /zones/{}/acm/custom_trust_store/{}":{"operationId":"custom-origin-trust-store-details","declarations":[{"kind":"data-source","name":"cloudflare_custom_origin_trust_store","stainlessResource":"acm.custom_trust_store","methodName":"get","snippet":"data \"cloudflare_custom_origin_trust_store\" \"example_custom_origin_trust_store\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_origin_trust_store_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"custom_origin_trust_store_id","type":"String","description":"Certificate identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."}]}],"computed":[{"name":"id","type":"String","description":"Certificate identifier tag."},{"name":"certificate","type":"String","description":"The root CA certificate in PEM format. Only root CA certificates are accepted; intermediate and leaf certificates are not supported."},{"name":"expires_on","type":"Time","description":"When the certificate expires."},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"updated_at","type":"Time","description":"When the certificate was last modified."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."}]}]},"get /zones/{}/acm/total_tls":{"operationId":"total-tls-total-tls-settings-details","declarations":[{"kind":"data-source","name":"cloudflare_total_tls","stainlessResource":"acm.total_tls","methodName":"get","snippet":"data \"cloudflare_total_tls\" \"example_total_tls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"certificate_authority","type":"String","description":"The Certificate Authority that Total TLS certificates will be issued through."},{"name":"enabled","type":"Bool","description":"If enabled, Total TLS will order a hostname specific TLS certificate for any proxied A, AAAA, or CNAME record in your zone."},{"name":"validity_period","type":"Int64","description":"The validity period in days for the certificates ordered via Total TLS."}]}]},"get /zones/{}/addressing/regional_hostnames":{"operationId":"dls-zone-regional-hostnames-list","declarations":[{"kind":"list-data-source","name":"cloudflare_regional_hostnames","stainlessResource":"addressing.regional_hostnames","methodName":"list","snippet":"data \"cloudflare_regional_hostnames\" \"example_regional_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"created_on","type":"Time","description":"When the regional hostname was created"},{"name":"hostname","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"region_key","type":"String","description":"Identifying key for the region"},{"name":"routing","type":"String","description":"Configure which routing method to use for the regional hostname"}]}]}]},"get /zones/{}/addressing/regional_hostnames/{}":{"operationId":"dls-zone-regional-hostnames-fetch","declarations":[{"kind":"data-source","name":"cloudflare_regional_hostname","stainlessResource":"addressing.regional_hostnames","methodName":"get","snippet":"data \"cloudflare_regional_hostname\" \"example_regional_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"foo.example.com\"\n}\n","required":[{"name":"hostname","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"created_on","type":"Time","description":"When the regional hostname was created"},{"name":"region_key","type":"String","description":"Identifying key for the region"},{"name":"routing","type":"String","description":"Configure which routing method to use for the regional hostname"}]}]},"get /zones/{}/api_gateway/configuration":{"operationId":"api-shield-settings-retrieve-information-about-specific-configuration-properties","declarations":[{"kind":"data-source","name":"cloudflare_api_shield","stainlessResource":"api_gateway.configurations","methodName":"get","snippet":"data \"cloudflare_api_shield\" \"example_api_shield\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n normalize = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"normalize","type":"Bool","description":"Ensures that the configuration is written or retrieved in normalized fashion"}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"auth_id_characteristics","type":"List[Attributes]","children":[{"name":"name","type":"String","description":"The name of the characteristic field, i.e., the header or cookie name."},{"name":"type","type":"String","description":"The type of characteristic."}]}]}]},"get /zones/{}/api_gateway/discovery/operations":{"operationId":"api-shield-api-discovery-retrieve-discovered-operations-on-a-zone","declarations":[{"kind":"list-data-source","name":"cloudflare_api_shield_discovery_operations","stainlessResource":"api_gateway.discovery.operations","methodName":"list","snippet":"data \"cloudflare_api_shield_discovery_operations\" \"example_api_shield_discovery_operations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n diff = true\n direction = \"desc\"\n endpoint = \"/api/v1\"\n host = [\"api.cloudflare.com\"]\n method = [\"GET\"]\n order = \"method\"\n origin = \"ML\"\n state = \"review\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"diff","type":"Bool","description":"When `true`, only return API Discovery results that are not saved into API Shield Endpoint Management"},{"name":"direction","type":"String","description":"Direction to order results."},{"name":"endpoint","type":"String","description":"Filter results to only include endpoints containing this pattern."},{"name":"order","type":"String","description":"Field to order by"},{"name":"origin","type":"String","description":"Filter results to only include discovery results sourced from a particular discovery engine\n * `ML` - Discovered operations that were sourced using ML API Discovery\n * `SessionIdentifier` - Discovered operations that were sourced using Session Identifier API Discovery\n"},{"name":"state","type":"String","description":"Filter results to only include discovery results in a particular state. States are as follows\n * `review` - Discovered operations that are not saved into API Shield Endpoint Management\n * `saved` - Discovered operations that are already saved into API Shield Endpoint Management\n * `ignored` - Discovered operations that have been marked as ignored\n"},{"name":"host","type":"List[String]","description":"Filter results to only include the specified hosts."},{"name":"method","type":"List[String]","description":"Filter results to only include the specified HTTP methods."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"endpoint","type":"String","description":"The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/."},{"name":"host","type":"String","description":"RFC3986-compliant host."},{"name":"last_updated","type":"Time"},{"name":"method","type":"String","description":"The HTTP method used to access the endpoint."},{"name":"origin","type":"List[String]","description":"API discovery engine(s) that discovered this operation"},{"name":"state","type":"String","description":"State of operation in API Discovery\n * `review` - Operation is not saved into API Shield Endpoint Management\n * `saved` - Operation is saved into API Shield Endpoint Management\n * `ignored` - Operation is marked as ignored\n"},{"name":"features","type":"Attributes","children":[{"name":"traffic_stats","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"period_seconds","type":"Int64","description":"The period in seconds these statistics were computed over"},{"name":"requests","type":"Float64","description":"The average number of requests seen during this period"}]}]}]}]}]},"get /zones/{}/api_gateway/operations":{"operationId":"api-shield-endpoint-management-retrieve-information-about-all-operations-on-a-zone","declarations":[{"kind":"list-data-source","name":"cloudflare_api_shield_operations","stainlessResource":"api_gateway.operations","methodName":"list","snippet":"data \"cloudflare_api_shield_operations\" \"example_api_shield_operations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n endpoint = \"/api/v1\"\n feature = [\"thresholds\"]\n host = [\"api.cloudflare.com\"]\n method = [\"GET\"]\n order = \"method\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"endpoint","type":"String","description":"Filter results to only include endpoints containing this pattern."},{"name":"order","type":"String","description":"Field to order by. When requesting a feature, the feature keys are available for ordering as well, e.g., `thresholds.suggested_threshold`."},{"name":"feature","type":"List[String]","description":"Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning."},{"name":"host","type":"List[String]","description":"Filter results to only include the specified hosts."},{"name":"method","type":"List[String]","description":"Filter results to only include the specified HTTP methods."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"endpoint","type":"String","description":"The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/."},{"name":"host","type":"String","description":"RFC3986-compliant host."},{"name":"last_updated","type":"Time"},{"name":"method","type":"String","description":"The HTTP method used to access the endpoint."},{"name":"operation_id","type":"String","description":"UUID."},{"name":"features","type":"Attributes","children":[{"name":"thresholds","type":"Attributes","children":[{"name":"auth_id_tokens","type":"Int64","description":"The total number of auth-ids seen across this calculation."},{"name":"data_points","type":"Int64","description":"The number of data points used for the threshold suggestion calculation."},{"name":"last_updated","type":"Time"},{"name":"p50","type":"Int64","description":"The p50 quantile of requests (in period_seconds)."},{"name":"p90","type":"Int64","description":"The p90 quantile of requests (in period_seconds)."},{"name":"p99","type":"Int64","description":"The p99 quantile of requests (in period_seconds)."},{"name":"period_seconds","type":"Int64","description":"The period over which this threshold is suggested."},{"name":"requests","type":"Int64","description":"The estimated number of requests covered by these calculations."},{"name":"suggested_threshold","type":"Int64","description":"The suggested threshold in requests done by the same auth_id or period_seconds."}]},{"name":"parameter_schemas","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"parameter_schemas","type":"Attributes","description":"An operation schema object containing a response.","children":[{"name":"parameters","type":"List[unknown]","description":"An array containing the learned parameter schemas."},{"name":"responses","type":"unknown","description":"An empty response object. This field is required to yield a valid operation schema."}]}]},{"name":"api_routing","type":"Attributes","description":"API Routing settings on endpoint.","children":[{"name":"last_updated","type":"Time"},{"name":"route","type":"String","description":"Target route."}]},{"name":"confidence_intervals","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"suggested_threshold","type":"Attributes","children":[{"name":"confidence_intervals","type":"Attributes","children":[{"name":"p90","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p95","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p99","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]}]},{"name":"mean","type":"Float64","description":"Suggested threshold."}]}]},{"name":"schema_info","type":"Attributes","children":[{"name":"active_schema","type":"Attributes","description":"Schema active on endpoint.","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"Schema file name."}]},{"name":"mitigation_action","type":"String","description":"Action taken on requests failing validation."}]}]}]}]}]},"get /zones/{}/api_gateway/operations/{}":{"operationId":"api-shield-endpoint-management-retrieve-information-about-an-operation","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_operation","stainlessResource":"api_gateway.operations","methodName":"get","snippet":"data \"cloudflare_api_shield_operation\" \"example_api_shield_operation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n feature = [\"thresholds\"]\n with_schemas = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"operation_id","type":"String","description":"UUID."},{"name":"feature","type":"List[String]","description":"Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning."},{"name":"with_schemas","type":"Bool","description":"When true, includes OpenAPI schemas (both uploaded and learned) for the operation in the response. Due to the conversion overhead, this parameter is only supported on single-operation retrieval."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"endpoint","type":"String","description":"Filter results to only include endpoints containing this pattern."},{"name":"feature","type":"List[String]","description":"Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning."},{"name":"host","type":"List[String]","description":"Filter results to only include the specified hosts."},{"name":"method","type":"List[String]","description":"Filter results to only include the specified HTTP methods."},{"name":"order","type":"String","description":"Field to order by. When requesting a feature, the feature keys are available for ordering as well, e.g., `thresholds.suggested_threshold`."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"endpoint","type":"String","description":"The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/."},{"name":"host","type":"String","description":"RFC3986-compliant host."},{"name":"last_updated","type":"Time"},{"name":"method","type":"String","description":"The HTTP method used to access the endpoint."},{"name":"features","type":"Attributes","children":[{"name":"thresholds","type":"Attributes","children":[{"name":"auth_id_tokens","type":"Int64","description":"The total number of auth-ids seen across this calculation."},{"name":"data_points","type":"Int64","description":"The number of data points used for the threshold suggestion calculation."},{"name":"last_updated","type":"Time"},{"name":"p50","type":"Int64","description":"The p50 quantile of requests (in period_seconds)."},{"name":"p90","type":"Int64","description":"The p90 quantile of requests (in period_seconds)."},{"name":"p99","type":"Int64","description":"The p99 quantile of requests (in period_seconds)."},{"name":"period_seconds","type":"Int64","description":"The period over which this threshold is suggested."},{"name":"requests","type":"Int64","description":"The estimated number of requests covered by these calculations."},{"name":"suggested_threshold","type":"Int64","description":"The suggested threshold in requests done by the same auth_id or period_seconds."}]},{"name":"parameter_schemas","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"parameter_schemas","type":"Attributes","description":"An operation schema object containing a response.","children":[{"name":"parameters","type":"List[unknown]","description":"An array containing the learned parameter schemas."},{"name":"responses","type":"unknown","description":"An empty response object. This field is required to yield a valid operation schema."}]}]},{"name":"api_routing","type":"Attributes","description":"API Routing settings on endpoint.","children":[{"name":"last_updated","type":"Time"},{"name":"route","type":"String","description":"Target route."}]},{"name":"confidence_intervals","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"suggested_threshold","type":"Attributes","children":[{"name":"confidence_intervals","type":"Attributes","children":[{"name":"p90","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p95","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p99","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]}]},{"name":"mean","type":"Float64","description":"Suggested threshold."}]}]},{"name":"schema_info","type":"Attributes","children":[{"name":"active_schema","type":"Attributes","description":"Schema active on endpoint.","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"Schema file name."}]},{"name":"mitigation_action","type":"String","description":"Action taken on requests failing validation."}]}]},{"name":"schemas","type":"Attributes","description":"OpenAPI JSON schemas for an operation, including both user-uploaded and Cloudflare-learned schemas.","children":[{"name":"learned","type":"Attributes","description":"An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.","children":[{"name":"parameters","type":"List[Map[unknown]]","description":"OpenAPI parameter objects describing path, query, header, or cookie parameters."},{"name":"request_body","type":"Map[unknown]","description":"OpenAPI request body object describing the expected request payload."}]},{"name":"uploaded","type":"Attributes","description":"An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.","children":[{"name":"parameters","type":"List[Map[unknown]]","description":"OpenAPI parameter objects describing path, query, header, or cookie parameters."},{"name":"request_body","type":"Map[unknown]","description":"OpenAPI request body object describing the expected request payload."}]}]}]}]},"get /zones/{}/api_gateway/operations/{}/schema_validation":{"operationId":"api-shield-schema-validation-retrieve-operation-level-settings","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_operation_schema_validation_settings","stainlessResource":"api_gateway.operations.schema_validation","methodName":"get","snippet":"data \"cloudflare_api_shield_operation_schema_validation_settings\" \"example_api_shield_operation_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation\n\n - `log` log request when request does not conform to schema for this operation\n - `block` deny access to the site when request does not conform to schema for this operation\n - `none` will skip mitigation for this operation\n - `null` indicates that no operation level mitigation is in place, see Zone Level Schema Validation Settings for mitigation action that will be applied\n"}]}]},"get /zones/{}/api_gateway/settings/schema_validation":{"operationId":"api-shield-schema-validation-retrieve-zone-level-settings","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_schema_validation_settings","stainlessResource":"api_gateway.settings.schema_validation","methodName":"get","snippet":"data \"cloudflare_api_shield_schema_validation_settings\" \"example_api_shield_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used when there is no mitigation action defined on the operation\n\nMitigation actions are as follows:\n\n * `log` - log request when request does not conform to schema\n * `block` - deny access to the site when request does not conform to schema\n\nA special value of of `none` will skip running schema validation entirely for the request when there is no mitigation action defined on the operation\n"},{"name":"validation_override_mitigation_action","type":"String","description":"When set, this overrides both zone level and operation level mitigation actions.\n\n - `none` will skip running schema validation entirely for the request\n - `null` indicates that no override is in place\n"}]}]},"get /zones/{}/api_gateway/user_schemas":{"operationId":"api-shield-schema-validation-retrieve-information-about-all-schemas","declarations":[{"kind":"list-data-source","name":"cloudflare_api_shield_schemas","stainlessResource":"api_gateway.user_schemas","methodName":"list","snippet":"data \"cloudflare_api_shield_schemas\" \"example_api_shield_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"validation_enabled","type":"Bool","description":"Flag whether schema is enabled for validation."},{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"Kind of schema"},{"name":"name","type":"String","description":"Name of the schema"},{"name":"schema_id","type":"String","description":"UUID."},{"name":"source","type":"String","description":"Source of the schema"},{"name":"validation_enabled","type":"Bool","description":"Flag whether schema is enabled for validation."}]}]}]},"get /zones/{}/api_gateway/user_schemas/{}":{"operationId":"api-shield-schema-validation-retrieve-information-about-specific-schema","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_schema","stainlessResource":"api_gateway.user_schemas","methodName":"get","snippet":"data \"cloudflare_api_shield_schema\" \"example_api_shield_schema\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n schema_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n omit_source = true\n}\n","required":[{"name":"schema_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."}],"computed":[{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"Kind of schema"},{"name":"name","type":"String","description":"Name of the schema"},{"name":"source","type":"String","description":"Source of the schema"},{"name":"validation_enabled","type":"Bool","description":"Flag whether schema is enabled for validation."}]}]},"get /zones/{}/argo/smart_routing":{"operationId":"argo-smart-routing-get-argo-smart-routing-setting","declarations":[{"kind":"data-source","name":"cloudflare_argo_smart_routing","stainlessResource":"argo.smart_routing","methodName":"get","snippet":"data \"cloudflare_argo_smart_routing\" \"example_argo_smart_routing\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specifies the zone associated with the API call."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the zone associated with the API call."},{"name":"editable","type":"Bool","description":"Specifies if the setting is editable."},{"name":"modified_on","type":"Time","description":"Specifies the time when the setting was last modified."},{"name":"value","type":"String","description":"Specifies the enablement value of Argo Smart Routing."}]}]},"get /zones/{}/argo/tiered_caching":{"operationId":"tiered-caching-get-tiered-caching-setting","declarations":[{"kind":"data-source","name":"cloudflare_argo_tiered_caching","stainlessResource":"argo.tiered_caching","methodName":"get","snippet":"data \"cloudflare_argo_tiered_caching\" \"example_argo_tiered_caching\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Tiered Cache zone setting."}]}]},"get /zones/{}/bot_management":{"operationId":"bot-management-for-a-zone-get-config","declarations":[{"kind":"data-source","name":"cloudflare_bot_management","stainlessResource":"bot_management","methodName":"get","snippet":"data \"cloudflare_bot_management\" \"example_bot_management\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"ai_bots_migration_opt_out","type":"Bool","description":"Temporary migration flag tracking zones opted out of AI bots managed-rule updates."},{"name":"ai_bots_protection","type":"String","description":"Enable rule to block AI Scrapers and Crawlers."},{"name":"ai_training","type":"String","description":"Configure robots.txt policy for AI model training bots."},{"name":"ai_user","type":"String","description":"Configure robots.txt policy for AI assistant and agent bots."},{"name":"aisearch","type":"String","description":"Configure robots.txt policy for AI search bots."},{"name":"auto_update_model","type":"Bool","description":"Automatically update to the newest bot detection models created by Cloudflare as they are released. [Learn more.](https://developers.cloudflare.com/bots/reference/machine-learning-models#model-versions-and-release-notes)"},{"name":"bm_cookie_enabled","type":"Bool","description":"Indicates that the bot management cookie can be placed on end user devices accessing the site. Defaults to true"},{"name":"bot_preference_sync_enabled","type":"Bool","description":"Enable Bot Preference Sync for this zone. When enabled, Cloudflare can serve robots.txt content derived from the zone's AI Search, AI User, and AI Training preferences."},{"name":"cf_robots_variant","type":"String","description":"Specifies the Robots Access Control License variant to use."},{"name":"content_bots_protection","type":"String","description":"Enable rule to block content bots. When enabled, blocks automated traffic with low bot scores, excluding safe verified bot categories. Exceptions should be managed via skip rules."},{"name":"crawler_protection","type":"String","description":"Enable rule to punish AI Scrapers and Crawlers via a link maze."},{"name":"enable_js","type":"Bool","description":"Use lightweight, invisible JavaScript detections to improve Bot Management. [Learn more about JavaScript Detections](https://developers.cloudflare.com/bots/reference/javascript-detections/)."},{"name":"fight_mode","type":"Bool","description":"Whether to enable Bot Fight Mode."},{"name":"is_robots_txt_managed","type":"Bool","description":"Enable cloudflare managed robots.txt. If an existing robots.txt is detected, then managed robots.txt will be prepended to the existing robots.txt."},{"name":"jsd_api_results_enabled","type":"Bool","description":"Whether to use JavaScript Detection results submitted through the API for this zone."},{"name":"optimize_wordpress","type":"Bool","description":"Whether to optimize Super Bot Fight Mode protections for Wordpress."},{"name":"sbfm_definitely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on definitely automated requests."},{"name":"sbfm_likely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on likely automated requests."},{"name":"sbfm_static_resource_protection","type":"Bool","description":"Super Bot Fight Mode (SBFM) to enable static resource protection.\nEnable if static resources on your application need bot protection.\nNote: Static resource protection can also result in legitimate traffic being blocked.\n"},{"name":"sbfm_verified_bots","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on verified bots requests."},{"name":"suppress_session_score","type":"Bool","description":"Whether to disable tracking the highest bot score for a session in the Bot Management cookie."},{"name":"using_latest_model","type":"Bool","description":"A read-only field that indicates whether the zone currently is running the latest ML model.\n"},{"name":"stale_zone_configuration","type":"Attributes","description":"A read-only field that shows which unauthorized settings are currently active on the zone. These settings typically result from upgrades or downgrades.","children":[{"name":"optimize_wordpress","type":"Bool","description":"Indicates that the zone's wordpress optimization for SBFM is turned on."},{"name":"sbfm_definitely_automated","type":"String","description":"Indicates that the zone's definitely automated requests are being blocked or challenged."},{"name":"sbfm_likely_automated","type":"String","description":"Indicates that the zone's likely automated requests are being blocked or challenged."},{"name":"sbfm_static_resource_protection","type":"String","description":"Indicates that the zone's static resource protection is turned on."},{"name":"sbfm_verified_bots","type":"String","description":"Indicates that the zone's verified bot requests are being blocked."},{"name":"suppress_session_score","type":"Bool","description":"Indicates that the zone's session score tracking is disabled."},{"name":"fight_mode","type":"Bool","description":"Indicates that the zone's Bot Fight Mode is turned on."}]}]}]},"get /zones/{}/cache/cache_reserve":{"operationId":"zone-cache-settings-get-cache-reserve-setting","declarations":[{"kind":"data-source","name":"cloudflare_zone_cache_reserve","stainlessResource":"cache.cache_reserve","methodName":"get","snippet":"data \"cloudflare_zone_cache_reserve\" \"example_zone_cache_reserve\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Cache Reserve zone setting."}]}]},"get /zones/{}/cache/regional_tiered_cache":{"operationId":"zone-cache-settings-get-regional-tiered-cache-setting","declarations":[{"kind":"data-source","name":"cloudflare_regional_tiered_cache","stainlessResource":"cache.regional_tiered_cache","methodName":"get","snippet":"data \"cloudflare_regional_tiered_cache\" \"example_regional_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Regional Tiered Cache zone setting."}]}]},"get /zones/{}/cache/tiered_cache_smart_topology_enable":{"operationId":"smart-tiered-cache-get-smart-tiered-cache-setting","declarations":[{"kind":"data-source","name":"cloudflare_tiered_cache","stainlessResource":"cache.smart_tiered_cache","methodName":"get","snippet":"data \"cloudflare_tiered_cache\" \"example_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Smart Tiered Cache zone setting."}]}]},"get /zones/{}/cache/variants":{"operationId":"zone-cache-settings-get-variants-setting","declarations":[{"kind":"data-source","name":"cloudflare_zone_cache_variants","stainlessResource":"cache.variants","methodName":"get","snippet":"data \"cloudflare_zone_cache_variants\" \"example_zone_cache_variants\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"Attributes","description":"Value of the zone setting.","children":[{"name":"avif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for avif."},{"name":"bmp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for bmp."},{"name":"gif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for gif."},{"name":"jp2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jp2."},{"name":"jpeg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpeg."},{"name":"jpg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg."},{"name":"jpg2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg2."},{"name":"png","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for png."},{"name":"tif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tif."},{"name":"tiff","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tiff."},{"name":"webp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for webp."}]}]}]},"get /zones/{}/certificate_authorities/hostname_associations":{"operationId":"client-certificate-for-a-zone-list-hostname-associations","declarations":[{"kind":"data-source","name":"cloudflare_certificate_authorities_hostname_associations","stainlessResource":"certificate_authorities.hostname_associations","methodName":"get","snippet":"data \"cloudflare_certificate_authorities_hostname_associations\" \"example_certificate_authorities_hostname_associations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n mtls_certificate_id = \"b2134436-2555-4acf-be5b-26c48136575e\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"mtls_certificate_id","type":"String","description":"The UUID to match against for a certificate that was uploaded to the mTLS Certificate Management endpoint. If no mtls_certificate_id is given, the results will be the hostnames associated to your active Cloudflare Managed CA."}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"hostnames","type":"List[String]"}]}]},"get /zones/{}/client_certificates":{"operationId":"client-certificate-for-a-zone-list-client-certificates","declarations":[{"kind":"list-data-source","name":"cloudflare_client_certificates","stainlessResource":"client_certificates","methodName":"list","snippet":"data \"cloudflare_client_certificates\" \"example_client_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n status = \"all\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"status","type":"String","description":"Client Certitifcate Status to filter results by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Client Certificate Tag"},{"name":"certificate","type":"String","description":"The Client Certificate PEM."},{"name":"certificate_authority","type":"Attributes","description":"Certificate Authority used to issue the Client Certificate.","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"common_name","type":"String","description":"Common Name of the Client Certificate."},{"name":"country","type":"String","description":"Country, provided by the CSR."},{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"expires_on","type":"String","description":"Date that the Client Certificate expires."},{"name":"fingerprint_sha256","type":"String","description":"Unique identifier of the Client Certificate."},{"name":"issued_on","type":"String","description":"Date that the Client Certificate was issued by the Certificate Authority."},{"name":"location","type":"String","description":"Location, provided by the CSR."},{"name":"organization","type":"String","description":"Organization, provided by the CSR."},{"name":"organizational_unit","type":"String","description":"Organizational Unit, provided by the CSR."},{"name":"serial_number","type":"String","description":"The serial number on the created Client Certificate."},{"name":"signature","type":"String","description":"The type of hash used for the Client Certificate.."},{"name":"ski","type":"String","description":"Subject Key Identifier."},{"name":"state","type":"String","description":"State, provided by the CSR."},{"name":"status","type":"String","description":"Client Certificates may be active or revoked, and the pending_reactivation or pending_revocation represent in-progress asynchronous transitions."},{"name":"validity_days","type":"Int64","description":"The number of days the Client Certificate will be valid after the issued_on date."}]}]}]},"get /zones/{}/client_certificates/{}":{"operationId":"client-certificate-for-a-zone-client-certificate-details","declarations":[{"kind":"data-source","name":"cloudflare_client_certificate","stainlessResource":"client_certificates","methodName":"get","snippet":"data \"cloudflare_client_certificate\" \"example_client_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n client_certificate_id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"client_certificate_id","type":"String","description":"Client Certificate Tag"},{"name":"filter","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"status","type":"String","description":"Client Certitifcate Status to filter results by."}]}],"computed":[{"name":"id","type":"String","description":"Client Certificate Tag"},{"name":"certificate","type":"String","description":"The Client Certificate PEM."},{"name":"common_name","type":"String","description":"Common Name of the Client Certificate."},{"name":"country","type":"String","description":"Country, provided by the CSR."},{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"expires_on","type":"String","description":"Date that the Client Certificate expires."},{"name":"fingerprint_sha256","type":"String","description":"Unique identifier of the Client Certificate."},{"name":"issued_on","type":"String","description":"Date that the Client Certificate was issued by the Certificate Authority."},{"name":"location","type":"String","description":"Location, provided by the CSR."},{"name":"organization","type":"String","description":"Organization, provided by the CSR."},{"name":"organizational_unit","type":"String","description":"Organizational Unit, provided by the CSR."},{"name":"serial_number","type":"String","description":"The serial number on the created Client Certificate."},{"name":"signature","type":"String","description":"The type of hash used for the Client Certificate.."},{"name":"ski","type":"String","description":"Subject Key Identifier."},{"name":"state","type":"String","description":"State, provided by the CSR."},{"name":"status","type":"String","description":"Client Certificates may be active or revoked, and the pending_reactivation or pending_revocation represent in-progress asynchronous transitions."},{"name":"validity_days","type":"Int64","description":"The number of days the Client Certificate will be valid after the issued_on date."},{"name":"certificate_authority","type":"Attributes","description":"Certificate Authority used to issue the Client Certificate.","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]}]}]},"get /zones/{}/cloud_connector/rules":{"operationId":"zone-cloud-connector-rules","declarations":[{"kind":"data-source","name":"cloudflare_cloud_connector_rules","stainlessResource":"cloud_connector.rules","methodName":"list","snippet":"data \"cloudflare_cloud_connector_rules\" \"example_cloud_connector_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"cloud_connector_rules_provider","type":"String","description":"Cloud Provider type"},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String"},{"name":"parameters","type":"Attributes","description":"Parameters of Cloud Connector Rule","children":[{"name":"host","type":"String","description":"Host to perform Cloud Connection to"}]}]}]},"get /zones/{}/content-upload-scan/payloads":{"operationId":"waf-content-scanning-list-custom-scan-expressions","declarations":[{"kind":"list-data-source","name":"cloudflare_content_scanning_expressions","stainlessResource":"content_scanning.payloads","methodName":"list","snippet":"data \"cloudflare_content_scanning_expressions\" \"example_content_scanning_expressions\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Defines the unique ID for this Content Scanning custom expression."},{"name":"payload","type":"String","description":"Defines the custom content extraction expression used to reach content objects in the request."}]}]}]},"get /zones/{}/content-upload-scan/settings":{"operationId":"waf-content-scanning-get-status","declarations":[{"kind":"data-source","name":"cloudflare_content_scanning","stainlessResource":"content_scanning","methodName":"get","snippet":"data \"cloudflare_content_scanning\" \"example_content_scanning\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[{"name":"modified","type":"String","description":"Defines the last modification date (ISO 8601) of the Content Scanning status."},{"name":"value","type":"String","description":"Defines the status of Content Scanning."}]}]},"get /zones/{}/ct/alerting":{"operationId":"ct-alerting-get-subscription","declarations":[{"kind":"data-source","name":"cloudflare_ct_alerting","stainlessResource":"zones.ct.alerting","methodName":"get","snippet":"data \"cloudflare_ct_alerting\" \"example_ct_alerting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Whether CT alerting is enabled for the zone."},{"name":"emails","type":"List[String]","description":"Email addresses that receive CT alert notifications for the zone. A maximum of 100 addresses may be configured. Each address must be a valid RFC 5322 email address and must not contain a comma.\n"}]}]},"get /zones/{}/custom_certificates":{"operationId":"custom-ssl-for-a-zone-list-ssl-configurations","declarations":[{"kind":"list-data-source","name":"cloudflare_custom_ssls","stainlessResource":"custom_certificates","methodName":"list","snippet":"data \"cloudflare_custom_ssls\" \"example_custom_ssls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n status = \"active\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Custom certificate identifier tag."},{"name":"zone_id","type":"String","description":"Identifier."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.","children":[{"name":"label","type":"String"}]},{"name":"hosts","type":"List[String]"},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"keyless_server","type":"Attributes","children":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"policy_restrictions","type":"String","description":"The policy restrictions returned by the API. This field is returned in responses\nwhen a policy has been set. The API accepts the \"policy\" field in requests but\nreturns this field as \"policy_restrictions\" in responses.\n\nSpecifies the region(s) where your private key can be held locally for optimal\nTLS performance. Format is a boolean expression, for example:\n\"(country: US) or (region: EU)\"\n"},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacy_custom' certificates, but 'legacy_custom' certificates will always supercede 'sni_custom' certificates."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."}]}]}]},"get /zones/{}/custom_certificates/{}":{"operationId":"custom-ssl-for-a-zone-ssl-configuration-details","declarations":[{"kind":"data-source","name":"cloudflare_custom_ssl","stainlessResource":"custom_certificates","methodName":"get","snippet":"data \"cloudflare_custom_ssl\" \"example_custom_ssl\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_certificate_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"custom_certificate_id","type":"String","description":"Custom certificate identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."}]}],"computed":[{"name":"id","type":"String","description":"Custom certificate identifier tag."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"policy_restrictions","type":"String","description":"The policy restrictions returned by the API. This field is returned in responses\nwhen a policy has been set. The API accepts the \"policy\" field in requests but\nreturns this field as \"policy_restrictions\" in responses.\n\nSpecifies the region(s) where your private key can be held locally for optimal\nTLS performance. Format is a boolean expression, for example:\n\"(country: US) or (region: EU)\"\n"},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacy_custom' certificates, but 'legacy_custom' certificates will always supercede 'sni_custom' certificates."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"hosts","type":"List[String]"},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.","children":[{"name":"label","type":"String"}]},{"name":"keyless_server","type":"Attributes","children":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]}]}]},"get /zones/{}/custom_hostnames":{"operationId":"custom-hostname-for-a-zone-list-custom-hostnames","declarations":[{"kind":"list-data-source","name":"cloudflare_custom_hostnames","stainlessResource":"custom_hostnames","methodName":"list","snippet":"data \"cloudflare_custom_hostnames\" \"example_custom_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n certificate_authority = \"google\"\n custom_origin_server = \"origin2.example.com\"\n direction = \"desc\"\n hostname = {\n contain = \"example.com\"\n exact = \"app.example.com\"\n starts_with = \"app\"\n }\n hostname_status = \"provisioned\"\n ssl_status = \"active\"\n wildcard = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"certificate_authority","type":"String","description":"Filter by the certificate authority that issued the SSL certificate."},{"name":"custom_origin_server","type":"String","description":"Filter by custom origin server name."},{"name":"direction","type":"String","description":"Direction to order hostnames."},{"name":"hostname_status","type":"String","description":"Filter by the hostname's activation status."},{"name":"id","type":"String","description":"Hostname ID to match against. This ID was generated and returned during the initial custom_hostname creation. This parameter cannot be used with the 'hostname', 'hostname.exact', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"ssl_status","type":"String","description":"Filter by SSL certificate status."},{"name":"wildcard","type":"Bool","description":"Filter by whether the custom hostname is a wildcard hostname."},{"name":"hostname","type":"Attributes","children":[{"name":"contain","type":"String","description":"Filters hostnames by a substring match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.startsWith' parameters."},{"name":"exact","type":"String","description":"Fully qualified domain name to match against. This parameter cannot be used with the 'id', 'hostname', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"starts_with","type":"String","description":"Filters hostnames by a prefix match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.contain' parameters."}]},{"name":"order","type":"String","description":"Field to order hostnames by."},{"name":"ssl","type":"Int64","description":"Whether to filter hostnames based on if they have SSL enabled."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Custom hostname identifier tag."},{"name":"hostname","type":"String","description":"The custom hostname that will point to your hostname via CNAME."},{"name":"created_at","type":"Time","description":"This is the time the hostname was created."},{"name":"custom_metadata","type":"Map[String]","description":"Unique key/value metadata for this hostname. These are per-hostname (customer) settings."},{"name":"custom_origin_server","type":"String","description":"a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record."},{"name":"custom_origin_sni","type":"String","description":"A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or the string ':request_host_header:' which will cause the host header in the request to be used as SNI. Not configurable with default/fallback origin server."},{"name":"ownership_verification","type":"Attributes","description":"This is a record which can be placed to activate a hostname.","children":[{"name":"name","type":"String","description":"DNS Name for record."},{"name":"type","type":"String","description":"DNS Record type."},{"name":"value","type":"String","description":"Content for the record."}]},{"name":"ownership_verification_http","type":"Attributes","description":"This presents the token to be served by the given http url to activate a hostname.","children":[{"name":"http_body","type":"String","description":"Token to be served."},{"name":"http_url","type":"String","description":"The HTTP URL that will be checked during custom hostname verification and where the customer should host the token."}]},{"name":"ssl","type":"Attributes","children":[{"name":"id","type":"String","description":"Custom hostname SSL identifier tag."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"certificate_authority","type":"String","description":"The Certificate Authority that will issue the certificate."},{"name":"custom_certificate","type":"String","description":"If a custom uploaded certificate is used."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"custom_key","type":"String","description":"The key for a custom uploaded certificate.","sensitive":true},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"expires_on","type":"Time","description":"The time the custom certificate expires on."},{"name":"hosts","type":"List[String]","description":"A list of Hostnames on a custom uploaded certificate."},{"name":"issuer","type":"String","description":"The issuer on a custom uploaded certificate."},{"name":"method","type":"String","description":"Domain control validation (DCV) method used for this hostname."},{"name":"serial_number","type":"String","description":"The serial number on a custom uploaded certificate."},{"name":"settings","type":"Attributes","children":[{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."},{"name":"early_hints","type":"String","description":"Whether or not Early Hints is enabled."},{"name":"http2","type":"String","description":"Whether or not HTTP2 is enabled."},{"name":"min_tls_version","type":"String","description":"The minimum TLS version supported."},{"name":"tls_1_3","type":"String","description":"Whether or not TLS 1.3 is enabled."}]},{"name":"signature","type":"String","description":"The signature on a custom uploaded certificate."},{"name":"status","type":"String","description":"Status of the hostname's SSL certificates."},{"name":"type","type":"String","description":"Level of validation to be used for this hostname. Domain validation (dv) must be used."},{"name":"uploaded_on","type":"Time","description":"The time the custom certificate was uploaded."},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"wildcard","type":"Bool","description":"Indicates whether the certificate covers a wildcard."}]},{"name":"status","type":"String","description":"Status of the hostname's activation."},{"name":"verification_errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a hostname."}]}]}]},"get /zones/{}/custom_hostnames/{}":{"operationId":"custom-hostname-for-a-zone-custom-hostname-details","declarations":[{"kind":"data-source","name":"cloudflare_custom_hostname","stainlessResource":"custom_hostnames","methodName":"get","snippet":"data \"cloudflare_custom_hostname\" \"example_custom_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_hostname_id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"custom_hostname_id","type":"String","description":"Custom hostname identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"Hostname ID to match against. This ID was generated and returned during the initial custom_hostname creation. This parameter cannot be used with the 'hostname', 'hostname.exact', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"certificate_authority","type":"String","description":"Filter by the certificate authority that issued the SSL certificate."},{"name":"custom_origin_server","type":"String","description":"Filter by custom origin server name."},{"name":"direction","type":"String","description":"Direction to order hostnames."},{"name":"hostname","type":"Attributes","children":[{"name":"contain","type":"String","description":"Filters hostnames by a substring match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.startsWith' parameters."},{"name":"exact","type":"String","description":"Fully qualified domain name to match against. This parameter cannot be used with the 'id', 'hostname', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"starts_with","type":"String","description":"Filters hostnames by a prefix match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.contain' parameters."}]},{"name":"hostname_status","type":"String","description":"Filter by the hostname's activation status."},{"name":"order","type":"String","description":"Field to order hostnames by."},{"name":"ssl","type":"Int64","description":"Whether to filter hostnames based on if they have SSL enabled."},{"name":"ssl_status","type":"String","description":"Filter by SSL certificate status."},{"name":"wildcard","type":"Bool","description":"Filter by whether the custom hostname is a wildcard hostname."}]}],"computed":[{"name":"id","type":"String","description":"Custom hostname identifier tag."},{"name":"created_at","type":"Time","description":"This is the time the hostname was created."},{"name":"custom_origin_server","type":"String","description":"a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record."},{"name":"custom_origin_sni","type":"String","description":"A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or the string ':request_host_header:' which will cause the host header in the request to be used as SNI. Not configurable with default/fallback origin server."},{"name":"hostname","type":"String","description":"The custom hostname that will point to your hostname via CNAME."},{"name":"status","type":"String","description":"Status of the hostname's activation."},{"name":"custom_metadata","type":"Map[String]","description":"Unique key/value metadata for this hostname. These are per-hostname (customer) settings."},{"name":"verification_errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a hostname."},{"name":"ownership_verification","type":"Attributes","description":"This is a record which can be placed to activate a hostname.","children":[{"name":"name","type":"String","description":"DNS Name for record."},{"name":"type","type":"String","description":"DNS Record type."},{"name":"value","type":"String","description":"Content for the record."}]},{"name":"ownership_verification_http","type":"Attributes","description":"This presents the token to be served by the given http url to activate a hostname.","children":[{"name":"http_body","type":"String","description":"Token to be served."},{"name":"http_url","type":"String","description":"The HTTP URL that will be checked during custom hostname verification and where the customer should host the token."}]},{"name":"ssl","type":"Attributes","children":[{"name":"id","type":"String","description":"Custom hostname SSL identifier tag."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"certificate_authority","type":"String","description":"The Certificate Authority that will issue the certificate."},{"name":"custom_certificate","type":"String","description":"If a custom uploaded certificate is used."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"custom_key","type":"String","description":"The key for a custom uploaded certificate.","sensitive":true},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"expires_on","type":"Time","description":"The time the custom certificate expires on."},{"name":"hosts","type":"List[String]","description":"A list of Hostnames on a custom uploaded certificate."},{"name":"issuer","type":"String","description":"The issuer on a custom uploaded certificate."},{"name":"method","type":"String","description":"Domain control validation (DCV) method used for this hostname."},{"name":"serial_number","type":"String","description":"The serial number on a custom uploaded certificate."},{"name":"settings","type":"Attributes","children":[{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."},{"name":"early_hints","type":"String","description":"Whether or not Early Hints is enabled."},{"name":"http2","type":"String","description":"Whether or not HTTP2 is enabled."},{"name":"min_tls_version","type":"String","description":"The minimum TLS version supported."},{"name":"tls_1_3","type":"String","description":"Whether or not TLS 1.3 is enabled."}]},{"name":"signature","type":"String","description":"The signature on a custom uploaded certificate."},{"name":"status","type":"String","description":"Status of the hostname's SSL certificates."},{"name":"type","type":"String","description":"Level of validation to be used for this hostname. Domain validation (dv) must be used."},{"name":"uploaded_on","type":"Time","description":"The time the custom certificate was uploaded."},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"wildcard","type":"Bool","description":"Indicates whether the certificate covers a wildcard."}]}]}]},"get /zones/{}/custom_hostnames/fallback_origin":{"operationId":"custom-hostname-fallback-origin-for-a-zone-get-fallback-origin-for-custom-hostnames","declarations":[{"kind":"data-source","name":"cloudflare_custom_hostname_fallback_origin","stainlessResource":"custom_hostnames.fallback_origin","methodName":"get","snippet":"data \"cloudflare_custom_hostname_fallback_origin\" \"example_custom_hostname_fallback_origin\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_at","type":"Time","description":"This is the time the fallback origin was created."},{"name":"origin","type":"String","description":"Your origin hostname that requests to your custom hostnames will be sent to."},{"name":"status","type":"String","description":"Status of the fallback origin's activation."},{"name":"updated_at","type":"Time","description":"This is the time the fallback origin was updated."},{"name":"errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a fallback origin."}]}]},"get /zones/{}/dcv_delegation/uuid":{"operationId":"dcv-delegation-uuid-get","declarations":[{"kind":"data-source","name":"cloudflare_dcv_delegation","stainlessResource":"dcv_delegation","methodName":"get","snippet":"data \"cloudflare_dcv_delegation\" \"example_dcv_delegation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"uuid","type":"String","description":"The DCV Delegation unique identifier."}]}]},"get /zones/{}/devices/policy/certificates":{"operationId":"devices-get-policy-certificates","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_default_profile_certificates","stainlessResource":"zero_trust.devices.policies.default.certificates","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_default_profile_certificates\" \"example_zero_trust_device_default_profile_certificates\" {\n zone_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"The current status of the device policy certificate provisioning feature for WARP clients."}]}]},"get /zones/{}/dns_records":{"operationId":"dns-records-for-a-zone-list-dns-records","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_records","stainlessResource":"dns.records","methodName":"list","snippet":"data \"cloudflare_dns_records\" \"example_dns_records\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n comment = {\n absent = \"absent\"\n contains = \"ello, worl\"\n endswith = \"o, world\"\n exact = \"Hello, world\"\n present = \"present\"\n startswith = \"Hello, w\"\n }\n content = {\n contains = \"7.0.0.\"\n endswith = \".0.1\"\n exact = \"127.0.0.1\"\n startswith = \"127.0.\"\n }\n name = {\n contains = \"w.example.\"\n endswith = \".example.com\"\n exact = \"www.example.com\"\n startswith = \"www.example\"\n }\n search = \"www.cloudflare.com\"\n shadowed_by_name = \"sub.example.com\"\n shadowing_name = \"www.sub.example.com\"\n tag = {\n absent = \"important\"\n contains = \"greeting:ello, worl\"\n endswith = \"greeting:o, world\"\n exact = \"greeting:Hello, world\"\n present = \"important\"\n startswith = \"greeting:Hello, w\"\n }\n type = \"A\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"search","type":"String","description":"Allows searching in multiple properties of a DNS record simultaneously. This parameter is intended for human users, not automation. Its exact behavior is intentionally left unspecified and is subject to change in the future. This parameter works independently of the `match` setting. For automated searches, please use the other available parameters.\n"},{"name":"shadowed_by_name","type":"String","description":"Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires `include_shadow_metadata=true`. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowing_name","type":"String","description":"Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"type","type":"String","description":"Record type."},{"name":"comment","type":"Attributes","children":[{"name":"absent","type":"String","description":"If this parameter is present, only records *without* a comment are returned.\n"},{"name":"contains","type":"String","description":"Substring of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"present","type":"String","description":"If this parameter is present, only records *with* a comment are returned.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record comment. Comment filters are case-insensitive.\n"}]},{"name":"content","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record content. Content filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record content. Content filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record content. Content filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record content. Content filters are case-insensitive.\n"}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record name. Name filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record name. Name filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record name. Name filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record name. Name filters are case-insensitive.\n"}]},{"name":"tag","type":"Attributes","children":[{"name":"absent","type":"String","description":"Name of a tag which must *not* be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"contains","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value contains ``. Tag filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value ends with ``. Tag filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value is ``. Tag filters are case-insensitive.\n"},{"name":"present","type":"String","description":"Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value starts with ``. Tag filters are case-insensitive.\n"}]},{"name":"direction","type":"String","description":"Direction to order DNS records in."},{"name":"include_shadow_metadata","type":"Bool","description":"Whether to include shadow metadata in the `meta` field of each record in the response. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead. Note that the interaction between tag filters is controlled by the `tag-match` parameter instead.\n"},{"name":"order","type":"String","description":"Field to order DNS records by."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"tag_match","type":"String","description":"Whether to match all tag search requirements or at least one (any). If set to `all`, acts like a logical AND between tag filters. If set to `any`, acts like a logical OR instead. Note that the regular `match` parameter is still used to combine the resulting condition with other filters that aren't related to tags.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"name","type":"String","description":"Complete DNS record name, including the zone name, in Punycode."},{"name":"ttl","type":"Float64","description":"Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterprise zones."},{"name":"type","type":"String","description":"Record type."},{"name":"comment","type":"String","description":"Comments or notes about the DNS record. This field has no effect on DNS responses."},{"name":"content","type":"String","description":"A valid IPv4 address."},{"name":"private_routing","type":"Bool","description":"Enables private network routing to the origin."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"settings","type":"Attributes","description":"Settings for the DNS record.","children":[{"name":"ipv4_only","type":"Bool","description":"When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"ipv6_only","type":"Bool","description":"When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"flatten_cname","type":"Bool","description":"If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened."}]},{"name":"tags","type":"Set[String]","description":"Custom tags for the DNS record. This field has no effect on DNS responses."},{"name":"id","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the record was created."},{"name":"meta","type":"Attributes","description":"Extra Cloudflare-specific metadata about the record.","children":[{"name":"dead_glue","type":"Bool","description":"Whether this glue record is not served because a shallower NS delegation takes precedence over the deeper delegation that needs it. Present only when true; reachable glue carries only `is_glue`. See [Unreachable glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#unreachable-glue-records).\n"},{"name":"is_glue","type":"Bool","description":"Whether this A or AAAA record is glue for a subdomain NS delegation. See [Glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#glue-records).\n"},{"name":"shadowed_by","type":"List[String]","description":"IDs of the NS records that shadow this record. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowed_records_count","type":"Int64","description":"Number of records shadowed by this NS delegation. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"}]},{"name":"modified_on","type":"Time","description":"When the record was last modified."},{"name":"proxiable","type":"Bool","description":"Whether the record can be proxied by Cloudflare or not."},{"name":"comment_modified_on","type":"Time","description":"When the record comment was last modified. Omitted if there is no comment."},{"name":"tags_modified_on","type":"Time","description":"When the record tags were last modified. Omitted if there are no tags."},{"name":"priority","type":"Float64","description":"Required for MX and URI records; ignored for other record types (but may still be returned by the API). Records with lower priorities are preferred. This field is to be deprecated in favor of the priority field within the data map."},{"name":"data","type":"Attributes","description":"Components of a CAA record.","children":[{"name":"flags","type":"Dynamic Float64 | String","description":"Flags for the CAA record."},{"name":"tag","type":"String","description":"Name of the property controlled by this record (e.g.: issue, issuewild, iodef)."},{"name":"value","type":"String","description":"Value of the record. This field's semantics depend on the chosen tag."},{"name":"algorithm","type":"Float64","description":"Algorithm."},{"name":"certificate","type":"String","description":"Certificate."},{"name":"key_tag","type":"Float64","description":"Key Tag."},{"name":"type","type":"Float64","description":"Type."},{"name":"protocol","type":"Float64","description":"Protocol."},{"name":"public_key","type":"String","description":"Public Key."},{"name":"digest","type":"String","description":"Digest."},{"name":"digest_type","type":"Float64","description":"Digest Type."},{"name":"priority","type":"Float64","description":"Priority."},{"name":"target","type":"String","description":"Target."},{"name":"altitude","type":"Float64","description":"Altitude of location in meters."},{"name":"lat_degrees","type":"Float64","description":"Degrees of latitude."},{"name":"lat_direction","type":"String","description":"Latitude direction."},{"name":"lat_minutes","type":"Float64","description":"Minutes of latitude."},{"name":"lat_seconds","type":"Float64","description":"Seconds of latitude."},{"name":"long_degrees","type":"Float64","description":"Degrees of longitude."},{"name":"long_direction","type":"String","description":"Longitude direction."},{"name":"long_minutes","type":"Float64","description":"Minutes of longitude."},{"name":"long_seconds","type":"Float64","description":"Seconds of longitude."},{"name":"precision_horz","type":"Float64","description":"Horizontal precision of location."},{"name":"precision_vert","type":"Float64","description":"Vertical precision of location."},{"name":"size","type":"Float64","description":"Size of location in meters."},{"name":"order","type":"Float64","description":"Order."},{"name":"preference","type":"Float64","description":"Preference."},{"name":"regex","type":"String","description":"Regex."},{"name":"replacement","type":"String","description":"Replacement."},{"name":"service","type":"String","description":"Service."},{"name":"matching_type","type":"Float64","description":"Matching Type."},{"name":"selector","type":"Float64","description":"Selector."},{"name":"usage","type":"Float64","description":"Usage."},{"name":"port","type":"Float64","description":"The port of the service."},{"name":"weight","type":"Float64","description":"The record weight."},{"name":"fingerprint","type":"String","description":"Fingerprint."}]}]}]}]},"get /zones/{}/dns_records/{}":{"operationId":"dns-records-for-a-zone-dns-record-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_record","stainlessResource":"dns.records","methodName":"get","snippet":"data \"cloudflare_dns_record\" \"example_dns_record\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns_record_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n include_shadow_metadata = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"dns_record_id","type":"String","description":"Identifier."},{"name":"include_shadow_metadata","type":"Bool","description":"Whether to include shadow metadata in the `meta` field of each record in the response. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"filter","type":"Attributes","children":[{"name":"comment","type":"Attributes","children":[{"name":"absent","type":"String","description":"If this parameter is present, only records *without* a comment are returned.\n"},{"name":"contains","type":"String","description":"Substring of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"present","type":"String","description":"If this parameter is present, only records *with* a comment are returned.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record comment. Comment filters are case-insensitive.\n"}]},{"name":"content","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record content. Content filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record content. Content filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record content. Content filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record content. Content filters are case-insensitive.\n"}]},{"name":"direction","type":"String","description":"Direction to order DNS records in."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead. Note that the interaction between tag filters is controlled by the `tag-match` parameter instead.\n"},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record name. Name filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record name. Name filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record name. Name filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record name. Name filters are case-insensitive.\n"}]},{"name":"order","type":"String","description":"Field to order DNS records by."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"search","type":"String","description":"Allows searching in multiple properties of a DNS record simultaneously. This parameter is intended for human users, not automation. Its exact behavior is intentionally left unspecified and is subject to change in the future. This parameter works independently of the `match` setting. For automated searches, please use the other available parameters.\n"},{"name":"shadowed_by_name","type":"String","description":"Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires `include_shadow_metadata=true`. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowing_name","type":"String","description":"Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"tag","type":"Attributes","children":[{"name":"absent","type":"String","description":"Name of a tag which must *not* be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"contains","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value contains ``. Tag filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value ends with ``. Tag filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value is ``. Tag filters are case-insensitive.\n"},{"name":"present","type":"String","description":"Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value starts with ``. Tag filters are case-insensitive.\n"}]},{"name":"tag_match","type":"String","description":"Whether to match all tag search requirements or at least one (any). If set to `all`, acts like a logical AND between tag filters. If set to `any`, acts like a logical OR instead. Note that the regular `match` parameter is still used to combine the resulting condition with other filters that aren't related to tags.\n"},{"name":"type","type":"String","description":"Record type."}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"comment","type":"String","description":"Comments or notes about the DNS record. This field has no effect on DNS responses."},{"name":"comment_modified_on","type":"Time","description":"When the record comment was last modified. Omitted if there is no comment."},{"name":"content","type":"String","description":"A valid IPv4 address."},{"name":"created_on","type":"Time","description":"When the record was created."},{"name":"modified_on","type":"Time","description":"When the record was last modified."},{"name":"name","type":"String","description":"Complete DNS record name, including the zone name, in Punycode."},{"name":"priority","type":"Float64","description":"Required for MX and URI records; ignored for other record types (but may still be returned by the API). Records with lower priorities are preferred. This field is to be deprecated in favor of the priority field within the data map."},{"name":"private_routing","type":"Bool","description":"Enables private network routing to the origin."},{"name":"proxiable","type":"Bool","description":"Whether the record can be proxied by Cloudflare or not."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"tags_modified_on","type":"Time","description":"When the record tags were last modified. Omitted if there are no tags."},{"name":"ttl","type":"Float64","description":"Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterprise zones."},{"name":"type","type":"String","description":"Record type."},{"name":"tags","type":"Set[String]","description":"Custom tags for the DNS record. This field has no effect on DNS responses."},{"name":"data","type":"Attributes","description":"Components of a CAA record.","children":[{"name":"flags","type":"Dynamic Float64 | String","description":"Flags for the CAA record."},{"name":"tag","type":"String","description":"Name of the property controlled by this record (e.g.: issue, issuewild, iodef)."},{"name":"value","type":"String","description":"Value of the record. This field's semantics depend on the chosen tag."},{"name":"algorithm","type":"Float64","description":"Algorithm."},{"name":"certificate","type":"String","description":"Certificate."},{"name":"key_tag","type":"Float64","description":"Key Tag."},{"name":"type","type":"Float64","description":"Type."},{"name":"protocol","type":"Float64","description":"Protocol."},{"name":"public_key","type":"String","description":"Public Key."},{"name":"digest","type":"String","description":"Digest."},{"name":"digest_type","type":"Float64","description":"Digest Type."},{"name":"priority","type":"Float64","description":"Priority."},{"name":"target","type":"String","description":"Target."},{"name":"altitude","type":"Float64","description":"Altitude of location in meters."},{"name":"lat_degrees","type":"Float64","description":"Degrees of latitude."},{"name":"lat_direction","type":"String","description":"Latitude direction."},{"name":"lat_minutes","type":"Float64","description":"Minutes of latitude."},{"name":"lat_seconds","type":"Float64","description":"Seconds of latitude."},{"name":"long_degrees","type":"Float64","description":"Degrees of longitude."},{"name":"long_direction","type":"String","description":"Longitude direction."},{"name":"long_minutes","type":"Float64","description":"Minutes of longitude."},{"name":"long_seconds","type":"Float64","description":"Seconds of longitude."},{"name":"precision_horz","type":"Float64","description":"Horizontal precision of location."},{"name":"precision_vert","type":"Float64","description":"Vertical precision of location."},{"name":"size","type":"Float64","description":"Size of location in meters."},{"name":"order","type":"Float64","description":"Order."},{"name":"preference","type":"Float64","description":"Preference."},{"name":"regex","type":"String","description":"Regex."},{"name":"replacement","type":"String","description":"Replacement."},{"name":"service","type":"String","description":"Service."},{"name":"matching_type","type":"Float64","description":"Matching Type."},{"name":"selector","type":"Float64","description":"Selector."},{"name":"usage","type":"Float64","description":"Usage."},{"name":"port","type":"Float64","description":"The port of the service."},{"name":"weight","type":"Float64","description":"The record weight."},{"name":"fingerprint","type":"String","description":"Fingerprint."}]},{"name":"meta","type":"Attributes","description":"Extra Cloudflare-specific metadata about the record.","children":[{"name":"dead_glue","type":"Bool","description":"Whether this glue record is not served because a shallower NS delegation takes precedence over the deeper delegation that needs it. Present only when true; reachable glue carries only `is_glue`. See [Unreachable glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#unreachable-glue-records).\n"},{"name":"is_glue","type":"Bool","description":"Whether this A or AAAA record is glue for a subdomain NS delegation. See [Glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#glue-records).\n"},{"name":"shadowed_by","type":"List[String]","description":"IDs of the NS records that shadow this record. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowed_records_count","type":"Int64","description":"Number of records shadowed by this NS delegation. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"}]},{"name":"settings","type":"Attributes","description":"Settings for the DNS record.","children":[{"name":"ipv4_only","type":"Bool","description":"When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"ipv6_only","type":"Bool","description":"When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"flatten_cname","type":"Bool","description":"If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened."}]}]}]},"get /zones/{}/dnssec":{"operationId":"dnssec-dnssec-details","declarations":[{"kind":"data-source","name":"cloudflare_zone_dnssec","stainlessResource":"dns.dnssec","methodName":"get","snippet":"data \"cloudflare_zone_dnssec\" \"example_zone_dnssec\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"algorithm","type":"String","description":"Algorithm key code."},{"name":"digest","type":"String","description":"Digest hash."},{"name":"digest_algorithm","type":"String","description":"Type of digest algorithm."},{"name":"digest_type","type":"String","description":"Coded type for digest algorithm."},{"name":"dnssec_multi_signer","type":"Bool","description":"If true, multi-signer DNSSEC is enabled on the zone, allowing multiple\nproviders to serve a DNSSEC-signed zone at the same time.\nThis is required for DNSKEY records (except those automatically\ngenerated by Cloudflare) to be added to the zone.\n\nSee [Multi-signer DNSSEC](https://developers.cloudflare.com/dns/dnssec/multi-signer-dnssec/) for details."},{"name":"dnssec_presigned","type":"Bool","description":"If true, allows Cloudflare to transfer in a DNSSEC-signed zone\nincluding signatures from an external provider, without requiring\nCloudflare to sign any records on the fly.\n\nNote that this feature has some limitations.\nSee [Cloudflare as Secondary](https://developers.cloudflare.com/dns/zone-setups/zone-transfers/cloudflare-as-secondary/setup/#dnssec) for details."},{"name":"dnssec_use_nsec3","type":"Bool","description":"If true, enables the use of NSEC3 together with DNSSEC on the zone.\nCombined with setting dnssec_presigned to true, this enables the use of\nNSEC3 records when transferring in from an external provider.\nIf dnssec_presigned is instead set to false (default), NSEC3 records will be\ngenerated and signed at request time.\n\nSee [DNSSEC with NSEC3](https://developers.cloudflare.com/dns/dnssec/enable-nsec3/) for details."},{"name":"ds","type":"String","description":"Full DS record."},{"name":"flags","type":"Float64","description":"Flag for DNSSEC record."},{"name":"key_tag","type":"Float64","description":"Code for key tag."},{"name":"key_type","type":"String","description":"Algorithm key type."},{"name":"modified_on","type":"Time","description":"When DNSSEC was last modified."},{"name":"public_key","type":"String","description":"Public key for DS record."},{"name":"status","type":"String","description":"Status of DNSSEC, based on user-desired state and presence of necessary records."}]}]},"get /zones/{}/email/routing":{"operationId":"email-routing-settings-get-email-routing-settings","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_settings","stainlessResource":"email_routing","methodName":"get","snippet":"data \"cloudflare_email_routing_settings\" \"example_email_routing_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created","type":"Time","description":"The date and time the settings have been created."},{"name":"enabled","type":"Bool","description":"State of the zone settings for Email Routing."},{"name":"modified","type":"Time","description":"The date and time the settings have been modified."},{"name":"name","type":"String","description":"Domain of your zone."},{"name":"skip_wizard","type":"Bool","description":"Flag to check if the user skipped the configuration wizard."},{"name":"status","type":"String","description":"Show the state of your account, and the type or configuration error."},{"name":"support_subaddress","type":"Bool","description":"Whether subaddressing (plus-addressing) is honored when matching incoming mail against routing rules."},{"name":"tag","type":"String","description":"Email Routing settings tag. (Deprecated, replaced by Email Routing settings identifier)","deprecated":"Deprecated."}]}]},"get /zones/{}/email/routing/dns":{"operationId":"email-routing-settings-email-routing-dns-settings","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_dns","stainlessResource":"email_routing.dns","methodName":"get","snippet":"data \"cloudflare_email_routing_dns\" \"example_email_routing_dns\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n subdomain = \"example.net\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"subdomain","type":"String","description":"Deprecated. When supplied, the response shape differs from the documented default and is not modeled in generated SDKs. Do not rely on this parameter."}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"dns","type":"List[Attributes]","children":[{"name":"content","type":"String","description":"DNS record content."},{"name":"name","type":"String","description":"DNS record name (or @ for the zone apex)."},{"name":"priority","type":"Float64","description":"Required for MX, SRV and URI records. Unused by other record types. Records with lower priorities are preferred."},{"name":"ttl","type":"Float64","description":"Time to live, in seconds, of the DNS record. Must be between 60 and 86400, or 1 for 'automatic'."},{"name":"type","type":"String","description":"DNS record type."}]}]}]},"get /zones/{}/email/routing/rules/{}":{"operationId":"email-routing-routing-rules-get-routing-rule","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_rule","stainlessResource":"email_routing.rules","methodName":"get","snippet":"data \"cloudflare_email_routing_rule\" \"example_email_routing_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_identifier = \"a7e6fb77503c41d8a7f3113c6918f10c\"\n}\n","required":[{"name":"rule_identifier","type":"String","description":"Routing rule identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Routing rule identifier."},{"name":"enabled","type":"Bool","description":"Routing rule status."},{"name":"name","type":"String","description":"Routing rule name."},{"name":"priority","type":"Float64","description":"Priority of the routing rule."},{"name":"source","type":"String","description":"Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\n"},{"name":"tag","type":"String","description":"Routing rule tag. (Deprecated, replaced by routing rule identifier)","deprecated":"Deprecated."},{"name":"actions","type":"List[Attributes]","description":"List actions patterns.","children":[{"name":"type","type":"String","description":"Type of supported action."},{"name":"value","type":"List[String]","description":"List of values for the action. Currently limited to a single value."}]},{"name":"matchers","type":"List[Attributes]","description":"Matching patterns to forward to your actions.","children":[{"name":"type","type":"String","description":"Type of matcher."},{"name":"field","type":"String","description":"Field for type matcher."},{"name":"value","type":"String","description":"Value for matcher."}]}]}]},"get /zones/{}/email/routing/rules/catch_all":{"operationId":"email-routing-routing-rules-get-catch-all-rule","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_catch_all","stainlessResource":"email_routing.rules.catch_alls","methodName":"get","snippet":"data \"cloudflare_email_routing_catch_all\" \"example_email_routing_catch_all\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Routing rule status."},{"name":"name","type":"String","description":"Routing rule name."},{"name":"source","type":"String","description":"Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\n"},{"name":"tag","type":"String","description":"Routing rule tag. (Deprecated, replaced by routing rule identifier)","deprecated":"Deprecated."},{"name":"actions","type":"List[Attributes]","description":"List actions for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of action for catch-all rule."},{"name":"value","type":"List[String]","description":"List of values for the action. Currently limited to a single value."}]},{"name":"matchers","type":"List[Attributes]","description":"List of matchers for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of matcher. Default is 'all'."}]}]}]},"get /zones/{}/email/sending/subdomains":{"operationId":"email-sending-subdomains-list-sending-subdomains","declarations":[{"kind":"list-data-source","name":"cloudflare_email_sending_subdomains","stainlessResource":"email_sending.subdomains","methodName":"list","snippet":"data \"cloudflare_email_sending_subdomains\" \"example_email_sending_subdomains\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Sending subdomain identifier."},{"name":"enabled","type":"Bool","description":"Whether Email Sending is enabled on this subdomain."},{"name":"name","type":"String","description":"The exact domain name or a leftmost wildcard such as `*.example.com`."},{"name":"tag","type":"String","description":"Sending subdomain identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"dkim_selector","type":"String","description":"The DKIM selector used for email signing. Wildcard rows publish the selector and sign with `d=`."},{"name":"drop_suppressed_recipients","type":"Bool","description":"Whether a send request that includes a recipient suppressed on\nthis subdomain drops that recipient and still delivers to the\nrest, instead of failing the entire request.\n"},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"preview_enabled","type":"Bool","description":"Whether sent messages from this subdomain can be previewed in the activity log."},{"name":"return_path_domain","type":"String","description":"The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`."}]}]}]},"get /zones/{}/email/sending/subdomains/{}":{"operationId":"email-sending-subdomains-get-sending-subdomain","declarations":[{"kind":"data-source","name":"cloudflare_email_sending_subdomain","stainlessResource":"email_sending.subdomains","methodName":"get","snippet":"data \"cloudflare_email_sending_subdomain\" \"example_email_sending_subdomain\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n subdomain_id = \"aabbccdd11223344aabbccdd11223344\"\n}\n","required":[{"name":"subdomain_id","type":"String","description":"Sending subdomain identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Sending subdomain identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"dkim_selector","type":"String","description":"The DKIM selector used for email signing. Wildcard rows publish the selector and sign with `d=`."},{"name":"drop_suppressed_recipients","type":"Bool","description":"Whether a send request that includes a recipient suppressed on\nthis subdomain drops that recipient and still delivers to the\nrest, instead of failing the entire request.\n"},{"name":"enabled","type":"Bool","description":"Whether Email Sending is enabled on this subdomain."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"name","type":"String","description":"The exact domain name or a leftmost wildcard such as `*.example.com`."},{"name":"preview_enabled","type":"Bool","description":"Whether sent messages from this subdomain can be previewed in the activity log."},{"name":"return_path_domain","type":"String","description":"The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`."},{"name":"tag","type":"String","description":"Sending subdomain identifier."}]}]},"get /zones/{}/filters":{"operationId":"filters-list-filters","declarations":[{"kind":"list-data-source","name":"cloudflare_filters","stainlessResource":"filters","methodName":"list","snippet":"data \"cloudflare_filters\" \"example_filters\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"372e67954025e0ba6aaa6d586b9e0b61\"\n description = \"browsers\"\n expression = \"php\"\n paused = false\n ref = \"FIL-100\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"description","type":"String","description":"A case-insensitive string to find in the description."},{"name":"expression","type":"String","description":"A case-insensitive string to find in the expression."},{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"The filter ref (a short reference tag) to search for. Must be an exact match."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}]}]},"get /zones/{}/filters/{}":{"operationId":"filters-get-a-filter","declarations":[{"kind":"data-source","name":"cloudflare_filter","stainlessResource":"filters","methodName":"get","snippet":"data \"cloudflare_filter\" \"example_filter\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n filter_id = \"372e67954025e0ba6aaa6d586b9e0b61\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"filter_id","type":"String","description":"The unique identifier of the filter."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"A case-insensitive string to find in the description."},{"name":"expression","type":"String","description":"A case-insensitive string to find in the expression."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"The filter ref (a short reference tag) to search for. Must be an exact match."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}]},"get /zones/{}/firewall/lockdowns":{"operationId":"zone-lockdown-list-zone-lockdown-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zone_lockdowns","stainlessResource":"firewall.lockdowns","methodName":"list","snippet":"data \"cloudflare_zone_lockdowns\" \"example_zone_lockdowns\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_on = \"2014-01-01T05:20:00.12345Z\"\n description = \"endpoints\"\n description_search = \"endpoints\"\n ip = \"1.2.3.4\"\n ip_range_search = \"1.2.3.0/16\"\n ip_search = \"1.2.3.4\"\n modified_on = \"2014-01-01T05:20:00.12345Z\"\n priority = 5\n uri_search = \"/some/path\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"description_search","type":"String","description":"A string to search for in the description of existing rules."},{"name":"ip","type":"String","description":"A single IP address to search for in existing rules."},{"name":"ip_range_search","type":"String","description":"A single IP address range to search for in existing rules."},{"name":"ip_search","type":"String","description":"A single IP address to search for in existing rules."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"priority","type":"Float64","description":"The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority."},{"name":"uri_search","type":"String","description":"A single URI to search for in the list of URLs of existing rules."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"configurations","type":"List[Attributes]","description":"A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule."},{"name":"value","type":"String","description":"The IP address to match. This address will be compared to the IP address of incoming requests."}]},{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"urls","type":"Set[String]","description":"The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns."}]}]}]},"get /zones/{}/firewall/lockdowns/{}":{"operationId":"zone-lockdown-get-a-zone-lockdown-rule","declarations":[{"kind":"data-source","name":"cloudflare_zone_lockdown","stainlessResource":"firewall.lockdowns","methodName":"get","snippet":"data \"cloudflare_zone_lockdown\" \"example_zone_lockdown\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lock_downs_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"lock_downs_id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"filter","type":"Attributes","children":[{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"description_search","type":"String","description":"A string to search for in the description of existing rules."},{"name":"ip","type":"String","description":"A single IP address to search for in existing rules."},{"name":"ip_range_search","type":"String","description":"A single IP address range to search for in existing rules."},{"name":"ip_search","type":"String","description":"A single IP address to search for in existing rules."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"priority","type":"Float64","description":"The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority."},{"name":"uri_search","type":"String","description":"A single URI to search for in the list of URLs of existing rules."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"urls","type":"Set[String]","description":"The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns."},{"name":"configurations","type":"List[Attributes]","description":"A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule."},{"name":"value","type":"String","description":"The IP address to match. This address will be compared to the IP address of incoming requests."}]}]}]},"get /zones/{}/firewall/rules":{"operationId":"firewall-rules-list-firewall-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_firewall_rules","stainlessResource":"firewall.rules","methodName":"list","snippet":"data \"cloudflare_firewall_rules\" \"example_firewall_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"372e67954025e0ba6aaa6d586b9e0b60\"\n action = \"block\"\n description = \"mir\"\n paused = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"action","type":"String","description":"The action to search for. Must be an exact match."},{"name":"description","type":"String","description":"A case-insensitive string to find in the description."},{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"action","type":"String","description":"The action to apply to a matched request. The `log` action is only available on an Enterprise plan."},{"name":"description","type":"String","description":"An informative summary of the firewall rule."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."},{"name":"deleted","type":"Bool","description":"When true, indicates that the firewall rule was deleted."}]},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"priority","type":"Float64","description":"The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority."},{"name":"products","type":"List[String]"},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related firewall rules."}]}]}]},"get /zones/{}/firewall/rules/{}":{"operationId":"firewall-rules-get-a-firewall-rule","declarations":[{"kind":"data-source","name":"cloudflare_firewall_rule","stainlessResource":"firewall.rules","methodName":"get","snippet":"data \"cloudflare_firewall_rule\" \"example_firewall_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_id = \"372e67954025e0ba6aaa6d586b9e0b60\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"rule_id","type":"String","description":"The unique identifier of the firewall rule."}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"action","type":"String","description":"The action to apply to a matched request. The `log` action is only available on an Enterprise plan."},{"name":"description","type":"String","description":"An informative summary of the firewall rule."},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"priority","type":"Float64","description":"The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related firewall rules."},{"name":"products","type":"List[String]"}]}]},"get /zones/{}/firewall/ua_rules":{"operationId":"user-agent-blocking-rules-list-user-agent-blocking-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_user_agent_blocking_rules","stainlessResource":"firewall.ua_rules","methodName":"list","snippet":"data \"cloudflare_user_agent_blocking_rules\" \"example_user_agent_blocking_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n description = \"abusive\"\n paused = false\n user_agent = \"Safari\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"user_agent","type":"String","description":"A string to search for in the user agent values of existing rules."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the User Agent Blocking rule."},{"name":"configuration","type":"Attributes","description":"The configuration object for the current rule.","children":[{"name":"target","type":"String","description":"The configuration target for this rule. You must set the target to `ua` for User Agent Blocking rules."},{"name":"value","type":"String","description":"The exact user agent string to match. This value will be compared to the received `User-Agent` HTTP header value."}]},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"mode","type":"String","description":"The action to apply to a matched request."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."}]}]}]},"get /zones/{}/firewall/ua_rules/{}":{"operationId":"user-agent-blocking-rules-get-a-user-agent-blocking-rule","declarations":[{"kind":"data-source","name":"cloudflare_user_agent_blocking_rule","stainlessResource":"firewall.ua_rules","methodName":"get","snippet":"data \"cloudflare_user_agent_blocking_rule\" \"example_user_agent_blocking_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ua_rule_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"ua_rule_id","type":"String","description":"The unique identifier of the User Agent Blocking rule."},{"name":"filter","type":"Attributes","children":[{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"user_agent","type":"String","description":"A string to search for in the user agent values of existing rules."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the User Agent Blocking rule."},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"mode","type":"String","description":"The action to apply to a matched request."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"configuration","type":"Attributes","description":"The configuration object for the current rule.","children":[{"name":"target","type":"String","description":"The configuration target for this rule. You must set the target to `ua` for User Agent Blocking rules."},{"name":"value","type":"String","description":"The exact user agent string to match. This value will be compared to the received `User-Agent` HTTP header value."}]}]}]},"get /zones/{}/healthchecks":{"operationId":"health-checks-list-health-checks","declarations":[{"kind":"list-data-source","name":"cloudflare_healthchecks","stainlessResource":"healthchecks","methodName":"list","snippet":"data \"cloudflare_healthchecks\" \"example_healthchecks\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"address","type":"String","description":"The hostname or IP address of the origin server to run health checks on."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means Cloudflare will pick a default region."},{"name":"consecutive_fails","type":"Int64","description":"The number of consecutive fails required from a health check before changing the health to unhealthy."},{"name":"consecutive_successes","type":"Int64","description":"The number of consecutive successes required from a health check before changing the health to healthy."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-readable description of the health check."},{"name":"failure_reason","type":"String","description":"The current failure reason if status is unhealthy."},{"name":"http_config","type":"Attributes","description":"Parameters specific to an HTTP or HTTPS health check.","children":[{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when the health check uses HTTPS."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy."},{"name":"expected_codes","type":"List[String]","description":"The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if the origin returns a 3xx status code."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden."},{"name":"method","type":"String","description":"The HTTP method to use for the health check."},{"name":"path","type":"String","description":"The endpoint path to health check against."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS."}]},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"status","type":"String","description":"The current status of the origin server according to the health check."},{"name":"suspended","type":"Bool","description":"If suspended, no health checks are sent to the origin."},{"name":"tcp_config","type":"Attributes","description":"Parameters specific to TCP health check.","children":[{"name":"method","type":"String","description":"The TCP connection method to use for the health check."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80."}]},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'."}]}]}]},"get /zones/{}/healthchecks/{}":{"operationId":"health-checks-health-check-details","declarations":[{"kind":"data-source","name":"cloudflare_healthcheck","stainlessResource":"healthchecks","methodName":"get","snippet":"data \"cloudflare_healthcheck\" \"example_healthcheck\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n healthcheck_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"healthcheck_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"address","type":"String","description":"The hostname or IP address of the origin server to run health checks on."},{"name":"consecutive_fails","type":"Int64","description":"The number of consecutive fails required from a health check before changing the health to unhealthy."},{"name":"consecutive_successes","type":"Int64","description":"The number of consecutive successes required from a health check before changing the health to healthy."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-readable description of the health check."},{"name":"failure_reason","type":"String","description":"The current failure reason if status is unhealthy."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"status","type":"String","description":"The current status of the origin server according to the health check."},{"name":"suspended","type":"Bool","description":"If suspended, no health checks are sent to the origin."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means Cloudflare will pick a default region."},{"name":"http_config","type":"Attributes","description":"Parameters specific to an HTTP or HTTPS health check.","children":[{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when the health check uses HTTPS."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy."},{"name":"expected_codes","type":"List[String]","description":"The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if the origin returns a 3xx status code."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden."},{"name":"method","type":"String","description":"The HTTP method to use for the health check."},{"name":"path","type":"String","description":"The endpoint path to health check against."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS."}]},{"name":"tcp_config","type":"Attributes","description":"Parameters specific to TCP health check.","children":[{"name":"method","type":"String","description":"The TCP connection method to use for the health check."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80."}]}]}]},"get /zones/{}/hold":{"operationId":"zones-0-hold-get","declarations":[{"kind":"data-source","name":"cloudflare_zone_hold","stainlessResource":"zones.holds","methodName":"get","snippet":"data \"cloudflare_zone_hold\" \"example_zone_hold\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"hold","type":"Bool"},{"name":"hold_after","type":"String"},{"name":"include_subdomains","type":"String"}]}]},"get /zones/{}/hostnames/settings/{}":{"operationId":"per-hostname-tls-settings-list","declarations":[{"kind":"list-data-source","name":"cloudflare_hostname_tls_settings","stainlessResource":"hostnames.settings.tls","methodName":"list","snippet":"data \"cloudflare_hostname_tls_settings\" \"example_hostname_tls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n}\n","required":[{"name":"setting_id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created_at","type":"Time","description":"This is the time the tls setting was originally created for this hostname."},{"name":"hostname","type":"String","description":"The hostname for which the tls settings are set."},{"name":"status","type":"String","description":"Deployment status for the given tls setting."},{"name":"updated_at","type":"Time","description":"This is the time the tls setting was updated."},{"name":"value","type":"String","description":"The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`)."}]}]}]},"get /zones/{}/hostnames/settings/{}/{}":{"operationId":"per-hostname-tls-settings-get","declarations":[{"kind":"data-source","name":"cloudflare_hostname_tls_setting","stainlessResource":"hostnames.settings.tls","methodName":"get","snippet":"data \"cloudflare_hostname_tls_setting\" \"example_hostname_tls_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n hostname = \"app.example.com\"\n}\n","required":[{"name":"hostname","type":"String","description":"The hostname for which the tls settings are set."},{"name":"setting_id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"created_at","type":"Time","description":"This is the time the tls setting was originally created for this hostname."},{"name":"status","type":"String","description":"Deployment status for the given tls setting."},{"name":"updated_at","type":"Time","description":"This is the time the tls setting was updated."},{"name":"value","type":"String","description":"The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`)."}]}]},"get /zones/{}/keyless_certificates":{"operationId":"keyless-ssl-for-a-zone-list-keyless-ssl-configurations","declarations":[{"kind":"list-data-source","name":"cloudflare_keyless_certificates","stainlessResource":"keyless_certificates","methodName":"list","snippet":"data \"cloudflare_keyless_certificates\" \"example_keyless_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]}]}]},"get /zones/{}/keyless_certificates/{}":{"operationId":"keyless-ssl-for-a-zone-get-keyless-ssl-configuration","declarations":[{"kind":"data-source","name":"cloudflare_keyless_certificate","stainlessResource":"keyless_certificates","methodName":"get","snippet":"data \"cloudflare_keyless_certificate\" \"example_keyless_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n keyless_certificate_id = \"4d2844d2ce78891c34d0b6c0535a291e\"\n}\n","required":[{"name":"keyless_certificate_id","type":"String","description":"Keyless certificate identifier tag."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]}]},"get /zones/{}/leaked-credential-checks":{"operationId":"waf-product-api-leaked-credentials-get-status","declarations":[{"kind":"data-source","name":"cloudflare_leaked_credential_check","stainlessResource":"leaked_credential_checks","methodName":"get","snippet":"data \"cloudflare_leaked_credential_check\" \"example_leaked_credential_check\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"Determines whether or not Leaked Credential Checks are enabled."}]}]},"get /zones/{}/leaked-credential-checks/detections":{"operationId":"waf-product-api-leaked-credentials-list-detections","declarations":[{"kind":"list-data-source","name":"cloudflare_leaked_credential_check_rules","stainlessResource":"leaked_credential_checks.detections","methodName":"list","snippet":"data \"cloudflare_leaked_credential_check_rules\" \"example_leaked_credential_check_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Defines the unique ID for this custom detection."},{"name":"password","type":"String","description":"Defines ehe ruleset expression to use in matching the password in a request."},{"name":"username","type":"String","description":"Defines the ruleset expression to use in matching the username in a request."}]}]}]},"get /zones/{}/leaked-credential-checks/detections/{}":{"operationId":"waf-product-api-leaked-credentials-get-detection","declarations":[{"kind":"data-source","name":"cloudflare_leaked_credential_check_rule","stainlessResource":"leaked_credential_checks.detections","methodName":"get","snippet":"data \"cloudflare_leaked_credential_check_rule\" \"example_leaked_credential_check_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n detection_id = \"18a14bafaa8eb1df04ce683ec18c765e\"\n}\n","required":[{"name":"detection_id","type":"String","description":"Defines the unique ID for this custom detection."},{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Defines the unique ID for this custom detection."},{"name":"password","type":"String","description":"Defines ehe ruleset expression to use in matching the password in a request."},{"name":"username","type":"String","description":"Defines the ruleset expression to use in matching the username in a request."}]}]},"get /zones/{}/logs/control/retention/flag":{"operationId":"get-zones-zone_id-logs-control-retention-flag","declarations":[{"kind":"data-source","name":"cloudflare_logpull_retention","stainlessResource":"logs.control.retention","methodName":"get","snippet":"data \"cloudflare_logpull_retention\" \"example_logpull_retention\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"flag","type":"Bool","description":"The log retention flag for Logpull API."}]}]},"get /zones/{}/managed_headers":{"operationId":"listManagedTransforms","declarations":[{"kind":"data-source","name":"cloudflare_managed_transforms","stainlessResource":"managed_transforms","methodName":"list","snippet":"data \"cloudflare_managed_transforms\" \"example_managed_transforms\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone."},{"name":"managed_request_headers","type":"List[Attributes]","description":"The list of Managed Request Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]},{"name":"managed_response_headers","type":"List[Attributes]","description":"The list of Managed Response Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]}]}]},"get /zones/{}/observability/tracing/rules":{"operationId":"zone.observability.tracing.rules.get","declarations":[{"kind":"data-source","name":"cloudflare_zone_tracing_rules","stainlessResource":"zones.observability.tracing.rules","methodName":"get","snippet":"data \"cloudflare_zone_tracing_rules\" \"example_zone_tracing_rules\" {\n zone_id = \"zone_id\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the zone ID."},{"name":"rules","type":"List[Attributes]","description":"Trace rules in evaluation order.","children":[{"name":"action","type":"String"},{"name":"action_parameters","type":"Attributes","children":[{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."}]},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String","description":"A Rules language expression that selects requests."}]}]}]},"get /zones/{}/observability/tracing/settings":{"operationId":"zone.observability.tracing.settings.get","declarations":[{"kind":"data-source","name":"cloudflare_zone_tracing","stainlessResource":"zones.observability.tracing.settings","methodName":"get","snippet":"data \"cloudflare_zone_tracing\" \"example_zone_tracing\" {\n zone_id = \"zone_id\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the zone ID."},{"name":"enabled","type":"Bool","description":"Whether Cloudflare Traces is enabled for the zone."},{"name":"forward_context","type":"Bool","description":"Whether trace context is sent externally or across a zone boundary."},{"name":"persist","type":"Bool","description":"Whether traces are persisted in Cloudflare."},{"name":"propagation_policy","type":"String","description":"When inbound trace context may be continued. Authenticated propagation is not supported yet."},{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."},{"name":"destinations","type":"List[String]","description":"Up to 100 OpenTelemetry destination identifiers that receive traces."}]}]},"get /zones/{}/origin_tls_client_auth/settings":{"operationId":"zone-level-authenticated-origin-pulls-get-enablement-setting-for-zone","declarations":[{"kind":"data-source","name":"cloudflare_authenticated_origin_pulls_settings","stainlessResource":"origin_tls_client_auth.settings","methodName":"get","snippet":"data \"cloudflare_authenticated_origin_pulls_settings\" \"example_authenticated_origin_pulls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Indicates whether zone-level authenticated origin pulls is enabled."}]}]},"get /zones/{}/origin/cloud_regions":{"operationId":"origin-cloud-regions-v2-list","declarations":[{"kind":"list-data-source","name":"cloudflare_origin_cloud_regions","stainlessResource":"cache.origin_cloud_regions","methodName":"list","snippet":"data \"cloudflare_origin_cloud_regions\" \"example_origin_cloud_regions\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The origin IP address (IPv4 or IPv6). Normalized to canonical form (RFC 5952 for IPv6)."},{"name":"origin_ip","type":"String","description":"The origin IP address (IPv4 or IPv6). Normalized to canonical form (RFC 5952 for IPv6)."},{"name":"region","type":"String","description":"Cloud vendor region identifier."},{"name":"vendor","type":"String","description":"Cloud vendor hosting the origin."},{"name":"modified_on","type":"Time","description":"Time this mapping was last modified."}]}]}]},"get /zones/{}/origin/cloud_regions/{}":{"operationId":"origin-cloud-regions-v2-get","declarations":[{"kind":"data-source","name":"cloudflare_origin_cloud_region","stainlessResource":"cache.origin_cloud_regions","methodName":"get","snippet":"data \"cloudflare_origin_cloud_region\" \"example_origin_cloud_region\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin_ip = \"192.0.2.1\"\n}\n","required":[{"name":"origin_ip","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"modified_on","type":"Time","description":"Time this mapping was last modified."},{"name":"region","type":"String","description":"Cloud vendor region identifier."},{"name":"vendor","type":"String","description":"Cloud vendor hosting the origin."}]}]},"get /zones/{}/page_shield/connections":{"operationId":"page-shield-list-connections","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_connections_list","stainlessResource":"page_shield.connections","methodName":"list","snippet":"data \"cloudflare_page_shield_connections_list\" \"example_page_shield_connections_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n exclude_cdn_cgi = true\n exclude_urls = \"blog.cloudflare.com,www.example\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n per_page = 100\n prioritize_malicious = true\n status = \"active,inactive\"\n urls = \"blog.cloudflare.com,www.example\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"The direction used to sort returned connections."},{"name":"exclude_cdn_cgi","type":"Bool","description":"When true, excludes connections seen in a `/cdn-cgi` path from the returned connections. The default value is true."},{"name":"exclude_urls","type":"String","description":"Excludes connections whose URL contains one of the URL-encoded URLs separated by commas.\n"},{"name":"export","type":"String","description":"Export the list of connections as a file, limited to 50000 entries."},{"name":"hosts","type":"String","description":"Includes connections that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"order_by","type":"String","description":"The field used to sort returned connections."},{"name":"page","type":"String","description":"The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the connections\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of connections\n"},{"name":"page_url","type":"String","description":"Includes connections that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"per_page","type":"Float64","description":"The number of results per page."},{"name":"prioritize_malicious","type":"Bool","description":"When true, malicious connections appear first in the returned connections."},{"name":"status","type":"String","description":"Filters the returned connections using a comma-separated list of connection statuses. Accepted values: `active`, `infrequent`, and `inactive`. The default value is `active`."},{"name":"urls","type":"String","description":"Includes connections whose URL contain one or more URL-encoded URLs separated by commas.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"added_at","type":"Time"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"last_seen_at","type":"Time"},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"domain_reported_malicious","type":"Bool"},{"name":"first_page_url","type":"String"},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"page_urls","type":"List[String]"},{"name":"url_reported_malicious","type":"Bool"}]}]}]},"get /zones/{}/page_shield/connections/{}":{"operationId":"page-shield-get-connection","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_connections","stainlessResource":"page_shield.connections","methodName":"get","snippet":"data \"cloudflare_page_shield_connections\" \"example_page_shield_connections\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connection_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"connection_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"added_at","type":"Time"},{"name":"domain_reported_malicious","type":"Bool"},{"name":"first_page_url","type":"String"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"id","type":"String","description":"Identifier"},{"name":"last_seen_at","type":"Time"},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"url_reported_malicious","type":"Bool"},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"page_urls","type":"List[String]"}]}]},"get /zones/{}/page_shield/cookies":{"operationId":"page-shield-list-cookies","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_cookies_list","stainlessResource":"page_shield.cookies","methodName":"list","snippet":"data \"cloudflare_page_shield_cookies_list\" \"example_page_shield_cookies_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n domain = \"example.com\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n http_only = true\n name = \"session_id\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n path = \"/\"\n per_page = 100\n same_site = \"strict\"\n secure = true\n type = \"first_party\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"The direction used to sort returned cookies.'"},{"name":"domain","type":"String","description":"Filters the returned cookies that match the specified domain attribute"},{"name":"export","type":"String","description":"Export the list of cookies as a file, limited to 50000 entries."},{"name":"hosts","type":"String","description":"Includes cookies that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"http_only","type":"Bool","description":"Filters the returned cookies that are set with HttpOnly"},{"name":"name","type":"String","description":"Filters the returned cookies that match the specified name.\nWildcards are supported at the start and end to support starts with, ends with\nand contains. e.g. session*\n"},{"name":"order_by","type":"String","description":"The field used to sort returned cookies."},{"name":"page","type":"String","description":"The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the cookies\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of cookies\n"},{"name":"page_url","type":"String","description":"Includes connections that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"path","type":"String","description":"Filters the returned cookies that match the specified path attribute"},{"name":"per_page","type":"Float64","description":"The number of results per page."},{"name":"same_site","type":"String","description":"Filters the returned cookies that match the specified same_site attribute"},{"name":"secure","type":"Bool","description":"Filters the returned cookies that are set with Secure"},{"name":"type","type":"String","description":"Filters the returned cookies that match the specified type attribute"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"last_seen_at","type":"Time"},{"name":"name","type":"String"},{"name":"type","type":"String"},{"name":"domain_attribute","type":"String"},{"name":"expires_attribute","type":"Time"},{"name":"http_only_attribute","type":"Bool"},{"name":"max_age_attribute","type":"Int64"},{"name":"page_urls","type":"List[String]"},{"name":"path_attribute","type":"String"},{"name":"same_site_attribute","type":"String"},{"name":"secure_attribute","type":"Bool"}]}]}]},"get /zones/{}/page_shield/cookies/{}":{"operationId":"page-shield-get-cookie","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_cookies","stainlessResource":"page_shield.cookies","methodName":"get","snippet":"data \"cloudflare_page_shield_cookies\" \"example_page_shield_cookies\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cookie_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"cookie_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"domain_attribute","type":"String"},{"name":"expires_attribute","type":"Time"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"http_only_attribute","type":"Bool"},{"name":"id","type":"String","description":"Identifier"},{"name":"last_seen_at","type":"Time"},{"name":"max_age_attribute","type":"Int64"},{"name":"name","type":"String"},{"name":"path_attribute","type":"String"},{"name":"same_site_attribute","type":"String"},{"name":"secure_attribute","type":"Bool"},{"name":"type","type":"String"},{"name":"page_urls","type":"List[String]"}]}]},"get /zones/{}/page_shield/policies":{"operationId":"page-shield-list-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_policies","stainlessResource":"page_shield.policies","methodName":"list","snippet":"data \"cloudflare_page_shield_policies\" \"example_page_shield_policies\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"action","type":"String","description":"The action to take if the expression matches"},{"name":"description","type":"String","description":"A description for the policy"},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled"},{"name":"expression","type":"String","description":"The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax"},{"name":"value","type":"String","description":"The policy which will be applied"}]}]}]},"get /zones/{}/page_shield/policies/{}":{"operationId":"page-shield-get-policy","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_policy","stainlessResource":"page_shield.policies","methodName":"get","snippet":"data \"cloudflare_page_shield_policy\" \"example_page_shield_policy\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"policy_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"action","type":"String","description":"The action to take if the expression matches"},{"name":"description","type":"String","description":"A description for the policy"},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled"},{"name":"expression","type":"String","description":"The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax"},{"name":"value","type":"String","description":"The policy which will be applied"}]}]},"get /zones/{}/page_shield/scripts":{"operationId":"page-shield-list-scripts","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_scripts_list","stainlessResource":"page_shield.scripts","methodName":"list","snippet":"data \"cloudflare_page_shield_scripts_list\" \"example_page_shield_scripts_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n exclude_urls = \"blog.cloudflare.com,www.example\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n per_page = 100\n prioritize_malicious = true\n status = \"active,inactive\"\n urls = \"blog.cloudflare.com,www.example\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"The direction used to sort returned scripts."},{"name":"exclude_urls","type":"String","description":"Excludes scripts whose URL contains one of the URL-encoded URLs separated by commas.\n"},{"name":"export","type":"String","description":"Export the list of scripts as a file, limited to 50000 entries."},{"name":"hosts","type":"String","description":"Includes scripts that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"order_by","type":"String","description":"The field used to sort returned scripts."},{"name":"page","type":"String","description":"The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the scripts\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of scripts\n"},{"name":"page_url","type":"String","description":"Includes scripts that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"per_page","type":"Float64","description":"The number of results per page."},{"name":"prioritize_malicious","type":"Bool","description":"When true, malicious scripts appear first in the returned scripts."},{"name":"status","type":"String","description":"Filters the returned scripts using a comma-separated list of scripts statuses. Accepted values: `active`, `infrequent`, and `inactive`. The default value is `active`."},{"name":"urls","type":"String","description":"Includes scripts whose URL contain one or more URL-encoded URLs separated by commas.\n"},{"name":"exclude_cdn_cgi","type":"Bool","description":"When true, excludes scripts seen in a `/cdn-cgi` path from the returned scripts. The default value is true."},{"name":"exclude_duplicates","type":"Bool","description":"When true, excludes duplicate scripts. We consider a script duplicate of another if their javascript\ncontent matches and they share the same url host and zone hostname. In such case, we return the most\nrecent script for the URL host and zone hostname combination.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"added_at","type":"Time"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"last_seen_at","type":"Time"},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"cryptomining_score","type":"Int64","description":"The cryptomining score of the JavaScript content."},{"name":"dataflow_score","type":"Int64","description":"The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"domain_reported_malicious","type":"Bool"},{"name":"fetched_at","type":"String","description":"The timestamp of when the script was last fetched."},{"name":"first_page_url","type":"String"},{"name":"hash","type":"String","description":"The computed hash of the analyzed script."},{"name":"js_integrity_score","type":"Int64","description":"The integrity score of the JavaScript content."},{"name":"magecart_score","type":"Int64","description":"The magecart score of the JavaScript content."},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"malware_score","type":"Int64","description":"The malware score of the JavaScript content."},{"name":"obfuscation_score","type":"Int64","description":"The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"page_urls","type":"List[String]"},{"name":"url_reported_malicious","type":"Bool"}]}]}]},"get /zones/{}/page_shield/scripts/{}":{"operationId":"page-shield-get-script","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_scripts","stainlessResource":"page_shield.scripts","methodName":"get","snippet":"data \"cloudflare_page_shield_scripts\" \"example_page_shield_scripts\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"script_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"added_at","type":"Time"},{"name":"cryptomining_score","type":"Int64","description":"The cryptomining score of the JavaScript content."},{"name":"dataflow_score","type":"Int64","description":"The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"domain_reported_malicious","type":"Bool"},{"name":"fetched_at","type":"String","description":"The timestamp of when the script was last fetched."},{"name":"first_page_url","type":"String"},{"name":"first_seen_at","type":"Time"},{"name":"hash","type":"String","description":"The computed hash of the analyzed script."},{"name":"host","type":"String"},{"name":"id","type":"String","description":"Identifier"},{"name":"js_integrity_score","type":"Int64","description":"The integrity score of the JavaScript content."},{"name":"last_seen_at","type":"Time"},{"name":"magecart_score","type":"Int64","description":"The magecart score of the JavaScript content."},{"name":"malware_score","type":"Int64","description":"The malware score of the JavaScript content."},{"name":"obfuscation_score","type":"Int64","description":"The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"url_reported_malicious","type":"Bool"},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"page_urls","type":"List[String]"},{"name":"versions","type":"List[Attributes]","children":[{"name":"cryptomining_score","type":"Int64","description":"The cryptomining score of the JavaScript content."},{"name":"dataflow_score","type":"Int64","description":"The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"fetched_at","type":"String","description":"The timestamp of when the script was last fetched."},{"name":"hash","type":"String","description":"The computed hash of the analyzed script."},{"name":"js_integrity_score","type":"Int64","description":"The integrity score of the JavaScript content."},{"name":"magecart_score","type":"Int64","description":"The magecart score of the JavaScript content."},{"name":"malware_score","type":"Int64","description":"The malware score of the JavaScript content."},{"name":"obfuscation_score","type":"Int64","description":"The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."}]}]}]},"get /zones/{}/pagerules/{}":{"operationId":"page-rules-get-a-page-rule","declarations":[{"kind":"data-source","name":"cloudflare_page_rule","stainlessResource":"page_rules","methodName":"get","snippet":"data \"cloudflare_page_rule\" \"example_page_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pagerule_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"pagerule_id","type":"String","description":"Identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"The timestamp of when the Page Rule was created."},{"name":"modified_on","type":"Time","description":"The timestamp of when the Page Rule was last modified."},{"name":"priority","type":"Int64","description":"The priority of the rule, used to define which Page Rule is processed\nover another. A higher number indicates a higher priority. For example,\nif you have a catch-all Page Rule (rule A: `/images/*`) but want a more\nspecific Page Rule to take precedence (rule B: `/images/special/*`),\nspecify a higher priority for rule B so it overrides rule A.\n"},{"name":"status","type":"String","description":"The status of the Page Rule."},{"name":"actions","type":"List[Attributes]","description":"The set of actions to perform if the targets of this rule match the\nrequest. Actions can redirect to another URL or override settings, but\nnot both.\n","children":[{"name":"id","type":"String","description":"If enabled, any `http://`` URL is converted to `https://` through a\n301 redirect.\n"},{"name":"value","type":"String","description":"The status of Automatic HTTPS Rewrites.\n"}]},{"name":"targets","type":"List[Attributes]","description":"The rule targets to evaluate on each request.","children":[{"name":"constraint","type":"Attributes","description":"String constraint.","children":[{"name":"operator","type":"String","description":"The matches operator can use asterisks and pipes as wildcard and 'or' operators."},{"name":"value","type":"String","description":"The URL pattern to match against the current request. The pattern may contain up to four asterisks ('*') as placeholders."}]},{"name":"target","type":"String","description":"A target based on the URL of the request."}]}]}]},"get /zones/{}/precursor":{"operationId":"precursor-for-a-zone-get-config","declarations":[{"kind":"data-source","name":"cloudflare_precursor","stainlessResource":"precursor","methodName":"get","snippet":"data \"cloudflare_precursor\" \"example_precursor\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"default_mode","type":"String","description":"The zone-level Precursor enforcement mode applied to requests that do\nnot match a more specific enforcement rule.\n","deprecated":"Deprecated."},{"name":"enforcement_rules","type":"List[Attributes]","description":"The ordered list of enforcement rules for the zone.","deprecated":"Deprecated.","children":[{"name":"expression","type":"String","description":"The filter expression that determines which requests the rule matches."},{"name":"mode","type":"String","description":"The override mode Precursor applies to requests matching an enforcement\nrule. Unlike `default_mode`, this cannot be `off`.\n"},{"name":"id","type":"String","description":"The read-only identifier that Cloudflare assigns to the rule."},{"name":"description","type":"String","description":"An informative description of the rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is active."}]}]}]},"get /zones/{}/rate_limits/{}":{"operationId":"rate-limits-for-a-zone-get-a-rate-limit","declarations":[{"kind":"data-source","name":"cloudflare_rate_limit","stainlessResource":"rate_limits","methodName":"get","snippet":"data \"cloudflare_rate_limit\" \"example_rate_limit\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rate_limit_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"rate_limit_id","type":"String","description":"Defines the unique identifier of the rate limit."},{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[]}]},"get /zones/{}/schema_validation/schemas":{"operationId":"schema-validation-list-schemas-paginated","declarations":[{"kind":"list-data-source","name":"cloudflare_schema_validation_schemas_list","stainlessResource":"schema_validation.schemas","methodName":"list","snippet":"data \"cloudflare_schema_validation_schemas_list\" \"example_schema_validation_schemas_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"validation_enabled","type":"Bool","description":"Filter for enabled schemas"},{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"A unique identifier of this schema"},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The kind of the schema"},{"name":"name","type":"String","description":"A human-readable name for the schema"},{"name":"schema_id","type":"String","description":"A unique identifier of this schema"},{"name":"source","type":"String","description":"The raw schema, e.g., the OpenAPI schema, either as JSON or YAML"},{"name":"validation_enabled","type":"Bool","description":"An indicator if this schema is enabled"}]}]}]},"get /zones/{}/schema_validation/schemas/{}":{"operationId":"schema-validation-get-schema","declarations":[{"kind":"data-source","name":"cloudflare_schema_validation_schemas","stainlessResource":"schema_validation.schemas","methodName":"get","snippet":"data \"cloudflare_schema_validation_schemas\" \"example_schema_validation_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n schema_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n omit_source = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"schema_id","type":"String","description":"UUID."},{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."},{"name":"filter","type":"Attributes","children":[{"name":"validation_enabled","type":"Bool","description":"Filter for enabled schemas"}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The kind of the schema"},{"name":"name","type":"String","description":"A human-readable name for the schema"},{"name":"source","type":"String","description":"The raw schema, e.g., the OpenAPI schema, either as JSON or YAML"},{"name":"validation_enabled","type":"Bool","description":"An indicator if this schema is enabled"}]}]},"get /zones/{}/schema_validation/settings":{"operationId":"schema-validation-get-settings","declarations":[{"kind":"data-source","name":"cloudflare_schema_validation_settings","stainlessResource":"schema_validation.settings","methodName":"get","snippet":"data \"cloudflare_schema_validation_settings\" \"example_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used\n\nMitigation actions are as follows:\n\n - `log` - log request when request does not conform to schema\n - `block` - deny access to the site when request does not conform to schema\n - `none` - skip running schema validation\n"},{"name":"validation_override_mitigation_action","type":"String","description":"When not null, this overrides global both zone level and operation level mitigation actions. This can serve as a quick way to disable schema validation for the whole zone.\n\n - `\"none\"` will skip running schema validation entirely for the request\n"}]}]},"get /zones/{}/schema_validation/settings/operations":{"operationId":"schema-validation-list-per-operation-settings","declarations":[{"kind":"list-data-source","name":"cloudflare_schema_validation_operation_settings_list","stainlessResource":"schema_validation.settings.operations","methodName":"list","snippet":"data \"cloudflare_schema_validation_operation_settings_list\" \"example_schema_validation_operation_settings_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation which supersedes a global schema validation setting just for this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\n"},{"name":"operation_id","type":"String","description":"UUID."}]}]}]},"get /zones/{}/schema_validation/settings/operations/{}":{"operationId":"schema-validation-get-per-operation-setting","declarations":[{"kind":"data-source","name":"cloudflare_schema_validation_operation_settings","stainlessResource":"schema_validation.settings.operations","methodName":"get","snippet":"data \"cloudflare_schema_validation_operation_settings\" \"example_schema_validation_operation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation which supersedes a global schema validation setting just for this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\n"}]}]},"get /zones/{}/secondary_dns/incoming":{"operationId":"secondary-dns-(-secondary-zone)-secondary-zone-configuration-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_incoming","stainlessResource":"dns.zone_transfers.incoming","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_incoming\" \"example_dns_zone_transfers_incoming\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"auto_refresh_seconds","type":"Float64","description":"How often should a secondary zone auto refresh regardless of DNS NOTIFY.\nNot applicable for primary zones."},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"modified_time","type":"String","description":"The time for a specific event."},{"name":"name","type":"String","description":"Zone name."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}]}]},"get /zones/{}/secondary_dns/outgoing":{"operationId":"secondary-dns-(-primary-zone)-primary-zone-configuration-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_outgoing","stainlessResource":"dns.zone_transfers.outgoing","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_outgoing\" \"example_dns_zone_transfers_outgoing\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"last_transferred_time","type":"String","description":"The time for a specific event."},{"name":"name","type":"String","description":"Zone name."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}]}]},"get /zones/{}/settings":{"operationId":"zone-settings-get-all-zone-settings","declarations":[{"kind":"list-data-source","name":"cloudflare_zone_settings","stainlessResource":"zones.settings","methodName":"list","snippet":"data \"cloudflare_zone_settings\" \"example_zone_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"ID of the zone setting."},{"name":"value","type":"String","description":"Current value of the zone setting."},{"name":"editable","type":"Bool","description":"Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)."},{"name":"modified_on","type":"Time","description":"last time this setting was modified."},{"name":"time_remaining","type":"Float64","description":"Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false."},{"name":"enabled","type":"Bool","description":"ssl-recommender enrollment setting."}]}]}]},"get /zones/{}/settings/{}":{"operationId":"zone-settings-get-single-setting","declarations":[{"kind":"data-source","name":"cloudflare_zone_setting","stainlessResource":"zones.settings","methodName":"get","snippet":"data \"cloudflare_zone_setting\" \"example_zone_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"always_online\"\n}\n","required":[{"name":"setting_id","type":"String","description":"Setting name"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Setting name"},{"name":"editable","type":"Bool","description":"Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)."},{"name":"enabled","type":"Bool","description":"ssl-recommender enrollment setting."},{"name":"modified_on","type":"Time","description":"last time this setting was modified."},{"name":"time_remaining","type":"Float64","description":"Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false."},{"name":"value","type":"String","description":"Current value of the zone setting."}]}]},"get /zones/{}/settings/auto_origin_tls_kex":{"operationId":"ssl-detector-auto-origin-tls-kex-get-enrollment","declarations":[{"kind":"data-source","name":"cloudflare_zone_auto_origin_tls_kex","stainlessResource":"ssl.auto_origin_tls_kex","methodName":"get","snippet":"data \"cloudflare_zone_auto_origin_tls_kex\" \"example_zone_auto_origin_tls_kex\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"enabled","type":"Bool","description":"Whether Auto-Origin TLS KEX selection is enabled for the zone."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"get /zones/{}/settings/google-tag-gateway/config":{"operationId":"zone-settings-get-google-tag-gateway-config","declarations":[{"kind":"data-source","name":"cloudflare_google_tag_gateway","stainlessResource":"google_tag_gateway.config","methodName":"get","snippet":"data \"cloudflare_google_tag_gateway\" \"example_google_tag_gateway\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Enables or disables Google Tag Gateway for this zone."},{"name":"endpoint","type":"String","description":"Specifies the endpoint path for proxying Google Tag Manager requests. Use an absolute path starting with '/', with no nested paths and alphanumeric characters only (e.g. /metrics)."},{"name":"hide_original_ip","type":"Bool","description":"Hides the original client IP address from Google when enabled."},{"name":"measurement_id","type":"String","description":"Specify the Google Tag Manager container or measurement ID (e.g. GTM-XXXXXXX or G-XXXXXXXXXX)."},{"name":"set_up_tag","type":"Bool","description":"Set up the associated Google Tag on the zone automatically when enabled."}]}]},"get /zones/{}/settings/nel":{"operationId":"nel-settings-get","declarations":[{"kind":"data-source","name":"cloudflare_nel_setting","stainlessResource":"zones.nel","methodName":"get","snippet":"data \"cloudflare_nel_setting\" \"example_nel_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of the zone."},{"name":"editable","type":"Bool","description":"Whether the setting is editable. This is false when the zone's plan does not include NEL or the NEL product feature is not enabled.\n"},{"name":"modified_on","type":"Time","description":"When the setting was last modified. A zero value (0001-01-01T00:00:00Z) indicates the setting has never been explicitly set and is using the default value.\n"},{"name":"value","type":"Attributes","description":"The NEL configuration value.","children":[{"name":"enabled","type":"Bool","description":"Whether Network Error Logging is enabled for the zone. When enabled, browsers report network errors to Cloudflare's NEL endpoint.\n"}]}]}]},"get /zones/{}/settings/origin_tls_compliance_modes":{"operationId":"zone-cache-settings-get-origin-tls-compliance-modes-setting","declarations":[{"kind":"data-source","name":"cloudflare_origin_tls_compliance_modes","stainlessResource":"origin_tls_compliance_modes","methodName":"get","snippet":"data \"cloudflare_origin_tls_compliance_modes\" \"example_origin_tls_compliance_modes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"List[String]","description":"List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone's origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint."}]}]},"get /zones/{}/snippets":{"operationId":"listZoneSnippets","declarations":[{"kind":"list-data-source","name":"cloudflare_snippets","stainlessResource":"snippets","methodName":"list","snippet":"data \"cloudflare_snippets\" \"example_snippets\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identify the snippet."},{"name":"created_on","type":"Time","description":"Indicates when the snippet was created."},{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"modified_on","type":"Time","description":"Indicates when the snippet was last modified."}]}]}]},"get /zones/{}/snippets/{}":{"operationId":"getZoneSnippet","declarations":[{"kind":"data-source","name":"cloudflare_snippet","stainlessResource":"snippets","methodName":"get","snippet":"data \"cloudflare_snippet\" \"example_snippet\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n snippet_name = \"my_snippet\"\n}\n","required":[{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identify the snippet."},{"name":"created_on","type":"Time","description":"Indicates when the snippet was created."},{"name":"modified_on","type":"Time","description":"Indicates when the snippet was last modified."}]}]},"get /zones/{}/snippets/snippet_rules":{"operationId":"listZoneSnippetRules","declarations":[{"kind":"data-source","name":"cloudflare_snippet_rules","stainlessResource":"snippets.rules","methodName":"get","snippet":"data \"cloudflare_snippet_rules\" \"example_snippet_rules\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Use this field to specify the unique ID of the zone."},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."}]},{"kind":"list-data-source","name":"cloudflare_snippet_rules_list","stainlessResource":"snippets.rules","methodName":"list","snippet":"data \"cloudflare_snippet_rules_list\" \"example_snippet_rules_list\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Specify the unique ID of the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."}]}]}]},"get /zones/{}/spectrum/apps":{"operationId":"spectrum-applications-list-spectrum-applications","declarations":[{"kind":"list-data-source","name":"cloudflare_spectrum_applications","stainlessResource":"spectrum.apps","methodName":"list","snippet":"data \"cloudflare_spectrum_applications\" \"example_spectrum_applications\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier."}],"optional":[{"name":"direction","type":"String","description":"Sets the direction by which results are ordered."},{"name":"order","type":"String","description":"Application field by which results are ordered."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"App identifier."},{"name":"created_on","type":"Time","description":"When the Application was created."},{"name":"dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the application."},{"name":"type","type":"String","description":"The type of DNS record associated with the application."}]},{"name":"modified_on","type":"Time","description":"When the Application was last modified."},{"name":"protocol","type":"String","description":"The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`."},{"name":"traffic_type","type":"String","description":"Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`."},{"name":"argo_smart_routing","type":"Bool","description":"Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"."},{"name":"edge_ips","type":"Attributes","description":"The anycast edge IP configuration for the hostname of this application.","children":[{"name":"connectivity","type":"String","description":"The IP versions supported for inbound connections on Spectrum anycast IPs."},{"name":"type","type":"String","description":"The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names."},{"name":"ips","type":"List[String]","description":"The array of customer owned IPs we broadcast via anycast for this hostname and application."}]},{"name":"ip_firewall","type":"Bool","description":"Enables IP Access Rules for this application.\nNotes: Only available for TCP applications."},{"name":"origin_direct","type":"List[String]","description":"List of origin IP addresses. Array may contain multiple IP addresses for load balancing."},{"name":"origin_dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the origin."},{"name":"ttl","type":"Int64","description":"The TTL of our resolution of your DNS record in seconds."},{"name":"type","type":"String","description":"The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records."}]},{"name":"origin_port","type":"Dynamic Int64 | String","description":"The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field."},{"name":"origin_worker_id","type":"String","description":"Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"."},{"name":"proxy_protocol","type":"String","description":"Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol."},{"name":"tls","type":"String","description":"The type of TLS termination associated with the application."},{"name":"virtual_network_id","type":"String","description":"Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks."}]}]}]},"get /zones/{}/spectrum/apps/{}":{"operationId":"spectrum-applications-get-spectrum-application-configuration","declarations":[{"kind":"data-source","name":"cloudflare_spectrum_application","stainlessResource":"spectrum.apps","methodName":"get","snippet":"data \"cloudflare_spectrum_application\" \"example_spectrum_application\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n app_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier."}],"optional":[{"name":"app_id","type":"String","description":"App identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sets the direction by which results are ordered."},{"name":"order","type":"String","description":"Application field by which results are ordered."}]}],"computed":[{"name":"id","type":"String","description":"App identifier."},{"name":"argo_smart_routing","type":"Bool","description":"Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"."},{"name":"created_on","type":"Time","description":"When the Application was created."},{"name":"ip_firewall","type":"Bool","description":"Enables IP Access Rules for this application.\nNotes: Only available for TCP applications."},{"name":"modified_on","type":"Time","description":"When the Application was last modified."},{"name":"origin_worker_id","type":"String","description":"Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"."},{"name":"protocol","type":"String","description":"The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`."},{"name":"proxy_protocol","type":"String","description":"Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol."},{"name":"tls","type":"String","description":"The type of TLS termination associated with the application."},{"name":"traffic_type","type":"String","description":"Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`."},{"name":"virtual_network_id","type":"String","description":"Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks."},{"name":"origin_direct","type":"List[String]","description":"List of origin IP addresses. Array may contain multiple IP addresses for load balancing."},{"name":"dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the application."},{"name":"type","type":"String","description":"The type of DNS record associated with the application."}]},{"name":"edge_ips","type":"Attributes","description":"The anycast edge IP configuration for the hostname of this application.","children":[{"name":"connectivity","type":"String","description":"The IP versions supported for inbound connections on Spectrum anycast IPs."},{"name":"type","type":"String","description":"The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names."},{"name":"ips","type":"List[String]","description":"The array of customer owned IPs we broadcast via anycast for this hostname and application."}]},{"name":"origin_dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the origin."},{"name":"ttl","type":"Int64","description":"The TTL of our resolution of your DNS record in seconds."},{"name":"type","type":"String","description":"The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records."}]},{"name":"origin_port","type":"Dynamic Int64 | String","description":"The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field."}]}]},"get /zones/{}/spectrum/protocols":{"operationId":"spectrum-applications-list-spectrum-application-protocols","declarations":[{"kind":"list-data-source","name":"cloudflare_spectrum_protocols","stainlessResource":"spectrum.protocols","methodName":"list","snippet":"data \"cloudflare_spectrum_protocols\" \"example_spectrum_protocols\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"description","type":"String","description":"The full name of the application protocol."},{"name":"name","type":"String","description":"The short name of the application protocol."},{"name":"ports","type":"List[Int64]","description":"The available listening ports for the given protocol."},{"name":"transport","type":"String","description":"The transport layer protocol used by the application protocol"}]}]}]},"get /zones/{}/speed_api/schedule/{}":{"operationId":"speed-get-scheduled-test","declarations":[{"kind":"data-source","name":"cloudflare_observatory_scheduled_test","stainlessResource":"speed.schedule","methodName":"get","snippet":"data \"cloudflare_observatory_scheduled_test\" \"example_observatory_scheduled_test\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n url = \"example.com\"\n region = \"us-central1\"\n}\n","required":[{"name":"url","type":"String","description":"A URL."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"region","type":"String","description":"A test region."}],"computed":[{"name":"frequency","type":"String","description":"The frequency of the test."}]}]},"get /zones/{}/ssl/certificate_packs":{"operationId":"certificate-packs-list-certificate-packs","declarations":[{"kind":"list-data-source","name":"cloudflare_certificate_packs","stainlessResource":"ssl.certificate_packs","methodName":"list","snippet":"data \"cloudflare_certificate_packs\" \"example_certificate_packs\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n deploy = \"staging\"\n status = \"all\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"deploy","type":"String","description":"Specify the deployment environment for the certificate packs."},{"name":"status","type":"String","description":"Include Certificate Packs of all statuses, not just active ones."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier for a certificate_pack."},{"name":"certificates","type":"List[Attributes]","description":"Array of certificates in this pack.","children":[{"name":"id","type":"String","description":"Certificate identifier."},{"name":"hosts","type":"List[String]","description":"Hostnames covered by this certificate."},{"name":"status","type":"String","description":"Certificate status."},{"name":"bundle_method","type":"String","description":"Certificate bundle method."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally.","children":[{"name":"label","type":"String"}]},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"zone_id","type":"String","description":"Identifier."}]},{"name":"hosts","type":"Set[String]","description":"Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty."},{"name":"status","type":"String","description":"Status of certificate pack."},{"name":"type","type":"String","description":"Type of certificate pack."},{"name":"certificate_authority","type":"String","description":"Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities)."},{"name":"cloudflare_branding","type":"Bool","description":"Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true."},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"primary_certificate","type":"String","description":"Identifier of the primary certificate in a pack."},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_method","type":"String","description":"Validation Method selected for the order."},{"name":"validation_records","type":"List[Attributes]","description":"Certificates' validation records.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"validity_days","type":"Int64","description":"Validity Days selected for the order."}]}]}]},"get /zones/{}/ssl/certificate_packs/{}":{"operationId":"certificate-packs-get-certificate-pack","declarations":[{"kind":"data-source","name":"cloudflare_certificate_pack","stainlessResource":"ssl.certificate_packs","methodName":"get","snippet":"data \"cloudflare_certificate_pack\" \"example_certificate_pack\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_pack_id = \"3822ff90-ea29-44df-9e55-21300bb9419b\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"certificate_pack_id","type":"String","description":"The unique identifier for a certificate_pack."},{"name":"filter","type":"Attributes","children":[{"name":"deploy","type":"String","description":"Specify the deployment environment for the certificate packs."},{"name":"status","type":"String","description":"Include Certificate Packs of all statuses, not just active ones."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier for a certificate_pack."},{"name":"certificate_authority","type":"String","description":"Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities)."},{"name":"cloudflare_branding","type":"Bool","description":"Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true."},{"name":"primary_certificate","type":"String","description":"Identifier of the primary certificate in a pack."},{"name":"status","type":"String","description":"Status of certificate pack."},{"name":"type","type":"String","description":"Type of certificate pack."},{"name":"validation_method","type":"String","description":"Validation Method selected for the order."},{"name":"validity_days","type":"Int64","description":"Validity Days selected for the order."},{"name":"hosts","type":"Set[String]","description":"Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty."},{"name":"certificates","type":"List[Attributes]","description":"Array of certificates in this pack.","children":[{"name":"id","type":"String","description":"Certificate identifier."},{"name":"hosts","type":"List[String]","description":"Hostnames covered by this certificate."},{"name":"status","type":"String","description":"Certificate status."},{"name":"bundle_method","type":"String","description":"Certificate bundle method."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally.","children":[{"name":"label","type":"String"}]},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"zone_id","type":"String","description":"Identifier."}]},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","description":"Certificates' validation records.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]}]}]},"get /zones/{}/ssl/universal/settings":{"operationId":"universal-ssl-settings-for-a-zone-universal-ssl-settings-details","declarations":[{"kind":"data-source","name":"cloudflare_universal_ssl_setting","stainlessResource":"ssl.universal.settings","methodName":"get","snippet":"data \"cloudflare_universal_ssl_setting\" \"example_universal_ssl_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.\n\nBy disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.\n\n* HSTS\n* Always Use HTTPS\n* Opportunistic Encryption\n* Onion Routing\n* Any Page Rules redirecting traffic to HTTPS\n\nSimilarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare's edge.\n\nIf you do not have a valid custom or advanced certificate at Cloudflare's edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain."}]}]},"get /zones/{}/subscription":{"operationId":"zone-subscription-zone-subscription-details","declarations":[{"kind":"data-source","name":"cloudflare_zone_subscription","stainlessResource":"zones.subscriptions","methodName":"get","snippet":"data \"cloudflare_zone_subscription\" \"example_zone_subscription\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"currency","type":"String","description":"The monetary unit in which pricing information is displayed."},{"name":"current_period_end","type":"Time","description":"The end of the current period and also when the next billing is due."},{"name":"current_period_start","type":"Time","description":"When the current billing period started. May match initial_period_start if this is the first period."},{"name":"frequency","type":"String","description":"How often the subscription is renewed automatically."},{"name":"price","type":"Float64","description":"The price of the subscription that will be billed, in US dollars."},{"name":"state","type":"String","description":"The state that the subscription is in."},{"name":"rate_plan","type":"Attributes","description":"The rate plan applied to the subscription.","children":[{"name":"id","type":"String","description":"The ID of the rate plan."},{"name":"currency","type":"String","description":"The currency applied to the rate plan subscription."},{"name":"externally_managed","type":"Bool","description":"Whether this rate plan is managed externally from Cloudflare."},{"name":"is_contract","type":"Bool","description":"Whether a rate plan is enterprise-based (or newly adopted term contract)."},{"name":"public_name","type":"String","description":"The full name of the rate plan."},{"name":"scope","type":"String","description":"The scope that this rate plan applies to."},{"name":"sets","type":"List[String]","description":"The list of sets this rate plan applies to. Returns array of strings."}]}]}]},"get /zones/{}/token_validation/config":{"operationId":"token-validation-config-list","declarations":[{"kind":"list-data-source","name":"cloudflare_token_validation_configs","stainlessResource":"token_validation.configuration","methodName":"list","snippet":"data \"cloudflare_token_validation_configs\" \"example_token_validation_configs\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"credentials","type":"Attributes","children":[{"name":"keys","type":"List[Attributes]","children":[{"name":"alg","type":"String","description":"Algorithm"},{"name":"e","type":"String","description":"RSA exponent"},{"name":"kid","type":"String","description":"Key ID"},{"name":"kty","type":"String","description":"Key Type"},{"name":"n","type":"String","description":"RSA modulus"},{"name":"crv","type":"String","description":"Curve"},{"name":"x","type":"String","description":"X EC coordinate"},{"name":"y","type":"String","description":"Y EC coordinate"}]}]},{"name":"description","type":"String"},{"name":"last_updated","type":"Time"},{"name":"title","type":"String"},{"name":"token_sources","type":"List[String]"},{"name":"token_type","type":"String"}]}]}]},"get /zones/{}/token_validation/config/{}":{"operationId":"token-validation-config-get","declarations":[{"kind":"data-source","name":"cloudflare_token_validation_config","stainlessResource":"token_validation.configuration","methodName":"get","snippet":"data \"cloudflare_token_validation_config\" \"example_token_validation_config\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n config_id = \"4a7ee8d3-dd63-4ceb-9d5f-c27831854ce7\"\n}\n","required":[{"name":"config_id","type":"String","description":"UUID."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"last_updated","type":"Time"},{"name":"title","type":"String"},{"name":"token_type","type":"String"},{"name":"token_sources","type":"List[String]"},{"name":"credentials","type":"Attributes","children":[{"name":"keys","type":"List[Attributes]","children":[{"name":"alg","type":"String","description":"Algorithm"},{"name":"e","type":"String","description":"RSA exponent"},{"name":"kid","type":"String","description":"Key ID"},{"name":"kty","type":"String","description":"Key Type"},{"name":"n","type":"String","description":"RSA modulus"},{"name":"crv","type":"String","description":"Curve"},{"name":"x","type":"String","description":"X EC coordinate"},{"name":"y","type":"String","description":"Y EC coordinate"}]}]}]}]},"get /zones/{}/token_validation/rules":{"operationId":"token-validation-rules-list","declarations":[{"kind":"list-data-source","name":"cloudflare_token_validation_rules_list","stainlessResource":"token_validation.rules","methodName":"list","snippet":"data \"cloudflare_token_validation_rules_list\" \"example_token_validation_rules_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n action = \"log\"\n enabled = true\n host = \"www.example.com\"\n hostname = \"www.example.com\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n token_configuration = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"host","type":"String","description":"Select rules with this host in `include`."},{"name":"hostname","type":"String","description":"Select rules with this host in `include`."},{"name":"id","type":"String","description":"Select rules with these IDs."},{"name":"rule_id","type":"String","description":"Select rules with these IDs."},{"name":"token_configuration","type":"List[String]","description":"Select rules using any of these token configurations."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"description","type":"String","description":"A human-readable description that gives more details than `title`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"expression","type":"String","description":"Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n"},{"name":"selector","type":"Attributes","description":"Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n","children":[{"name":"exclude","type":"List[Attributes]","description":"Ignore operations that were otherwise included by `include`.","children":[{"name":"operation_ids","type":"List[String]","description":"Excluded operation IDs."}]},{"name":"include","type":"List[Attributes]","description":"Select all matching operations.","children":[{"name":"host","type":"List[String]","description":"Included hostnames."}]}]},{"name":"title","type":"String","description":"A human-readable name for the rule."},{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"last_updated","type":"Time"}]}]}]},"get /zones/{}/token_validation/rules/{}":{"operationId":"token-validation-rules-get","declarations":[{"kind":"data-source","name":"cloudflare_token_validation_rules","stainlessResource":"token_validation.rules","methodName":"get","snippet":"data \"cloudflare_token_validation_rules\" \"example_token_validation_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_id = \"4a7ee8d3-dd63-4ceb-9d5f-c27831854ce7\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"rule_id","type":"String","description":"UUID."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"Select rules with these IDs."},{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"host","type":"String","description":"Select rules with this host in `include`."},{"name":"hostname","type":"String","description":"Select rules with this host in `include`."},{"name":"token_configuration","type":"List[String]","description":"Select rules using any of these token configurations."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"A human-readable description that gives more details than `title`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"expression","type":"String","description":"Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n"},{"name":"last_updated","type":"Time"},{"name":"title","type":"String","description":"A human-readable name for the rule."},{"name":"selector","type":"Attributes","description":"Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n","children":[{"name":"exclude","type":"List[Attributes]","description":"Ignore operations that were otherwise included by `include`.","children":[{"name":"operation_ids","type":"List[String]","description":"Excluded operation IDs."}]},{"name":"include","type":"List[Attributes]","description":"Select all matching operations.","children":[{"name":"host","type":"List[String]","description":"Included hostnames."}]}]}]}]},"get /zones/{}/url_normalization":{"operationId":"getUrlNormalization","declarations":[{"kind":"data-source","name":"cloudflare_url_normalization_settings","stainlessResource":"url_normalization","methodName":"get","snippet":"data \"cloudflare_url_normalization_settings\" \"example_url_normalization_settings\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone."},{"name":"scope","type":"String","description":"The scope of the URL normalization."},{"name":"type","type":"String","description":"The type of URL normalization performed by Cloudflare."}]}]},"get /zones/{}/waiting_rooms/{}":{"operationId":"waiting-room-waiting-room-details","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room","stainlessResource":"waiting_rooms","methodName":"get","snippet":"data \"cloudflare_waiting_room\" \"example_waiting_room\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"cookie_suffix","type":"String","description":"Appends a '_' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(__cf_waitingroom). If `cookie_suffix` is \"abcd\", the cookie name will be `__cf_waitingroom_abcd`. This field is required if using `additional_routes`."},{"name":"created_on","type":"Time"},{"name":"custom_page_html","type":"String","description":"Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custom_page_html is provided, the default waiting room will be used. The template is based on mustache ( https://mustache.github.io/ ). There are several variables that are evaluated by the Cloudflare edge:\n1. {{`waitTimeKnown`}} Acts like a boolean value that indicates the behavior to take when wait time is not available, for instance when queue_all is **true**.\n2. {{`waitTimeFormatted`}} Estimated wait time for the user. For example, five minutes. Alternatively, you can use:\n3. {{`waitTime`}} Number of minutes of estimated wait for a user.\n4. {{`waitTimeHours`}} Number of hours of estimated wait for a user (`Math.floor(waitTime/60)`).\n5. {{`waitTimeHourMinutes`}} Number of minutes above the `waitTimeHours` value (`waitTime%60`).\n6. {{`queueIsFull`}} Changes to **true** when no more people can be added to the queue.\n\nTo view the full list of variables, look at the `cfWaitingRoom` object described under the `json_response_enabled` property in other Waiting Room API calls."},{"name":"default_template_language","type":"String","description":"The language of the default page template. If no default_template_language is provided, then `en-US` (English) will be used."},{"name":"description","type":"String","description":"A note that you can use to add more details about the waiting room."},{"name":"disable_session_renewal","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If `true`, an accepted user will have session_duration minutes to browse the site. After that, they will have to go through the waiting room again. If `false`, a user's session cookie will be automatically renewed on every request."},{"name":"host","type":"String","description":"The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination must be unique."},{"name":"json_response_enabled","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. If `true`, requests to the waiting room with the header `Accept: application/json` will receive a JSON response object with information on the user's status in the waiting room as opposed to the configured static HTML page. This JSON response object has one property `cfWaitingRoom` which is an object containing the following fields:\n1. `inWaitingRoom`: Boolean indicating if the user is in the waiting room (always **true**).\n2. `waitTimeKnown`: Boolean indicating if the current estimated wait times are accurate. If **false**, they are not available.\n3. `waitTime`: Valid only when `waitTimeKnown` is **true**. Integer indicating the current estimated time in minutes the user will wait in the waiting room. When `queueingMethod` is **random**, this is set to `waitTime50Percentile`.\n4. `waitTime25Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 25% of users that gain entry the fastest (25th percentile).\n5. `waitTime50Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 50% of users that gain entry the fastest (50th percentile). In other words, half of the queued users are expected to let into the origin website before `waitTime50Percentile` and half are expected to be let in after it.\n6. `waitTime75Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 75% of users that gain entry the fastest (75th percentile).\n7. `waitTimeFormatted`: String displaying the `waitTime` formatted in English for users. If `waitTimeKnown` is **false**, `waitTimeFormatted` will display **unavailable**.\n8. `queueIsFull`: Boolean indicating if the waiting room's queue is currently full and not accepting new users at the moment.\n9. `queueAll`: Boolean indicating if all users will be queued in the waiting room and no one will be let into the origin website.\n10. `lastUpdated`: String displaying the timestamp as an ISO 8601 string of the user's last attempt to leave the waiting room and be let into the origin website. The user is able to make another attempt after `refreshIntervalSeconds` past this time. If the user makes a request too soon, it will be ignored and `lastUpdated` will not change.\n11. `refreshIntervalSeconds`: Integer indicating the number of seconds after `lastUpdated` until the user is able to make another attempt to leave the waiting room and be let into the origin website. When the `queueingMethod` is `reject`, there is no specified refresh time —\\_it will always be **zero**.\n12. `queueingMethod`: The queueing method currently used by the waiting room. It is either **fifo**, **random**, **passthrough**, or **reject**.\n13. `isFIFOQueue`: Boolean indicating if the waiting room uses a FIFO (First-In-First-Out) queue.\n14. `isRandomQueue`: Boolean indicating if the waiting room uses a Random queue where users gain access randomly.\n15. `isPassthroughQueue`: Boolean indicating if the waiting room uses a passthrough queue. Keep in mind that when passthrough is enabled, this JSON response will only exist when `queueAll` is **true** or `isEventPrequeueing` is **true** because in all other cases requests will go directly to the origin.\n16. `isRejectQueue`: Boolean indicating if the waiting room uses a reject queue.\n17. `isEventActive`: Boolean indicating if an event is currently occurring. Events are able to change a waiting room's behavior during a specified period of time. For additional information, look at the event properties `prequeue_start_time`, `event_start_time`, and `event_end_time` in the documentation for creating waiting room events. Events are considered active between these start and end times, as well as during the prequeueing period if it exists.\n18. `isEventPrequeueing`: Valid only when `isEventActive` is **true**. Boolean indicating if an event is currently prequeueing users before it starts.\n19. `timeUntilEventStart`: Valid only when `isEventPrequeueing` is **true**. Integer indicating the number of minutes until the event starts.\n20. `timeUntilEventStartFormatted`: String displaying the `timeUntilEventStart` formatted in English for users. If `isEventPrequeueing` is **false**, `timeUntilEventStartFormatted` will display **unavailable**.\n21. `timeUntilEventEnd`: Valid only when `isEventActive` is **true**. Integer indicating the number of minutes until the event ends.\n22. `timeUntilEventEndFormatted`: String displaying the `timeUntilEventEnd` formatted in English for users. If `isEventActive` is **false**, `timeUntilEventEndFormatted` will display **unavailable**.\n23. `shuffleAtEventStart`: Valid only when `isEventActive` is **true**. Boolean indicating if the users in the prequeue are shuffled randomly when the event starts.\n24. `turnstile`: Empty when turnstile isn't enabled. String displaying an html tag to display the Turnstile widget. Please add the `{{{turnstile}}}` tag to the `custom_html` template to ensure the Turnstile widget appears.\n25. `infiniteQueue`: Boolean indicating whether the response is for a user in the infinite queue.\n\nAn example cURL to a waiting room could be:\n\n\tcurl -X GET \"https://example.com/waitingroom\" \\\n\t\t-H \"Accept: application/json\"\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **fifo** and no event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 0,\n\t\t\t\"waitTime50Percentile\": 0,\n\t\t\t\"waitTime75Percentile\": 0,\n\t\t\t\"waitTimeFormatted\": \"10 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"fifo\",\n\t\t\t\"isFIFOQueue\": true,\n\t\t\t\"isRandomQueue\": false,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": false,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 0,\n\t\t\t\"timeUntilEventEndFormatted\": \"unavailable\",\n\t\t\t\"shuffleAtEventStart\": false\n\t\t}\n\t}\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **random** and an event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 5,\n\t\t\t\"waitTime50Percentile\": 10,\n\t\t\t\"waitTime75Percentile\": 15,\n\t\t\t\"waitTimeFormatted\": \"5 minutes to 15 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"random\",\n\t\t\t\"isFIFOQueue\": false,\n\t\t\t\"isRandomQueue\": true,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": true,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 15,\n\t\t\t\"timeUntilEventEndFormatted\": \"15 minutes\",\n\t\t\t\"shuffleAtEventStart\": true\n\t\t}\n\t}"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. So it is possible that there is a little more or little less traffic coming to the route based on the traffic patterns at that time around the world."},{"name":"next_event_prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will begin queueing."},{"name":"next_event_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will start."},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."},{"name":"queue_all","type":"Bool","description":"If queue_all is `true`, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and estimated time will become unavailable."},{"name":"queueing_method","type":"String","description":"Sets the queueing method used by the waiting room. Changing this parameter from the **default** queueing method is only available for the Waiting Room Advanced subscription. Regardless of the queueing method, if `queue_all` is enabled or an event is prequeueing, users in the waiting room will not be accepted to the origin. These users will always see a waiting room page that refreshes automatically. The valid queueing methods are:\n1. `fifo` **(default)**: First-In-First-Out queue where customers gain access in the order they arrived.\n2. `random`: Random queue where customers gain access randomly, regardless of arrival time.\n3. `passthrough`: Users will pass directly through the waiting room and into the origin website. As a result, any configured limits will not be respected while this is enabled. This method can be used as an alternative to disabling a waiting room (with `suspended`) so that analytics are still reported. This can be used if you wish to allow all traffic normally, but want to restrict traffic during a waiting room event, or vice versa.\n4. `reject`: Users will be immediately rejected from the waiting room. As a result, no users will reach the origin website while this is enabled. This can be used if you wish to reject all traffic while performing maintenance, block traffic during a specified period of time (an event), or block traffic while events are not occurring. Consider a waiting room used for vaccine distribution that only allows traffic during sign-up events, and otherwise blocks all traffic. For this case, the waiting room uses `reject`, and its events override this with `fifo`, `random`, or `passthrough`. When this queueing method is enabled and neither `queueAll` is enabled nor an event is prequeueing, the waiting room page **will not refresh automatically**."},{"name":"queueing_status_code","type":"Int64","description":"HTTP status code returned to a user while in the queue."},{"name":"session_duration","type":"Int64","description":"Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they will be treated as a new user that visits the route."},{"name":"suspended","type":"Bool","description":"Suspends or allows traffic going to the waiting room. If set to `true`, the traffic will not go to the waiting room."},{"name":"total_active_users","type":"Int64","description":"Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available. This value is used as a baseline for the total number of active user sessions on the route. It is possible to have a situation where there are more or less active users sessions on the route based on the traffic patterns at that time around the world."},{"name":"turnstile_action","type":"String","description":"Which action to take when a bot is detected using Turnstile. `log` will\nhave no impact on queueing behavior, simply keeping track of how many\nbots are detected in Waiting Room Analytics. `infinite_queue` will send\nbots to a false queueing state, where they will never reach your\norigin. `infinite_queue` requires Advanced Waiting Room.\n"},{"name":"turnstile_mode","type":"String","description":"Which Turnstile widget type to use for detecting bot traffic. See\n[the Turnstile documentation](https://developers.cloudflare.com/turnstile/concepts/widget/#widget-types)\nfor the definitions of these widget types. Set to `off` to disable the\nTurnstile integration entirely. Setting this to anything other than\n`off` or `invisible` requires Advanced Waiting Room.\n"},{"name":"enabled_origin_commands","type":"List[String]","description":"A list of enabled origin commands."},{"name":"additional_routes","type":"List[Attributes]","description":"Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an implied wildcard at the end of the path. The hostname and path combination must be unique to this and all other waiting rooms.","children":[{"name":"host","type":"String","description":"The hostname to which this waiting room will be applied (no wildcards). The hostname must be the primary domain, subdomain, or custom hostname (if using SSL for SaaS) of this zone. Please do not include the scheme (http:// or https://)."},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."}]},{"name":"cookie_attributes","type":"Attributes","description":"Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.","children":[{"name":"samesite","type":"String","description":"Configures the SameSite attribute on the waiting room cookie. Value `auto` will be translated to `lax` or `none` depending if **Always Use HTTPS** is enabled. Note that when using value `none`, the secure attribute cannot be set to `never`."},{"name":"secure","type":"String","description":"Configures the Secure attribute on the waiting room cookie. Value `always` indicates that the Secure attribute will be set in the Set-Cookie header, `never` indicates that the Secure attribute will not be set, and `auto` will set the Secure attribute depending if **Always Use HTTPS** is enabled."}]}]}]},"get /zones/{}/waiting_rooms/{}/events":{"operationId":"waiting-room-list-events","declarations":[{"kind":"list-data-source","name":"cloudflare_waiting_room_events","stainlessResource":"waiting_rooms.events","methodName":"list","snippet":"data \"cloudflare_waiting_room_events\" \"example_waiting_room_events\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"custom_page_html","type":"String","description":"If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it."},{"name":"description","type":"String","description":"A note that you can use to add more details about the event."},{"name":"disable_session_renewal","type":"Bool","description":"If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it."},{"name":"event_end_time","type":"String","description":"An ISO 8601 timestamp that marks the end of the event."},{"name":"event_start_time","type":"String","description":"An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set."},{"name":"prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`."},{"name":"queueing_method","type":"String","description":"If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it."},{"name":"session_duration","type":"Int64","description":"If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it."},{"name":"shuffle_at_event_start","type":"Bool","description":"If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary."},{"name":"suspended","type":"Bool","description":"Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration."},{"name":"total_active_users","type":"Int64","description":"If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set."},{"name":"turnstile_action","type":"String","description":"If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it."},{"name":"turnstile_mode","type":"String","description":"If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it."}]}]}]},"get /zones/{}/waiting_rooms/{}/events/{}":{"operationId":"waiting-room-event-details","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room_event","stainlessResource":"waiting_rooms.events","methodName":"get","snippet":"data \"cloudflare_waiting_room_event\" \"example_waiting_room_event\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n event_id = \"25756b2dfe6e378a06b033b670413757\"\n}\n","required":[{"name":"event_id","type":"String"},{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"custom_page_html","type":"String","description":"If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it."},{"name":"description","type":"String","description":"A note that you can use to add more details about the event."},{"name":"disable_session_renewal","type":"Bool","description":"If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it."},{"name":"event_end_time","type":"String","description":"An ISO 8601 timestamp that marks the end of the event."},{"name":"event_start_time","type":"String","description":"An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set."},{"name":"prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`."},{"name":"queueing_method","type":"String","description":"If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it."},{"name":"session_duration","type":"Int64","description":"If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it."},{"name":"shuffle_at_event_start","type":"Bool","description":"If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary."},{"name":"suspended","type":"Bool","description":"Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration."},{"name":"total_active_users","type":"Int64","description":"If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set."},{"name":"turnstile_action","type":"String","description":"If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it."},{"name":"turnstile_mode","type":"String","description":"If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it."}]}]},"get /zones/{}/waiting_rooms/{}/rules":{"operationId":"waiting-room-list-waiting-room-rules","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room_rules","stainlessResource":"waiting_rooms.rules","methodName":"get","snippet":"data \"cloudflare_waiting_room_rules\" \"example_waiting_room_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"action","type":"String","description":"The action to take when the expression matches."},{"name":"description","type":"String","description":"The description of the rule."},{"name":"enabled","type":"Bool","description":"When set to true, the rule is enabled."},{"name":"expression","type":"String","description":"Criteria defining when there is a match for the current rule."},{"name":"last_updated","type":"Time"},{"name":"version","type":"String","description":"The version of the rule."}]}]},"get /zones/{}/waiting_rooms/settings":{"operationId":"waiting-room-get-zone-settings","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room_settings","stainlessResource":"waiting_rooms.settings","methodName":"get","snippet":"data \"cloudflare_waiting_room_settings\" \"example_waiting_room_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"search_engine_crawler_bypass","type":"Bool","description":"Whether to allow verified search engine crawlers to bypass all waiting rooms on this zone.\nVerified search engine crawlers will not be tracked or counted by the waiting room system,\nand will not appear in waiting room analytics.\n"}]}]},"get /zones/{}/web3/hostnames":{"operationId":"web3-hostname-list-web3-hostnames","declarations":[{"kind":"list-data-source","name":"cloudflare_web3_hostnames","stainlessResource":"web3.hostnames","methodName":"list","snippet":"data \"cloudflare_web3_hostnames\" \"example_web3_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the identifier of the hostname."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Specify the identifier of the hostname."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"Specify an optional description of the hostname."},{"name":"dnslink","type":"String","description":"Specify the DNSLink value used if the target is ipfs."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"Specify the hostname that points to the target gateway via CNAME."},{"name":"status","type":"String","description":"Specifies the status of the hostname's activation."},{"name":"target","type":"String","description":"Specify the target gateway of the hostname."}]}]}]},"get /zones/{}/web3/hostnames/{}":{"operationId":"web3-hostname-web3-hostname-details","declarations":[{"kind":"data-source","name":"cloudflare_web3_hostname","stainlessResource":"web3.hostnames","methodName":"get","snippet":"data \"cloudflare_web3_hostname\" \"example_web3_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"identifier","type":"String","description":"Specify the identifier of the hostname."},{"name":"zone_id","type":"String","description":"Specify the identifier of the hostname."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the identifier of the hostname."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"Specify an optional description of the hostname."},{"name":"dnslink","type":"String","description":"Specify the DNSLink value used if the target is ipfs."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"Specify the hostname that points to the target gateway via CNAME."},{"name":"status","type":"String","description":"Specifies the status of the hostname's activation."},{"name":"target","type":"String","description":"Specify the target gateway of the hostname."}]}]},"get /zones/{}/workers/routes":{"operationId":"worker-routes-list-routes","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_routes","stainlessResource":"workers.routes","methodName":"list","snippet":"data \"cloudflare_workers_routes\" \"example_workers_routes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."},{"name":"script","type":"String","description":"Name of the script to run if the route matches."}]}]}]},"get /zones/{}/workers/routes/{}":{"operationId":"worker-routes-get-route","declarations":[{"kind":"data-source","name":"cloudflare_workers_route","stainlessResource":"workers.routes","methodName":"get","snippet":"data \"cloudflare_workers_route\" \"example_workers_route\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n route_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"route_id","type":"String","description":"Identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."},{"name":"script","type":"String","description":"Name of the script to run if the route matches."}]}]},"patch /accounts/{}/devices/policy":{"operationId":"devices-update-default-device-settings-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_default_profile","stainlessResource":"zero_trust.devices.policies.default","methodName":"edit","snippet":"resource \"cloudflare_zero_trust_device_default_profile\" \"example_zero_trust_device_default_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n allow_mode_switch = true\n allow_updates = true\n allowed_to_leave = true\n auto_connect = 0\n captive_portal = 180\n disable_auto_fallback = true\n dns_search_suffixes = [{\n suffix = \"internal.corp\"\n description = \"Example internal domains\"\n }]\n exclude = [{\n address = \"192.0.2.0/24\"\n description = \"Exclude testing domains from the tunnel\"\n }]\n exclude_office_ips = true\n global_acceleration = {\n api_endpoints = [\"198.51.100.1:443\"]\n enabled = true\n masque_endpoints = [\"198.51.100.1:443\"]\n wireguard_endpoints = [\"198.51.100.1:2408\"]\n autoswitch = true\n }\n include = [{\n address = \"192.0.2.0/24\"\n description = \"Include testing domains in the tunnel\"\n }]\n lan_allow_minutes = 30\n lan_allow_subnet_size = 24\n register_interface_ip_with_dns = true\n sccm_vpn_boundary_support = false\n service_mode_v2 = {\n mode = \"proxy\"\n port = 3000\n }\n support_url = \"https://1.1.1.1/help\"\n switch_locked = true\n tunnel_protocol = \"wireguard\"\n uninstall_protection = false\n virtual_networks = {\n allowed = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n default = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]}],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"default","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"gateway_unique_id","type":"String"},{"name":"policy_id","type":"String"},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}]}]},"patch /accounts/{}/stream/{}/audio/{}":{"operationId":"edit-audio-tracks","declarations":[{"kind":"resource","name":"cloudflare_stream_audio_track","stainlessResource":"stream.audio_tracks","methodName":"edit","snippet":"resource \"cloudflare_stream_audio_track\" \"example_stream_audio_track\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n audio_identifier = \"ea95132c15732412d22c1476fa83f27a\"\n default = true\n label = \"director commentary\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true}],"optional":[{"name":"audio_identifier","type":"String","description":"The unique identifier for an additional audio track.","requiresReplace":true},{"name":"label","type":"String","description":"A string to uniquely identify the track amongst other audio track labels for the specified video."},{"name":"default","type":"Bool","description":"Denotes whether the audio track will be played by default in a player."}],"computed":[{"name":"status","type":"String","description":"Specifies the processing status of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"audio","type":"List[Attributes]","description":"Array of audio tracks for the video.","children":[{"name":"default","type":"Bool","description":"Denotes whether the audio track will be played by default in a player."},{"name":"label","type":"String","description":"A string to uniquely identify the track amongst other audio track labels for the specified video."},{"name":"status","type":"String","description":"Specifies the processing status of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}]}]}]},"patch /accounts/{}/zerotrust/connectivity_settings":{"operationId":"zero-trust-accounts-patch-connectivity-settings","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_connectivity_settings","stainlessResource":"zero_trust.connectivity_settings","methodName":"edit","snippet":"resource \"cloudflare_zero_trust_connectivity_settings\" \"example_zero_trust_connectivity_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n icmp_proxy_enabled = true\n offramp_warp_enabled = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true}],"optional":[{"name":"icmp_proxy_enabled","type":"Bool","description":"A flag to enable the ICMP proxy for the account network."},{"name":"offramp_warp_enabled","type":"Bool","description":"A flag to enable WARP to WARP traffic."}],"computed":[{"name":"id","type":"String","description":"Cloudflare account ID","requiresReplace":true}]}]},"patch /user":{"operationId":"user-edit-user","declarations":[{"kind":"resource","name":"cloudflare_user","stainlessResource":"user","methodName":"edit","snippet":"resource \"cloudflare_user\" \"example_user\" {\n country = \"US\"\n first_name = \"John\"\n last_name = \"Appleseed\"\n telephone = \"+1 123-123-1234\"\n zipcode = \"12345\"\n}\n","required":[],"optional":[{"name":"country","type":"String","description":"The country in which the user lives."},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"telephone","type":"String","description":"User's telephone number"},{"name":"zipcode","type":"String","description":"The zipcode or postal code where the user lives."}],"computed":[{"name":"id","type":"String","description":"Identifier of the user."},{"name":"email","type":"String","description":"Current email address of the user."},{"name":"has_business_zones","type":"Bool","description":"Indicates whether user has any business zones"},{"name":"has_enterprise_zones","type":"Bool","description":"Indicates whether user has any enterprise zones"},{"name":"has_pro_zones","type":"Bool","description":"Indicates whether user has any pro zones"},{"name":"suspended","type":"Bool","description":"Indicates whether user has been suspended"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."},{"name":"two_factor_authentication_locked","type":"Bool","description":"Indicates whether two-factor authentication is required by one of the accounts that the user is a member of."},{"name":"betas","type":"List[String]","description":"Lists the betas that the user is participating in."},{"name":"organizations","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Organization name."},{"name":"permissions","type":"List[String]","description":"Access permissions for this User."},{"name":"roles","type":"List[String]","description":"List of roles that a user has within an organization."},{"name":"status","type":"String","description":"Whether the user is a member of the organization or has an invitation pending."}]}]}]},"patch /zones/{}/argo/smart_routing":{"operationId":"argo-smart-routing-patch-argo-smart-routing-setting","declarations":[{"kind":"resource","name":"cloudflare_argo_smart_routing","stainlessResource":"argo.smart_routing","methodName":"edit","snippet":"resource \"cloudflare_argo_smart_routing\" \"example_argo_smart_routing\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specifies the zone associated with the API call.","requiresReplace":true},{"name":"value","type":"String","description":"Specifies the enablement value of Argo Smart Routing."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the zone associated with the API call.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Specifies if the setting is editable."},{"name":"modified_on","type":"Time","description":"Specifies the time when the setting was last modified."}]}]},"patch /zones/{}/argo/tiered_caching":{"operationId":"tiered-caching-patch-tiered-caching-setting","declarations":[{"kind":"resource","name":"cloudflare_argo_tiered_caching","stainlessResource":"argo.tiered_caching","methodName":"edit","snippet":"resource \"cloudflare_argo_tiered_caching\" \"example_argo_tiered_caching\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"String","description":"Enables Tiered Caching."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/cache/cache_reserve":{"operationId":"zone-cache-settings-change-cache-reserve-setting","declarations":[{"kind":"resource","name":"cloudflare_zone_cache_reserve","stainlessResource":"cache.cache_reserve","methodName":"edit","snippet":"resource \"cloudflare_zone_cache_reserve\" \"example_zone_cache_reserve\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"value","type":"String","description":"Value of the Cache Reserve zone setting."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/cache/regional_tiered_cache":{"operationId":"zone-cache-settings-change-regional-tiered-cache-setting","declarations":[{"kind":"resource","name":"cloudflare_regional_tiered_cache","stainlessResource":"cache.regional_tiered_cache","methodName":"edit","snippet":"resource \"cloudflare_regional_tiered_cache\" \"example_regional_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"value","type":"String","description":"Value of the Regional Tiered Cache zone setting."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/cache/variants":{"operationId":"zone-cache-settings-change-variants-setting","declarations":[{"kind":"resource","name":"cloudflare_zone_cache_variants","stainlessResource":"cache.variants","methodName":"edit","snippet":"resource \"cloudflare_zone_cache_variants\" \"example_zone_cache_variants\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = {\n avif = [\"image/webp\", \"image/jpeg\"]\n bmp = [\"image/webp\", \"image/jpeg\"]\n gif = [\"image/webp\", \"image/jpeg\"]\n jp2 = [\"image/webp\", \"image/avif\"]\n jpeg = [\"image/webp\", \"image/avif\"]\n jpg = [\"image/webp\", \"image/avif\"]\n jpg2 = [\"image/webp\", \"image/avif\"]\n png = [\"image/webp\", \"image/avif\"]\n tif = [\"image/webp\", \"image/avif\"]\n tiff = [\"image/webp\", \"image/avif\"]\n webp = [\"image/jpeg\", \"image/avif\"]\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"Attributes","description":"Value of the zone setting.","children":[{"name":"avif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for avif."},{"name":"bmp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for bmp."},{"name":"gif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for gif."},{"name":"jp2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jp2."},{"name":"jpeg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpeg."},{"name":"jpg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg."},{"name":"jpg2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg2."},{"name":"png","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for png."},{"name":"tif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tif."},{"name":"tiff","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tiff."},{"name":"webp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for webp."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/ct/alerting":{"operationId":"ct-alerting-update-subscription","declarations":[{"kind":"resource","name":"cloudflare_ct_alerting","stainlessResource":"zones.ct.alerting","methodName":"edit","snippet":"resource \"cloudflare_ct_alerting\" \"example_ct_alerting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n emails = [\"security@example.com\", \"admin@example.com\"]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether CT alerting is enabled for the zone."}],"optional":[{"name":"emails","type":"List[String]","description":"Email addresses that receive CT alert notifications for the zone. A maximum of 100 addresses may be configured. Each address must be a valid RFC 5322 email address and must not contain a comma.\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"patch /zones/{}/devices/policy/certificates":{"operationId":"devices-update-policy-certificates","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_default_profile_certificates","stainlessResource":"zero_trust.devices.policies.default.certificates","methodName":"edit","snippet":"resource \"cloudflare_zero_trust_device_default_profile_certificates\" \"example_zero_trust_device_default_profile_certificates\" {\n zone_id = \"699d98642c564d2e855e9661899b7252\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool","description":"The current status of the device policy certificate provisioning feature for WARP clients."}],"optional":[],"computed":[]}]},"patch /zones/{}/dnssec":{"operationId":"dnssec-edit-dnssec-status","declarations":[{"kind":"resource","name":"cloudflare_zone_dnssec","stainlessResource":"dns.dnssec","methodName":"edit","snippet":"resource \"cloudflare_zone_dnssec\" \"example_zone_dnssec\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dnssec_multi_signer = false\n dnssec_presigned = true\n dnssec_use_nsec3 = false\n status = \"active\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"dnssec_multi_signer","type":"Bool","description":"If true, multi-signer DNSSEC is enabled on the zone, allowing multiple\nproviders to serve a DNSSEC-signed zone at the same time.\nThis is required for DNSKEY records (except those automatically\ngenerated by Cloudflare) to be added to the zone.\n\nSee [Multi-signer DNSSEC](https://developers.cloudflare.com/dns/dnssec/multi-signer-dnssec/) for details."},{"name":"dnssec_presigned","type":"Bool","description":"If true, allows Cloudflare to transfer in a DNSSEC-signed zone\nincluding signatures from an external provider, without requiring\nCloudflare to sign any records on the fly.\n\nNote that this feature has some limitations.\nSee [Cloudflare as Secondary](https://developers.cloudflare.com/dns/zone-setups/zone-transfers/cloudflare-as-secondary/setup/#dnssec) for details."},{"name":"dnssec_use_nsec3","type":"Bool","description":"If true, enables the use of NSEC3 together with DNSSEC on the zone.\nCombined with setting dnssec_presigned to true, this enables the use of\nNSEC3 records when transferring in from an external provider.\nIf dnssec_presigned is instead set to false (default), NSEC3 records will be\ngenerated and signed at request time.\n\nSee [DNSSEC with NSEC3](https://developers.cloudflare.com/dns/dnssec/enable-nsec3/) for details."},{"name":"status","type":"String","description":"Status of DNSSEC, based on user-desired state and presence of necessary records."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"algorithm","type":"String","description":"Algorithm key code."},{"name":"digest","type":"String","description":"Digest hash."},{"name":"digest_algorithm","type":"String","description":"Type of digest algorithm."},{"name":"digest_type","type":"String","description":"Coded type for digest algorithm."},{"name":"ds","type":"String","description":"Full DS record."},{"name":"flags","type":"Float64","description":"Flag for DNSSEC record."},{"name":"key_tag","type":"Float64","description":"Code for key tag."},{"name":"key_type","type":"String","description":"Algorithm key type."},{"name":"modified_on","type":"Time","description":"When DNSSEC was last modified."},{"name":"public_key","type":"String","description":"Public key for DS record."}]}]},"patch /zones/{}/managed_headers":{"operationId":"updateManagedTransforms","declarations":[{"kind":"resource","name":"cloudflare_managed_transforms","stainlessResource":"managed_transforms","methodName":"edit","snippet":"resource \"cloudflare_managed_transforms\" \"example_managed_transforms\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n managed_request_headers = [{\n id = \"add_bot_protection_headers\"\n enabled = true\n }]\n managed_response_headers = [{\n id = \"add_security_headers\"\n enabled = true\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone.","requiresReplace":true}],"optional":[{"name":"managed_request_headers","type":"List[Attributes]","description":"The list of Managed Request Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]},{"name":"managed_response_headers","type":"List[Attributes]","description":"The list of Managed Response Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]}],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone.","requiresReplace":true}]}]},"patch /zones/{}/observability/tracing/settings":{"operationId":"zone.observability.tracing.settings.update","declarations":[{"kind":"resource","name":"cloudflare_zone_tracing","stainlessResource":"zones.observability.tracing.settings","methodName":"update","snippet":"resource \"cloudflare_zone_tracing\" \"example_zone_tracing\" {\n zone_id = \"zone_id\"\n destinations = [\"x\"]\n enabled = true\n forward_context = true\n persist = true\n propagation_policy = \"accept\"\n sampling_ratio = 0\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID.","requiresReplace":true}],"optional":[{"name":"enabled","type":"Bool","description":"Whether Cloudflare Traces is enabled for the zone."},{"name":"forward_context","type":"Bool","description":"Whether trace context is sent externally or across a zone boundary."},{"name":"persist","type":"Bool","description":"Whether traces are persisted in Cloudflare."},{"name":"propagation_policy","type":"String","description":"When inbound trace context may be continued. Authenticated propagation is not supported yet."},{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."},{"name":"destinations","type":"List[String]","description":"Up to 100 OpenTelemetry destination identifiers that receive traces."}],"computed":[{"name":"id","type":"String","description":"Specify the zone ID.","requiresReplace":true}]}]},"patch /zones/{}/settings/{}":{"operationId":"zone-settings-edit-single-setting","declarations":[{"kind":"resource","name":"cloudflare_zone_setting","stainlessResource":"zones.settings","methodName":"edit","snippet":"resource \"cloudflare_zone_setting\" \"example_zone_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"always_online\"\n enabled = true\n}\n","required":[{"name":"setting_id","type":"String","description":"Setting name","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier","requiresReplace":true}],"optional":[{"name":"value","type":"unknown","description":"Value of the zone setting."},{"name":"enabled","type":"Bool","description":"ssl-recommender enrollment setting."}],"computed":[{"name":"id","type":"String","description":"Setting name","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)."},{"name":"modified_on","type":"Time","description":"last time this setting was modified."},{"name":"time_remaining","type":"Float64","description":"Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false."}]}]},"patch /zones/{}/settings/auto_origin_tls_kex":{"operationId":"ssl-detector-auto-origin-tls-kex-patch-enrollment","declarations":[{"kind":"resource","name":"cloudflare_zone_auto_origin_tls_kex","stainlessResource":"ssl.auto_origin_tls_kex","methodName":"edit","snippet":"resource \"cloudflare_zone_auto_origin_tls_kex\" \"example_zone_auto_origin_tls_kex\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Controls enablement of Auto-Origin TLS KEX selection for the zone."}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/settings/nel":{"operationId":"nel-settings-edit","declarations":[{"kind":"resource","name":"cloudflare_nel_setting","stainlessResource":"zones.nel","methodName":"edit","snippet":"resource \"cloudflare_nel_setting\" \"example_nel_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = {\n enabled = false\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier of the zone.","requiresReplace":true},{"name":"value","type":"Attributes","description":"The NEL configuration value.","children":[{"name":"enabled","type":"Bool","description":"Whether Network Error Logging is enabled for the zone. When enabled, browsers report network errors to Cloudflare's NEL endpoint.\n"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Zone setting identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable. This is false when the zone's plan does not include NEL or the NEL product feature is not enabled.\n"},{"name":"modified_on","type":"Time","description":"When the setting was last modified. A zero value (0001-01-01T00:00:00Z) indicates the setting has never been explicitly set and is using the default value.\n"}]}]},"patch /zones/{}/ssl/universal/settings":{"operationId":"universal-ssl-settings-for-a-zone-edit-universal-ssl-settings","declarations":[{"kind":"resource","name":"cloudflare_universal_ssl_setting","stainlessResource":"ssl.universal.settings","methodName":"edit","snippet":"resource \"cloudflare_universal_ssl_setting\" \"example_universal_ssl_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"enabled","type":"Bool","description":"Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.\n\nBy disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.\n\n* HSTS\n* Always Use HTTPS\n* Opportunistic Encryption\n* Onion Routing\n* Any Page Rules redirecting traffic to HTTPS\n\nSimilarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare's edge.\n\nIf you do not have a valid custom or advanced certificate at Cloudflare's edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"post /accounts":{"operationId":"account-creation","declarations":[{"kind":"resource","name":"cloudflare_account","stainlessResource":"accounts","methodName":"create","snippet":"resource \"cloudflare_account\" \"example_account\" {\n name = \"name\"\n standalone = true\n type = \"standard\"\n unit = {\n id = \"f267e341f3dd4697bd3b9f71dd96247f\"\n }\n}\n","required":[{"name":"name","type":"String","description":"Account name"}],"optional":[{"name":"standalone","type":"Bool","description":"Set to `true` and omit `unit` to create a standalone Free Account. If provided, this field must be `true`.","requiresReplace":true},{"name":"unit","type":"Attributes","description":"Information related to the tenant unit. Provide its ID and omit `standalone` to create the Account within an Organization. See https://developers.cloudflare.com/tenant/how-to/manage-accounts/.","requiresReplace":true,"children":[{"name":"id","type":"String","description":"Tenant unit ID"}]},{"name":"type","type":"String"},{"name":"managed_by","type":"Attributes","description":"Parent container details","children":[{"name":"parent_org_id","type":"String","description":"ID of the parent Organization, if one exists"},{"name":"parent_org_name","type":"String","description":"Name of the parent Organization, if one exists"}]},{"name":"settings","type":"Attributes","description":"Account settings","children":[{"name":"abuse_contact_email","type":"String","description":"Sets an abuse contact email to notify for abuse reports."},{"name":"enforce_twofactor","type":"Bool","description":"Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled"}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the account"}]}]},"post /accounts/{}/access/ai-controls/mcp/portals":{"operationId":"mcp-portals-api-create-portals","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_ai_controls_mcp_portal","stainlessResource":"zero_trust.access.ai_controls.mcp.portals","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_ai_controls_mcp_portal\" \"example_zero_trust_access_ai_controls_mcp_portal\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-portal\"\n hostname = \"example.com\"\n name = \"My MCP Portal\"\n allow_code_mode = true\n code_mode = \"opt_in\"\n description = \"This is my custom MCP Portal\"\n secure_web_gateway = false\n servers = [{\n server_id = \"my-mcp-server\"\n default_disabled = true\n on_behalf = true\n updated_prompts = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n updated_tools = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n }]\n}\n","required":[{"name":"id","type":"String","description":"Unique identifier for the MCP portal.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"hostname","type":"String","description":"Hostname where the MCP portal is available."},{"name":"name","type":"String","description":"Display name for the MCP portal."}],"optional":[{"name":"allow_code_mode","type":"Bool","description":"Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.","deprecated":"Deprecated."},{"name":"code_mode","type":"String","description":"Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400."},{"name":"description","type":"String","description":"Optional description of the MCP portal."},{"name":"servers","type":"Set[Attributes]","description":"MCP servers attached to the portal and their portal-specific settings.","children":[{"name":"server_id","type":"String","description":"Unique identifier for the MCP server."},{"name":"default_disabled","type":"Bool","description":"Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in this server entry's updated_tools or updated_prompts fields when creating or updating the portal."},{"name":"on_behalf","type":"Bool","description":"Use end-user OAuth credentials when connecting this server to the portal."},{"name":"updated_prompts","type":"List[Attributes]","description":"Portal-specific prompt overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Portal-specific tool overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]}]},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound MCP traffic through Zero Trust Secure Web Gateway."}],"computed":[{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"}]}]},"post /accounts/{}/access/ai-controls/mcp/servers":{"operationId":"mcp-portals-api-create-servers","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_ai_controls_mcp_server","stainlessResource":"zero_trust.access.ai_controls.mcp.servers","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_ai_controls_mcp_server\" \"example_zero_trust_access_ai_controls_mcp_server\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-server\"\n auth_type = \"unauthenticated\"\n hostname = \"https://example.com/mcp\"\n name = \"My MCP Server\"\n auth_credentials = \"sk-my-bearer-token\"\n client_secret = \"client_secret\"\n description = \"This is one remote MCP server\"\n is_shared_oauth_callback_enabled = true\n secure_web_gateway = false\n updated_prompts = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n updated_tools = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n}\n","required":[{"name":"id","type":"String","description":"Unique identifier for the MCP server.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server.","requiresReplace":true},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint.","requiresReplace":true},{"name":"name","type":"String","description":"Display name for the MCP server."}],"optional":[{"name":"auth_credentials","type":"String","description":"Static credential for the upstream MCP server. For auth_type \"bearer\", either a raw token string (e.g. \"sk-abc123\"), which is wrapped server-side as `Authorization: Bearer `, or a JSON-encoded object of the form `{\"headers\":{\"Header-Name\":\"value\",...}}` for custom or multiple static headers (e.g. Cloudflare Access service tokens: `{\"headers\":{\"cf-access-client-id\":\"...\",\"cf-access-client-secret\":\"...\"}}`).","sensitive":true},{"name":"client_secret","type":"String","description":"Pre-registered OAuth client_secret. Write-only - accepted on create/update when auth_credentials.auth_mode is 'manual'. Stored AES-GCM-encrypted in server_oauth_secrets; never returned by read endpoints.","sensitive":true},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"updated_prompts","type":"List[Attributes]","description":"Server-wide prompt capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Server-wide tool capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."}],"computed":[{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"error","type":"String"},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]}]}]},"post /accounts/{}/access/custom_pages":{"operationId":"access-custom-pages-create-a-custom-page","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_custom_page","stainlessResource":"zero_trust.access.custom_pages","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_custom_page\" \"example_zero_trust_access_custom_page\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_html = \"

Access Denied

\"\n name = \"name\"\n type = \"identity_denied\"\n contract_version = 0\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"custom_html","type":"String","description":"Custom page HTML."},{"name":"name","type":"String","description":"Custom page name."},{"name":"type","type":"String","description":"Custom page type."}],"optional":[{"name":"app_count","type":"Int64","description":"Number of apps the custom page is assigned to."},{"name":"contract_version","type":"Int64","description":"Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim."}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"uid","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"},{"name":"warnings","type":"List[Attributes]","description":"Advisory validation findings returned when creating or updating a template. Omitted when empty.","children":[{"name":"message","type":"String","description":"Human-readable description of the finding."},{"name":"tier","type":"String","description":"The validation tier that produced the finding (e.g. html, liquid)."},{"name":"ref","type":"String","description":"Optional pointer to the part of the template the finding refers to."}]}]}]},"post /accounts/{}/access/policies":{"operationId":"access-policies-create-an-access-reusable-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_policy","stainlessResource":"zero_trust.access.policies","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_policy\" \"example_zero_trust_access_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n decision = \"allow\"\n include = [{\n certificate = {\n\n }\n }]\n name = \"Allow devs\"\n approval_groups = [{\n approvals_needed = 1\n email_addresses = [\"test1@cloudflare.com\", \"test2@cloudflare.com\"]\n email_list_uuid = \"email_list_uuid\"\n }, {\n approvals_needed = 3\n email_addresses = [\"test@cloudflare.com\", \"test2@cloudflare.com\"]\n email_list_uuid = \"597147a1-976b-4ef2-9af0-81d5d007fc34\"\n }]\n approval_required = true\n connection_rules = {\n rdp = {\n allowed_clipboard_local_to_remote_formats = [\"text\", \"file\"]\n allowed_clipboard_remote_to_local_formats = [\"text\", \"file\"]\n }\n }\n exclude = [{\n certificate = {\n\n }\n }]\n isolation_required = false\n mfa_config = {\n allowed_authenticators = [\"totp\", \"biometrics\", \"security_key\"]\n mfa_disabled = false\n session_duration = \"24h\"\n }\n purpose_justification_prompt = \"Please enter a justification for entering this protected domain.\"\n purpose_justification_required = true\n require = [{\n certificate = {\n\n }\n }]\n session_duration = \"24h\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"decision","type":"String","description":"The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action."},{"name":"name","type":"String","description":"The name of the Access policy."}],"optional":[{"name":"approval_required","type":"Bool","description":"Requires the user to request access from an administrator at the start of each session."},{"name":"isolation_required","type":"Bool","description":"Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature."},{"name":"purpose_justification_prompt","type":"String","description":"A custom message that will appear on the purpose justification screen."},{"name":"purpose_justification_required","type":"Bool","description":"Require users to enter a justification when they log in to the application."},{"name":"session_duration","type":"String","description":"The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h."},{"name":"approval_groups","type":"Set[Attributes]","description":"Administrators who can approve a temporary authentication request.","children":[{"name":"approvals_needed","type":"Float64","description":"The number of approvals needed to obtain access."},{"name":"email_addresses","type":"List[String]","description":"A list of emails that can approve the access request."},{"name":"email_list_uuid","type":"String","description":"The UUID of an re-usable email list."}]},{"name":"connection_rules","type":"Attributes","description":"The rules that define how users may connect to targets secured by your application.","children":[{"name":"rdp","type":"Attributes","description":"The RDP-specific rules that define clipboard behavior for RDP connections.","children":[{"name":"allowed_clipboard_local_to_remote_formats","type":"List[String]","description":"Clipboard formats allowed when copying from local machine to remote RDP session."},{"name":"allowed_clipboard_remote_to_local_formats","type":"List[String]","description":"Clipboard formats allowed when copying from remote RDP session to local machine."}]}]},{"name":"mfa_config","type":"Attributes","description":"Configures multi-factor authentication (MFA) settings.","children":[{"name":"allowed_authenticators","type":"List[String]","description":"Lists the MFA methods that users can authenticate with."},{"name":"mfa_disabled","type":"Bool","description":"Indicates whether to disable MFA for this resource. This option is available at the application and policy level."},{"name":"session_duration","type":"String","description":"Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`."}]},{"name":"exclude","type":"Set[Attributes]","description":"Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"include","type":"Set[Attributes]","description":"Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"require","type":"Set[Attributes]","description":"Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]}],"computed":[{"name":"id","type":"String","description":"The UUID of the policy"},{"name":"app_count","type":"Int64","description":"Number of access applications currently using this policy."},{"name":"created_at","type":"Time"},{"name":"reusable","type":"Bool"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/access/tags":{"operationId":"access-tags-create-tag","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_tag","stainlessResource":"zero_trust.access.tags","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_tag\" \"example_zero_trust_access_tag\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"engineers\"\n}\n","required":[{"name":"name","type":"String","description":"The name of the tag","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"The name of the tag","requiresReplace":true},{"name":"app_count","type":"Int64","description":"The number of applications that have this tag"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/addressing/address_maps":{"operationId":"ip-address-management-address-maps-create-address-map","declarations":[{"kind":"resource","name":"cloudflare_address_map","stainlessResource":"addressing.address_maps","methodName":"create","snippet":"resource \"cloudflare_address_map\" \"example_address_map\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n description = \"My Ecommerce zones\"\n enabled = true\n ips = [\"192.0.2.1\"]\n memberships = [{\n identifier = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"zone\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account.","requiresReplace":true}],"optional":[{"name":"ips","type":"List[String]","requiresReplace":true},{"name":"memberships","type":"List[Attributes]","description":"Zones and Accounts which will be assigned IPs on this Address Map. A zone membership will take priority over an account membership.","requiresReplace":true,"children":[{"name":"identifier","type":"String","description":"The identifier for the membership (eg. a zone or account tag)."},{"name":"kind","type":"String","description":"The type of the membership."}]},{"name":"default_sni","type":"String","description":"If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account."},{"name":"description","type":"String","description":"An optional description field which may be used to describe the types of IPs or zones on the map."},{"name":"enabled","type":"Bool","description":"Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled."}],"computed":[{"name":"id","type":"String","description":"Identifier of an Address Map."},{"name":"can_delete","type":"Bool","description":"If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps."},{"name":"can_modify_ips","type":"Bool","description":"If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps."},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/addressing/prefixes":{"operationId":"ip-address-management-prefixes-add-prefix","declarations":[{"kind":"resource","name":"cloudflare_byo_ip_prefix","stainlessResource":"addressing.prefixes","methodName":"create","snippet":"resource \"cloudflare_byo_ip_prefix\" \"example_byo_ip_prefix\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n asn = 13335\n cidr = \"192.0.2.0/24\"\n delegate_loa_creation = true\n description = \"Internal test prefix\"\n loa_document_id = \"d933b1530bc56c9953cf8ce166da8004\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account.","requiresReplace":true},{"name":"asn","type":"Int64","description":"Autonomous System Number (ASN) the prefix will be advertised under.","requiresReplace":true},{"name":"cidr","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format.","requiresReplace":true}],"optional":[{"name":"loa_document_id","type":"String","description":"Identifier for the uploaded LOA document.","requiresReplace":true},{"name":"delegate_loa_creation","type":"Bool","description":"Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner.","requiresReplace":true},{"name":"description","type":"String","description":"Description of the prefix."}],"computed":[{"name":"id","type":"String","description":"Identifier of an IP Prefix."},{"name":"advertised","type":"Bool","description":"Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"advertised_modified_at","type":"Time","description":"Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"approved","type":"String","description":"Approval state of the prefix (P = pending, V = active)."},{"name":"created_at","type":"Time"},{"name":"irr_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"modified_at","type":"Time"},{"name":"on_demand_enabled","type":"Bool","description":"Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"on_demand_locked","type":"Bool","description":"Whether advertisement status of the prefix is locked, meaning it cannot be changed.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"ownership_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"ownership_validation_token","type":"String","description":"Token provided to demonstrate ownership of the prefix."},{"name":"rpki_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."}]}]},"post /accounts/{}/ai-gateway/gateways":{"operationId":"aig-config-create-gateway","declarations":[{"kind":"resource","name":"cloudflare_ai_gateway","stainlessResource":"ai_gateway","methodName":"create","snippet":"resource \"cloudflare_ai_gateway\" \"example_ai_gateway\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n id = \"my-gateway\"\n cache_invalidate_on_update = true\n cache_ttl = 0\n collect_logs = true\n rate_limiting_interval = 0\n rate_limiting_limit = 0\n authentication = true\n byok_only = true\n dlp = {\n action = \"BLOCK\"\n enabled = true\n profiles = [\"string\"]\n }\n guardrails = {\n prompt = {\n p1 = \"FLAG\"\n s1 = \"FLAG\"\n s10 = \"FLAG\"\n s11 = \"FLAG\"\n s12 = \"FLAG\"\n s13 = \"FLAG\"\n s2 = \"FLAG\"\n s3 = \"FLAG\"\n s4 = \"FLAG\"\n s5 = \"FLAG\"\n s6 = \"FLAG\"\n s7 = \"FLAG\"\n s8 = \"FLAG\"\n s9 = \"FLAG\"\n }\n response = {\n p1 = \"FLAG\"\n s1 = \"FLAG\"\n s10 = \"FLAG\"\n s11 = \"FLAG\"\n s12 = \"FLAG\"\n s13 = \"FLAG\"\n s2 = \"FLAG\"\n s3 = \"FLAG\"\n s4 = \"FLAG\"\n s5 = \"FLAG\"\n s6 = \"FLAG\"\n s7 = \"FLAG\"\n s8 = \"FLAG\"\n s9 = \"FLAG\"\n }\n }\n log_classification = true\n log_management = 10000\n log_management_strategy = \"STOP_INSERTING\"\n logpush = true\n logpush_public_key = \"xxxxxxxxxxxxxxxx\"\n otel = [{\n headers = {\n foo = \"string\"\n }\n url = \"https://example.com\"\n authorization = \"authorization\"\n content_type = \"json\"\n }]\n rate_limiting_technique = \"fixed\"\n retry_backoff = \"constant\"\n retry_delay = 0\n retry_max_attempts = 1\n spend_limits = {\n enabled = true\n rules = [{\n limit = 1\n limit_type = \"cost\"\n window = 1\n id = \"x\"\n enabled = true\n metadata = {\n foo = {\n mode = \"partition\"\n }\n }\n model = {\n mode = \"filter\"\n values = [\"string\"]\n }\n ai_gateway_provider = {\n mode = \"filter\"\n values = [\"string\"]\n }\n technique = \"fixed\"\n }]\n }\n store_id = \"store_id\"\n stripe = {\n authorization = \"authorization\"\n usage_events = [{\n payload = \"payload\"\n }]\n }\n workers_ai_billing_mode = \"postpaid\"\n zdr = true\n}\n","required":[{"name":"id","type":"String","description":"Unique identifier of the AI Gateway within the account.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"cache_invalidate_on_update","type":"Bool"},{"name":"cache_ttl","type":"Int64"},{"name":"collect_logs","type":"Bool"},{"name":"rate_limiting_interval","type":"Int64"},{"name":"rate_limiting_limit","type":"Int64"}],"optional":[{"name":"logpush_public_key","type":"String"},{"name":"rate_limiting_technique","type":"String"},{"name":"retry_backoff","type":"String","description":"Backoff strategy for retry delays"},{"name":"retry_delay","type":"Int64","description":"Delay between retry attempts in milliseconds (0-60000)"},{"name":"retry_max_attempts","type":"Int64","description":"Maximum number of retry attempts for failed requests (1-5)"},{"name":"dlp","type":"Attributes","children":[{"name":"action","type":"String"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"},{"name":"policies","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"action","type":"String"},{"name":"check","type":"List[String]"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"}]}]},{"name":"guardrails","type":"Attributes","children":[{"name":"prompt","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]},{"name":"response","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]}]},{"name":"stripe","type":"Attributes","children":[{"name":"authorization","type":"String"},{"name":"usage_events","type":"List[Attributes]","children":[{"name":"payload","type":"String"}]}]},{"name":"authentication","type":"Bool"},{"name":"byok_only","type":"Bool","description":"Requires customer-provided provider credentials and prevents fallback to Unified Billing."},{"name":"log_classification","type":"Bool"},{"name":"log_management","type":"Int64"},{"name":"log_management_strategy","type":"String"},{"name":"logpush","type":"Bool"},{"name":"store_id","type":"String"},{"name":"workers_ai_billing_mode","type":"String","description":"Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway."},{"name":"zdr","type":"Bool"},{"name":"otel","type":"List[Attributes]","children":[{"name":"headers","type":"Map[String]"},{"name":"url","type":"String"},{"name":"authorization","type":"String"},{"name":"content_type","type":"String"}]},{"name":"spend_limits","type":"Attributes","children":[{"name":"enabled","type":"Bool"},{"name":"rules","type":"List[Attributes]","children":[{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Int64"},{"name":"id","type":"String"},{"name":"enabled","type":"Bool"},{"name":"metadata","type":"Map[Attributes]","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"model","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"ai_gateway_provider","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"technique","type":"String"}]}]}],"computed":[{"name":"created_at","type":"Time"},{"name":"is_default","type":"Bool"},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/ai-gateway/gateways/{}/routes":{"operationId":"aig-config-post-gateway-dynamic-route","declarations":[{"kind":"resource","name":"cloudflare_ai_gateway_dynamic_routing","stainlessResource":"ai_gateway.dynamic_routing","methodName":"create","snippet":"resource \"cloudflare_ai_gateway_dynamic_routing\" \"example_ai_gateway_dynamic_routing\" {\n account_id = \"0d37909e38d3e99c29fa2cd343ac421a\"\n gateway_id = \"54442216\"\n elements = [{\n id = \"id\"\n outputs = {\n next = {\n element_id = \"elementId\"\n }\n }\n type = \"start\"\n }]\n name = \"x\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"gateway_id","type":"String","requiresReplace":true},{"name":"elements","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"id","type":"String"},{"name":"outputs","type":"Attributes","children":[{"name":"next","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"false","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"true","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"element_id","type":"String"},{"name":"fallback","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"success","type":"Attributes","children":[{"name":"element_id","type":"String"}]}]},{"name":"type","type":"String"},{"name":"properties","type":"Attributes","children":[{"name":"conditions","type":"unknown"},{"name":"key","type":"String"},{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Float64"},{"name":"model","type":"String"},{"name":"ai_gateway_dynamic_routing_provider","type":"String"},{"name":"retries","type":"Float64"},{"name":"timeout","type":"Float64"}]}]},{"name":"name","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"success","type":"Bool"},{"name":"deployment","type":"Attributes","children":[{"name":"created_at","type":"String"},{"name":"deployment_id","type":"String"},{"name":"version_id","type":"String"}]},{"name":"route","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"account_tag","type":"String"},{"name":"created_at","type":"Time"},{"name":"deployment","type":"Attributes","children":[{"name":"created_at","type":"String"},{"name":"deployment_id","type":"String"},{"name":"version_id","type":"String"}]},{"name":"elements","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"outputs","type":"Attributes","children":[{"name":"next","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"false","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"true","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"element_id","type":"String"},{"name":"fallback","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"success","type":"Attributes","children":[{"name":"element_id","type":"String"}]}]},{"name":"type","type":"String"},{"name":"properties","type":"Attributes","children":[{"name":"conditions","type":"unknown"},{"name":"key","type":"String"},{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Float64"},{"name":"model","type":"String"},{"name":"ai_gateway_dynamic_routing_provider","type":"String"},{"name":"retries","type":"Float64"},{"name":"timeout","type":"Float64"}]}]},{"name":"gateway_id","type":"String"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String"},{"name":"version","type":"Attributes","children":[{"name":"active","type":"String"},{"name":"created_at","type":"String"},{"name":"data","type":"String"},{"name":"version_id","type":"String"},{"name":"is_valid","type":"Bool"}]}]},{"name":"version","type":"Attributes","children":[{"name":"active","type":"String"},{"name":"created_at","type":"String"},{"name":"data","type":"String"},{"name":"version_id","type":"String"},{"name":"is_valid","type":"Bool"}]}]}]},"post /accounts/{}/ai-search/instances":{"operationId":"ai-search-create-instance","declarations":[{"kind":"resource","name":"cloudflare_ai_search_instance","stainlessResource":"ai_search.instances","methodName":"create","snippet":"resource \"cloudflare_ai_search_instance\" \"example_ai_search_instance\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n id = \"my-ai-search\"\n ai_gateway_id = \"ai_gateway_id\"\n aisearch_model = \"ai_search_model\"\n cache = true\n cache_threshold = \"super_strict_match\"\n cache_ttl = 600\n chunk = true\n chunk_overlap = 0\n chunk_size = 64\n custom_metadata = [{\n data_type = \"text\"\n field_name = \"x\"\n }]\n embedding_model = \"embedding_model\"\n fusion_method = \"max\"\n hybrid_search_enabled = true\n index_method = {\n keyword = true\n vector = true\n }\n indexing_options = {\n keyword_tokenizer = \"porter\"\n use_ocr = true\n }\n max_num_results = 1\n metadata = {\n created_from_aisearch_wizard = true\n worker_domain = \"worker_domain\"\n }\n public_endpoint_params = {\n authorized_hosts = [\"string\"]\n chat_completions_endpoint = {\n disabled = true\n }\n custom_domains = [\"search.example.com\"]\n default_domain_enabled = true\n enabled = true\n mcp = {\n description = \"description\"\n disabled = true\n }\n rate_limit = {\n period_ms = 60000\n requests = 1\n technique = \"fixed\"\n }\n search_endpoint = {\n disabled = true\n }\n }\n reranking = true\n reranking_model = \"reranking_model\"\n retrieval_options = {\n boost_by = [{\n field = \"timestamp\"\n direction = \"desc\"\n }]\n keyword_match_mode = \"and\"\n }\n rewrite_model = \"rewrite_model\"\n rewrite_query = true\n score_threshold = 0\n source = \"source\"\n source_params = {\n exclude_items = [\"/admin/**\", \"/private/**\", \"**\\\\temp\\\\**\"]\n include_items = [\"/blog/**\", \"/docs/**/*.html\", \"**\\\\blog\\\\**.html\"]\n prefix = \"prefix\"\n r2_jurisdiction = \"r2_jurisdiction\"\n web_crawler = {\n discover_options = {\n depth = 5\n include_external_links = false\n include_subdomains = false\n limit = 10000\n max_age = 86400\n source = \"all\"\n }\n parse_options = {\n content_selector = [{\n path = \"**/blog/**\"\n selector = \"article div.post-body\"\n }, {\n path = \"**/docs/**\"\n selector = \"main\"\n }]\n include_headers = {\n cache-control = \"no-cache, no-store\"\n }\n include_images = true\n specific_sitemaps = [\"https://example.com/sitemap.xml\", \"https://example.com/blog-sitemap.xml\"]\n use_browser_rendering = true\n }\n parse_type = \"sitemap\"\n }\n }\n sync_interval = 900\n token_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n type = \"r2\"\n}\n","required":[{"name":"id","type":"String","description":"AI Search instance ID. Lowercase alphanumeric, hyphens, and underscores.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"type","type":"String","description":"Source type. When omitted or null with a non-blank source, HTTP(S) URLs infer web-crawler and existing R2 bucket names infer r2. A missing or blank source without a type uses managed upload-only storage.","requiresReplace":true},{"name":"hybrid_search_enabled","type":"Bool","description":"Deprecated — use index_method instead. Defaults to true for new instances; set false to create a vector-only instance.","deprecated":"Deprecated.","requiresReplace":true},{"name":"ai_gateway_id","type":"String"},{"name":"aisearch_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"chunk_size","type":"Int64"},{"name":"embedding_model","type":"String"},{"name":"reranking_model","type":"String"},{"name":"rewrite_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"source","type":"String"},{"name":"summarization_model","type":"String"},{"name":"system_prompt_aisearch","type":"String"},{"name":"system_prompt_index_summarization","type":"String"},{"name":"system_prompt_rewrite_query","type":"String"},{"name":"token_id","type":"String"},{"name":"custom_metadata","type":"List[Attributes]","children":[{"name":"data_type","type":"String"},{"name":"field_name","type":"String"}]},{"name":"metadata","type":"Attributes","children":[{"name":"created_from_aisearch_wizard","type":"Bool"},{"name":"worker_domain","type":"String"}]},{"name":"retrieval_options","type":"Attributes","children":[{"name":"boost_by","type":"List[Attributes]","description":"Metadata fields to boost search results by. Each entry specifies a metadata field and an optional direction. Direction defaults to 'asc' for numeric/datetime fields and 'exists' for text/boolean fields. Fields must match 'timestamp' or a defined custom_metadata field.","children":[{"name":"field","type":"String","description":"Metadata field name to boost by. Use 'timestamp' for document freshness, or any custom_metadata field. Numeric and datetime fields support all four directions (asc, desc, exists, not_exists); text/boolean fields only support exists/not_exists."},{"name":"direction","type":"String","description":"Boost direction. 'desc' = higher values rank higher (e.g. newer timestamps). 'asc' = lower values rank higher. 'exists' = boost chunks that have the field. 'not_exists' = boost chunks that lack the field. Optional — defaults to 'asc' for numeric/datetime fields, 'exists' for text/boolean fields."}]},{"name":"keyword_match_mode","type":"String","description":"Controls which documents are candidates for BM25 scoring. 'and' restricts candidates to documents containing all query terms; 'or' includes any document containing at least one term, ranked by BM25 relevance. When omitted on an update, the existing stored value is preserved; when never set, search falls back to 'and'."}]},{"name":"cache","type":"Bool"},{"name":"cache_threshold","type":"String"},{"name":"cache_ttl","type":"Float64","description":"Cache entry TTL in seconds. Allowed values: 600 (10min), 1800 (30min), 3600 (1h), 7200 (2h), 21600 (6h), 43200 (12h), 86400 (24h), 172800 (48h), 259200 (72h), 518400 (6d)."},{"name":"chunk","type":"Bool"},{"name":"chunk_overlap","type":"Int64"},{"name":"fusion_method","type":"String"},{"name":"max_num_results","type":"Int64"},{"name":"paused","type":"Bool"},{"name":"reranking","type":"Bool"},{"name":"rewrite_query","type":"Bool"},{"name":"score_threshold","type":"Float64"},{"name":"summarization","type":"Bool"},{"name":"sync_interval","type":"Float64","description":"Interval between automatic syncs, in seconds. Allowed values: 900 (15min), 1800 (30min), 3600 (1h), 7200 (2h), 14400 (4h), 21600 (6h), 43200 (12h), 86400 (24h)."},{"name":"index_method","type":"Attributes","description":"Controls which storage backends are used during indexing. Defaults to vector and keyword indexing for new instances.","children":[{"name":"keyword","type":"Bool","description":"Enable keyword (BM25) storage backend."},{"name":"vector","type":"Bool","description":"Enable vector (embedding) storage backend."}]},{"name":"indexing_options","type":"Attributes","children":[{"name":"keyword_tokenizer","type":"String","description":"Tokenizer used for keyword search indexing. porter provides word-level tokenization with Porter stemming (good for natural language queries). trigram enables character-level substring matching (good for partial matches, code, identifiers). Changing this triggers a full re-index. Defaults to porter."},{"name":"use_ocr","type":"Bool","description":"Enables OCR ingestion for PDFs and images. Changing this triggers a full re-index. Defaults to false."}]},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]},{"name":"source_params","type":"Attributes","children":[{"name":"exclude_items","type":"List[String]","description":"List of path patterns to exclude. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /admin/** matches /admin/users and /admin/settings/advanced). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"include_items","type":"List[String]","description":"List of path patterns to include. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /blog/** matches /blog/post and /blog/2024/post). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"prefix","type":"String"},{"name":"r2_jurisdiction","type":"String"},{"name":"web_crawler","type":"Attributes","children":[{"name":"discover_options","type":"Attributes","description":"Options for parse_type 'discover', where Browser Run discovers URLs by link following and sitemaps. Ignored for 'sitemap'.","children":[{"name":"depth","type":"Float64","description":"Maximum link-follow depth from the seed URL."},{"name":"include_external_links","type":"Bool","description":"Follow links that point outside the source domain. Must stay `false` — discover crawls are restricted to the zone you own."},{"name":"include_subdomains","type":"Bool","description":"Follow links to subdomains of the source host."},{"name":"limit","type":"Float64","description":"Maximum number of pages to crawl (1-100000)."},{"name":"max_age","type":"Float64","description":"Maximum content age in seconds to accept (0–604800)."},{"name":"source","type":"String","description":"Where the crawler looks for URLs: 'sitemaps' reads sitemap XML only, 'links' follows page links only, 'all' does both."}]},{"name":"parse_options","type":"Attributes","children":[{"name":"content_selector","type":"List[Attributes]","description":"List of path-to-selector mappings for extracting specific content from crawled pages. Each entry pairs a URL glob pattern with a CSS selector. The first matching path wins. Only the matched HTML fragment is stored and indexed. Omit the field to disable content selection — empty arrays are rejected.","children":[{"name":"path","type":"String","description":"Glob pattern to match against the page URL path. Uses standard glob syntax: * matches within a segment, ** crosses directories."},{"name":"selector","type":"String","description":"CSS selector to extract content from pages matching the path pattern. Must not contain disallowed characters (;, `, $, {, }, \\). Must target a single element; if multiple elements match, the selector is ignored and the full page is used."}]},{"name":"include_headers","type":"Map[String]","description":"Up to 5 custom HTTP headers sent with each crawl request. Names must be RFC-7230 token characters (no spaces, colons, or control characters); values must be HTAB + printable ASCII (no CR/LF)."},{"name":"include_images","type":"Bool"},{"name":"specific_sitemaps","type":"List[String]","description":"List of specific sitemap URLs to use for crawling. Only valid when parse_type is 'sitemap'."},{"name":"use_browser_rendering","type":"Bool"}]},{"name":"parse_type","type":"String","description":"How URLs are discovered. 'sitemap' reads XML sitemaps; 'discover' follows links recursively and requires the source to be a Verified zone on this account."}]}]}],"computed":[{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"enable","type":"Bool"},{"name":"engine_version","type":"Float64"},{"name":"last_activity","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"namespace","type":"String"},{"name":"public_endpoint_id","type":"String"},{"name":"status","type":"String"}]}]},"post /accounts/{}/ai-search/namespaces":{"operationId":"ai-search-create-namespace","declarations":[{"kind":"resource","name":"cloudflare_ai_search_namespace","stainlessResource":"ai_search.namespaces","methodName":"create","snippet":"resource \"cloudflare_ai_search_namespace\" \"example_ai_search_namespace\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n name = \"name\"\n description = \"Production environment\"\n public_endpoint_params = {\n authorized_hosts = [\"string\"]\n chat_completions_endpoint = {\n disabled = true\n }\n custom_domains = [\"search.example.com\"]\n default_domain_enabled = true\n enabled = true\n instances_allowed = [\"docs\", \"blog\"]\n mcp = {\n description = \"description\"\n disabled = true\n }\n rate_limit = {\n period_ms = 60000\n requests = 1\n technique = \"fixed\"\n }\n search_endpoint = {\n disabled = true\n }\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","requiresReplace":true}],"optional":[{"name":"description","type":"String","description":"Optional description for the namespace. Max 256 characters."},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"instances_allowed","type":"List[String]","description":"Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit."},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]}],"computed":[{"name":"created_at","type":"Time"},{"name":"public_endpoint_id","type":"String"}]}]},"post /accounts/{}/ai-search/tokens":{"operationId":"ai-search-create-tokens","declarations":[{"kind":"resource","name":"cloudflare_ai_search_token","stainlessResource":"ai_search.tokens","methodName":"create","snippet":"resource \"cloudflare_ai_search_token\" \"example_ai_search_token\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n cf_api_id = \"a1b2c3d4e5f6\"\n cf_api_key = \"abc123\"\n name = \"my-token\"\n legacy = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"cf_api_id","type":"String"},{"name":"cf_api_key","type":"String","sensitive":true},{"name":"name","type":"String"}],"optional":[{"name":"legacy","type":"Bool"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"enabled","type":"Bool"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"}]}]},"post /accounts/{}/alerting/v3/destinations/webhooks":{"operationId":"notification-webhooks-create-a-webhook","declarations":[{"kind":"resource","name":"cloudflare_notification_policy_webhooks","stainlessResource":"alerting.destinations.webhooks","methodName":"create","snippet":"resource \"cloudflare_notification_policy_webhooks\" \"example_notification_policy_webhooks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Slack Webhook\"\n url = \"https://hooks.slack.com/services/Ds3fdBFbV/456464Gdd\"\n secret = \"secret\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account id","requiresReplace":true},{"name":"name","type":"String","description":"The name of the webhook destination. This will be included in the request body when you receive a webhook notification."},{"name":"url","type":"String","description":"The POST endpoint to call when dispatching a notification."}],"optional":[{"name":"secret","type":"String","description":"Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.","sensitive":true}],"computed":[{"name":"id","type":"String","description":"UUID"},{"name":"created_at","type":"Time","description":"Timestamp of when the webhook destination was created."},{"name":"last_failure","type":"Time","description":"Timestamp of the last time an attempt to dispatch a notification to this webhook failed."},{"name":"last_success","type":"Time","description":"Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook."},{"name":"type","type":"String","description":"Type of webhook endpoint."}]}]},"post /accounts/{}/alerting/v3/policies":{"operationId":"notification-policies-create-a-notification-policy","declarations":[{"kind":"resource","name":"cloudflare_notification_policy","stainlessResource":"alerting.policies","methodName":"create","snippet":"resource \"cloudflare_notification_policy\" \"example_notification_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n alert_type = \"universal_ssl_event_type\"\n enabled = true\n mechanisms = {\n email = [{\n id = \"id\"\n }]\n pagerduty = [{\n id = \"f174e90afafe4643bbbc4a0ed4fc8415\"\n }]\n webhooks = [{\n id = \"f174e90afafe4643bbbc4a0ed4fc8415\"\n }]\n }\n name = \"SSL Notification Event Policy\"\n alert_interval = \"30m\"\n description = \"Something describing the policy.\"\n filters = {\n actions = [\"string\"]\n affected_asns = [\"string\"]\n affected_components = [\"string\"]\n affected_locations = [\"string\"]\n airport_code = [\"string\"]\n alert_trigger_preferences = [\"string\"]\n alert_trigger_preferences_value = [\"string\"]\n enabled = [\"string\"]\n environment = [\"string\"]\n event = [\"string\"]\n event_source = [\"string\"]\n event_type = [\"string\"]\n group_by = [\"string\"]\n health_check_id = [\"string\"]\n incident_impact = [\"INCIDENT_IMPACT_NONE\"]\n input_id = [\"string\"]\n insight_class = [\"string\"]\n limit = [\"string\"]\n logo_tag = [\"string\"]\n megabits_per_second = [\"string\"]\n new_health = [\"string\"]\n new_status = [\"string\"]\n packets_per_second = [\"string\"]\n pool_id = [\"string\"]\n pop_names = [\"string\"]\n product = [\"string\"]\n project_id = [\"string\"]\n protocol = [\"string\"]\n query_tag = [\"string\"]\n requests_per_second = [\"string\"]\n selectors = [\"string\"]\n services = [\"string\"]\n slo = [\"99.9\"]\n status = [\"string\"]\n target_hostname = [\"string\"]\n target_ip = [\"string\"]\n target_zone_name = [\"string\"]\n token_id = [\"x\"]\n traffic_exclusions = [\"security_events\"]\n tunnel_id = [\"string\"]\n tunnel_name = [\"string\"]\n type = [\"string\"]\n where = [\"string\"]\n zones = [\"string\"]\n }\n}\n","required":[{"name":"account_id","type":"String","description":"The account id","requiresReplace":true},{"name":"alert_type","type":"String","description":"Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values."},{"name":"name","type":"String","description":"Name of the policy."},{"name":"mechanisms","type":"Attributes","description":"List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.","children":[{"name":"email","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The email address"}]},{"name":"pagerduty","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]},{"name":"webhooks","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]}]}],"optional":[{"name":"alert_interval","type":"String","description":"Optional specification of how often to re-alert from the same incident, not support on all alert types."},{"name":"description","type":"String","description":"Optional description for the Notification policy."},{"name":"filters","type":"Attributes","description":"Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.","children":[{"name":"actions","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"affected_asns","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"affected_components","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"affected_locations","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"airport_code","type":"List[String]","description":"Used for configuring maintenance_event_notification"},{"name":"alert_trigger_preferences","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"alert_trigger_preferences_value","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"enabled","type":"List[String]","description":"Used for configuring load_balancing_pool_enablement_alert"},{"name":"environment","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event_source","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"event_type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"group_by","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"health_check_id","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"incident_impact","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"input_id","type":"List[String]","description":"Used for configuring stream_live_notifications"},{"name":"insight_class","type":"List[String]","description":"Used for configuring security_insights_alert"},{"name":"limit","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"logo_tag","type":"List[String]","description":"Used for configuring logo_match_alert"},{"name":"megabits_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"new_health","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"new_status","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"packets_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"pool_id","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"pop_names","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"product","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"project_id","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"protocol","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"query_tag","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"requests_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"selectors","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"services","type":"List[String]","description":"Used for configuring clickhouse_alert_fw_ent_anomaly"},{"name":"slo","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"status","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"target_hostname","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"target_ip","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"target_zone_name","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"token_id","type":"List[String]","description":"Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens."},{"name":"traffic_exclusions","type":"List[String]","description":"Used for configuring traffic_anomalies_alert"},{"name":"tunnel_id","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"tunnel_name","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"where","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"zones","type":"List[String]","description":"Usage depends on specific alert type"}]},{"name":"enabled","type":"Bool","description":"Whether or not the Notification policy is enabled."}],"computed":[{"name":"id","type":"String","description":"UUID"},{"name":"created","type":"Time"},{"name":"modified","type":"Time"}]}]},"post /accounts/{}/calls/apps":{"operationId":"calls-apps-create-a-new-app","declarations":[{"kind":"resource","name":"cloudflare_calls_sfu_app","stainlessResource":"calls.sfu","methodName":"create","snippet":"resource \"cloudflare_calls_sfu_app\" \"example_calls_sfu_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"production-realtime-app\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"app_id","type":"String","description":"A Cloudflare-generated unique identifier for a item.","requiresReplace":true},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."}],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"secret","type":"String","description":"Bearer token","sensitive":true},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"post /accounts/{}/calls/turn_keys":{"operationId":"calls-turn-key-create","declarations":[{"kind":"resource","name":"cloudflare_calls_turn_app","stainlessResource":"calls.turn","methodName":"create","snippet":"resource \"cloudflare_calls_turn_app\" \"example_calls_turn_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-turn-key\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"key_id","type":"String","description":"A Cloudflare-generated unique identifier for a item.","requiresReplace":true},{"name":"name","type":"String","description":"A short description of a TURN key, not shown to end users."}],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"key","type":"String","description":"Bearer token","sensitive":true},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"post /accounts/{}/cfd_tunnel":{"operationId":"cloudflare-tunnel-create-a-cloudflare-tunnel","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared","stainlessResource":"zero_trust.tunnels.cloudflared","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared\" \"example_zero_trust_tunnel_cloudflared\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"blog\"\n config_src = \"cloudflare\"\n tunnel_secret = \"AQIDBAUGBwgBAgMEBQYHCAECAwQFBgcIAQIDBAUGBwg=\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."}],"optional":[{"name":"config_src","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard.","requiresReplace":true},{"name":"tunnel_secret","type":"String","description":"Sets the password required to run a locally-managed tunnel. Must be at least 32 bytes and encoded as a base64 string.","sensitive":true}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"remote_config","type":"Bool","description":"If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.","deprecated":"Use the config_src field instead."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"post /accounts/{}/challenges/widgets":{"operationId":"accounts-turnstile-widget-create","declarations":[{"kind":"resource","name":"cloudflare_turnstile_widget","stainlessResource":"turnstile.widgets","methodName":"create","snippet":"resource \"cloudflare_turnstile_widget\" \"example_turnstile_widget\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domains = [\"203.0.113.1\", \"cloudflare.com\", \"blog.example.com\"]\n mode = \"invisible\"\n name = \"blog.cloudflare.com login form\"\n bot_fight_mode = false\n clearance_level = \"interactive\"\n ephemeral_id = false\n offlabel = false\n region = \"world\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"mode","type":"String","description":"Widget Mode"},{"name":"name","type":"String","description":"Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used.\n"},{"name":"domains","type":"List[String]"}],"optional":[{"name":"bot_fight_mode","type":"Bool","description":"If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only).\n"},{"name":"clearance_level","type":"String","description":"If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\n"},{"name":"ephemeral_id","type":"Bool","description":"Return the Ephemeral ID in /siteverify (ENT only).\n"},{"name":"offlabel","type":"Bool","description":"Do not show any Cloudflare branding on the widget (ENT only).\n"},{"name":"region","type":"String","description":"Region where this widget can be used. This cannot be changed after creation.\n"}],"computed":[{"name":"id","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"sitekey","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"created_on","type":"Time","description":"When the widget was created."},{"name":"deployed_via","type":"String","description":"Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\n"},{"name":"last_modified_via","type":"String","description":"Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\n"},{"name":"modified_on","type":"Time","description":"When the widget was modified."},{"name":"secret","type":"String","description":"Secret key for this widget.","sensitive":true}]}]},"post /accounts/{}/cloudforce-one/requests":{"operationId":"cloudforce-one-request-list","declarations":[{"kind":"list-data-source","name":"cloudflare_cloudforce_one_requests","stainlessResource":"cloudforce_one.requests","methodName":"list","snippet":"data \"cloudflare_cloudforce_one_requests\" \"example_cloudforce_one_requests\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n page = 0\n per_page = 10\n completed_after = \"2022-01-01T00:00:00Z\"\n completed_before = \"2024-01-01T00:00:00Z\"\n created_after = \"2022-01-01T00:00:00Z\"\n created_before = \"2024-01-01T00:00:00Z\"\n request_type = \"Victomology\"\n sort_by = \"created\"\n sort_order = \"asc\"\n status = \"open\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"page","type":"Int64","description":"Page number of results."},{"name":"per_page","type":"Int64","description":"Number of results per page."}],"optional":[{"name":"completed_after","type":"Time","description":"Retrieve requests completed after this time."},{"name":"completed_before","type":"Time","description":"Retrieve requests completed before this time."},{"name":"created_after","type":"Time","description":"Retrieve requests created after this time."},{"name":"created_before","type":"Time","description":"Retrieve requests created before this time."},{"name":"request_type","type":"String","description":"Requested information from request."},{"name":"sort_by","type":"String","description":"Field to sort results by."},{"name":"sort_order","type":"String","description":"Sort order (asc or desc)."},{"name":"status","type":"String","description":"Request Status."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created","type":"Time","description":"Request creation time."},{"name":"priority","type":"String"},{"name":"request","type":"String","description":"Requested information from request."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"updated","type":"Time","description":"Request last updated time."},{"name":"completed","type":"Time","description":"Request completion time."},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"status","type":"String","description":"Request Status."},{"name":"tokens","type":"Int64","description":"Tokens for the request."}]}]}]},"post /accounts/{}/cloudforce-one/requests/{}/asset":{"operationId":"cloudforce-one-request-asset-list","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request_asset","stainlessResource":"cloudforce_one.requests.assets","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request_asset\" \"example_cloudforce_one_request_asset\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n page = 0\n per_page = 10\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"request_id","type":"String","description":"UUID.","requiresReplace":true},{"name":"page","type":"Int64","description":"Page number of results.","requiresReplace":true},{"name":"per_page","type":"Int64","description":"Number of results per page.","requiresReplace":true}],"optional":[{"name":"source","type":"String","description":"Asset file to upload."}],"computed":[{"name":"id","type":"Int64","description":"Asset ID."},{"name":"created","type":"Time","description":"Defines the asset creation time."},{"name":"description","type":"String","description":"Asset description."},{"name":"file_type","type":"String","description":"Asset file type."},{"name":"name","type":"String","description":"Asset name."}]}]},"post /accounts/{}/cloudforce-one/requests/{}/message":{"operationId":"cloudforce-one-request-message-list","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request_message","stainlessResource":"cloudforce_one.requests.message","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request_message\" \"example_cloudforce_one_request_message\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n page = 0\n per_page = 10\n after = \"2019-12-27T18:11:19.117Z\"\n before = \"2024-01-01T00:00:00Z\"\n sort_by = \"created\"\n sort_order = \"asc\"\n}\n","required":[{"name":"request_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"page","type":"Int64","description":"Page number of results."},{"name":"per_page","type":"Int64","description":"Number of results per page."}],"optional":[{"name":"after","type":"Time","description":"Retrieve mes ges created after this time."},{"name":"before","type":"Time","description":"Retrieve messages created before this time."},{"name":"sort_by","type":"String","description":"Field to sort results by."},{"name":"sort_order","type":"String","description":"Sort order (asc or desc)."}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"author","type":"String","description":"Author of message."},{"name":"content","type":"String","description":"Content of message."},{"name":"created","type":"Time","description":"Defines the message creation time."},{"name":"is_follow_on_request","type":"Bool","description":"Whether the message is a follow-on request."},{"name":"updated","type":"Time","description":"Defines the message last updated time."}]}]},"post /accounts/{}/cloudforce-one/requests/{}/message/new":{"operationId":"cloudforce-one-request-message-new","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request_message","stainlessResource":"cloudforce_one.requests.message","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request_message\" \"example_cloudforce_one_request_message\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n content = \"Can you elaborate on the type of DoS that occurred?\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"request_id","type":"String","description":"UUID.","requiresReplace":true}],"optional":[{"name":"content","type":"String","description":"Content of message."}],"computed":[{"name":"id","type":"Int64","description":"Message ID."},{"name":"author","type":"String","description":"Author of message."},{"name":"created","type":"Time","description":"Defines the message creation time."},{"name":"is_follow_on_request","type":"Bool","description":"Whether the message is a follow-on request."},{"name":"updated","type":"Time","description":"Defines the message last updated time."}]}]},"post /accounts/{}/cloudforce-one/requests/new":{"operationId":"cloudforce-one-request-new","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request","stainlessResource":"cloudforce_one.requests","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request\" \"example_cloudforce_one_request\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n content = \"What regions were most effected by the recent DoS?\"\n priority = \"routine\"\n request_type = \"Victomology\"\n summary = \"DoS attack\"\n tlp = \"clear\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"content","type":"String","description":"Request content."},{"name":"priority","type":"String","description":"Priority for analyzing the request."},{"name":"request_type","type":"String","description":"Requested information from request."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"post /accounts/{}/cloudforce-one/requests/priority/new":{"operationId":"cloudforce-one-priority-new","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request_priority","stainlessResource":"cloudforce_one.requests.priority","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request_priority\" \"example_cloudforce_one_request_priority\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n labels = [\"DoS\", \"CVE\"]\n priority = 1\n requirement = \"DoS attacks carried out by CVEs\"\n tlp = \"clear\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"priority","type":"Int64","description":"Priority."},{"name":"requirement","type":"String","description":"Requirement."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"labels","type":"List[String]","description":"List of labels."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"content","type":"String","description":"Request content."},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"post /accounts/{}/connectivity/directory/services":{"operationId":"connectivity-services-post","declarations":[{"kind":"resource","name":"cloudflare_connectivity_directory_service","stainlessResource":"connectivity.directory.services","methodName":"create","snippet":"resource \"cloudflare_connectivity_directory_service\" \"example_connectivity_directory_service\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n host = {\n ipv4 = \"10.0.0.1\"\n network = {\n tunnel_id = \"0191dce4-9ab4-7fce-b660-8e5dec5172da\"\n }\n }\n name = \"web-app\"\n type = \"http\"\n http_port = 8080\n https_port = 8443\n tls_settings = {\n cert_verification_mode = \"verify_full\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier","requiresReplace":true},{"name":"name","type":"String"},{"name":"type","type":"String"},{"name":"host","type":"Attributes","children":[{"name":"ipv4","type":"String"},{"name":"network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"}]},{"name":"ipv6","type":"String"},{"name":"hostname","type":"String"},{"name":"resolver_network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"},{"name":"resolver_ips","type":"List[String]"}]}]}],"optional":[{"name":"app_protocol","type":"String"},{"name":"http_port","type":"Int64"},{"name":"https_port","type":"Int64"},{"name":"tcp_port","type":"Int64"},{"name":"tls_settings","type":"Attributes","description":"TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.","children":[{"name":"cert_verification_mode","type":"String","description":"TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all"}]}],"computed":[{"name":"id","type":"String"},{"name":"service_id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/d1/database":{"operationId":"d1-create-database","declarations":[{"kind":"resource","name":"cloudflare_d1_database","stainlessResource":"d1.database","methodName":"create","snippet":"resource \"cloudflare_d1_database\" \"example_d1_database\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-database\"\n jurisdiction = \"eu\"\n primary_location_hint = \"wnam\"\n read_replication = {\n mode = \"auto\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"name","type":"String","description":"D1 database name.","requiresReplace":true}],"optional":[{"name":"jurisdiction","type":"String","description":"Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored.","requiresReplace":true},{"name":"primary_location_hint","type":"String","description":"Specify the region to create the D1 primary, if available. If this option is omitted, the D1 will be created as close as possible to the current user.","requiresReplace":true},{"name":"read_replication","type":"Attributes","description":"Configuration for D1 read replication.","children":[{"name":"mode","type":"String","description":"The read replication mode for the database. Use 'auto' to create replicas and allow D1 automatically place them around the world, or 'disabled' to not use any database replicas (it can take a few hours for all replicas to be deleted)."}]}],"computed":[{"name":"id","type":"String","description":"D1 database identifier (UUID)."},{"name":"uuid","type":"String","description":"D1 database identifier (UUID)."},{"name":"created_at","type":"Time","description":"Specifies the timestamp the resource was created as an ISO8601 string."},{"name":"file_size","type":"Float64","description":"The D1 database's size, in bytes."},{"name":"num_tables","type":"Float64","description":"The number of tables in the D1 database. This count is no longer accurate and should not be relied upon.","deprecated":"Deprecated."},{"name":"version","type":"String"}]}]},"post /accounts/{}/data-security/posture/policies":{"operationId":"CreatePolicy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_casb_policy","stainlessResource":"zero_trust.casb.posture.policies","methodName":"create","snippet":"resource \"cloudflare_zero_trust_casb_policy\" \"example_zero_trust_casb_policy\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n actions = {\n remediation_types = [{\n remediation_type_id = \"5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a\"\n }]\n webhook_configs = [{\n webhook_config_id = \"3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e\"\n }]\n }\n applies_to_all_integrations = false\n display_name = \"Auto-remediate public files\"\n enabled = true\n finding_type_id = \"5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a\"\n description = \"Automatically remove public access from files when detected\"\n integration_ids = [\"497f6eca-6276-4993-bfeb-53cbbbba6f08\"]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"finding_type_id","type":"String","description":"The finding type this policy is associated with. All remediation actions must match this finding type.","requiresReplace":true},{"name":"applies_to_all_integrations","type":"Bool","description":"When true, the policy applies to all integrations for the account. When false, integration_ids must be provided."},{"name":"display_name","type":"String","description":"Display name for the policy configuration."},{"name":"enabled","type":"Bool","description":"Boolean specifying if the policy is enabled or disabled."},{"name":"actions","type":"Attributes","description":"Actions to execute when this policy is triggered, grouped by action type.\nA policy must contain at least one action across all groups and may include\nat most one remediation.","children":[{"name":"remediation_types","type":"List[Attributes]","description":"Remediation actions to execute (at most one).","children":[{"name":"remediation_type_id","type":"String","description":"The ID of the remediation type to execute."}]},{"name":"webhook_configs","type":"List[Attributes]","description":"Webhook actions to execute.","children":[{"name":"webhook_config_id","type":"String","description":"The ID of the webhook configuration to use."}]}]}],"optional":[{"name":"description","type":"String","description":"Optional description of what this policy does."},{"name":"integration_ids","type":"List[String]","description":"The integrations this policy applies to. Required when applies_to_all_integrations is false."}],"computed":[{"name":"id","type":"String","description":"Unique identifier for the policy configuration."},{"name":"created_at","type":"Time","description":"Timestamp when the policy was created."},{"name":"disabled_at","type":"Time","description":"Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled."},{"name":"last_triggered_at","type":"Time","description":"Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints."},{"name":"updated_at","type":"Time","description":"Timestamp when the policy was last updated."}]}]},"post /accounts/{}/data-security/posture/webhooks":{"operationId":"CreateWebhook","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_casb_webhook","stainlessResource":"zero_trust.casb.posture.webhooks","methodName":"create","snippet":"resource \"cloudflare_zero_trust_casb_webhook\" \"example_zero_trust_casb_webhook\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n authentication_type = \"Bearer Auth\"\n destination_url = \"https://example.com/webhook\"\n label = \"Send to Slack\"\n headers = [{\n key = \"Authorization\"\n value = \"Bearer token123\"\n }, {\n key = \"X-Custom-Header\"\n value = \"value\"\n }]\n signing_secret = \"my-secret-key\"\n status = \"enabled\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"authentication_type","type":"String","description":"Type of authentication used for the webhook."},{"name":"destination_url","type":"String","description":"Target URL for the webhook configuration. Where resulting data will be sent."},{"name":"label","type":"String","description":"Account-specified display label for the webhook configuration."}],"optional":[{"name":"signing_secret","type":"String","description":"Secret key used for HMAC signing when authentication_type is \"HMAC-Signing\".","sensitive":true},{"name":"headers","type":"List[Attributes]","description":"List of custom headers to include in webhook requests.","children":[{"name":"key","type":"String","description":"Header key name."},{"name":"value","type":"String","description":"Header value. Required on Create and Evaluate. On Update, omit or set to null to keep existing value.","sensitive":true}]},{"name":"status","type":"String","description":"Status of the webhook configuration. Defaults to enabled when omitted."}],"computed":[{"name":"id","type":"String","description":"Unique identifier for the specific webhook configuration."},{"name":"created_at","type":"Time","description":"Timestamp when the webhook configuration was created."},{"name":"updated_at","type":"Time","description":"Timestamp when the webhook configuration was last updated."},{"name":"version","type":"Int64","description":"Version number of the configuration."}]}]},"post /accounts/{}/devices/deployment-groups":{"operationId":"create-deployment-group","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_deployment_groups","stainlessResource":"zero_trust.devices.deployment_groups","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_deployment_groups\" \"example_zero_trust_device_deployment_groups\" {\n account_id = \"account_id\"\n name = \"Engineering Ring 0\"\n version_config = [{\n target_environment = \"windows\"\n version = \"2026.6.234.0\"\n }]\n policy_ids = [\"string\"]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for the deployment group."},{"name":"version_config","type":"List[Attributes]","description":"Contains at least one version configuration.","children":[{"name":"target_environment","type":"String","description":"The target environment for the client version (e.g., windows, macos)."},{"name":"version","type":"String","description":"The specific client version to deploy."}]}],"optional":[{"name":"policy_ids","type":"List[String]","description":"Contains an optional list of policy IDs assigned to a group."}],"computed":[{"name":"id","type":"String","description":"The ID of the deployment group."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was created."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was last updated."}]}]},"post /accounts/{}/devices/ip-profiles":{"operationId":"create-ip-profile","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_ip_profile","stainlessResource":"zero_trust.devices.ip_profiles","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_ip_profile\" \"example_zero_trust_device_ip_profile\" {\n account_id = \"account_id\"\n match = \"identity.email == \\\"test@cloudflare.com\\\"\"\n name = \"IPv4 Cloudflare Source IPs\"\n precedence = 100\n subnet_id = \"b70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n description = \"example comment\"\n enabled = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"match","type":"String","description":"The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"."},{"name":"name","type":"String","description":"A user-friendly name for the Device IP profile."},{"name":"precedence","type":"Int64","description":"The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field."},{"name":"subnet_id","type":"String","description":"The ID of the Subnet."}],"optional":[{"name":"description","type":"String","description":"An optional description of the Device IP profile."},{"name":"enabled","type":"Bool","description":"Whether the Device IP profile will be applied to matching devices."}],"computed":[{"name":"id","type":"String","description":"The ID of the Device IP profile."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was created."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was last updated."}]}]},"post /accounts/{}/devices/networks":{"operationId":"device-managed-networks-create-device-managed-network","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_managed_networks","stainlessResource":"zero_trust.devices.networks","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_managed_networks\" \"example_zero_trust_device_managed_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n config = {\n tls_sockaddr = \"foo.bar:1234\"\n sha256 = \"b5bb9d8014a0f9b1d61e21e796d78dccdf1352f23cd32812f4850b878ae4944c\"\n }\n name = \"managed-network-1\"\n type = \"tls\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the device managed network. This name must be unique."},{"name":"type","type":"String","description":"The type of device managed network."},{"name":"config","type":"Attributes","description":"The configuration object containing information for the WARP client to detect the managed network.","children":[{"name":"tls_sockaddr","type":"String","description":"A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host."},{"name":"sha256","type":"String","description":"The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"network_id","type":"String","description":"API UUID."}]}]},"post /accounts/{}/devices/policy":{"operationId":"devices-create-device-settings-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_custom_profile","stainlessResource":"zero_trust.devices.policies.custom","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_custom_profile\" \"example_zero_trust_device_custom_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Allow Developers\"\n allow_mode_switch = true\n allow_updates = true\n allowed_to_leave = true\n auto_connect = 0\n browser_extension_config = {\n proxy_control = \"unlocked\"\n proxy_enabled = true\n }\n captive_portal = 180\n default = false\n description = \"Policy for test teams.\"\n disable_auto_fallback = true\n dns_search_suffixes = [{\n suffix = \"internal.corp\"\n description = \"Example internal domains\"\n }]\n enabled = true\n exclude = [{\n address = \"192.0.2.0/24\"\n description = \"Exclude testing domains from the tunnel\"\n }]\n exclude_office_ips = true\n global_acceleration = {\n api_endpoints = [\"198.51.100.1:443\"]\n enabled = true\n masque_endpoints = [\"198.51.100.1:443\"]\n wireguard_endpoints = [\"198.51.100.1:2408\"]\n autoswitch = true\n }\n include = [{\n address = \"192.0.2.0/24\"\n description = \"Include testing domains in the tunnel\"\n }]\n lan_allow_minutes = 30\n lan_allow_subnet_size = 24\n match = \"identity.email == \\\"test@cloudflare.com\\\"\"\n precedence = 100\n profile_type = \"warp\"\n register_interface_ip_with_dns = true\n sccm_vpn_boundary_support = false\n service_mode_v2 = {\n mode = \"proxy\"\n port = 3000\n }\n support_url = \"https://1.1.1.1/help\"\n switch_locked = true\n tunnel_protocol = \"wireguard\"\n uninstall_protection = false\n virtual_networks = {\n allowed = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n default = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the device settings profile."}],"optional":[{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.","requiresReplace":true},{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"match","type":"String","description":"The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"."},{"name":"precedence","type":"Float64","description":"The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field."},{"name":"browser_extension_config","type":"Attributes","description":"Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.","children":[{"name":"proxy_control","type":"String","description":"Whether the user may disable the browser extension proxy."},{"name":"proxy_enabled","type":"Bool","description":"Whether the browser extension proxy is active."}]},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy is the account default. WARP group profiles cannot set this field."},{"name":"description","type":"String","description":"A description of the policy."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]}],"computed":[{"name":"id","type":"String"},{"name":"policy_id","type":"String"},{"name":"gateway_unique_id","type":"String"},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"target_tests","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The id of the DEX test targeting this policy."},{"name":"name","type":"String","description":"The name of the DEX test targeting this policy."}]}]}]},"post /accounts/{}/devices/posture":{"operationId":"device-posture-rules-create-device-posture-rule","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_posture_rule","stainlessResource":"zero_trust.devices.posture","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_posture_rule\" \"example_zero_trust_device_posture_rule\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Admin Serial Numbers\"\n type = \"file\"\n description = \"The rule for admin serial numbers\"\n expiration = \"1h\"\n input = {\n operating_system = \"linux\"\n path = \"/bin/cat\"\n exists = true\n sha256 = \"https://api.us-2.crowdstrike.com\"\n thumbprint = \"0aabab210bdb998e9cf45da2c9ce352977ab531c681b74cf1e487be1bbe9fe6e\"\n }\n match = [{\n platform = \"windows\"\n }]\n schedule = \"1h\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the device posture rule."},{"name":"type","type":"String","description":"The type of device posture rule."}],"optional":[{"name":"description","type":"String","description":"The description of the device posture rule."},{"name":"expiration","type":"String","description":"Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client."},{"name":"schedule","type":"String","description":"Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`."},{"name":"input","type":"Attributes","description":"The value to be checked against.","children":[{"name":"operating_system","type":"String","description":"Operating system."},{"name":"path","type":"String","description":"File path."},{"name":"exists","type":"Bool","description":"Whether or not file exists."},{"name":"sha256","type":"String","description":"SHA-256."},{"name":"thumbprint","type":"String","description":"Signing certificate thumbprint."},{"name":"id","type":"String","description":"List ID."},{"name":"domain","type":"String","description":"Domain."},{"name":"operator","type":"String","description":"Operator."},{"name":"version","type":"String","description":"Version of OS."},{"name":"os_distro_name","type":"String","description":"Operating System Distribution Name (linux only)."},{"name":"os_distro_revision","type":"String","description":"Version of OS Distribution (linux only)."},{"name":"os_version_extra","type":"String","description":"Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version."},{"name":"enabled","type":"Bool","description":"Enabled."},{"name":"check_disks","type":"List[String]","description":"List of volume names to be checked for encryption."},{"name":"require_all","type":"Bool","description":"Whether to check all disks for encryption."},{"name":"certificate_id","type":"String","description":"UUID of Cloudflare managed certificate."},{"name":"cn","type":"String","description":"Common Name that is protected by the certificate."},{"name":"check_private_key","type":"Bool","description":"Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key."},{"name":"extended_key_usage","type":"List[String]","description":"List of values indicating purposes for which the certificate public key can be used."},{"name":"locations","type":"Attributes","children":[{"name":"paths","type":"List[String]","description":"List of paths to check for client certificate on linux."},{"name":"trust_stores","type":"List[String]","description":"List of trust stores to check for client certificate."}]},{"name":"subject_alternative_names","type":"List[String]","description":"List of certificate Subject Alternative Names."},{"name":"update_window_days","type":"Float64","description":"Number of days that the antivirus should be updated within."},{"name":"compliance_status","type":"String","description":"Compliance Status."},{"name":"connection_id","type":"String","description":"Posture Integration ID."},{"name":"last_seen","type":"String","description":"For more details on last seen, please refer to the Crowdstrike documentation."},{"name":"os","type":"String","description":"Os Version."},{"name":"overall","type":"String","description":"Overall."},{"name":"sensor_config","type":"String","description":"SensorConfig."},{"name":"state","type":"String","description":"For more details on state, please refer to the Crowdstrike documentation."},{"name":"version_operator","type":"String","description":"Version Operator."},{"name":"auth_state","type":"List[String]","description":"The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states."},{"name":"count_operator","type":"String","description":"Count Operator."},{"name":"issue_count","type":"String","description":"The Number of Issues."},{"name":"eid_last_seen","type":"String","description":"For more details on eid last seen, refer to the Tanium documentation."},{"name":"risk_level","type":"String","description":"For more details on risk level, refer to the Tanium documentation."},{"name":"score_operator","type":"String","description":"Score Operator."},{"name":"total_score","type":"Float64","description":"For more details on total score, refer to the Tanium documentation."},{"name":"active_threats","type":"Float64","description":"The Number of active threats."},{"name":"infected","type":"Bool","description":"Whether device is infected."},{"name":"is_active","type":"Bool","description":"Whether device is active."},{"name":"network_status","type":"String","description":"Network status of device."},{"name":"operational_state","type":"String","description":"Agent operational state."},{"name":"score","type":"Float64","description":"A value between 0-100 assigned to devices set by the 3rd party posture provider."}]},{"name":"match","type":"List[Attributes]","description":"The conditions that the client must match to run the rule.","children":[{"name":"platform","type":"String"}]}],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"enabled","type":"Bool","description":"Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise."}]}]},"post /accounts/{}/devices/posture/integration":{"operationId":"device-posture-integrations-create-device-posture-integration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_posture_integration","stainlessResource":"zero_trust.devices.posture.integrations","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_posture_integration\" \"example_zero_trust_device_posture_integration\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n config = {\n api_url = \"https://as123.awmdm.com/API\"\n auth_url = \"https://na.uemauth.workspaceone.com/connect/token\"\n client_id = \"example client id\"\n client_secret = \"example client secret\"\n }\n interval = \"10m\"\n name = \"My Workspace One Integration\"\n type = \"workspace_one\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"interval","type":"String","description":"The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)."},{"name":"name","type":"String","description":"The name of the device posture integration."},{"name":"type","type":"String","description":"The type of device posture integration."},{"name":"config","type":"Attributes","description":"The configuration object containing third-party integration information.","children":[{"name":"api_url","type":"String","description":"The Workspace One API URL provided in the Workspace One Admin Dashboard."},{"name":"auth_url","type":"String","description":"The Workspace One Authorization URL depending on your region."},{"name":"client_id","type":"String","description":"The Workspace One client ID provided in the Workspace One Admin Dashboard."},{"name":"client_secret","type":"String","description":"The Workspace One client secret provided in the Workspace One Admin Dashboard.","sensitive":true},{"name":"customer_id","type":"String","description":"The Crowdstrike customer ID."},{"name":"client_key","type":"String","description":"The Uptycs client secret.","sensitive":true},{"name":"access_client_id","type":"String","description":"If present, this id will be passed in the `CF-Access-Client-ID` header when hitting the `api_url`."},{"name":"access_client_secret","type":"String","description":"If present, this secret will be passed in the `CF-Access-Client-Secret` header when hitting the `api_url`.","sensitive":true}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."}]}]},"post /accounts/{}/dex/devices/dex_tests":{"operationId":"device-dex-test-create-device-dex-test","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dex_test","stainlessResource":"zero_trust.devices.dex_tests","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dex_test\" \"example_zero_trust_dex_test\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n data = {\n host = \"https://dash.cloudflare.com\"\n kind = \"http\"\n method = \"GET\"\n }\n enabled = true\n interval = \"30m\"\n name = \"HTTP dash health check\"\n description = \"Checks the dash endpoint every 30 minutes\"\n target_policies = [{\n id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n default = true\n name = \"name\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Determines whether or not the test is active."},{"name":"interval","type":"String","description":"How often the test will run."},{"name":"name","type":"String","description":"The name of the DEX test. Must be unique."},{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]}],"optional":[{"name":"description","type":"String","description":"Additional details about the test."},{"name":"target_policies","type":"List[Attributes]","description":"DEX rules targeted by this test","children":[{"name":"id","type":"String","description":"The id of the DEX rule."},{"name":"default","type":"Bool","description":"Whether the DEX rule is the account default."},{"name":"name","type":"String","description":"The name of the DEX rule."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier for the test."},{"name":"test_id","type":"String","description":"The unique identifier for the test."},{"name":"created","type":"Time","description":"Date the test was created, in RFC 3339 format."},{"name":"targeted","type":"Bool"},{"name":"updated","type":"Time","description":"Date the test was last updated, in RFC 3339 format."}]}]},"post /accounts/{}/dex/rules":{"operationId":"create-dex-rule","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dex_rule","stainlessResource":"zero_trust.dex.rules","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dex_rule\" \"example_zero_trust_dex_rule\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n match = \"match\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account.","requiresReplace":true},{"name":"match","type":"String","description":"The wirefilter expression to match."},{"name":"name","type":"String","description":"The name of the Rule."}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String","description":"API Resource UUID tag."},{"name":"created_at","type":"String"},{"name":"updated_at","type":"String"},{"name":"targeted_tests","type":"List[Attributes]","children":[{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"test_id","type":"String"}]}]}]},"post /accounts/{}/dlp/data_classes":{"operationId":"dlp-data-classes-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_data_class","stainlessResource":"zero_trust.dlp.data_classes","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_data_class\" \"example_zero_trust_dlp_data_class\" {\n account_id = \"account_id\"\n data_tags = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n expression = \"expression\"\n name = \"name\"\n sensitivity_levels = [{\n group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"expression","type":"String"},{"name":"name","type":"String"},{"name":"data_tags","type":"List[String]"},{"name":"sensitivity_levels","type":"List[Attributes]","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/data_tag_categories":{"operationId":"dlp-data-tag-categories-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_data_tag_category","stainlessResource":"zero_trust.dlp.data_tag_categories","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_data_tag_category\" \"example_zero_trust_dlp_data_tag_category\" {\n account_id = \"account_id\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"template_id","type":"String","requiresReplace":true},{"name":"description","type":"String"},{"name":"tags","type":"List[Attributes]","description":"Tags to create with the category. Mutually exclusive with `template_id`.","children":[{"name":"name","type":"String"},{"name":"description","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/data_tag_categories/{}/data_tags":{"operationId":"dlp-data-tags-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_data_tag","stainlessResource":"zero_trust.dlp.data_tag_categories.data_tags","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_data_tag\" \"example_zero_trust_dlp_data_tag\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"category_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/datasets":{"operationId":"dlp-datasets-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_dataset","stainlessResource":"zero_trust.dlp.datasets","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_dataset\" \"example_zero_trust_dlp_dataset\" {\n account_id = \"account_id\"\n name = \"name\"\n case_sensitive = true\n description = \"description\"\n encoding_version = 0\n secret = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"dataset_id","type":"String","requiresReplace":true},{"name":"encoding_version","type":"Int64","description":"Dataset encoding version\n\nNon-secret custom word lists with no header are always version 1.\nSecret EDM lists with no header are version 1.\nMulticolumn CSV with headers are version 2.\nOmitting this field provides the default value 0, which is interpreted\nthe same as 1.","requiresReplace":true},{"name":"secret","type":"Bool","description":"Generate a secret dataset.\n\nIf true, the response will include a secret to use with the EDM encoder.\nIf false, the response has no secret and the dataset is uploaded in plaintext.","requiresReplace":true},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if `secret` is true or undefined"},{"name":"description","type":"String","description":"The description of the dataset."}],"computed":[{"name":"created_at","type":"Time"},{"name":"id","type":"String"},{"name":"max_cells","type":"Int64"},{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"version","type":"Int64","description":"The version to use when uploading the dataset."},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"dataset","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"created_at","type":"Time"},{"name":"encoding_version","type":"Int64"},{"name":"name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"secret","type":"Bool"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]},{"name":"case_sensitive","type":"Bool"},{"name":"description","type":"String","description":"The description of the dataset."}]},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]}]}]},"post /accounts/{}/dlp/entries":{"operationId":"dlp-entries-create-entry","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_custom_entry","stainlessResource":"zero_trust.dlp.entries.custom","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_custom_entry\" \"example_zero_trust_dlp_custom_entry\" {\n account_id = \"account_id\"\n enabled = true\n name = \"name\"\n pattern = {\n regex = \"regex\"\n validation = \"luhn\"\n }\n description = \"description\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]}],"optional":[{"name":"profile_id","type":"String","requiresReplace":true},{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"resource","name":"cloudflare_zero_trust_dlp_entry","stainlessResource":"zero_trust.dlp.entries","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_entry\" \"example_zero_trust_dlp_entry\" {\n account_id = \"account_id\"\n enabled = true\n name = \"name\"\n pattern = {\n regex = \"regex\"\n validation = \"luhn\"\n }\n description = \"description\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]}],"optional":[{"name":"profile_id","type":"String","requiresReplace":true},{"name":"description","type":"String"},{"name":"type","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"secret","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"post /accounts/{}/dlp/entries/integration":{"operationId":"dlp-entries-create-integration-entry","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_integration_entry","stainlessResource":"zero_trust.dlp.entries.integration","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_integration_entry\" \"example_zero_trust_dlp_integration_entry\" {\n account_id = \"account_id\"\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"entry_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"}],"optional":[{"name":"profile_id","type":"String","description":"This field is not used as the owning profile.\nFor predefined entries it is already set to a predefined profile.","requiresReplace":true}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"post /accounts/{}/dlp/entries/predefined":{"operationId":"dlp-entries-create-predefined-entry","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_predefined_entry","stainlessResource":"zero_trust.dlp.entries.predefined","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_predefined_entry\" \"example_zero_trust_dlp_predefined_entry\" {\n account_id = \"account_id\"\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"entry_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"}],"optional":[{"name":"profile_id","type":"String","description":"This field is not used as the owning profile.\nFor predefined entries it is already set to a predefined profile.","requiresReplace":true}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"post /accounts/{}/dlp/profiles/custom":{"operationId":"dlp-profiles-create-custom-profiles","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_custom_profile","stainlessResource":"zero_trust.dlp.profiles.custom","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_custom_profile\" \"example_zero_trust_dlp_custom_profile\" {\n account_id = \"account_id\"\n name = \"name\"\n ai_context_enabled = true\n allowed_match_count = 5\n confidence_threshold = \"confidence_threshold\"\n context_awareness = {\n enabled = true\n skip = {\n files = true\n }\n }\n data_classes = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n data_tags = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n description = \"description\"\n ocr_enabled = true\n sensitivity_levels = [{\n group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n shared_entries = [{\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"description","type":"String","description":"The description of the profile."},{"name":"data_classes","type":"List[String]","description":"Data class IDs to associate with the profile."},{"name":"data_tags","type":"List[String]","description":"Data tag IDs to associate with the profile."},{"name":"context_awareness","type":"Attributes","description":"Scan the context of predefined entries to only return matches surrounded by keywords.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"If true, scan the context of predefined entries to only return matches surrounded by keywords."},{"name":"skip","type":"Attributes","description":"Content types to exclude from context analysis and return all matches.","children":[{"name":"files","type":"Bool","description":"If the content type is a file, skip context analysis and return all matches."}]}]},{"name":"entries","type":"List[Attributes]","children":[{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"description","type":"String"},{"name":"words","type":"List[String]"}]},{"name":"sensitivity_levels","type":"List[Attributes]","description":"Sensitivity levels to associate with the profile.","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]},{"name":"shared_entries","type":"List[Attributes]","description":"Entries from other profiles (e.g. pre-defined Cloudflare profiles, or your Microsoft Information Protection profiles).","children":[{"name":"enabled","type":"Bool"},{"name":"entry_id","type":"String"}]},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64","description":"Related DLP policies will trigger when the match count exceeds the number set."},{"name":"confidence_threshold","type":"String"},{"name":"ocr_enabled","type":"Bool"}],"computed":[{"name":"id","type":"String","description":"The id of the profile (uuid)."},{"name":"created_at","type":"Time","description":"When the profile was created."},{"name":"integration_id","type":"String"},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."},{"name":"type","type":"String"},{"name":"updated_at","type":"Time","description":"When the profile was lasted updated."}]}]},"post /accounts/{}/dlp/sensitivity_groups":{"operationId":"dlp-sensitivity-groups-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_sensitivity_group","stainlessResource":"zero_trust.dlp.sensitivity_groups","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_sensitivity_group\" \"example_zero_trust_dlp_sensitivity_group\" {\n account_id = \"account_id\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"template_id","type":"String","requiresReplace":true},{"name":"description","type":"String"},{"name":"levels","type":"List[Attributes]","description":"Levels to create with the group. Mutually exclusive with `template_id`.","children":[{"name":"name","type":"String"},{"name":"description","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/sensitivity_groups/{}/levels":{"operationId":"dlp-sensitivity-levels-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_sensitivity_level","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_sensitivity_level\" \"example_zero_trust_dlp_sensitivity_level\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"sensitivity_group_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dls/regional_services/prefix_bindings":{"operationId":"publicCreatePrefixBinding","declarations":[{"kind":"resource","name":"cloudflare_dls_prefix_binding","stainlessResource":"dls.regional_services.prefix_bindings","methodName":"create","snippet":"resource \"cloudflare_dls_prefix_binding\" \"example_dls_prefix_binding\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cidr = \"10.0.1.0/24\"\n prefix_id = \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n region_key = \"eu\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account.","requiresReplace":true},{"name":"cidr","type":"String","description":"IP prefix in CIDR notation to bind.","requiresReplace":true},{"name":"prefix_id","type":"String","description":"The ID of the parent IP prefix that contains the CIDR.","requiresReplace":true},{"name":"region_key","type":"String","description":"Region key from managed regions (e.g., \"us\", \"eu\")."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The ID of the binding."}]}]},"post /accounts/{}/dns_firewall":{"operationId":"dns-firewall-create-dns-firewall-cluster","declarations":[{"kind":"resource","name":"cloudflare_dns_firewall","stainlessResource":"dns_firewall","methodName":"create","snippet":"resource \"cloudflare_dns_firewall\" \"example_dns_firewall\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Awesome DNS Firewall cluster\"\n upstream_ips = [\"192.0.2.1\", \"198.51.100.1\", \"2001:DB8:100::CF\"]\n attack_mitigation = {\n enabled = true\n only_when_upstream_unhealthy = false\n }\n deprecate_any_requests = true\n dns_firewall_ip_count = 2\n ecs_fallback = false\n maximum_cache_ttl = 900\n minimum_cache_ttl = 60\n negative_cache_ttl = 900\n ratelimit = 600\n retries = 2\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"DNS Firewall cluster name"},{"name":"upstream_ips","type":"Set[String]"}],"optional":[{"name":"dns_firewall_ip_count","type":"Int64","description":"Number of IPv4 addresses to assign to the DNS Firewall cluster. Only used during cluster creation and cannot be changed later.","requiresReplace":true},{"name":"deprecate_any_requests","type":"Bool","description":"Whether to refuse to answer queries for the ANY type"},{"name":"ecs_fallback","type":"Bool","description":"Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent"},{"name":"negative_cache_ttl","type":"Float64","description":"This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"ratelimit","type":"Float64","description":"Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting."},{"name":"maximum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"minimum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons.\n"},{"name":"retries","type":"Float64","description":"Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)"},{"name":"attack_mitigation","type":"Attributes","description":"Attack mitigation settings","children":[{"name":"enabled","type":"Bool","description":"When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers"},{"name":"only_when_upstream_unhealthy","type":"Bool","description":"Only mitigate attacks when upstream servers seem unhealthy"}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"Last modification of DNS Firewall cluster"},{"name":"dns_firewall_ips","type":"Set[String]"}]}]},"post /accounts/{}/dns_settings/views":{"operationId":"dns-views-for-an-account-create-internal-dns-views","declarations":[{"kind":"resource","name":"cloudflare_account_dns_settings_internal_view","stainlessResource":"dns.settings.account.views","methodName":"create","snippet":"resource \"cloudflare_account_dns_settings_internal_view\" \"example_account_dns_settings_internal_view\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my view\"\n zones = [\"372e67954025e0ba6aaa6d586b9e0b59\"]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"The name of the view."},{"name":"zones","type":"Set[String]","description":"The list of zones linked to this view."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_time","type":"Time","description":"When the view was created."},{"name":"modified_time","type":"Time","description":"When the view was last modified."}]}]},"post /accounts/{}/email-security/settings/allow_policies":{"operationId":"email_security_create_allow_policy","declarations":[{"kind":"resource","name":"cloudflare_email_security_allow_policy","stainlessResource":"email_security.settings.allow_policies","methodName":"create","snippet":"resource \"cloudflare_email_security_allow_policy\" \"example_email_security_allow_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_acceptable_sender = false\n is_exempt_recipient = false\n is_regex = false\n is_trusted_sender = true\n pattern = \"test@example.com\"\n pattern_type = \"EMAIL\"\n verify_sender = true\n comments = \"Trust all messages send from test@example.com\"\n is_recipient = false\n is_sender = true\n is_spoof = false\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"is_acceptable_sender","type":"Bool","description":"Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply."},{"name":"is_exempt_recipient","type":"Bool","description":"Bypasses all detections for messages to this recipient."},{"name":"is_regex","type":"Bool"},{"name":"is_trusted_sender","type":"Bool","description":"Bypasses all detections and link following for messages from this sender."},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"},{"name":"verify_sender","type":"Bool","description":"Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication."}],"optional":[{"name":"comments","type":"String"},{"name":"is_recipient","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.","deprecated":"Use `is_exempt_recipient` instead."},{"name":"is_sender","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_trusted_sender` instead."},{"name":"is_spoof","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_acceptable_sender` instead."}],"computed":[{"name":"id","type":"String","description":"Allow policy identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email-security/settings/block_senders":{"operationId":"email_security_create_blocked_sender","declarations":[{"kind":"resource","name":"cloudflare_email_security_block_sender","stainlessResource":"email_security.settings.block_senders","methodName":"create","snippet":"resource \"cloudflare_email_security_block_sender\" \"example_email_security_block_sender\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_regex = false\n pattern = \"test@example.com\"\n pattern_type = \"EMAIL\"\n comments = \"Block sender with email test@example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal value."},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"}],"optional":[{"name":"comments","type":"String"}],"computed":[{"name":"id","type":"String","description":"Blocked sender pattern identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email-security/settings/domains":{"operationId":"email_security_create_domains","declarations":[{"kind":"resource","name":"cloudflare_email_security_domain","stainlessResource":"email_security.settings.domains","methodName":"create","snippet":"resource \"cloudflare_email_security_domain\" \"example_email_security_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n allowed_delivery_modes = [\"DIRECT\"]\n domain = \"domain\"\n drop_dispositions = [\"MALICIOUS\"]\n ip_restrictions = [\"192.0.2.0/24\", \"2001:db8::/32\"]\n regions = [\"GLOBAL\"]\n folder = \"AllItems\"\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n lookback_hops = 1\n require_tls_inbound = true\n require_tls_outbound = true\n transport = \"transport\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"domain","type":"String","description":"The email domain to protect.","requiresReplace":true},{"name":"allowed_delivery_modes","type":"Set[String]","description":"Delivery modes to onboard the domain through."},{"name":"drop_dispositions","type":"Set[String]","description":"Dispositions to drop instead of delivering, e.g. `[\"MALICIOUS\", \"SPAM\"]`."},{"name":"ip_restrictions","type":"Set[String]","description":"Source IP ranges mail is accepted from. Any other source is rejected."},{"name":"regions","type":"Set[String]","description":"Regions that process messages for this domain, e.g. `[\"GLOBAL\"]` or `[\"US\"]`."}],"optional":[{"name":"integration_id","type":"String","description":"Identifier of the CASB integration that authorizes this domain. The integration also enables API scanning, post-delivery actions, and directory sync."},{"name":"transport","type":"String","description":"The mail transport hostname for MX/Inline delivery — the MX record Cloudflare delivers email to (e.g. `mx.example.com`)."},{"name":"folder","type":"String","description":"The mailbox folder to scan, for API-scanning domains."},{"name":"lookback_hops","type":"Int64","description":"Number of hops to trace back through received headers when reconstructing the original message (1-20)."},{"name":"require_tls_inbound","type":"Bool","description":"Require TLS on inbound connections."},{"name":"require_tls_outbound","type":"Bool","description":"Require TLS on outbound connections."}],"computed":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"created_at","type":"Time"},{"name":"dmarc_status","type":"String"},{"name":"inbox_provider","type":"String"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"o365_tenant_id","type":"String"},{"name":"spf_status","type":"String"},{"name":"status","type":"String"},{"name":"authorization","type":"Attributes","children":[{"name":"authorized","type":"Bool"},{"name":"timestamp","type":"Time"},{"name":"status_message","type":"String"}]},{"name":"emails_processed","type":"Attributes","children":[{"name":"timestamp","type":"Time"},{"name":"total_emails_processed","type":"Int64"},{"name":"total_emails_processed_previous","type":"Int64"}]}]}]},"post /accounts/{}/email-security/settings/impersonation_registry":{"operationId":"email_security_create_impersonation_registry","declarations":[{"kind":"resource","name":"cloudflare_email_security_impersonation_registry","stainlessResource":"email_security.settings.impersonation_registry","methodName":"create","snippet":"resource \"cloudflare_email_security_impersonation_registry\" \"example_email_security_impersonation_registry\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"john.doe@example.com\"\n is_email_regex = false\n name = \"John Doe\"\n comments = \"comments\"\n directory_id = 0\n directory_node_id = 0\n external_directory_node_id = \"external_directory_node_id\"\n provenance = \"A1S_INTERNAL\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"email","type":"String","description":"Email address (or pattern) of the protected identity."},{"name":"is_email_regex","type":"Bool","description":"Whether `email` is a regular expression instead of a literal address."},{"name":"name","type":"String","description":"Display name of the protected identity."}],"optional":[{"name":"comments","type":"String","description":"Optional note describing the entry."},{"name":"directory_id","type":"Int64","description":"Identifier of the directory the entry was synced from, when directory-synced."},{"name":"directory_node_id","type":"Int64","description":"Identifier of the directory node the entry was synced from, when directory-synced."},{"name":"external_directory_node_id","type":"String","description":"Deprecated. External identifier of the directory node.","deprecated":"This field is deprecated."},{"name":"provenance","type":"String","description":"Source the entry was created from."}],"computed":[{"name":"id","type":"String","description":"Impersonation registry entry identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email-security/settings/trusted_domains":{"operationId":"email_security_create_trusted_domain","declarations":[{"kind":"resource","name":"cloudflare_email_security_trusted_domains","stainlessResource":"email_security.settings.trusted_domains","methodName":"create","snippet":"resource \"cloudflare_email_security_trusted_domains\" \"example_email_security_trusted_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_recent = true\n is_regex = false\n is_similarity = false\n pattern = \"example.com\"\n comments = \"Trusted partner domain\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"is_recent","type":"Bool","description":"Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition."},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal domain."},{"name":"is_similarity","type":"Bool","description":"Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition."},{"name":"pattern","type":"String","description":"The domain pattern to trust, e.g. `example.com`."}],"optional":[{"name":"comments","type":"String"}],"computed":[{"name":"id","type":"String","description":"Trusted domain identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email/routing/addresses":{"operationId":"email-routing-destination-addresses-create-a-destination-address","declarations":[{"kind":"resource","name":"cloudflare_email_routing_address","stainlessResource":"email_routing.addresses","methodName":"create","snippet":"resource \"cloudflare_email_routing_address\" \"example_email_routing_address\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"user@example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"email","type":"String","description":"The contact email address of the user.","requiresReplace":true}],"optional":[{"name":"status","type":"String","description":"Destination address status. Non-admin callers may only set verified addresses back to unverified; setting to verified requires admin privileges."}],"computed":[{"name":"id","type":"String","description":"Destination address identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"tag","type":"String","description":"Destination address tag. (Deprecated, replaced by destination address identifier)","deprecated":"Deprecated."},{"name":"verified","type":"Time","description":"The date and time the destination address has been verified. Null means not verified yet."}]}]},"post /accounts/{}/flagship/apps":{"operationId":"flagship_create_app","declarations":[{"kind":"resource","name":"cloudflare_flagship_app","stainlessResource":"flagship.apps","methodName":"create","snippet":"resource \"cloudflare_flagship_app\" \"example_flagship_app\" {\n account_id = \"account_id\"\n name = \"x\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app.","requiresReplace":true},{"name":"name","type":"String","description":"Name of the Flagship app (1–64 letters, numbers, hyphens, or underscores)."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"String"},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String","description":"Email of the actor who last modified the app, or `unknown` when unavailable."}]}]},"post /accounts/{}/flagship/apps/{}/flags":{"operationId":"flagship_create_flag","declarations":[{"kind":"resource","name":"cloudflare_flagship_flag","stainlessResource":"flagship.apps.flags","methodName":"create","snippet":"resource \"cloudflare_flagship_flag\" \"example_flagship_flag\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n default_variation = \"x\"\n enabled = true\n key = \"x\"\n rules = [{\n conditions = [{\n attribute = \"x\"\n operator = \"equals\"\n value = \"string\"\n }]\n priority = 1\n serve_variation = \"x\"\n rollout = {\n percentage = 0\n attribute = \"x\"\n }\n }]\n variations = {\n foo = \"string\"\n }\n description = \"description\"\n type = \"boolean\"\n}\n","required":[{"name":"key","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls.","requiresReplace":true},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app.","requiresReplace":true},{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created.","requiresReplace":true},{"name":"default_variation","type":"String","description":"Variation the API serves when the flag is off, or when it's on but no rule matches the context. Must be a key in `variations`."},{"name":"enabled","type":"Bool","description":"When false, the flag bypasses all rules and always serves `default_variation`."},{"name":"variations","type":"Map[String]","description":"Map of variation name to value. All values share the same type (boolean, string, number, or JSON object/array), and each serialized value stays within 10KB."},{"name":"rules","type":"List[Attributes]","description":"Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.","children":[{"name":"conditions","type":"List[Attributes]","description":"Conditions the context must satisfy for this rule to match. An empty array matches all contexts.","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[String]"},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"priority","type":"Int64","description":"Evaluation order: the API evaluates rules with lower numbers first. Must be unique across the flag's rules."},{"name":"serve_variation","type":"String","description":"Variation the API serves when this rule matches. Must be a key in `variations`."},{"name":"rollout","type":"Attributes","children":[{"name":"percentage","type":"Float64","description":"Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)."},{"name":"attribute","type":"String","description":"Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request."}]}]}],"optional":[{"name":"description","type":"String","description":"Optional operator-facing description. It does not affect flag evaluation."},{"name":"type","type":"String","description":"Deprecated compatibility field. Omit it; the API ignores this value and infers the type from the flag's variations.","deprecated":"Deprecated."}],"computed":[{"name":"id","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls.","requiresReplace":true},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String"}]}]},"post /accounts/{}/gateway/certificates":{"operationId":"zero-trust-certificates-create-zero-trust-certificate","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_certificate","stainlessResource":"zero_trust.gateway.certificates","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_certificate\" \"example_zero_trust_gateway_certificate\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n validity_period_days = 1826\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}],"optional":[{"name":"validity_period_days","type":"Int64","description":"Sets the certificate validity period in days (range: 1-10,950 days / ~30 years). Defaults to 1,825 days (5 years). **Important**: This field is only settable during the certificate creation. Certificates becomes immutable after creation - use the `/activate` and `/deactivate` endpoints to manage certificate lifecycle.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Identify the certificate with a UUID.","requiresReplace":true},{"name":"binding_status","type":"String","description":"Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state."},{"name":"certificate","type":"String","description":"Provide the CA certificate (read-only)."},{"name":"created_at","type":"Time"},{"name":"expires_on","type":"Time"},{"name":"fingerprint","type":"String","description":"Provide the SHA256 fingerprint of the certificate (read-only)."},{"name":"in_use","type":"Bool","description":"Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)."},{"name":"issuer_org","type":"String","description":"Indicate the organization that issued the certificate (read-only)."},{"name":"issuer_raw","type":"String","description":"Provide the entire issuer field of the certificate (read-only)."},{"name":"type","type":"String","description":"Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed."},{"name":"updated_at","type":"Time"},{"name":"uploaded_on","type":"Time"}]}]},"post /accounts/{}/gateway/lists":{"operationId":"zero-trust-lists-create-zero-trust-list","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_list","stainlessResource":"zero_trust.gateway.lists","methodName":"create","snippet":"resource \"cloudflare_zero_trust_list\" \"example_zero_trust_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Admin Serial Numbers\"\n type = \"SERIAL\"\n description = \"The serial numbers for administrators\"\n items = [{\n description = \"Austin office IP\"\n value = \"8GE8721REF\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"type","type":"String","description":"Specify the list type.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the list name."}],"optional":[{"name":"items","type":"Set[Attributes]","description":"Add items to the list.","children":[{"name":"description","type":"String","description":"Provide the list item description (optional)."},{"name":"value","type":"String","description":"Specify the item value."}]},{"name":"description","type":"String","description":"Provide the list description."}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"list_count","type":"Float64","description":"Indicate the number of items in the list."},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/gateway/locations":{"operationId":"zero-trust-gateway-locations-create-zero-trust-gateway-location","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dns_location","stainlessResource":"zero_trust.gateway.locations","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dns_location\" \"example_zero_trust_dns_location\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Austin Office Location\"\n client_default = false\n dns_destination_ips_id = \"0e4a32c6-6fb8-4858-9296-98f51631e8e6\"\n ecs_support = false\n endpoints = {\n doh = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n require_token = true\n }\n dot = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n }\n ipv4 = {\n enabled = true\n }\n ipv6 = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n }\n }\n max_ttl = {\n mode = \"override\"\n ttl_secs = 3600\n }\n networks = [{\n network = \"192.0.2.1/32\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the location name."}],"optional":[{"name":"endpoints","type":"Attributes","description":"Configure the destination endpoints for this location.","children":[{"name":"doh","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOH endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]},{"name":"require_token","type":"Bool","description":"Specify whether the DOH endpoint requires user identity authentication."}]},{"name":"dot","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOT endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]}]},{"name":"ipv4","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPv4 endpoint is enabled for this location."}]},{"name":"ipv6","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPV6 endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv6 address or IPv6 CIDR."}]}]}]},{"name":"max_ttl","type":"Attributes","description":"Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.","children":[{"name":"mode","type":"String","description":"`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged."},{"name":"ttl_secs","type":"Int64","description":"Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`."}]},{"name":"networks","type":"List[Attributes]","description":"Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24."}]},{"name":"client_default","type":"Bool","description":"Indicate whether this location is the default location."},{"name":"dns_destination_ips_id","type":"String","description":"Specify the identifier of the pair of IPv4 addresses assigned to this location. When creating a location, if this field is absent or set to null, the pair of shared IPv4 addresses (0e4a32c6-6fb8-4858-9296-98f51631e8e6) is auto-assigned. When updating a location, if this field is absent or set to null, the pre-assigned pair remains unchanged."},{"name":"ecs_support","type":"Bool","description":"Indicate whether the location must resolve EDNS queries."}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"dns_destination_ipv6_block_id","type":"String","description":"Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block."},{"name":"doh_subdomain","type":"String","description":"Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value."},{"name":"ip","type":"String","description":"Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location."},{"name":"ipv4_destination","type":"String","description":"Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"ipv4_destination_backup","type":"String","description":"Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/gateway/pacfiles":{"operationId":"zero-trust-gateway-pacfiles-create-pacfile","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_pacfile","stainlessResource":"zero_trust.gateway.pacfiles","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_pacfile\" \"example_zero_trust_gateway_pacfile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n contents = \"function FindProxyForURL(url, host) { return \\\"DIRECT\\\"; }\"\n name = \"Devops team\"\n description = \"PAC file for Devops team\"\n slug = \"pac_devops\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"contents","type":"String","description":"Actual contents of the PAC file"},{"name":"name","type":"String","description":"Name of the PAC file."}],"optional":[{"name":"slug","type":"String","description":"URL-friendly version of the PAC file name. If not provided, it will be auto-generated","requiresReplace":true},{"name":"description","type":"String","description":"Detailed description of the PAC file."}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"},{"name":"url","type":"String","description":"Unique URL to download the PAC file."}]}]},"post /accounts/{}/gateway/proxy_endpoints":{"operationId":"zero-trust-gateway-proxy-endpoints-create-proxy-endpoint","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_proxy_endpoint","stainlessResource":"zero_trust.gateway.proxy_endpoints","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_proxy_endpoint\" \"example_zero_trust_gateway_proxy_endpoint\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Devops team\"\n kind = \"ip\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the name of the proxy endpoint."}],"optional":[{"name":"kind","type":"String","description":"The proxy endpoint kind","requiresReplace":true},{"name":"ips","type":"List[String]","description":"Specify the list of CIDRs to restrict ingress connections."}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"subdomain","type":"String","description":"Specify the subdomain to use as the destination in the proxy client."},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/gateway/rules":{"operationId":"zero-trust-gateway-rules-create-zero-trust-gateway-rule","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_policy","stainlessResource":"zero_trust.gateway.rules","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_policy\" \"example_zero_trust_gateway_policy\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n action = \"allow\"\n name = \"block bad websites\"\n description = \"Block bad websites based on their host name.\"\n device_posture = \"any(device_posture.checks.passed[*] in {\\\"1308749e-fcfb-4ebc-b051-fe022b632644\\\"})\"\n enabled = true\n expiration = {\n expires_at = \"2014-01-01T05:20:20Z\"\n duration = 10\n }\n filters = [\"http\"]\n identity = \"any(identity.groups.name[*] in {\\\"finance\\\"})\"\n precedence = 0\n rule_settings = {\n add_headers = {\n My-Next-Header = [\"foo\", \"bar\"]\n X-Custom-Header-Name = [\"somecustomvalue\"]\n }\n allow_child_bypass = false\n audit_ssh = {\n command_logging = false\n }\n biso_admin_controls = {\n copy = \"remote_only\"\n dcp = true\n dd = true\n dk = true\n download = \"enabled\"\n dp = false\n du = true\n keyboard = \"enabled\"\n paste = \"enabled\"\n printing = \"enabled\"\n upload = \"enabled\"\n version = \"v1\"\n wm_id = \"475345dc-5299-4b6e-8f6a-3d3e4c8e9f1a\"\n }\n block_page = {\n target_uri = \"https://example.com\"\n include_context = true\n }\n block_page_enabled = true\n block_reason = \"This website is a security risk\"\n bypass_parent_rule = false\n check_session = {\n duration = \"300s\"\n enforce = true\n }\n delete_headers = [\"X-Old-Header\", \"X-Remove-Me\"]\n dns_resolvers = {\n ipv4 = [{\n ip = \"2.2.2.2\"\n port = 5053\n route_through_private_network = true\n vnet_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }]\n ipv6 = [{\n ip = \"2001:DB8::\"\n port = 5053\n route_through_private_network = true\n vnet_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }]\n }\n egress = {\n ipv4 = \"192.0.2.2\"\n ipv4_fallback = \"192.0.2.3\"\n ipv6 = \"2001:DB8::/64\"\n }\n forensic_copy = {\n enabled = true\n }\n ignore_cname_category_matches = true\n insecure_disable_dnssec_validation = false\n ip_categories = true\n ip_indicator_feeds = true\n l4override = {\n ip = \"1.1.1.1\"\n port = 0\n }\n notification_settings = {\n enabled = true\n include_context = true\n msg = \"msg\"\n support_url = \"support_url\"\n }\n override_host = \"example.com\"\n override_ips = [\"1.1.1.1\", \"2.2.2.2\"]\n payload_log = {\n enabled = true\n }\n quarantine = {\n file_types = [\"exe\"]\n }\n redirect = {\n target_uri = \"https://example.com\"\n include_context = true\n preserve_path_and_query = true\n }\n resolve_dns_internally = {\n fallback = \"none\"\n view_id = \"view_id\"\n }\n resolve_dns_through_cloudflare = true\n set_headers = {\n X-User-Identity = [\"user=@{identity.name}\"]\n }\n untrusted_cert = {\n action = \"error\"\n }\n }\n schedule = {\n fri = \"08:00-12:30,13:30-17:00\"\n mon = \"08:00-12:30,13:30-17:00\"\n sat = \"08:00-12:30,13:30-17:00\"\n sun = \"08:00-12:30,13:30-17:00\"\n thu = \"08:00-12:30,13:30-17:00\"\n time_zone = \"America/New York\"\n tue = \"08:00-12:30,13:30-17:00\"\n wed = \"08:00-12:30,13:30-17:00\"\n }\n traffic = \"http.request.uri matches \\\".*a/partial/uri.*\\\" and http.request.host in $01302951-49f9-47c9-a400-0297e60b6a10\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"action","type":"String","description":"Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`."},{"name":"name","type":"String","description":"Specify the rule name."}],"optional":[{"name":"description","type":"String","description":"Specify the rule description."},{"name":"filters","type":"List[String]","description":"Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value."},{"name":"device_posture","type":"String","description":"Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"enabled","type":"Bool","description":"Specify whether the rule is enabled."},{"name":"identity","type":"String","description":"Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"precedence","type":"Int64","description":"Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform."},{"name":"traffic","type":"String","description":"Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"expiration","type":"Attributes","description":"Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.","children":[{"name":"expires_at","type":"Time","description":"Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time."},{"name":"duration","type":"Int64","description":"Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule."},{"name":"expired","type":"Bool","description":"Indicates whether the policy is expired."}]},{"name":"rule_settings","type":"Attributes","description":"Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.","children":[{"name":"add_headers","type":"Map[List[String]]","description":"Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"allow_child_bypass","type":"Bool","description":"Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules."},{"name":"audit_ssh","type":"Attributes","description":"Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.","children":[{"name":"command_logging","type":"Bool","description":"Enable SSH command logging."}]},{"name":"biso_admin_controls","type":"Attributes","description":"Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.","children":[{"name":"copy","type":"String","description":"Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\"."},{"name":"dcp","type":"Bool","description":"Set to false to enable copy-pasting. Only applies when `version == \"v1\"`."},{"name":"dd","type":"Bool","description":"Set to false to enable downloading. Only applies when `version == \"v1\"`."},{"name":"dk","type":"Bool","description":"Set to false to enable keyboard usage. Only applies when `version == \"v1\"`."},{"name":"download","type":"String","description":"Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\"."},{"name":"dp","type":"Bool","description":"Set to false to enable printing. Only applies when `version == \"v1\"`."},{"name":"du","type":"Bool","description":"Set to false to enable uploading. Only applies when `version == \"v1\"`."},{"name":"keyboard","type":"String","description":"Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\"."},{"name":"paste","type":"String","description":"Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\"."},{"name":"printing","type":"String","description":"Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\"."},{"name":"upload","type":"String","description":"Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\"."},{"name":"version","type":"String","description":"Indicate which version of the browser isolation controls should apply."},{"name":"wm_id","type":"String","description":"Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser."}]},{"name":"block_page","type":"Attributes","description":"Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."}]},{"name":"block_page_enabled","type":"Bool","description":"Enable the custom block page. Settable only for `dns` rules with action `block`."},{"name":"block_reason","type":"String","description":"Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`."},{"name":"bypass_parent_rule","type":"Bool","description":"Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules."},{"name":"check_session","type":"Attributes","description":"Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.","children":[{"name":"duration","type":"String","description":"Sets the required session freshness threshold. The API returns a normalized version of this value."},{"name":"enforce","type":"Bool","description":"Enable session enforcement."}]},{"name":"delete_headers","type":"List[String]","description":"Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`."},{"name":"dns_resolvers","type":"Attributes","description":"Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"ipv4","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv4 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]},{"name":"ipv6","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv6 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]}]},{"name":"egress","type":"Attributes","description":"Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.","children":[{"name":"ipv4","type":"String","description":"Specify the IPv4 address to use for egress."},{"name":"ipv4_fallback","type":"String","description":"Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs."},{"name":"ipv6","type":"String","description":"Specify the IPv6 range to use for egress."}]},{"name":"forensic_copy","type":"Attributes","description":"Configure whether a copy of the HTTP request will be sent to storage when the rule matches.","children":[{"name":"enabled","type":"Bool","description":"Enable sending the copy to storage."}]},{"name":"ignore_cname_category_matches","type":"Bool","description":"Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules."},{"name":"insecure_disable_dnssec_validation","type":"Bool","description":"Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules."},{"name":"ip_categories","type":"Bool","description":"Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules."},{"name":"ip_indicator_feeds","type":"Bool","description":"Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules."},{"name":"l4override","type":"Attributes","description":"Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.","children":[{"name":"ip","type":"String","description":"Defines the IPv4 or IPv6 address."},{"name":"port","type":"Int64","description":"Defines a port number to use for TCP/UDP overrides."}]},{"name":"notification_settings","type":"Attributes","description":"Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.","children":[{"name":"enabled","type":"Bool","description":"Enable notification."},{"name":"include_context","type":"Bool","description":"Indicates whether to pass the context information as query parameters."},{"name":"msg","type":"String","description":"Customize the message shown in the notification."},{"name":"support_url","type":"String","description":"Defines an optional URL to direct users to additional information. If unset, the notification opens a block page."}]},{"name":"override_host","type":"String","description":"Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"override_ips","type":"List[String]","description":"Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"payload_log","type":"Attributes","description":"Configure DLP payload logging. Settable only for `http` rules.","children":[{"name":"enabled","type":"Bool","description":"Enable DLP payload logging for this rule."}]},{"name":"quarantine","type":"Attributes","description":"Configure settings that apply to quarantine rules. Settable only for `http` rules.","children":[{"name":"file_types","type":"List[String]","description":"Specify the types of files to sandbox."}]},{"name":"redirect","type":"Attributes","description":"Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."},{"name":"preserve_path_and_query","type":"Bool","description":"Specify whether to append the path and query parameters from the original request to target_uri."}]},{"name":"resolve_dns_internally","type":"Attributes","description":"Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"fallback","type":"String","description":"Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries."},{"name":"view_id","type":"String","description":"Specify the internal DNS view identifier to pass to the internal DNS service."}]},{"name":"resolve_dns_through_cloudflare","type":"Bool","description":"Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules."},{"name":"set_headers","type":"Map[List[String]]","description":"Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"untrusted_cert","type":"Attributes","description":"Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.","children":[{"name":"action","type":"String","description":"Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526."}]}]},{"name":"schedule","type":"Attributes","description":"Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.","children":[{"name":"fri","type":"String","description":"Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"mon","type":"String","description":"Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sat","type":"String","description":"Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sun","type":"String","description":"Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"thu","type":"String","description":"Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"time_zone","type":"String","description":"Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location."},{"name":"tue","type":"String","description":"Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"wed","type":"String","description":"Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."}]}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"deleted_at","type":"Time","description":"Indicate the date of deletion, if any."},{"name":"read_only","type":"Bool","description":"Indicate that this rule is shared via the Orgs API and read only."},{"name":"sharable","type":"Bool","description":"Indicate that this rule is sharable via the Orgs API."},{"name":"source_account","type":"String","description":"Provide the account tag of the account that created the rule."},{"name":"updated_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicate the version number of the rule(read-only)."},{"name":"warning_status","type":"String","description":"Indicate a warning for a misconfigured rule, if any."}]}]},"post /accounts/{}/hyperdrive/configs":{"operationId":"create-hyperdrive","declarations":[{"kind":"resource","name":"cloudflare_hyperdrive_config","stainlessResource":"hyperdrive.configs","methodName":"create","snippet":"resource \"cloudflare_hyperdrive_config\" \"example_hyperdrive_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example-hyperdrive\"\n origin = {\n database = \"postgres\"\n host = \"database.example.com\"\n password = \"password\"\n port = 5432\n scheme = \"postgres\"\n user = \"postgres\"\n }\n caching = {\n disabled = true\n max_age = 0\n stale_while_revalidate = 0\n }\n integration = {\n\n }\n mtls = {\n ca_certificate_id = \"00000000-0000-0000-0000-0000000000\"\n mtls_certificate_id = \"00000000-0000-0000-0000-0000000000\"\n sslmode = \"verify-full\"\n }\n origin_connection_limit = 60\n}\n","required":[{"name":"account_id","type":"String","description":"Define configurations using a unique string identifier.","requiresReplace":true},{"name":"name","type":"String","description":"The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API."}],"optional":[{"name":"integration","type":"unknown","requiresReplace":true},{"name":"origin_connection_limit","type":"Int64","description":"The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit.\n"},{"name":"caching","type":"Attributes","children":[{"name":"disabled","type":"Bool"},{"name":"max_age","type":"Int64"},{"name":"stale_while_revalidate","type":"Int64"}]},{"name":"mtls","type":"Attributes","description":"mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.","children":[{"name":"ca_certificate_id","type":"String","description":"Define CA certificate ID obtained after uploading CA cert."},{"name":"mtls_certificate_id","type":"String","description":"Define mTLS certificate ID obtained after uploading client cert."},{"name":"sslmode","type":"String","description":"PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate."}]},{"name":"origin","type":"Attributes","description":"Combines database connection fields with exactly one supported network location.","children":[{"name":"database","type":"String","description":"Set the name of your origin database."},{"name":"host","type":"String","description":"Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed."},{"name":"password","type":"String","description":"Set the password needed to access your origin database. The API never returns this write-only value.","sensitive":true},{"name":"port","type":"Int64","description":"Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"user","type":"String","description":"Set the user of your origin database."},{"name":"access_client_id","type":"String","description":"Defines the Client ID of the Access token to use when connecting to the origin database."},{"name":"access_client_secret","type":"String","description":"Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.","sensitive":true},{"name":"service_id","type":"String","description":"The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database."}]}],"computed":[{"name":"id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"created_on","type":"Time","description":"Defines the creation time of the Hyperdrive configuration."},{"name":"modified_on","type":"Time","description":"Defines the last modified time of the Hyperdrive configuration."},{"name":"restarted_on","type":"Time","description":"Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted."}]}]},"post /accounts/{}/iam/user_groups":{"operationId":"account-user-group-create","declarations":[{"kind":"resource","name":"cloudflare_user_group","stainlessResource":"iam.user_groups","methodName":"create","snippet":"resource \"cloudflare_user_group\" \"example_user_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My New User Group\"\n policies = [{\n access = \"allow\"\n permission_groups = [{\n id = \"c8fed203ed3043cba015a93ad1616f1f\"\n }, {\n id = \"82e64a83756745bbbb1c9c2701bf816b\"\n }]\n resource_groups = [{\n id = \"6d7f2f5f5b1d4a0e9081fdc98d432fd1\"\n }]\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"name","type":"String","description":"Name of the User group."}],"optional":[{"name":"policies","type":"List[Attributes]","description":"Policies attached to the User group","children":[{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Permission Group identifier tag."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A set of resource groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Resource Group identifier tag."}]}]}],"computed":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the user group"},{"name":"modified_on","type":"Time","description":"Last time the user group was modified."}]}]},"post /accounts/{}/iam/user_groups/{}/members":{"operationId":"account-user-group-member-create","declarations":[{"kind":"resource","name":"cloudflare_user_group_members","stainlessResource":"iam.user_groups.members","methodName":"create","snippet":"resource \"cloudflare_user_group_members\" \"example_user_group_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n members = [{\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n }]\n}\n","required":[{"name":"user_group_id","type":"String","description":"User Group identifier tag.","requiresReplace":true},{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"members","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The identifier of an existing account Member."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"User Group identifier tag.","requiresReplace":true}]}]},"post /accounts/{}/images/v1/variants":{"operationId":"cloudflare-images-variants-create-a-variant","declarations":[{"kind":"resource","name":"cloudflare_image_variant","stainlessResource":"images.v1.variants","methodName":"create","snippet":"resource \"cloudflare_image_variant\" \"example_image_variant\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"hero\"\n options = {\n fit = \"scale-down\"\n height = 768\n metadata = \"none\"\n width = 1366\n }\n never_require_signed_urls = true\n}\n","required":[{"name":"id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"options","type":"Attributes","description":"Allows you to define image resizing sizes for different use cases.","children":[{"name":"fit","type":"String","description":"The fit property describes how the width and height dimensions should be interpreted."},{"name":"height","type":"Float64","description":"Maximum height in image pixels."},{"name":"metadata","type":"String","description":"What EXIF data should be preserved in the output image."},{"name":"width","type":"Float64","description":"Maximum width in image pixels."}]}],"optional":[{"name":"never_require_signed_urls","type":"Bool","description":"Indicates whether the variant can access an image without a signature, regardless of image access control."}],"computed":[{"name":"variant","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"options","type":"Attributes","description":"Allows you to define image resizing sizes for different use cases.","children":[{"name":"fit","type":"String","description":"The fit property describes how the width and height dimensions should be interpreted."},{"name":"height","type":"Float64","description":"Maximum height in image pixels."},{"name":"metadata","type":"String","description":"What EXIF data should be preserved in the output image."},{"name":"width","type":"Float64","description":"Maximum width in image pixels."}]},{"name":"never_require_signed_urls","type":"Bool","description":"Indicates whether the variant can access an image without a signature, regardless of image access control."}]}]}]},"post /accounts/{}/infrastructure/targets":{"operationId":"infra-targets-post","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_infrastructure_target","stainlessResource":"zero_trust.access.infrastructure.targets","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_infrastructure_target\" \"example_zero_trust_access_infrastructure_target\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"infra-access-target\"\n ip = {\n ipv4 = {\n ip_addr = \"187.26.29.249\"\n virtual_network_id = \"c77b744e-acc8-428f-9257-6878c046ed55\"\n }\n ipv6 = {\n ip_addr = \"64c0:64e8:f0b4:8dbf:7104:72b0:ec8f:f5e0\"\n virtual_network_id = \"c77b744e-acc8-428f-9257-6878c046ed55\"\n }\n }\n tags = {\n foo = \"string\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier","requiresReplace":true},{"name":"hostname","type":"String","description":"A non-unique field that refers to a target. Case insensitive, maximum\nlength of 255 characters, supports the use of special characters dash\nand period, does not support spaces, and must start and end with an\nalphanumeric character."},{"name":"ip","type":"Attributes","description":"The IPv4/IPv6 address that identifies where to reach a target","children":[{"name":"ipv4","type":"Attributes","description":"The target's IPv4 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]},{"name":"ipv6","type":"Attributes","description":"The target's IPv6 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]}]}],"optional":[{"name":"tags","type":"Map[String]","description":"Optional tags to associate with the target. Keys and values are\nuser-defined strings."}],"computed":[{"name":"id","type":"String","description":"Target identifier"},{"name":"created_at","type":"Time","description":"Date and time at which the target was created"},{"name":"modified_at","type":"Time","description":"Date and time at which the target was modified"}]}]},"post /accounts/{}/load_balancers/monitor_groups":{"operationId":"account-load-balancer-monitor-groups-create-monitor-group","declarations":[{"kind":"resource","name":"cloudflare_load_balancer_monitor_group","stainlessResource":"load_balancers.monitor_groups","methodName":"create","snippet":"resource \"cloudflare_load_balancer_monitor_group\" \"example_load_balancer_monitor_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n description = \"Primary datacenter monitors\"\n members = [{\n enabled = true\n monitor_id = \"monitor_id\"\n monitoring_only = false\n must_be_healthy = true\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"description","type":"String","description":"A short description of the monitor group"},{"name":"members","type":"Set[Attributes]","description":"List of monitors in this group","children":[{"name":"enabled","type":"Bool","description":"Whether this monitor is enabled in the group"},{"name":"monitor_id","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitoring_only","type":"Bool","description":"Whether this monitor is used for monitoring only (does not affect pool health)"},{"name":"must_be_healthy","type":"Bool","description":"Whether this monitor must be healthy for the pool to be considered healthy"},{"name":"created_at","type":"Time","description":"The timestamp of when the monitor was added to the group"},{"name":"updated_at","type":"Time","description":"The timestamp of when the monitor group member was last updated"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"created_on","type":"Time","description":"The timestamp of when the monitor group was created"},{"name":"modified_on","type":"Time","description":"The timestamp of when the monitor group was last updated"}]}]},"post /accounts/{}/load_balancers/monitors":{"operationId":"account-load-balancer-monitors-create-monitor","declarations":[{"kind":"resource","name":"cloudflare_load_balancer_monitor","stainlessResource":"load_balancers.monitors","methodName":"create","snippet":"resource \"cloudflare_load_balancer_monitor\" \"example_load_balancer_monitor\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n allow_insecure = true\n consecutive_down = 0\n consecutive_up = 0\n description = \"Login page monitor\"\n expected_body = \"alive\"\n expected_codes = \"2xx\"\n follow_redirects = true\n header = {\n Host = [\"example.com\"]\n X-App-ID = [\"abc123\"]\n }\n interval = 0\n method = \"GET\"\n path = \"/health\"\n port = 0\n probe_zone = \"example.com\"\n retries = 0\n timeout = 0\n type = \"https\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"consecutive_down","type":"Int64","description":"To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times."},{"name":"consecutive_up","type":"Int64","description":"To be marked healthy the monitored origin must pass this healthcheck N consecutive times."},{"name":"port","type":"Int64","description":"The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors."},{"name":"description","type":"String","description":"Object description."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"expected_codes","type":"String","description":"The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations."},{"name":"method","type":"String","description":"The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks."},{"name":"path","type":"String","description":"The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"probe_zone","type":"String","description":"Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'."}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}]},"post /accounts/{}/load_balancers/pools":{"operationId":"account-load-balancer-pools-create-pool","declarations":[{"kind":"resource","name":"cloudflare_load_balancer_pool","stainlessResource":"load_balancers.pools","methodName":"create","snippet":"resource \"cloudflare_load_balancer_pool\" \"example_load_balancer_pool\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"primary-dc-1\"\n origins = [{\n address = \"0.0.0.0\"\n enabled = true\n flatten_cname = true\n header = {\n host = [\"example.com\"]\n }\n name = \"app-server-1\"\n port = 0\n virtual_network_id = \"a5624d4e-044a-4ff0-b3e1-e2465353d4b4\"\n weight = 0.6\n }]\n description = \"Primary data center - Provider XYZ\"\n enabled = false\n latitude = 0\n load_shedding = {\n default_percent = 0\n default_policy = \"random\"\n session_percent = 0\n session_policy = \"hash\"\n }\n longitude = 0\n minimum_origins = 0\n monitor = \"monitor\"\n monitor_group = \"monitor_group\"\n notification_email = \"someone@example.com,sometwo@example.com\"\n notification_filter = {\n origin = {\n disable = true\n healthy = true\n }\n pool = {\n disable = true\n healthy = false\n }\n }\n origin_steering = {\n policy = \"random\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed."},{"name":"origins","type":"Set[Attributes]","description":"The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.","children":[{"name":"address","type":"String","description":"The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the origin is disabled. This field is set with the time the origin was disabled."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool."},{"name":"flatten_cname","type":"Bool","description":"Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting."},{"name":"header","type":"Attributes","description":"The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.","children":[{"name":"host","type":"List[String]","description":"The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin."}]},{"name":"name","type":"String","description":"A human-identifiable name for the origin."},{"name":"port","type":"Int64","description":"The port for upstream connections. A value of 0 means the default port for the protocol will be used."},{"name":"virtual_network_id","type":"String","description":"The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account."},{"name":"weight","type":"Float64","description":"The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections."}]}],"optional":[{"name":"latitude","type":"Float64","description":"The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set."},{"name":"longitude","type":"Float64","description":"The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set."},{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitor_group","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means every Cloudflare data center."},{"name":"health_sources","type":"List[String]","description":"A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions."},{"name":"description","type":"String","description":"A human-readable description of the pool."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)."},{"name":"minimum_origins","type":"Int64","description":"The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool."},{"name":"notification_email","type":"String","description":"This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list."},{"name":"load_shedding","type":"Attributes","description":"Configures load shedding policies and percentages for the pool.","children":[{"name":"default_percent","type":"Float64","description":"The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity."},{"name":"default_policy","type":"String","description":"The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs."},{"name":"session_percent","type":"Float64","description":"The percent of existing sessions to shed from the pool, according to the session policy."},{"name":"session_policy","type":"String","description":"Only the hash policy is supported for existing sessions (to avoid exponential decay)."}]},{"name":"notification_filter","type":"Attributes","description":"Filter pool and origin health notifications by resource type or health status. Use null to reset.","children":[{"name":"origin","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]},{"name":"pool","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]}]},{"name":"origin_steering","type":"Attributes","description":"Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.","children":[{"name":"policy","type":"String","description":"The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"String"},{"name":"disabled_at","type":"Time","description":"This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at."},{"name":"modified_on","type":"String"},{"name":"networks","type":"List[String]","description":"List of networks where Load Balancer or Pool is enabled."}]}]},"post /accounts/{}/magic/bgp/filter_profiles":{"operationId":"magic-bgp-create-filter-profile","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_bgp_filter_profile","stainlessResource":"magic_transit.bgp_filter_profiles","methodName":"create","snippet":"resource \"cloudflare_magic_wan_bgp_filter_profile\" \"example_magic_wan_bgp_filter_profile\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n match_action = \"allow\"\n name = \"Allowed On-Prem Imports\"\n targets = [\"10.0.0.0/8{8,32}\"]\n description = \"Allowed corporate subnets from on-premises\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"match_action","type":"String","description":"Action to take when a route matches one of the targets in this profile"},{"name":"name","type":"String","description":"Friendly name for the filter profile"},{"name":"targets","type":"List[String]","description":"List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N."}],"optional":[{"name":"description","type":"String","description":"Description of the filter profile"}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]},"post /accounts/{}/magic/cf1_sites":{"operationId":"magic-cf1-sites-create-cf1-sites","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_cf1_site","stainlessResource":"magic_transit.cf1_sites","methodName":"create","snippet":"resource \"cloudflare_magic_transit_cf1_site\" \"example_magic_transit_cf1_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n body = [{\n name = \"Pad 34\"\n description = \"Launch Pad 34\"\n location = {\n lat = 28.521339842093845\n long = -80.56092644815843\n name = \"Cape Canaveral\"\n }\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"body","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]},{"name":"modified_on","type":"Time"}]}],"optional":[{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]},"post /accounts/{}/magic/connectors":{"operationId":"mconn-connectors-create","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_connector","stainlessResource":"magic_transit.connectors","methodName":"create","snippet":"resource \"cloudflare_magic_transit_connector\" \"example_magic_transit_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n device = {\n id = \"id\"\n provision_license = true\n serial_number = \"serial_number\"\n }\n activated = true\n interrupt_window_days_of_week = [\"Sunday\"]\n interrupt_window_duration_hours = 1\n interrupt_window_embargo_dates = [\"string\"]\n interrupt_window_hour_of_day = 0\n notes = \"notes\"\n timezone = \"timezone\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"device","type":"Attributes","description":"Exactly one of id, serial_number, or provision_license must be provided.","requiresReplace":true,"children":[{"name":"id","type":"String"},{"name":"provision_license","type":"Bool","description":"When true, create and provision a new licence key for the connector."},{"name":"serial_number","type":"String"}]}],"optional":[{"name":"provision_license","type":"Bool","description":"When true, regenerate license key for the connector."},{"name":"activated","type":"Bool"},{"name":"interrupt_window_duration_hours","type":"Float64"},{"name":"interrupt_window_hour_of_day","type":"Float64"},{"name":"notes","type":"String"},{"name":"timezone","type":"String"},{"name":"interrupt_window_days_of_week","type":"List[String]","description":"Allowed days of the week for upgrades. Default is all days."},{"name":"interrupt_window_embargo_dates","type":"List[String]","description":"List of dates (YYYY-MM-DD) when upgrades are blocked."}],"computed":[{"name":"id","type":"String"},{"name":"last_heartbeat","type":"String"},{"name":"last_seen_version","type":"String"},{"name":"last_updated","type":"String"},{"name":"license_key","type":"String"}]}]},"post /accounts/{}/magic/gre_tunnels":{"operationId":"magic-gre-tunnels-create-gre-tunnels","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_gre_tunnel","stainlessResource":"magic_transit.gre_tunnels","methodName":"create","snippet":"resource \"cloudflare_magic_wan_gre_tunnel\" \"example_magic_wan_gre_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cloudflare_gre_endpoint = \"203.0.113.1\"\n customer_gre_endpoint = \"203.0.113.1\"\n interface_address = \"192.0.2.0/31\"\n name = \"GRE_1\"\n automatic_return_routing = true\n bgp = {\n customer_asn = 0\n export_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n extra_prefixes = [\"string\"]\n import_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n md5_key = \"md5_key\"\n }\n description = \"Tunnel for ISP X\"\n health_check = {\n direction = \"bidirectional\"\n enabled = true\n rate = \"low\"\n target = {\n saved = \"203.0.113.1\"\n }\n type = \"request\"\n }\n interface_address6 = \"2606:54c1:7:0:a9fe:12d2:1:200/127\"\n mtu = 0\n ttl = 0\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."}],"optional":[{"name":"bgp","type":"Attributes","requiresReplace":true,"children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"modified","type":"Bool"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"gre_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."}]},{"name":"modified_gre_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."}]}]}]},"post /accounts/{}/magic/ipsec_tunnels":{"operationId":"magic-ipsec-tunnels-create-ipsec-tunnels","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_ipsec_tunnel","stainlessResource":"magic_transit.ipsec_tunnels","methodName":"create","snippet":"resource \"cloudflare_magic_wan_ipsec_tunnel\" \"example_magic_wan_ipsec_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cloudflare_endpoint = \"203.0.113.1\"\n interface_address = \"192.0.2.0/31\"\n name = \"IPsec_1\"\n automatic_return_routing = true\n bgp = {\n customer_asn = 0\n export_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n extra_prefixes = [\"string\"]\n import_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n md5_key = \"md5_key\"\n }\n custom_remote_identities = {\n fqdn_id = \"fqdn_id\"\n }\n customer_endpoint = \"203.0.113.1\"\n description = \"Tunnel for ISP X\"\n health_check = {\n direction = \"bidirectional\"\n enabled = true\n rate = \"low\"\n target = {\n saved = \"203.0.113.1\"\n }\n type = \"request\"\n }\n interface_address6 = \"2606:54c1:7:0:a9fe:12d2:1:200/127\"\n psk = \"O3bwKSjnaoCxDoUxjcq4Rk8ZKkezQUiy\"\n replay_protection = false\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."}],"optional":[{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"psk","type":"String","description":"A randomly generated or provided string for use in the IPsec tunnel.","sensitive":true},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"modified","type":"Bool"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"ipsec_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."}]},{"name":"modified_ipsec_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."}]},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]}]}]},"post /accounts/{}/magic/routes":{"operationId":"magic-static-routes-create-routes","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_static_route","stainlessResource":"magic_transit.routes","methodName":"create","snippet":"resource \"cloudflare_magic_wan_static_route\" \"example_magic_wan_static_route\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n nexthop = \"203.0.113.1\"\n prefix = \"192.0.2.0/24\"\n priority = 0\n description = \"New route for new prefix 203.0.113.1\"\n scope = {\n colo_names = [\"den01\"]\n colo_regions = [\"APAC\"]\n }\n weight = 0\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."}],"optional":[{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"modified","type":"Bool"},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"modified_route","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."}]},{"name":"route","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."}]}]}]},"post /accounts/{}/magic/sites":{"operationId":"magic-sites-create-site","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site","stainlessResource":"magic_transit.sites","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site\" \"example_magic_transit_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"site_1\"\n connector_id = \"ac60d3d0435248289d446cedd870bcf4\"\n description = \"description\"\n ha_mode = true\n location = {\n lat = \"37.6192\"\n lon = \"122.3816\"\n }\n secondary_connector_id = \"8d67040d3835dbcf46ce29da440dc482\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"name","type":"String","description":"The name of the site."}],"optional":[{"name":"connector_id","type":"String","description":"Magic Connector identifier tag."},{"name":"description","type":"String"},{"name":"ha_mode","type":"Bool","description":"Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode."},{"name":"secondary_connector_id","type":"String","description":"Magic Connector identifier tag. Used when high availability mode is on."},{"name":"location","type":"Attributes","description":"Location of site in latitude and longitude.","children":[{"name":"lat","type":"String","description":"Latitude"},{"name":"lon","type":"String","description":"Longitude"}]}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/magic/sites/{}/acls":{"operationId":"magic-site-acls-create-acl","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site_acl","stainlessResource":"magic_transit.sites.acls","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site_acl\" \"example_magic_transit_site_acl\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lan_1 = {\n lan_id = \"lan_id\"\n lan_name = \"lan_name\"\n port_ranges = [\"8080-9000\"]\n ports = [1]\n subnets = [\"192.0.2.1\"]\n }\n lan_2 = {\n lan_id = \"lan_id\"\n lan_name = \"lan_name\"\n port_ranges = [\"8080-9000\"]\n ports = [1]\n subnets = [\"192.0.2.1\"]\n }\n name = \"PIN Pad - Cash Register\"\n description = \"Allows local traffic between PIN pads and cash register.\"\n forward_locally = true\n protocols = [\"tcp\"]\n unidirectional = true\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"site_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"name","type":"String","description":"The name of the ACL."},{"name":"lan_1","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"lan_2","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]}],"optional":[{"name":"description","type":"String","description":"Description for the ACL."},{"name":"forward_locally","type":"Bool","description":"The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false."},{"name":"unidirectional","type":"Bool","description":"The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false."},{"name":"protocols","type":"List[String]"}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/magic/sites/{}/lans":{"operationId":"magic-site-lans-create-lan","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site_lan","stainlessResource":"magic_transit.sites.lans","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site_lan\" \"example_magic_transit_site_lan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bond_id = 2\n ha_link = true\n is_breakout = true\n is_prioritized = true\n name = \"name\"\n nat = {\n static_prefix = \"192.0.2.0/24\"\n }\n physport = 1\n routed_subnets = [{\n next_hop = \"192.0.2.1\"\n prefix = \"192.0.2.0/24\"\n nat = {\n static_prefix = \"192.0.2.0/24\"\n }\n }]\n static_addressing = {\n address = \"192.0.2.0/24\"\n dhcp_relay = {\n server_addresses = [\"192.0.2.1\"]\n }\n dhcp_server = {\n dhcp_options = [{\n code = 66\n type = \"ip\"\n value = \"10.20.30.40\"\n }]\n dhcp_pool_end = \"192.0.2.1\"\n dhcp_pool_start = \"192.0.2.1\"\n dns_server = \"192.0.2.1\"\n dns_servers = [\"192.0.2.1\"]\n reservations = {\n \"00:11:22:33:44:55\" = \"192.0.2.100\"\n \"AA:BB:CC:DD:EE:FF\" = \"192.168.1.101\"\n }\n }\n secondary_address = \"192.0.2.0/24\"\n virtual_address = \"192.0.2.0/24\"\n }\n vlan_tag = 42\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"site_id","type":"String","description":"Identifier","requiresReplace":true}],"optional":[{"name":"bond_id","type":"Int64"},{"name":"ha_link","type":"Bool","description":"mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link."},{"name":"is_breakout","type":"Bool","description":"mark true to use this LAN for source-based breakout traffic"},{"name":"is_prioritized","type":"Bool","description":"mark true to use this LAN for source-based prioritized traffic"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"routed_subnets","type":"List[Attributes]","children":[{"name":"next_hop","type":"String","description":"A valid IPv4 address."},{"name":"prefix","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]}]},{"name":"static_addressing","type":"Attributes","description":"If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"dhcp_relay","type":"Attributes","children":[{"name":"server_addresses","type":"List[String]","description":"List of DHCP server IPs."}]},{"name":"dhcp_server","type":"Attributes","children":[{"name":"dhcp_options","type":"List[Attributes]","description":"Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.","children":[{"name":"code","type":"Int64","description":"DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration."},{"name":"type","type":"String","description":"The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\n"},{"name":"value","type":"String","description":"The option value, interpreted according to the type field."}]},{"name":"dhcp_pool_end","type":"String","description":"A valid IPv4 address."},{"name":"dhcp_pool_start","type":"String","description":"A valid IPv4 address."},{"name":"dns_server","type":"String","description":"A valid IPv4 address.","deprecated":"Deprecated."},{"name":"dns_servers","type":"List[String]"},{"name":"reservations","type":"Map[String]","description":"Mapping of MAC addresses to IP addresses"}]},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"virtual_address","type":"String","description":"A valid CIDR notation representing an IP range."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/magic/sites/{}/wans":{"operationId":"magic-site-wans-create-wan","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site_wan","stainlessResource":"magic_transit.sites.wans","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site_wan\" \"example_magic_transit_site_wan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n physport = 1\n health_check_rate = \"low\"\n load_balance_inner_flows = true\n name = \"name\"\n priority = 0\n static_addressing = {\n address = \"192.0.2.0/24\"\n gateway_address = \"192.0.2.1\"\n secondary_address = \"192.0.2.0/24\"\n }\n vlan_tag = 42\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"site_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"physport","type":"Int64"}],"optional":[{"name":"name","type":"String"},{"name":"priority","type":"Int64"},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"static_addressing","type":"Attributes","description":"(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"gateway_address","type":"String","description":"A valid IPv4 address."},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"health_check_rate","type":"String","description":"Magic WAN health check rate for tunnels created on this link. The default value is `mid`."},{"name":"load_balance_inner_flows","type":"Bool"}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/members":{"operationId":"account-members-add-member","declarations":[{"kind":"resource","name":"cloudflare_account_member","stainlessResource":"accounts.members","methodName":"create","snippet":"resource \"cloudflare_account_member\" \"example_account_member\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"user@example.com\"\n roles = [\"3536bcfad5faccb999b47003c79917fb\"]\n status = \"accepted\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"email","type":"String","description":"The contact email address of the user.","requiresReplace":true}],"optional":[{"name":"status","type":"String","description":"Status of the member invitation. If not provided during creation, defaults to 'pending'.\nChanging from 'accepted' back to 'pending' will trigger a replacement of the member resource in Terraform.\n","requiresReplace":true},{"name":"roles","type":"List[String]","description":"Array of roles associated with this member."},{"name":"policies","type":"List[Attributes]","description":"Array of policies associated with this member.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the group."}]}]}],"computed":[{"name":"id","type":"String","description":"Membership identifier tag."},{"name":"user","type":"Attributes","description":"Details of the user associated to the membership.","children":[{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"id","type":"String","description":"Identifier"},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."}]}]}]},"post /accounts/{}/mnm/config":{"operationId":"magic-network-monitoring-configuration-create-account-configuration","declarations":[{"kind":"resource","name":"cloudflare_magic_network_monitoring_configuration","stainlessResource":"magic_network_monitoring.configs","methodName":"create","snippet":"resource \"cloudflare_magic_network_monitoring_configuration\" \"example_magic_network_monitoring_configuration\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n default_sampling = 1\n name = \"cloudflare user\\'s account\"\n router_ips = [\"203.0.113.1\"]\n warp_devices = [{\n id = \"5360368d-b351-4791-abe1-93550dabd351\"\n name = \"My warp device\"\n router_ip = \"203.0.113.1\"\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The account name."}],"optional":[{"name":"router_ips","type":"List[String]"},{"name":"warp_devices","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the warp device."},{"name":"name","type":"String","description":"Name of the warp device."},{"name":"router_ip","type":"String","description":"IPv4 CIDR of the router sourcing flow data associated with this warp device. Only /32 addresses are currently supported."}]},{"name":"default_sampling","type":"Float64","description":"Fallback sampling rate of flow messages being sent in packets per second. This should match the packet sampling rate configured on the router."}],"computed":[]}]},"post /accounts/{}/mnm/rules":{"operationId":"magic-network-monitoring-rules-create-rules","declarations":[{"kind":"resource","name":"cloudflare_magic_network_monitoring_rule","stainlessResource":"magic_network_monitoring.rules","methodName":"create","snippet":"resource \"cloudflare_magic_network_monitoring_rule\" \"example_magic_network_monitoring_rule\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n automatic_advertisement = true\n name = \"my_rule_1\"\n prefixes = [\"203.0.113.1/32\"]\n type = \"zscore\"\n bandwidth_threshold = 1000\n duration = \"1m\"\n packet_threshold = 10000\n prefix_match = \"exact\"\n zscore_sensitivity = \"high\"\n zscore_target = \"bits\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"automatic_advertisement","type":"Bool","description":"Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit."},{"name":"name","type":"String","description":"The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters."},{"name":"type","type":"String","description":"MNM rule type."},{"name":"prefixes","type":"List[String]"}],"optional":[{"name":"bandwidth_threshold","type":"Float64","description":"The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"packet_threshold","type":"Float64","description":"The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"prefix_match","type":"String","description":"Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule."},{"name":"zscore_sensitivity","type":"String","description":"Level of sensitivity set for zscore rules."},{"name":"zscore_target","type":"String","description":"Target of the zscore rule analysis."},{"name":"duration","type":"String","description":"The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"]."}],"computed":[{"name":"id","type":"String","description":"The id of the rule. Must be unique."}]}]},"post /accounts/{}/moq/relays":{"operationId":"moq-relays-create","declarations":[{"kind":"resource","name":"cloudflare_moq_relay","stainlessResource":"moq.relays","methodName":"create","snippet":"resource \"cloudflare_moq_relay\" \"example_moq_relay\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production Live Stream\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Human-readable name for the relay."}],"optional":[{"name":"config","type":"Attributes","children":[{"name":"upstreams","type":"Attributes","description":"Upstreams are external MOQT server publishers that a relay falls back\nto when it has no local publisher for a requested namespace/track.\n","children":[{"name":"enabled","type":"Bool"},{"name":"upstreams","type":"List[Attributes]","description":"Ordered list of upstream MOQT server publishers. Each entry is an\nobject (not a bare string) so per-upstream configuration can be\nadded in the future without another breaking change.\n","children":[{"name":"url","type":"String","description":"Upstream MOQT server publisher URL. Must be an absolute URL with a\nhost and a scheme the relay can dial: moqt:// (raw QUIC) or https://\n(WebTransport). Validated on update (PUT); rejected with 21013.\n"}]}]}]}],"computed":[{"name":"id","type":"String","description":"Server-generated unique identifier (32 hex chars)."},{"name":"uid","type":"String","description":"Server-generated unique identifier (32 hex chars)."},{"name":"created","type":"Time"},{"name":"modified","type":"Time"},{"name":"status","type":"String","description":"\"connected\" when active, omitted otherwise."},{"name":"issuers","type":"List[Attributes]","description":"Token collection (discriminated union on `type`). On create this\nholds the auto-created default pair, each including its one-time\nsecret.\n","children":[{"name":"cloudflare_tokens","type":"List[Attributes]","description":"Always present ([] when empty).","children":[{"name":"created","type":"Time"},{"name":"expires","type":"Time","description":"Mandatory; no more than 1 year after `created`."},{"name":"jti","type":"String","description":"Token identity and registry key (32 hex chars)."},{"name":"operations","type":"List[String]","description":"Signed allowlist of what the token may do. V1 coarse roles; the array\nform extends to fine-grained MoQT message names later without a\nbreaking change.\n"},{"name":"label","type":"String","description":"Optional, customer-set."},{"name":"secret","type":"String","description":"The signed JWT. Present ONLY in create / auto-create responses (shown\nonce); never returned by list, never stored.\n","sensitive":true}]},{"name":"issuer","type":"String"},{"name":"type","type":"String"}]}]}]},"post /accounts/{}/oauth_clients":{"operationId":"oauth-clients-create","declarations":[{"kind":"resource","name":"cloudflare_oauth_client","stainlessResource":"iam.oauth_clients","methodName":"create","snippet":"resource \"cloudflare_oauth_client\" \"example_oauth_client\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n client_name = \"My OAuth App\"\n grant_types = [\"authorization_code\", \"refresh_token\"]\n redirect_uris = [\"https://example.com/callback\"]\n response_types = [\"code\"]\n scopes = [\"account.read\"]\n token_endpoint_auth_method = \"client_secret_post\"\n allowed_cors_origins = [\"https://example.com\"]\n client_uri = \"https://example.com\"\n logo_uri = \"https://example.com/logo.png\"\n optional_scopes = [\"account.write\"]\n policy_uri = \"https://example.com/privacy\"\n post_logout_redirect_uris = [\"https://example.com/logout\"]\n tos_uri = \"https://example.com/tos\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"client_name","type":"String","description":"Human-readable name of the OAuth client."},{"name":"token_endpoint_auth_method","type":"String","description":"The authentication method the client uses at the token endpoint."},{"name":"grant_types","type":"List[String]","description":"Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally."},{"name":"redirect_uris","type":"List[String]","description":"Array of allowed redirect URIs for the client."},{"name":"response_types","type":"List[String]","description":"Array of OAuth response types the client is allowed to use."},{"name":"scopes","type":"List[String]","description":"Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`."}],"optional":[{"name":"oauth_client_id","type":"String","description":"The unique identifier for an OAuth client.","requiresReplace":true},{"name":"client_uri","type":"String","description":"URL of the home page of the client."},{"name":"logo_uri","type":"String","description":"URL of the client's logo."},{"name":"policy_uri","type":"String","description":"URL that points to a privacy policy document."},{"name":"tos_uri","type":"String","description":"URL that points to a terms of service document."},{"name":"visibility","type":"String","description":"Promote the OAuth client from private to public visibility. Only `public` is accepted; demotion to `private` is not supported. Promotion requires a non-empty client name, logo URI, verified client URI host, and at least one non-identity scope."},{"name":"allowed_cors_origins","type":"List[String]","description":"Array of allowed CORS origins."},{"name":"optional_scopes","type":"List[String]","description":"Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional."},{"name":"post_logout_redirect_uris","type":"List[String]","description":"Array of allowed post-logout redirect URIs."}],"computed":[{"name":"client_id","type":"String","description":"The unique identifier for an OAuth client."},{"name":"client_secret","type":"String","description":"The client secret. This is the only time the secret is returned in a response.","sensitive":true},{"name":"created_at","type":"Time","description":"Timestamp when the OAuth client was created."},{"name":"has_rotated_secret","type":"Bool","description":"Indicates whether the client has a rotated secret that has not yet been deleted."},{"name":"promoted_at","type":"Time","description":"Timestamp when the OAuth client was promoted to public visibility."},{"name":"updated_at","type":"Time","description":"Timestamp when the OAuth client was last updated."},{"name":"client_uri_verification","type":"Attributes","description":"Client URI domain control verification state.","children":[{"name":"status","type":"String","description":"Current verification status for the client URI host."},{"name":"text","type":"String","description":"Exact TXT record value that must be added to DNS to prove ownership of the client URI host."}]}]}]},"post /accounts/{}/pages/projects":{"operationId":"pages-project-create-project","declarations":[{"kind":"resource","name":"cloudflare_pages_project","stainlessResource":"pages.projects","methodName":"create","snippet":"resource \"cloudflare_pages_project\" \"example_pages_project\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-pages-app\"\n production_branch = \"main\"\n build_config = {\n build_caching = true\n build_command = \"npm run build\"\n destination_dir = \"build\"\n root_dir = \"/\"\n web_analytics_tag = \"cee1c73f6e4743d0b5e6bb1a0bcaabcc\"\n web_analytics_token = \"021e1057c18547eca7b79f2516f06o7x\"\n }\n deployment_configs = {\n preview = {\n ai_bindings = {\n AI_BINDING = {\n project_id = \"some-project-id\"\n }\n }\n always_use_latest_compatibility_date = false\n analytics_engine_datasets = {\n ANALYTICS_ENGINE_BINDING = {\n dataset = \"api_analytics\"\n }\n }\n browsers = {\n BROWSER = {\n\n }\n }\n build_image_major_version = 3\n compatibility_date = \"2025-01-01T00:00:00Z\"\n compatibility_flags = [\"url_standard\"]\n d1_databases = {\n D1_BINDING = {\n id = \"445e2955-951a-43f8-a35b-a4d0c8138f63\"\n }\n }\n durable_object_namespaces = {\n DO_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n env_vars = {\n foo = {\n type = \"plain_text\"\n value = \"hello world\"\n }\n }\n fail_open = true\n hyperdrive_bindings = {\n HYPERDRIVE = {\n id = \"a76a99bc342644deb02c38d66082262a\"\n }\n }\n kv_namespaces = {\n KV_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n limits = {\n cpu_ms = 100\n }\n mtls_certificates = {\n MTLS = {\n certificate_id = \"d7cdd17c-916f-4cb7-aabe-585eb382ec4e\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n queue_producers = {\n QUEUE_PRODUCER_BINDING = {\n name = \"some-queue\"\n }\n }\n r2_buckets = {\n R2_BINDING = {\n name = \"some-bucket\"\n jurisdiction = \"eu\"\n }\n }\n services = {\n SERVICE_BINDING = {\n service = \"example-worker\"\n entrypoint = \"MyHandler\"\n environment = \"production\"\n }\n }\n usage_model = \"standard\"\n vectorize_bindings = {\n VECTORIZE = {\n index_name = \"my_index\"\n }\n }\n wrangler_config_hash = \"abc123def456\"\n }\n production = {\n ai_bindings = {\n AI_BINDING = {\n project_id = \"some-project-id\"\n }\n }\n always_use_latest_compatibility_date = false\n analytics_engine_datasets = {\n ANALYTICS_ENGINE_BINDING = {\n dataset = \"api_analytics\"\n }\n }\n browsers = {\n BROWSER = {\n\n }\n }\n build_image_major_version = 3\n compatibility_date = \"2025-01-01T00:00:00Z\"\n compatibility_flags = [\"url_standard\"]\n d1_databases = {\n D1_BINDING = {\n id = \"445e2955-951a-43f8-a35b-a4d0c8138f63\"\n }\n }\n durable_object_namespaces = {\n DO_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n env_vars = {\n foo = {\n type = \"plain_text\"\n value = \"hello world\"\n }\n }\n fail_open = true\n hyperdrive_bindings = {\n HYPERDRIVE = {\n id = \"a76a99bc342644deb02c38d66082262a\"\n }\n }\n kv_namespaces = {\n KV_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n limits = {\n cpu_ms = 100\n }\n mtls_certificates = {\n MTLS = {\n certificate_id = \"d7cdd17c-916f-4cb7-aabe-585eb382ec4e\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n queue_producers = {\n QUEUE_PRODUCER_BINDING = {\n name = \"some-queue\"\n }\n }\n r2_buckets = {\n R2_BINDING = {\n name = \"some-bucket\"\n jurisdiction = \"eu\"\n }\n }\n services = {\n SERVICE_BINDING = {\n service = \"example-worker\"\n entrypoint = \"MyHandler\"\n environment = \"production\"\n }\n }\n usage_model = \"standard\"\n vectorize_bindings = {\n VECTORIZE = {\n index_name = \"my_index\"\n }\n }\n wrangler_config_hash = \"abc123def456\"\n }\n }\n source = {\n config = {\n deployments_enabled = true\n owner = \"my-org\"\n owner_id = \"12345678\"\n path_excludes = [\"string\"]\n path_includes = [\"string\"]\n pr_comments_enabled = true\n preview_branch_excludes = [\"string\"]\n preview_branch_includes = [\"string\"]\n preview_deployment_setting = \"all\"\n production_branch = \"main\"\n production_deployments_enabled = true\n repo_id = \"12345678\"\n repo_name = \"my-repo\"\n }\n type = \"github\"\n }\n}\n","required":[{"name":"name","type":"String","description":"Name for the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"production_branch","type":"String","description":"Production branch of the project. Used to identify production deployments."}],"optional":[{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."},{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true}]},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"deployment_configs","type":"Attributes","description":"Configs for deployments in a project.","children":[{"name":"preview","type":"Attributes","description":"Configs for preview deploys.","children":[{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."},{"name":"environment","type":"String","description":"The Service environment."}]},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]},{"name":"production","type":"Attributes","description":"Configs for production deploys.","children":[{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."},{"name":"environment","type":"String","description":"The Service environment."}]},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]}]}],"computed":[{"name":"id","type":"String","description":"Name for the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens.","requiresReplace":true},{"name":"created_on","type":"Time","description":"When the project was created."},{"name":"framework","type":"String","description":"Framework the project is using."},{"name":"framework_version","type":"String","description":"Version of the framework the project is using."},{"name":"preview_script_name","type":"String","description":"Name of the preview script."},{"name":"production_script_name","type":"String","description":"Name of the production script."},{"name":"subdomain","type":"String","description":"The Cloudflare subdomain associated with the project."},{"name":"uses_functions","type":"Bool","description":"Whether the project uses functions."},{"name":"domains","type":"List[String]","description":"A list of associated custom domains for the project."},{"name":"canonical_deployment","type":"Attributes","description":"Most recent production deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"latest_deployment","type":"Attributes","description":"Most recent deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]}]}]},"post /accounts/{}/pages/projects/{}/domains":{"operationId":"pages-domains-add-domain","declarations":[{"kind":"resource","name":"cloudflare_pages_domain","stainlessResource":"pages.projects.domains","methodName":"create","snippet":"resource \"cloudflare_pages_domain\" \"example_pages_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n name = \"example.com\"\n}\n","required":[{"name":"name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`.","requiresReplace":true},{"name":"certificate_authority","type":"String"},{"name":"created_on","type":"String"},{"name":"domain_id","type":"String"},{"name":"status","type":"String"},{"name":"zone_tag","type":"String"},{"name":"validation_data","type":"Attributes","children":[{"name":"method","type":"String"},{"name":"status","type":"String"},{"name":"error_message","type":"String"},{"name":"txt_name","type":"String"},{"name":"txt_value","type":"String"}]},{"name":"verification_data","type":"Attributes","children":[{"name":"status","type":"String"},{"name":"error_message","type":"String"}]}]}]},"post /accounts/{}/pipelines/v1/pipelines":{"operationId":"postV4AccountsByAccount_idPipelinesV1Pipelines","declarations":[{"kind":"resource","name":"cloudflare_pipeline","stainlessResource":"pipelines","methodName":"create_v1","snippet":"resource \"cloudflare_pipeline\" \"example_pipeline\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_pipeline\"\n sql = \"insert into sink select * from source;\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account.","requiresReplace":true},{"name":"name","type":"String","description":"Specifies the name of the Pipeline.","requiresReplace":true},{"name":"sql","type":"String","description":"Specifies SQL for the Pipeline processing flow.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Indicates a unique identifier for this pipeline.","requiresReplace":true},{"name":"created_at","type":"String"},{"name":"failure_reason","type":"String","description":"Indicates the reason for the failure of the Pipeline."},{"name":"modified_at","type":"String"},{"name":"status","type":"String","description":"Indicates the current status of the Pipeline."},{"name":"tables","type":"List[Attributes]","description":"List of streams and sinks used by this pipeline.","children":[{"name":"id","type":"String","description":"Unique identifier for the connection (stream or sink)."},{"name":"latest","type":"Int64","description":"Latest available version of the connection."},{"name":"name","type":"String","description":"Name of the connection."},{"name":"type","type":"String","description":"Type of the connection."},{"name":"version","type":"Int64","description":"Current version of the connection used by this pipeline."}]}]}]},"post /accounts/{}/pipelines/v1/sinks":{"operationId":"postV4AccountsByAccount_idPipelinesV1Sinks","declarations":[{"kind":"resource","name":"cloudflare_pipeline_sink","stainlessResource":"pipelines.sinks","methodName":"create","snippet":"resource \"cloudflare_pipeline_sink\" \"example_pipeline_sink\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_sink\"\n type = \"r2\"\n config = {\n account_id = \"account_id\"\n bucket = \"bucket\"\n credentials = {\n access_key_id = \"access_key_id\"\n secret_access_key = \"secret_access_key\"\n }\n file_naming = {\n prefix = \"prefix\"\n strategy = \"serial\"\n suffix = \"suffix\"\n }\n jurisdiction = \"jurisdiction\"\n partitioning = {\n time_pattern = \"year=%Y/month=%m/day=%d/hour=%H\"\n }\n path = \"path\"\n rolling_policy = {\n file_size_bytes = 0\n inactivity_seconds = 1\n interval_seconds = 1\n }\n }\n format = {\n type = \"json\"\n compression = \"uncompressed\"\n decimal_encoding = \"number\"\n timestamp_format = \"rfc3339\"\n unstructured = true\n }\n schema = {\n fields = [{\n type = \"int32\"\n metadata_key = \"metadata_key\"\n name = \"name\"\n required = true\n sql_name = \"sql_name\"\n }]\n inferred = true\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account.","requiresReplace":true},{"name":"name","type":"String","description":"Defines the name of the Sink.","requiresReplace":true},{"name":"type","type":"String","description":"Specifies the type of sink.","requiresReplace":true}],"optional":[{"name":"config","type":"Attributes","description":"Defines the configuration of the R2 Sink.","requiresReplace":true,"children":[{"name":"account_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"bucket","type":"String","description":"R2 Bucket to write to"},{"name":"credentials","type":"Attributes","children":[{"name":"access_key_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"secret_access_key","type":"String","description":"Cloudflare Account ID for the bucket","sensitive":true}]},{"name":"file_naming","type":"Attributes","description":"Controls filename prefix/suffix and strategy.","children":[{"name":"prefix","type":"String","description":"The prefix to use in file name. i.e prefix-.parquet"},{"name":"strategy","type":"String","description":"Filename generation strategy."},{"name":"suffix","type":"String","description":"This will overwrite the default file suffix. i.e .parquet, use with caution"}]},{"name":"jurisdiction","type":"String","description":"Jurisdiction this bucket is hosted in"},{"name":"partitioning","type":"Attributes","description":"Data-layout partitioning for sinks.","children":[{"name":"time_pattern","type":"String","description":"The pattern of the date string"}]},{"name":"path","type":"String","description":"Subpath within the bucket to write to"},{"name":"rolling_policy","type":"Attributes","description":"Rolling policy for file sinks (when & why to close a file and open a new one).","children":[{"name":"file_size_bytes","type":"Int64","description":"Files will be rolled after reaching this number of bytes"},{"name":"inactivity_seconds","type":"Int64","description":"Number of seconds of inactivity to wait before rolling over to a new file"},{"name":"interval_seconds","type":"Int64","description":"Number of seconds to wait before rolling over to a new file"}]},{"name":"token","type":"String","description":"Authentication token","sensitive":true},{"name":"table_name","type":"String","description":"Table name"},{"name":"namespace","type":"String","description":"Table namespace"}]},{"name":"format","type":"Attributes","description":"Defines the output data format of a sink.","requiresReplace":true,"children":[{"name":"type","type":"String"},{"name":"compression","type":"String","description":"Specifies the compression applied to JSON sink output."},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","requiresReplace":true,"children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}],"computed":[{"name":"id","type":"String","description":"Indicates a unique identifier for this sink.","requiresReplace":true},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/pipelines/v1/streams":{"operationId":"postV4AccountsByAccount_idPipelinesV1Streams","declarations":[{"kind":"resource","name":"cloudflare_pipeline_stream","stainlessResource":"pipelines.streams","methodName":"create","snippet":"resource \"cloudflare_pipeline_stream\" \"example_pipeline_stream\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_stream\"\n format = {\n type = \"json\"\n decimal_encoding = \"number\"\n timestamp_format = \"rfc3339\"\n unstructured = true\n }\n http = {\n authentication = false\n enabled = true\n cors = {\n origins = [\"string\"]\n }\n }\n schema = {\n fields = [{\n type = \"int32\"\n metadata_key = \"metadata_key\"\n name = \"name\"\n required = true\n sql_name = \"sql_name\"\n }]\n inferred = true\n }\n worker_binding = {\n enabled = true\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account.","requiresReplace":true},{"name":"name","type":"String","description":"Specifies the name of the Stream.","requiresReplace":true}],"optional":[{"name":"format","type":"Attributes","description":"Defines the data format of the events.","requiresReplace":true,"children":[{"name":"type","type":"String"},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"compression","type":"String"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","requiresReplace":true,"children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]},{"name":"http","type":"Attributes","children":[{"name":"authentication","type":"Bool","description":"Indicates that authentication is required for the HTTP endpoint."},{"name":"enabled","type":"Bool","description":"Indicates that the HTTP endpoint is enabled."},{"name":"cors","type":"Attributes","description":"Specifies the CORS options for the HTTP endpoint.","children":[{"name":"origins","type":"List[String]"}]}]},{"name":"worker_binding","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicates that the worker binding is enabled."}]}],"computed":[{"name":"id","type":"String","description":"Indicates a unique identifier for this stream."},{"name":"created_at","type":"Time"},{"name":"endpoint","type":"String","description":"Indicates the endpoint URL of this stream."},{"name":"modified_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicates the current version of this stream."}]}]},"post /accounts/{}/queues":{"operationId":"queues-create","declarations":[{"kind":"resource","name":"cloudflare_queue","stainlessResource":"queues","methodName":"create","snippet":"resource \"cloudflare_queue\" \"example_queue\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_name = \"example-queue\"\n jurisdiction = \"eu\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"queue_name","type":"String"}],"optional":[{"name":"jurisdiction","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"delivery_delay","type":"Float64","description":"Number of seconds to delay delivery of all messages to consumers."},{"name":"delivery_paused","type":"Bool","description":"Indicates if message delivery to consumers is currently paused."},{"name":"message_retention_period","type":"Float64","description":"Number of seconds after which an unconsumed message will be delayed."}]}],"computed":[{"name":"id","type":"String"},{"name":"queue_id","type":"String"},{"name":"consumers_total_count","type":"Float64"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"},{"name":"producers_total_count","type":"Float64"},{"name":"consumers","type":"List[Attributes]","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]},{"name":"producers","type":"List[Attributes]","children":[{"name":"script","type":"String"},{"name":"type","type":"String"},{"name":"bucket_name","type":"String"}]}]}]},"post /accounts/{}/queues/{}/consumers":{"operationId":"queues-create-consumer","declarations":[{"kind":"resource","name":"cloudflare_queue_consumer","stainlessResource":"queues.consumers","methodName":"create","snippet":"resource \"cloudflare_queue_consumer\" \"example_queue_consumer\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"my-consumer-worker\"\n type = \"worker\"\n dead_letter_queue = \"example-queue\"\n settings = {\n batch_size = 50\n max_concurrency = 10\n max_retries = 3\n max_wait_time_ms = 5000\n retry_delay = 10\n }\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"queue_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"type","type":"String"}],"optional":[{"name":"consumer_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"dead_letter_queue","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]}],"computed":[{"name":"created_on","type":"Time"},{"name":"queue_name","type":"String"}]}]},"post /accounts/{}/r2-catalog/{}/enable":{"operationId":"enable-catalog","declarations":[{"kind":"resource","name":"cloudflare_r2_data_catalog","stainlessResource":"r2_data_catalog","methodName":"enable","snippet":"resource \"cloudflare_r2_data_catalog\" \"example_r2_data_catalog\" {\n account_id = \"0123456789abcdef0123456789abcdef\"\n bucket_name = \"my-data-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Use this to identify the account.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Specifies the R2 bucket name.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Use this to uniquely identify the activated catalog.","requiresReplace":true},{"name":"bucket","type":"String","description":"Specifies the associated R2 bucket name."},{"name":"credential_status","type":"String","description":"Shows the credential configuration status."},{"name":"name","type":"String","description":"Specifies the catalog name (generated from account and bucket name)."},{"name":"status","type":"String","description":"Indicates the status of the catalog."},{"name":"maintenance_config","type":"Attributes","description":"Configures maintenance for the catalog.","children":[{"name":"compaction","type":"Attributes","description":"Configures compaction for catalog maintenance.","children":[{"name":"state","type":"String","description":"Specifies the state of maintenance operations."},{"name":"target_size_mb","type":"String","description":"Sets the target file size for compaction in megabytes. Defaults to \"128\"."}]},{"name":"interval","type":"String","description":"Scheduling interval between normal table maintenance runs."},{"name":"snapshot_expiration","type":"Attributes","description":"Configures snapshot expiration settings.","children":[{"name":"max_snapshot_age","type":"String","description":"Specifies the maximum age for snapshots. The system deletes snapshots older than this age.\nFormat: where unit is d (days), h (hours), m (minutes), or s (seconds).\nExamples: \"7d\" (7 days), \"48h\" (48 hours), \"2880m\" (2,880 minutes).\nDefaults to \"7d\".\n"},{"name":"min_snapshots_to_keep","type":"Int64","description":"Specifies the minimum number of snapshots to retain. Defaults to 100."},{"name":"state","type":"String","description":"Specifies the state of maintenance operations."}]}]}]}]},"post /accounts/{}/r2/buckets":{"operationId":"r2-create-bucket","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket","stainlessResource":"r2.buckets","methodName":"create","snippet":"resource \"cloudflare_r2_bucket\" \"example_r2_bucket\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example-bucket\"\n location = \"apac\"\n storage_class = \"Standard\"\n}\n","required":[{"name":"name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true}],"optional":[{"name":"location","type":"String","description":"Location of the bucket.","requiresReplace":true},{"name":"storage_class","type":"String","description":"Storage class for newly uploaded objects, unless specified otherwise.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"creation_date","type":"String","description":"Creation timestamp."},{"name":"jurisdiction","type":"String","description":"Jurisdiction where objects in this bucket are guaranteed to be stored."}]}]},"post /accounts/{}/r2/buckets/{}/domains/custom":{"operationId":"r2-add-custom-domain","declarations":[{"kind":"resource","name":"cloudflare_r2_custom_domain","stainlessResource":"r2.buckets.domains.custom","methodName":"create","snippet":"resource \"cloudflare_r2_custom_domain\" \"example_r2_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n domain = \"prefix.example-domain.com\"\n enabled = true\n zone_id = \"36ca64a6d92827b8a6b90be344bb1bfd\"\n ciphers = [\"string\"]\n min_tls = \"1.0\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"domain","type":"String","description":"Name of the custom domain to be added.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Zone ID of the custom domain.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether to enable public bucket access at the custom domain. If undefined, the domain will be enabled."}],"optional":[{"name":"min_tls","type":"String","description":"Minimum TLS Version the custom domain will accept for incoming connections. If not set, defaults to 1.0."},{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."}],"computed":[{"name":"zone_name","type":"String","description":"Zone that the custom domain resides in."},{"name":"status","type":"Attributes","children":[{"name":"ownership","type":"String","description":"Ownership status of the domain."},{"name":"ssl","type":"String","description":"SSL certificate status."}]}]}]},"post /accounts/{}/resource-library/applications":{"operationId":"createResourceLibraryApplication","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_resource_library_application","stainlessResource":"zero_trust.resource_library.applications","methodName":"create","snippet":"resource \"cloudflare_zero_trust_resource_library_application\" \"example_zero_trust_resource_library_application\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostnames = [\"example.com\", \"foo.com\"]\n category_id = 12\n human_id = \"HR\"\n ip_subnets = [\"192.168.1.0/24\", \"2001:db8::/48\"]\n name = \"HR\"\n port_protocols = [\"tcp/80\", \"tcp/443\"]\n support_domains = [\"example.com\", \"foo.com\"]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"category_id","type":"Int64","description":"Returns the category ID.","requiresReplace":true},{"name":"human_id","type":"String","description":"Returns the human readable ID.","requiresReplace":true},{"name":"name","type":"String","description":"Returns the application name.","requiresReplace":true},{"name":"hostnames","type":"Set[String]","description":"Hostnames matched by the application."},{"name":"ip_subnets","type":"Set[String]","description":"IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128."},{"name":"port_protocols","type":"Set[String]","description":"Port and protocol pairs matched by the application."},{"name":"support_domains","type":"Set[String]","description":"Support domains matched by the application."}],"computed":[{"name":"id","type":"Int64","description":"Returns the application ID."},{"name":"application_confidence_score","type":"Float64","description":"Confidence score for the application. Returns -1 when no score is available."},{"name":"application_source","type":"String","description":"Returns the application source."},{"name":"application_type","type":"String","description":"Returns the application type."},{"name":"application_type_description","type":"String","description":"Returns the application type description."},{"name":"created_at","type":"String","description":"Returns the application creation time."},{"name":"gen_ai_score","type":"Float64","description":"GenAI score for the application. Returns -1 when no score is available."},{"name":"updated_at","type":"String","description":"Returns the application update time."},{"name":"version","type":"String","description":"Returns the application version."},{"name":"supported","type":"Set[String]","description":"Cloudflare products that support this application."},{"name":"application_score_composition","type":"unknown","description":"Returns the score composition breakdown for the application."}]}]},"post /accounts/{}/rules/lists":{"operationId":"lists-create-a-list","declarations":[{"kind":"resource","name":"cloudflare_list","stainlessResource":"rules.lists","methodName":"create","snippet":"resource \"cloudflare_list\" \"example_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"ip\"\n name = \"list1\"\n description = \"This is a note\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource.","requiresReplace":true},{"name":"kind","type":"String","description":"The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects).","requiresReplace":true},{"name":"name","type":"String","description":"An informative name for the list. Use this name in filter and rule expressions.","requiresReplace":true}],"optional":[{"name":"description","type":"String","description":"An informative summary of the list."}],"computed":[{"name":"id","type":"String","description":"The unique ID of the list."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"num_items","type":"Float64","description":"The number of items in the list."},{"name":"num_referencing_filters","type":"Float64","description":"The number of [filters](/api/resources/filters/) referencing the list."}]}]},"post /accounts/{}/rules/lists/{}/items":{"operationId":"lists-create-list-items","declarations":[{"kind":"resource","name":"cloudflare_list_item","stainlessResource":"rules.lists.items","methodName":"create","snippet":"resource \"cloudflare_list_item\" \"example_list_item\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n body = [{\n ip = \"10.0.0.1\"\n comment = \"Private IP address\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource.","requiresReplace":true},{"name":"list_id","type":"String","description":"The unique ID of the list.","requiresReplace":true},{"name":"body","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."}]}],"optional":[{"name":"item_id","type":"String","description":"Defines the unique ID of the item in the List.","requiresReplace":true}],"computed":[{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"operation_id","type":"String","description":"The unique operation ID of the asynchronous action."},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]}]}]},"post /accounts/{}/rum/site_info":{"operationId":"web-analytics-create-site","declarations":[{"kind":"resource","name":"cloudflare_web_analytics_site","stainlessResource":"rum.site_info","methodName":"create","snippet":"resource \"cloudflare_web_analytics_site\" \"example_web_analytics_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n auto_install = true\n host = \"example.com\"\n zone_tag = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"auto_install","type":"Bool","description":"If enabled, the JavaScript snippet is automatically injected for orange-clouded sites."},{"name":"enabled","type":"Bool","description":"Enables or disables RUM. This option can be used only when auto_install is set to true."},{"name":"host","type":"String","description":"The hostname to use for gray-clouded sites."},{"name":"lite","type":"Bool","description":"If enabled, the JavaScript snippet will not be injected for visitors from the EU."},{"name":"zone_tag","type":"String","description":"The zone identifier."}],"computed":[{"name":"id","type":"String","description":"The Web Analytics site identifier."},{"name":"site_tag","type":"String","description":"The Web Analytics site identifier."},{"name":"created","type":"Time"},{"name":"site_token","type":"String","description":"The Web Analytics site token."},{"name":"snippet","type":"String","description":"Encoded JavaScript snippet."},{"name":"rules","type":"List[Attributes]","description":"A list of rules.","children":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"host","type":"String","description":"The hostname the rule will be applied to."},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]","description":"The paths the rule will be applied to."},{"name":"priority","type":"Float64"}]},{"name":"ruleset","type":"Attributes","children":[{"name":"id","type":"String","description":"The Web Analytics ruleset identifier."},{"name":"enabled","type":"Bool","description":"Whether the ruleset is enabled."},{"name":"zone_name","type":"String"},{"name":"zone_tag","type":"String","description":"The zone identifier."}]}]}]},"post /accounts/{}/rum/v2/{}/rule":{"operationId":"web-analytics-create-rule","declarations":[{"kind":"resource","name":"cloudflare_web_analytics_rule","stainlessResource":"rum.rules","methodName":"create","snippet":"resource \"cloudflare_web_analytics_rule\" \"example_web_analytics_rule\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ruleset_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n host = \"example.com\"\n inclusive = true\n is_paused = false\n paths = [\"*\"]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"ruleset_id","type":"String","description":"The Web Analytics ruleset identifier.","requiresReplace":true}],"optional":[{"name":"host","type":"String"},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]"}],"computed":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"priority","type":"Float64"}]}]},"post /accounts/{}/secondary_dns/acls":{"operationId":"secondary-dns-(-acl)-create-acl","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_acl","stainlessResource":"dns.zone_transfers.acls","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_acl\" \"example_dns_zone_transfers_acl\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n ip_range = \"192.0.2.53/28\"\n name = \"my-acl-1\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"ip_range","type":"String","description":"Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively."},{"name":"name","type":"String","description":"The name of the acl."}],"optional":[],"computed":[{"name":"id","type":"String"}]}]},"post /accounts/{}/secondary_dns/peers":{"operationId":"secondary-dns-(-peer)-create-peer","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_peer","stainlessResource":"dns.zone_transfers.peers","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_peer\" \"example_dns_zone_transfers_peer\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n name = \"my-peer-1\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the peer."}],"optional":[{"name":"ip","type":"String","description":"IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to."},{"name":"ixfr_enable","type":"Bool","description":"Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones."},{"name":"port","type":"Float64","description":"DNS port of primary or secondary nameserver, depending on what zone this peer is linked to."},{"name":"tsig_id","type":"String","description":"TSIG authentication will be used for zone transfer if configured."}],"computed":[{"name":"id","type":"String"}]}]},"post /accounts/{}/secondary_dns/tsigs":{"operationId":"secondary-dns-(-tsig)-create-tsig","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_tsig","stainlessResource":"dns.zone_transfers.tsigs","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_tsig\" \"example_dns_zone_transfers_tsig\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n algo = \"hmac-sha512.\"\n name = \"tsig.customer.cf.\"\n secret = \"caf79a7804b04337c9c66ccd7bef9190a1e1679b5dd03d8aa10f7ad45e1a9dab92b417896c15d4d007c7c14194538d2a5d0feffdecc5a7f0e1c570cfa700837c\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"algo","type":"String","description":"TSIG algorithm."},{"name":"name","type":"String","description":"TSIG key name."},{"name":"secret","type":"String","description":"TSIG secret.","sensitive":true}],"optional":[],"computed":[{"name":"id","type":"String"}]}]},"post /accounts/{}/secrets_store/stores":{"operationId":"secrets-store-create","declarations":[{"kind":"resource","name":"cloudflare_secrets_store","stainlessResource":"secrets_store.stores","methodName":"create","snippet":"resource \"cloudflare_secrets_store\" \"example_secrets_store\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n name = \"service_x_keys\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the store.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Store Identifier.","requiresReplace":true},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."}]}]},"post /accounts/{}/secrets_store/stores/{}/secrets":{"operationId":"secrets-store-secret-create","declarations":[{"kind":"resource","name":"cloudflare_secrets_store_secret","stainlessResource":"secrets_store.stores.secrets","methodName":"create","snippet":"resource \"cloudflare_secrets_store_secret\" \"example_secrets_store_secret\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"store_id","type":"String","requiresReplace":true},{"name":"body","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"name","type":"String","description":"The name of the secret."},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."},{"name":"value","type":"String","description":"The value of the secret. Maximum 64 KiB (65,536 bytes). Note that this is 'write only' - the API never returns this value; it exists only to create or modify secrets.","sensitive":true},{"name":"comment","type":"String","description":"Freeform text describing the secret."}]}],"optional":[{"name":"comment","type":"String","description":"Freeform text describing the secret."},{"name":"value","type":"String","description":"The value of the secret. Maximum 64 KiB (65,536 bytes). Note that this is 'write only' - the API never returns this value; it exists only to create or modify secrets.","sensitive":true},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."}],"computed":[{"name":"id","type":"String","description":"Secret identifier tag."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the secret."},{"name":"status","type":"String"}]}]},"post /accounts/{}/shares":{"operationId":"share-create","declarations":[{"kind":"resource","name":"cloudflare_share","stainlessResource":"resource_sharing","methodName":"create","snippet":"resource \"cloudflare_share\" \"example_share\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Shared WAF Managed Rule\"\n recipients = [{\n organization_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n recipient_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n }]\n resources = [{\n meta = {\n\n }\n resource_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_type = \"custom-ruleset\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier.","requiresReplace":true},{"name":"recipients","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"account_id","type":"String","description":"Deprecated alias for `recipient_account_id`. Use `recipient_account_id` instead.\nThe body field collided with the URL path parameter of the same name, which prevented SDK generators from distinguishing the source account (in the URL) from the recipient account (in the body). Both names will continue to be accepted until 2027-05-26 (see `x-sunset`).\n","deprecated":"This field has been renamed to `recipient_account_id`. Both names are accepted during the deprecation period."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"recipient_account_id","type":"String","description":"The account that will receive the share."}]},{"name":"resources","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."}]},{"name":"name","type":"String","description":"The name of the share."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Share identifier tag."},{"name":"account_name","type":"String","description":"The display name of an account."},{"name":"associated_recipient_count","type":"Int64","description":"The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"associating_recipient_count","type":"Int64","description":"The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"disassociated_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociating_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"kind","type":"String"},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"status","type":"String"},{"name":"target_type","type":"String"}]}]},"post /accounts/{}/shares/{}/recipients":{"operationId":"share-recipient-create","declarations":[{"kind":"resource","name":"cloudflare_share_recipient","stainlessResource":"resource_sharing.recipients","methodName":"create","snippet":"resource \"cloudflare_share_recipient\" \"example_share_recipient\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n organization_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n recipient_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"share_id","type":"String","description":"Share identifier tag.","requiresReplace":true},{"name":"account_id","type":"String","description":"Deprecated alias for `recipient_account_id`. Use `recipient_account_id` instead.\nThe body field collided with the URL path parameter of the same name, which prevented SDK generators from distinguishing the source account (in the URL) from the recipient account (in the body). Both names will continue to be accepted until 2027-05-26 (see `x-sunset`).\n","deprecated":"This field has been renamed to `recipient_account_id`. Both names are accepted during the deprecation period.","requiresReplace":true}],"optional":[{"name":"organization_id","type":"String","description":"Organization identifier.","requiresReplace":true},{"name":"recipient_account_id","type":"String","description":"The account that will receive the share.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Share Recipient identifier tag.","requiresReplace":true},{"name":"association_status","type":"String","description":"The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\n"},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resources","type":"List[Attributes]","children":[{"name":"error","type":"String","description":"Share Recipient error message."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"terminal","type":"Bool","description":"Whether the error is terminal or will be continually retried."}]}]}]},"post /accounts/{}/shares/{}/resources":{"operationId":"share-resource-create","declarations":[{"kind":"resource","name":"cloudflare_share_resource","stainlessResource":"resource_sharing.resources","methodName":"create","snippet":"resource \"cloudflare_share_resource\" \"example_share_resource\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n meta = {\n\n }\n resource_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_type = \"custom-ruleset\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier.","requiresReplace":true},{"name":"share_id","type":"String","description":"Share identifier tag.","requiresReplace":true},{"name":"resource_account_id","type":"String","description":"Account identifier.","requiresReplace":true},{"name":"resource_id","type":"String","description":"Share Resource identifier.","requiresReplace":true},{"name":"resource_type","type":"String","description":"Resource Type.","requiresReplace":true},{"name":"meta","type":"unknown","description":"Resource Metadata."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]},"post /accounts/{}/sso_connectors":{"operationId":"init-new-sso-connector","declarations":[{"kind":"resource","name":"cloudflare_sso_connector","stainlessResource":"iam.sso","methodName":"create","snippet":"resource \"cloudflare_sso_connector\" \"example_sso_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email_domain = \"example.com\"\n begin_verification = true\n use_fedramp_language = false\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"email_domain","type":"String","description":"Email domain of the new SSO connector","requiresReplace":true}],"optional":[{"name":"begin_verification","type":"Bool","description":"Begin the verification process after creation","requiresReplace":true},{"name":"enabled","type":"Bool","description":"SSO Connector enabled state"},{"name":"use_fedramp_language","type":"Bool","description":"Controls the display of FedRAMP language to the user during SSO login"}],"computed":[{"name":"id","type":"String","description":"SSO Connector identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the SSO connector"},{"name":"updated_on","type":"Time","description":"Timestamp for the last update of the SSO connector"},{"name":"verification","type":"Attributes","children":[{"name":"code","type":"String","description":"DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership."},{"name":"status","type":"String","description":"The status of the verification code from the verification process."}]}]}]},"post /accounts/{}/storage/kv/namespaces":{"operationId":"workers-kv-namespace-create-a-namespace","declarations":[{"kind":"resource","name":"cloudflare_workers_kv_namespace","stainlessResource":"kv.namespaces","methodName":"create","snippet":"resource \"cloudflare_workers_kv_namespace\" \"example_workers_kv_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n title = \"My Own Namespace\"\n jurisdiction = \"eu\"\n}\n","required":[{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces.","requiresReplace":true},{"name":"title","type":"String","description":"Human-readable string name for a Workers KV namespace."}],"optional":[{"name":"jurisdiction","type":"String","description":"Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"ID of the Workers KV namespace."},{"name":"supports_url_encoding","type":"Bool","description":"True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"."}]}]},"post /accounts/{}/stream":{"operationId":"stream-videos-initiate-video-uploads-using-tus","declarations":[{"kind":"resource","name":"cloudflare_stream","stainlessResource":"stream","methodName":"create","snippet":"resource \"cloudflare_stream\" \"example_stream\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"max_duration_seconds","type":"Int64","description":"The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown."},{"name":"scheduled_deletion","type":"Time","description":"Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time."},{"name":"uid","type":"String","description":"The unique identifier for the video. Can be used to verify the video being updated."},{"name":"upload_expiry","type":"Time","description":"The date and time when the video upload URL is no longer valid for direct user uploads."},{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin."},{"name":"public_details","type":"Attributes","description":"Public details for the video including title, share link, channel link, and logo.","children":[{"name":"channel_link","type":"String"},{"name":"logo","type":"String"},{"name":"share_link","type":"String"},{"name":"title","type":"String"}]},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing videos."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video."},{"name":"thumbnail_timestamp_pct","type":"Float64","description":"The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video."}],"computed":[{"name":"clipped_from","type":"String","description":"The unique identifier of the source video this video was clipped from."},{"name":"created","type":"Time","description":"The date and time the media item was created."},{"name":"duration","type":"Float64","description":"The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready."},{"name":"live_input","type":"String","description":"The live input ID used to upload a video with Stream Live."},{"name":"max_size_bytes","type":"Int64","description":"The maximum size in bytes for the video upload."},{"name":"modified","type":"Time","description":"The date and time the media item was last modified."},{"name":"preview","type":"String","description":"The video's preview page URI. This field is omitted until encoding is complete."},{"name":"ready_to_stream","type":"Bool","description":"Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"ready_to_stream_at","type":"Time","description":"Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"size","type":"Float64","description":"The size of the media item in bytes."},{"name":"thumbnail","type":"String","description":"The media item's thumbnail URI. This field is omitted until encoding is complete."},{"name":"uploaded","type":"Time","description":"The date and time the media item was uploaded."},{"name":"input","type":"Attributes","children":[{"name":"height","type":"Int64","description":"The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready."},{"name":"width","type":"Int64","description":"The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready."}]},{"name":"playback","type":"Attributes","children":[{"name":"dash","type":"String","description":"DASH Media Presentation Description for the video."},{"name":"hls","type":"String","description":"The HLS manifest for the video."}]},{"name":"status","type":"Attributes","description":"Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.","children":[{"name":"error_reason_code","type":"String","description":"Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use."},{"name":"error_reason_text","type":"String","description":"Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state."},{"name":"pct_complete","type":"String","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"state","type":"String","description":"Specifies the processing status for all quality levels for a video."}]},{"name":"watermark","type":"Attributes","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]}]},"post /accounts/{}/stream/{}/captions/{}/generate":{"operationId":"stream-subtitles/-captions-generate-caption-or-subtitle-for-language","declarations":[{"kind":"resource","name":"cloudflare_stream_caption_language","stainlessResource":"stream.captions.language","methodName":"create","snippet":"resource \"cloudflare_stream_caption_language\" \"example_stream_caption_language\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n language = \"tr\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true},{"name":"language","type":"String","description":"The language tag in BCP 47 format.","requiresReplace":true}],"optional":[{"name":"file","type":"String","description":"The WebVTT file containing the caption or subtitle content."}],"computed":[{"name":"generated","type":"Bool","description":"Whether the caption was generated via AI."},{"name":"label","type":"String","description":"The language label displayed in the native language to users."},{"name":"status","type":"String","description":"The status of a generated caption."}]}]},"post /accounts/{}/stream/{}/downloads":{"operationId":"stream-mp4-downloads-create-downloads","declarations":[{"kind":"resource","name":"cloudflare_stream_download","stainlessResource":"stream.downloads","methodName":"create","snippet":"resource \"cloudflare_stream_download\" \"example_stream_download\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true}],"optional":[],"computed":[{"name":"audio","type":"Attributes","description":"The audio-only download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]},{"name":"default","type":"Attributes","description":"The default video download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]}]}]},"post /accounts/{}/stream/keys":{"operationId":"stream-signing-keys-create-signing-keys","declarations":[{"kind":"resource","name":"cloudflare_stream_key","stainlessResource":"stream.keys","methodName":"create","snippet":"resource \"cloudflare_stream_key\" \"example_stream_key\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"created","type":"Time","description":"The date and time a signing key was created."},{"name":"jwk","type":"String","description":"The signing key in JWK format.","sensitive":true},{"name":"key_id","type":"String","description":"The unique identifier for the signing key."},{"name":"pem","type":"String","description":"The signing key in PEM format.","sensitive":true}]}]},"post /accounts/{}/stream/live_inputs":{"operationId":"stream-live-inputs-create-a-live-input","declarations":[{"kind":"resource","name":"cloudflare_stream_live_input","stainlessResource":"stream.live_inputs","methodName":"create","snippet":"resource \"cloudflare_stream_live_input\" \"example_stream_live_input\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n default_creator = \"defaultCreator\"\n delete_recording_after_days = 45\n enabled = true\n meta = {\n name = \"test stream 1\"\n }\n prefer_low_latency = true\n recording = {\n allowed_origins = [\"example.com\"]\n hide_live_viewer_count = false\n mode = \"off\"\n require_signed_urls = false\n timeout_seconds = 0\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"live_input_identifier","type":"String","description":"A unique identifier for a live input.","requiresReplace":true},{"name":"default_creator","type":"String","description":"Sets the creator ID asssociated with this live input."},{"name":"delete_recording_after_days","type":"Float64","description":"Indicates the number of days after which the live inputs recordings will be deleted. When a stream completes and the recording is ready, the value is used to calculate a scheduled deletion date for that recording. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion."},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing live inputs."},{"name":"enabled","type":"Bool","description":"Indicates whether the live input is enabled and can accept streams."},{"name":"prefer_low_latency","type":"Bool","description":"When enabled, the live stream is delivered using Low-Latency HLS (LL-HLS), reducing glass-to-glass latency for viewers at the cost of reduced player compatibility."},{"name":"recording","type":"Attributes","description":"Records the input to a Cloudflare Stream video. Behavior depends on the mode. In most cases, the video will initially be viewable as a live video and transition to on-demand after a condition is satisfied.","children":[{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display videos created with this input. Enter allowed origin domains in an array and use `*` for wildcard subdomains. An empty array allows videos to be viewed on any origin."},{"name":"hide_live_viewer_count","type":"Bool","description":"Disables reporting the number of live viewers when this property is set to `true`."},{"name":"mode","type":"String","description":"Specifies the recording behavior for the live input. Set this value to `off` to prevent a recording. Set the value to `automatic` to begin a recording and transition to on-demand after Stream Live stops receiving input."},{"name":"require_signed_urls","type":"Bool","description":"Indicates if a video using the live input has the `requireSignedURLs` property set. Also enforces access controls on any video recording of the livestream with the live input."},{"name":"timeout_seconds","type":"Int64","description":"Determines the amount of time a live input configured in `automatic` mode should wait before a recording transitions from live to on-demand. `0` is recommended for most use cases and indicates the platform default should be used."}]}],"computed":[{"name":"created","type":"Time","description":"The date and time the live input was created."},{"name":"keys_rotated_at","type":"Time","description":"The date and time the live input keys were last rotated. Omitted for live inputs that have never had their keys rotated."},{"name":"modified","type":"Time","description":"The date and time the live input was last modified."},{"name":"status","type":"String","description":"The connection status of a live input."},{"name":"uid","type":"String","description":"A unique identifier for a live input."},{"name":"playback","type":"Attributes","description":"Details for playing a live input's broadcast using the HLS or DASH manifests. URLs reference the live input ID.","children":[{"name":"dash","type":"String","description":"The DASH manifest URL used to play live video, referencing the live input ID."},{"name":"hls","type":"String","description":"The HLS manifest URL used to play live video, referencing the live input ID."}]},{"name":"rtmps","type":"Attributes","description":"Details for streaming to an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use when streaming via RTMPS to a live input.","sensitive":true},{"name":"url","type":"String","description":"The RTMPS URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"rtmps_playback","type":"Attributes","description":"Details for playback from an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use for playback via RTMPS.","sensitive":true},{"name":"url","type":"String","description":"The URL used to play live video over RTMPS.","sensitive":true}]},{"name":"srt","type":"Attributes","description":"Details for streaming to a live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use when streaming via SRT to a live input.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use when streaming via SRT."},{"name":"url","type":"String","description":"The SRT URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"srt_playback","type":"Attributes","description":"Details for playback from an live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use for playback via SRT.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use for playback via SRT."},{"name":"url","type":"String","description":"The URL used to play live video over SRT.","sensitive":true}]},{"name":"web_rtc","type":"Attributes","description":"Details for streaming to a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The WebRTC URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"web_rtc_playback","type":"Attributes","description":"Details for playback from a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The URL used to play live video over WebRTC.","sensitive":true}]}]}]},"post /accounts/{}/stream/watermarks":{"operationId":"stream-watermark-profile-create-watermark-profiles-via-basic-upload","declarations":[{"kind":"resource","name":"cloudflare_stream_watermark","stainlessResource":"stream.watermarks","methodName":"create","snippet":"resource \"cloudflare_stream_watermark\" \"example_stream_watermark\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Marketing Videos\"\n opacity = 0.75\n padding = 0.1\n position = \"center\"\n scale = 0.1\n url = \"https://example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"identifier","type":"String","description":"The unique identifier for a watermark profile.","requiresReplace":true},{"name":"url","type":"String","description":"URL of the watermark image to copy.","requiresReplace":true},{"name":"name","type":"String","description":"A short description of the watermark profile.","requiresReplace":true},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque.","requiresReplace":true},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm.","requiresReplace":true},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter.","requiresReplace":true},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video.","requiresReplace":true}],"computed":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]},"post /accounts/{}/teamnet/routes":{"operationId":"tunnel-route-create-a-tunnel-route","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared_route","stainlessResource":"zero_trust.networks.routes","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared_route\" \"example_zero_trust_tunnel_cloudflared_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n network = \"172.16.0.0/16\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n comment = \"Example comment for this route.\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range connected by the route, in CIDR notation."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."}],"computed":[{"name":"id","type":"String","description":"UUID of the route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."}]}]},"post /accounts/{}/teamnet/virtual_networks":{"operationId":"tunnel-virtual-network-create-a-virtual-network","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared_virtual_network","stainlessResource":"zero_trust.networks.virtual_networks","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared_virtual_network\" \"example_zero_trust_tunnel_cloudflared_virtual_network\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"us-east-1-vpc\"\n comment = \"Staging VPC for data science\"\n is_default = true\n is_default_network = false\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."}],"optional":[{"name":"is_default","type":"Bool","description":"If `true`, this virtual network is the default for the account.","deprecated":"Use the is_default_network property instead.","requiresReplace":true},{"name":"comment","type":"String","description":"Optional remark describing the virtual network."},{"name":"is_default_network","type":"Bool","description":"If `true`, this virtual network is the default for the account."}],"computed":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."}]}]},"post /accounts/{}/tokens":{"operationId":"account-api-tokens-create-token","declarations":[{"kind":"resource","name":"cloudflare_account_token","stainlessResource":"accounts.tokens","methodName":"create","snippet":"resource \"cloudflare_account_token\" \"example_account_token\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"readonly token\"\n policies = [{\n effect = \"allow\"\n permission_groups = [{\n id = \"c8fed203ed3043cba015a93ad1616f1f\"\n meta = {\n category = \"category\"\n deprecated = \"deprecated\"\n description = \"description\"\n editable = \"editable\"\n eol_at = \"2019-12-27T18:11:19.117Z\"\n label = \"load_balancer_admin\"\n scopes = \"com.cloudflare.api.account\"\n visibility = \"visibility\"\n }\n }, {\n id = \"82e64a83756745bbbb1c9c2701bf816b\"\n meta = {\n category = \"category\"\n deprecated = \"deprecated\"\n description = \"description\"\n editable = \"editable\"\n eol_at = \"2019-12-27T18:11:19.117Z\"\n label = \"fbm_user\"\n scopes = \"com.cloudflare.api.account\"\n visibility = \"visibility\"\n }\n }]\n resources = {\n \"com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43\" = \"*\"\n }\n }]\n condition = {\n request_ip = {\n in = [\"123.123.123.0/24\", \"2606:4700::/32\"]\n not_in = [\"123.123.123.100/24\", \"2606:4700:4700::/48\"]\n }\n }\n expires_on = \"2020-01-01T00:00:00Z\"\n not_before = \"2018-07-01T05:20:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"name","type":"String","description":"Token name."},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]}],"optional":[{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"status","type":"String","description":"Status of the token."}],"computed":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"value","type":"String","description":"The token value.","sensitive":true}]}]},"post /accounts/{}/vuln_scanner/credential_sets":{"operationId":"create-credential-set","declarations":[{"kind":"resource","name":"cloudflare_vulnerability_scanner_credential_set","stainlessResource":"vulnerability_scanner.credential_sets","methodName":"create","snippet":"resource \"cloudflare_vulnerability_scanner_credential_set\" \"example_vulnerability_scanner_credential_set\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production API credentials\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Human-readable name."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Credential set identifier."}]}]},"post /accounts/{}/vuln_scanner/credential_sets/{}/credentials":{"operationId":"create-credential","declarations":[{"kind":"resource","name":"cloudflare_vulnerability_scanner_credential","stainlessResource":"vulnerability_scanner.credential_sets.credentials","methodName":"create","snippet":"resource \"cloudflare_vulnerability_scanner_credential\" \"example_vulnerability_scanner_credential\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n location = \"header\"\n location_name = \"Authorization\"\n name = \"Admin API key\"\n value = \"Bearer EXAMPLE_TOKEN\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"credential_set_id","type":"String","requiresReplace":true},{"name":"location","type":"String","description":"Where the credential is attached in outgoing requests."},{"name":"location_name","type":"String","description":"Name of the header or cookie where the credential is attached.\n"},{"name":"name","type":"String","description":"Human-readable name."},{"name":"value","type":"String","description":"The credential value (e.g. API key, session token). Write-only.\nNever returned in responses.\n","sensitive":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Credential identifier."}]}]},"post /accounts/{}/vuln_scanner/target_environments":{"operationId":"create-target-environment","declarations":[{"kind":"resource","name":"cloudflare_vulnerability_scanner_target_environment","stainlessResource":"vulnerability_scanner.target_environments","methodName":"create","snippet":"resource \"cloudflare_vulnerability_scanner_target_environment\" \"example_vulnerability_scanner_target_environment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production Zone\"\n target = {\n type = \"zone\"\n zone_tag = \"d8e8fca2dc0f896fd7cb4cb0031ba249\"\n }\n description = \"Main production environment\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Human-readable name."},{"name":"target","type":"Attributes","description":"Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.\n","children":[{"name":"type","type":"String"},{"name":"zone_tag","type":"String","description":"Cloudflare zone tag. The zone must belong to the account.\n"}]}],"optional":[{"name":"description","type":"String","description":"Optional description."}],"computed":[{"name":"id","type":"String","description":"Target environment identifier."}]}]},"post /accounts/{}/warp_connector":{"operationId":"cloudflare-tunnel-create-a-warp-connector-tunnel","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_warp_connector","stainlessResource":"zero_trust.tunnels.warp_connector","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_warp_connector\" \"example_zero_trust_tunnel_warp_connector\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"blog\"\n ha = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."}],"optional":[{"name":"ha","type":"Bool","description":"Indicates that the tunnel will be created to be highly available. If omitted, defaults to false.","requiresReplace":true},{"name":"tunnel_secret","type":"String","description":"Sets the password required to run a locally-managed tunnel. Must be at least 32 bytes and encoded as a base64 string.","sensitive":true}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"post /accounts/{}/workers/dispatch/namespaces":{"operationId":"namespace-worker-create","declarations":[{"kind":"resource","name":"cloudflare_workers_for_platforms_dispatch_namespace","stainlessResource":"workers_for_platforms.dispatch.namespaces","methodName":"create","snippet":"resource \"cloudflare_workers_for_platforms_dispatch_namespace\" \"example_workers_for_platforms_dispatch_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-dispatch-namespace\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"name","type":"String","description":"The name of the dispatch namespace.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Name of the Workers for Platforms dispatch namespace.","requiresReplace":true},{"name":"namespace_name","type":"String","description":"Name of the Workers for Platforms dispatch namespace.","requiresReplace":true},{"name":"created_by","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"modified_by","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"namespace_id","type":"String","description":"API Resource UUID tag."},{"name":"script_count","type":"Int64","description":"The current number of scripts in this Dispatch Namespace."},{"name":"trusted_workers","type":"Bool","description":"Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"."}]}]},"post /accounts/{}/workers/scripts/{}/deployments":{"operationId":"worker-deployments-create-deployment","declarations":[{"kind":"resource","name":"cloudflare_workers_deployment","stainlessResource":"workers.scripts.deployments","methodName":"create","snippet":"resource \"cloudflare_workers_deployment\" \"example_workers_deployment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n strategy = \"percentage\"\n versions = [{\n percentage = 100\n version_id = \"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\"\n }]\n annotations = {\n workers_message = \"Deploy bug fix.\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"script_name","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"strategy","type":"String","requiresReplace":true},{"name":"versions","type":"List[Attributes]","description":"Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.","requiresReplace":true,"children":[{"name":"percentage","type":"Float64","description":"Percentage of traffic served by this version."},{"name":"version_id","type":"String","description":"Identifier of the Worker Version."}]}],"optional":[{"name":"annotations","type":"Attributes","requiresReplace":true,"children":[{"name":"workers_message","type":"String","description":"Human-readable message about the deployment. Truncated to 1000 bytes if longer."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the deployment."}]}],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"author_email","type":"String"},{"name":"created_on","type":"Time"},{"name":"source","type":"String"}]}]},"post /accounts/{}/workers/scripts/{}/subdomain":{"operationId":"worker-script-post-subdomain","declarations":[{"kind":"resource","name":"cloudflare_workers_script_subdomain","stainlessResource":"workers.scripts.subdomain","methodName":"create","snippet":"resource \"cloudflare_workers_script_subdomain\" \"example_workers_script_subdomain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n enabled = true\n previews_enabled = false\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"script_name","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether the Worker should be available on the workers.dev subdomain."}],"optional":[{"name":"previews_enabled","type":"Bool","description":"Whether the Worker's Preview URLs should be available on the workers.dev subdomain."}],"computed":[]}]},"post /accounts/{}/workers/workers":{"operationId":"createWorker","declarations":[{"kind":"resource","name":"cloudflare_worker","stainlessResource":"workers.beta.workers","methodName":"create","snippet":"resource \"cloudflare_worker\" \"example_worker\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-worker\"\n logpush = true\n observability = {\n enabled = true\n head_sampling_rate = 1\n issues = {\n enabled = true\n }\n logs = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n invocation_logs = true\n persist = true\n }\n redact_query_string = true\n traces = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n persist = true\n propagation_policy = \"authenticated\"\n }\n }\n previews_base_config = {\n cache_options = {\n enabled = true\n cross_version_cache = true\n }\n env = {\n MY_ENV_VAR = {\n type = \"plain_text\"\n }\n }\n limits = {\n cpu_ms = 50\n subrequests = 1000\n }\n logpush = true\n observability = {\n enabled = true\n head_sampling_rate = 1\n issues = {\n enabled = true\n }\n logs = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n invocation_logs = true\n persist = true\n }\n redact_query_string = true\n traces = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n persist = true\n propagation_policy = \"authenticated\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n tail_consumers = [{\n name = \"my-tail-consumer\"\n }]\n }\n subdomain = {\n enabled = true\n previews_enabled = true\n }\n tags = [\"my-team\", \"my-public-api\"]\n tail_consumers = [{\n name = \"my-tail-consumer\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Name of the Worker."}],"optional":[{"name":"logpush","type":"Bool","description":"Whether logpush is enabled for the Worker."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"previews_base_config","type":"Attributes","description":"Template configuration used when creating new Previews for this Worker.","children":[{"name":"cache_options","type":"Attributes","description":"Cache options used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"env","type":"Map[Attributes]","description":"Bindings used when creating new Previews, keyed by binding name.","children":[{"name":"type","type":"String","description":"The kind of resource that the binding provides."}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime for newly created Previews.","children":[{"name":"cpu_ms","type":"Int64","description":"The amount of CPU time this Worker can use in milliseconds."},{"name":"subrequests","type":"Int64","description":"The number of subrequests this Worker can make per request."}]},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled when creating new Previews."},{"name":"observability","type":"Attributes","description":"Observability settings used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Placement configuration used when creating new Previews.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from newly created Previews.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]},{"name":"subdomain","type":"Attributes","description":"Subdomain settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether the *.workers.dev subdomain is enabled for the Worker."},{"name":"preview_url_suffix","type":"String","description":"Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker."},{"name":"url","type":"String","description":"The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain."}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from the Worker.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}],"computed":[{"name":"id","type":"String","description":"Immutable ID of the Worker."},{"name":"created_on","type":"Time","description":"When the Worker was created."},{"name":"deployed_on","type":"Time","description":"When the Worker's most recent deployment was created. `null` if the Worker has never been deployed."},{"name":"updated_on","type":"Time","description":"When the Worker was most recently updated."},{"name":"references","type":"Attributes","description":"Other resources that reference the Worker and depend on it existing.","children":[{"name":"dispatch_namespace_outbounds","type":"List[Attributes]","description":"Other Workers that reference the Worker as an outbound for a dispatch namespace.","children":[{"name":"namespace_id","type":"String","description":"ID of the dispatch namespace."},{"name":"namespace_name","type":"String","description":"Name of the dispatch namespace."},{"name":"worker_id","type":"String","description":"ID of the Worker using the dispatch namespace."},{"name":"worker_name","type":"String","description":"Name of the Worker using the dispatch namespace."}]},{"name":"domains","type":"List[Attributes]","description":"Custom domains connected to the Worker.","children":[{"name":"id","type":"String","description":"ID of the custom domain."},{"name":"certificate_id","type":"String","description":"ID of the TLS certificate issued for the custom domain."},{"name":"hostname","type":"String","description":"Full hostname of the custom domain, including the zone name."},{"name":"zone_id","type":"String","description":"ID of the zone."},{"name":"zone_name","type":"String","description":"Name of the zone."}]},{"name":"durable_objects","type":"List[Attributes]","description":"Other Workers that reference Durable Object classes implemented by the Worker.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace being used."},{"name":"namespace_name","type":"String","description":"Name of the Durable Object namespace being used."},{"name":"worker_id","type":"String","description":"ID of the Worker using the Durable Object implementation."},{"name":"worker_name","type":"String","description":"Name of the Worker using the Durable Object implementation."}]},{"name":"queues","type":"List[Attributes]","description":"Queues that send messages to the Worker.","children":[{"name":"queue_consumer_id","type":"String","description":"ID of the queue consumer configuration."},{"name":"queue_id","type":"String","description":"ID of the queue."},{"name":"queue_name","type":"String","description":"Name of the queue."}]},{"name":"workers","type":"List[Attributes]","description":"Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).","children":[{"name":"id","type":"String","description":"ID of the referencing Worker."},{"name":"name","type":"String","description":"Name of the referencing Worker."}]}]}]}]},"post /accounts/{}/workers/workers/{}/versions":{"operationId":"createWorkerVersion","declarations":[{"kind":"resource","name":"cloudflare_worker_version","stainlessResource":"workers.beta.workers.versions","methodName":"create","snippet":"resource \"cloudflare_worker_version\" \"example_worker_version\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n annotations = {\n workers_message = \"Fixed bug.\"\n workers_tag = \"v1.0.1\"\n }\n assets = {\n config = {\n base_path = \"/docs/\"\n html_handling = \"auto-trailing-slash\"\n not_found_handling = \"404-page\"\n run_worker_first = []\n }\n jwt = \"jwt\"\n }\n bindings = [{\n name = \"MY_ENV_VAR\"\n text = \"my_data\"\n type = \"plain_text\"\n }]\n cache_options = {\n enabled = true\n cross_version_cache = true\n }\n compatibility_date = \"2021-01-01T00:00:00Z\"\n compatibility_flags = [\"nodejs_compat\"]\n containers = [{\n class_name = \"MyDurableObject\"\n }]\n exports = {\n Admin = {\n type = \"worker\"\n cache = {\n enabled = true\n }\n state = \"created\"\n }\n Counter = {\n storage = \"sqlite\"\n type = \"durable-object\"\n container = \"my-container\"\n state = \"created\"\n }\n OldCounter = {\n renamed_to = \"Counter\"\n state = \"renamed\"\n type = \"durable-object\"\n }\n default = {\n type = \"worker\"\n cache = {\n enabled = false\n }\n state = \"created\"\n }\n }\n limits = {\n cpu_ms = 50\n subrequests = 1000\n }\n main_module = \"index.js\"\n migrations = {\n deleted_classes = [\"string\"]\n new_classes = [\"string\"]\n new_sqlite_classes = [\"string\"]\n new_tag = \"v2\"\n old_tag = \"v1\"\n renamed_classes = [{\n from = \"from\"\n to = \"to\"\n }]\n transferred_classes = [{\n from = \"from\"\n from_script = \"from_script\"\n to = \"to\"\n }]\n }\n modules = [{\n content_base64 = \"ZXhwb3J0IGRlZmF1bHQgewogIGFzeW5jIGZldGNoKHJlcXVlc3QsIGVudiwgY3R4KSB7CiAgICByZXR1cm4gbmV3IFJlc3BvbnNlKCdIZWxsbyBXb3JsZCEnKQogIH0KfQ==\"\n content_type = \"application/javascript+module\"\n name = \"index.js\"\n }]\n package_dependencies = [{\n installed_version = \"4.17.22\"\n name = \"lodash\"\n package_json_version = \"^4.17.21\"\n }]\n placement = {\n mode = \"smart\"\n }\n usage_model = \"standard\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name.","requiresReplace":true}],"optional":[{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker.","requiresReplace":true},{"name":"main_module","type":"String","description":"The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler).","requiresReplace":true},{"name":"containers","type":"Set[Attributes]","description":"List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.","requiresReplace":true,"children":[{"name":"class_name","type":"String","description":"Select which Durable Object class should get this container attached."}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.\n","requiresReplace":true,"children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"migrations","type":"Attributes","description":"Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.","requiresReplace":true,"children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"new_tag","type":"String","description":"Tag to set as the latest migration tag."},{"name":"old_tag","type":"String","description":"Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]},{"name":"steps","type":"List[Attributes]","description":"Migrations to apply in order.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]}]}]},{"name":"modules","type":"Set[Attributes]","description":"Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","requiresReplace":true,"children":[{"name":"content_base64","type":"String","description":"The base64-encoded module content."},{"name":"content_type","type":"String","description":"The content type of the module."},{"name":"name","type":"String","description":"The name of the module."}]},{"name":"package_dependencies","type":"List[Attributes]","description":"The list of npm packages that were installed and used when this Worker\nversion was built.\n","requiresReplace":true,"children":[{"name":"installed_version","type":"String","description":"The exact version that was resolved and installed by the package manager."},{"name":"name","type":"String","description":"The npm package name."},{"name":"package_json_version","type":"String","description":"The version constraint as written in package.json."}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","requiresReplace":true,"children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"usage_model","type":"String","description":"Usage model for the version.","deprecated":"Deprecated.","requiresReplace":true},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`.","requiresReplace":true},{"name":"annotations","type":"Attributes","description":"Metadata about the version.","requiresReplace":true,"children":[{"name":"workers_message","type":"String","description":"Human-readable message about the version. Truncated to 1000 bytes if longer."},{"name":"workers_tag","type":"String","description":"User-provided identifier for the version. Maximum 100 bytes."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the version."}]},{"name":"assets","type":"Attributes","description":"Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","requiresReplace":true,"children":[{"name":"config","type":"Attributes","description":"Configuration for assets within a Worker.","children":[{"name":"base_path","type":"String","description":"The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%."},{"name":"html_handling","type":"String","description":"Determines the redirects and rewrites of requests for HTML content."},{"name":"not_found_handling","type":"String","description":"Determines the response when a request does not match a static asset, and there is no Worker script."},{"name":"run_worker_first","type":"List[String]","description":"Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules."}]},{"name":"jwt","type":"String","description":"Token provided upon successful upload of all files from a registered manifest.","sensitive":true}]},{"name":"bindings","type":"List[Attributes]","description":"List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.","requiresReplace":true,"children":[{"name":"name","type":"String","description":"A JavaScript variable name for the binding."},{"name":"type","type":"String","description":"The kind of resource that the binding provides."},{"name":"instance_name","type":"String","description":"The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance."},{"name":"namespace","type":"String","description":"The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field."},{"name":"dataset","type":"String","description":"The name of the dataset to bind to."},{"name":"database_id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"part","type":"String","description":"The name of the file containing the data content. Only accepted for `service worker syntax` Workers."},{"name":"outbound","type":"Attributes","description":"Outbound worker.","children":[{"name":"params","type":"List[Attributes]","description":"Pass information from the Dispatch Worker to the Outbound Worker through the parameters.","children":[{"name":"name","type":"String","description":"Name of the parameter."}]},{"name":"worker","type":"Attributes","description":"Outbound worker.","children":[{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the outbound worker."},{"name":"environment","type":"String","description":"Environment of the outbound worker."},{"name":"service","type":"String","description":"Name of the outbound worker."}]}]},{"name":"class_name","type":"String","description":"The exported class name of the Durable Object."},{"name":"dispatch_namespace","type":"String","description":"The dispatch namespace the Durable Object script belongs to."},{"name":"environment","type":"String","description":"The environment of the script_name to bind to."},{"name":"namespace_id","type":"String","description":"Namespace identifier tag."},{"name":"script_name","type":"String","description":"The script where the Durable Object is defined, if it is external to this Worker."},{"name":"old_name","type":"String","description":"The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions."},{"name":"version_id","type":"String","description":"Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version."},{"name":"json","type":"unknown","description":"JSON data to use."},{"name":"certificate_id","type":"String","description":"Identifier of the certificate to bind to."},{"name":"text","type":"String","description":"The text value to use.","sensitive":true},{"name":"pipeline","type":"String","description":"Name of the Pipeline to bind to."},{"name":"stream","type":"String","description":"ID of a K2 stream owned by the account deploying the Worker."},{"name":"queue_name","type":"String","description":"Name of the Queue to bind to."},{"name":"simple","type":"Attributes","description":"The rate limit configuration.","children":[{"name":"limit","type":"Float64","description":"The limit (requests per period)."},{"name":"period","type":"Int64","description":"The period in seconds."},{"name":"mitigation_timeout","type":"Int64","description":"Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero.\n"}]},{"name":"bucket_name","type":"String","description":"R2 bucket to bind to."},{"name":"jurisdiction","type":"String","description":"The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket."},{"name":"allowed_destination_addresses","type":"List[String]","description":"List of allowed destination addresses."},{"name":"allowed_sender_addresses","type":"List[String]","description":"List of allowed sender addresses."},{"name":"destination_address","type":"String","description":"Destination address for the email."},{"name":"service","type":"String","description":"Name of Worker to bind to."},{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the target Worker."},{"name":"index_name","type":"String","description":"Name of the Vectorize index to bind to."},{"name":"secret_name","type":"String","description":"Name of the secret in the store."},{"name":"store_id","type":"String","description":"ID of the store containing the secret."},{"name":"app_id","type":"String","description":"ID of the Flagship app to bind to for feature flag evaluation."},{"name":"algorithm","type":"unknown","description":"Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)."},{"name":"format","type":"String","description":"Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format)."},{"name":"usages","type":"Set[String]","description":"Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)."},{"name":"key_base64","type":"String","description":"Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".","sensitive":true},{"name":"key_jwk","type":"unknown","description":"Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".","sensitive":true},{"name":"workflow_name","type":"String","description":"Name of the Workflow to bind to."},{"name":"service_id","type":"String","description":"Identifier of the VPC service to bind to."},{"name":"identity","type":"String","description":"Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\n"},{"name":"network_id","type":"String","description":"Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id.\n"},{"name":"tunnel_id","type":"String","description":"UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id.\n"}]},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","requiresReplace":true,"children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime.","requiresReplace":true,"children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."},{"name":"subrequests","type":"Int64","description":"Subrequest limit per request."}]}],"computed":[{"name":"id","type":"String","description":"Version identifier.","requiresReplace":true},{"name":"author_email","type":"String","description":"Email of the user who created the version."},{"name":"author_id","type":"String","description":"Identifier of the user who created the version."},{"name":"created_on","type":"Time","description":"When the version was created."},{"name":"migration_tag","type":"String","description":"Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects."},{"name":"number","type":"Int64","description":"The integer version number, starting from one."},{"name":"source","type":"String","description":"The client used to create the version."},{"name":"startup_time_ms","type":"Int64","description":"Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)."},{"name":"urls","type":"List[String]","description":"All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version."},{"name":"exports_reconciliation","type":"Attributes","description":"Summary of the declarative exports reconciliation that ran on\nthis upload. Populated only when the uploaded metadata included\nan `exports` block. Durable Object entries drive reconciliation;\n`type: worker` entries do not contribute to this summary.\n","children":[{"name":"created","type":"List[String]","description":"Class names for which a new namespace was provisioned."},{"name":"deleted","type":"List[String]","description":"Class names whose namespace was deleted by a `deleted` tombstone."},{"name":"info","type":"List[Attributes]","description":"Non-blocking info entries (stale tombstones, tombstone applied\nwith class still in code). See `exports_reconciliation_info`.\n","children":[{"name":"class","type":"String","description":"The class name the info entry is about."},{"name":"message","type":"String","description":"Human-readable explanation."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the entry relates to, when applicable."},{"name":"referencing_scripts","type":"List[String]","description":"Other Workers in the account that still bind to the affected\nclass. Advisory: while non-empty the tombstone is not yet safe\nto remove — redeploy these Workers with bindings re-pointed\nfirst.\n"}]},{"name":"removable_entries","type":"List[String]","description":"Source class names whose tombstone entry is now stale and safe\nto delete from `exports` (no remaining referencing scripts).\n"},{"name":"renamed","type":"List[Attributes]","description":"Applied `renamed` tombstones.","children":[{"name":"from","type":"String","description":"The original (source) class name."},{"name":"to","type":"String","description":"The new class name (`renamed_to`)."}]},{"name":"transfer_pending","type":"List[Attributes]","description":"Phase-1 transfer hints recorded on the target side.","children":[{"name":"class","type":"String","description":"The target-side class name awaiting transfer."},{"name":"from","type":"String","description":"The source script the namespace will be transferred from."}]},{"name":"transferred","type":"List[Attributes]","description":"Committed `transferred` tombstones (phase-2).","children":[{"name":"class","type":"String","description":"The source class name that was transferred."},{"name":"phase","type":"String","description":"The transfer phase. Currently always `committed`."},{"name":"to","type":"String","description":"The destination script that now owns the namespace."}]},{"name":"updated","type":"List[String]","description":"Class names whose provisioned namespace was mutated in place."},{"name":"warnings","type":"List[Attributes]","description":"Non-blocking warnings. See `exports_reconciliation_warning`.","children":[{"name":"class","type":"String","description":"The class name the warning is about."},{"name":"message","type":"String","description":"Human-readable explanation of the warning."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the warning relates to, when applicable."}]}]}]}]},"post /accounts/{}/zerotrust/routes/hostname":{"operationId":"zero-trust-networks-route-hostname-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_network_hostname_route","stainlessResource":"zero_trust.networks.hostname_routes","methodName":"create","snippet":"resource \"cloudflare_zero_trust_network_hostname_route\" \"example_zero_trust_network_hostname_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n comment = \"example comment\"\n hostname = \"office-1.local\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true}],"optional":[{"name":"comment","type":"String","description":"An optional description of the hostname route."},{"name":"hostname","type":"String","description":"The hostname of the route."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"computed":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."}]}]},"post /accounts/{}/zerotrust/subnets/warp":{"operationId":"zero-trust-networks-subnet-create-warp","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_subnet","stainlessResource":"zero_trust.networks.subnets.warp","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_subnet\" \"example_zero_trust_device_subnet\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"IPv4 Cloudflare Source IPs\"\n network = \"100.64.0.0/12\"\n comment = \"example comment\"\n is_default_network = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for the subnet."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range defining the subnet, in CIDR notation."}],"optional":[{"name":"comment","type":"String","description":"An optional description of the subnet."},{"name":"is_default_network","type":"Bool","description":"If `true`, this is the default subnet for the account. There can only be one default subnet per account."}],"computed":[{"name":"id","type":"String","description":"The UUID of the subnet."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"subnet_type","type":"String","description":"The type of subnet."},{"name":"capacity","type":"Attributes","description":"IP capacity information for the subnet.","children":[{"name":"total","type":"Int64","description":"Total number of assignable IPs in the subnet."},{"name":"used","type":"Int64","description":"Number of assigned IPs in the subnet."}]}]}]},"post /accounts/{}/zt_risk_scoring/integrations":{"operationId":"dlp-zt-risk-score-integration-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_risk_scoring_integration","stainlessResource":"zero_trust.risk_scoring.integrations","methodName":"create","snippet":"resource \"cloudflare_zero_trust_risk_scoring_integration\" \"example_zero_trust_risk_scoring_integration\" {\n account_id = \"account_id\"\n integration_type = \"Okta\"\n tenant_url = \"https://example.com\"\n reference_id = \"reference_id\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"integration_type","type":"String","requiresReplace":true},{"name":"tenant_url","type":"String","description":"The base url of the tenant, e.g. \"https://tenant.okta.com\"."}],"optional":[{"name":"active","type":"Bool","description":"Whether this integration is enabled. If disabled, no risk changes will be exported to the third-party."},{"name":"reference_id","type":"String","description":"A reference id that can be supplied by the client. Currently this should be set to the Access-Okta IDP ID (a UUIDv4).\nhttps://developers.cloudflare.com/api/operations/access-identity-providers-get-an-access-identity-provider"}],"computed":[{"name":"id","type":"String","description":"The id of the integration, a UUIDv4."},{"name":"account_tag","type":"String","description":"The Cloudflare account tag."},{"name":"created_at","type":"Time","description":"When the integration was created in RFC3339 format."},{"name":"well_known_url","type":"String","description":"The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1."}]}]},"post /certificates":{"operationId":"origin-ca-create-certificate","declarations":[{"kind":"resource","name":"cloudflare_origin_ca_certificate","stainlessResource":"origin_ca_certificates","methodName":"create","snippet":"resource \"cloudflare_origin_ca_certificate\" \"example_origin_ca_certificate\" {\n csr = <`."},{"name":"enabled","type":"Bool","description":"Whether Email Sending is enabled on this subdomain."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"return_path_domain","type":"String","description":"The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`."}]}]},"post /zones/{}/filters":{"operationId":"filters-create-filters","declarations":[{"kind":"resource","name":"cloudflare_filter","stainlessResource":"filters","methodName":"create","snippet":"resource \"cloudflare_filter\" \"example_filter\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n body = [{\n description = \"Restrict access from these browsers on this address range.\"\n expression = \"(http.request.uri.path ~ \\\".*wp-login.php\\\" or http.request.uri.path ~ \\\".*xmlrpc.php\\\") and ip.addr ne 172.16.22.155\"\n paused = false\n ref = \"FIL-100\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"body","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}],"optional":[{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the filter."}]}]},"post /zones/{}/firewall/lockdowns":{"operationId":"zone-lockdown-create-a-zone-lockdown-rule","declarations":[{"kind":"resource","name":"cloudflare_zone_lockdown","stainlessResource":"firewall.lockdowns","methodName":"create","snippet":"resource \"cloudflare_zone_lockdown\" \"example_zone_lockdown\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n configurations = [{\n target = \"ip\"\n value = \"198.51.100.4\"\n }]\n urls = [\"shop.example.com/*\"]\n description = \"Prevent multiple login failures to mitigate brute force attacks\"\n paused = false\n priority = 5\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"urls","type":"Set[String]","description":"The URLs to include in the current WAF override. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns."},{"name":"configurations","type":"List[Attributes]","description":"A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule."},{"name":"value","type":"String","description":"The IP address to match. This address will be compared to the IP address of incoming requests."}]}],"optional":[{"name":"description","type":"String","description":"An informative summary of the rule. This value is sanitized and any tags will be removed.","requiresReplace":true},{"name":"priority","type":"Float64","description":"The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority.","requiresReplace":true},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."}]}]},"post /zones/{}/firewall/rules":{"operationId":"firewall-rules-create-firewall-rules","declarations":[{"kind":"resource","name":"cloudflare_firewall_rule","stainlessResource":"firewall.rules","methodName":"create","snippet":"resource \"cloudflare_firewall_rule\" \"example_firewall_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = {\n mode = \"challenge\"\n response = {\n body = \"This request has been rate-limited.\"\n content_type = \"text/xml\"\n }\n timeout = 86400\n }\n filter = {\n description = \"Restrict access from these browsers on this address range.\"\n expression = \"(http.request.uri.path ~ \\\".*wp-login.php\\\" or http.request.uri.path ~ \\\".*xmlrpc.php\\\") and ip.addr ne 172.16.22.155\"\n paused = false\n ref = \"FIL-100\"\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"action","type":"Attributes","description":"The action to perform when the threshold of matched traffic within the configured period is exceeded.","children":[{"name":"mode","type":"String","description":"The action to perform."},{"name":"response","type":"Attributes","description":"A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional.\nNotes: If you omit this object, Cloudflare will use the default HTML error page. If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone challenge pages and you should not provide the \"response\" object.","children":[{"name":"body","type":"String","description":"The response body to return. The value must conform to the configured content type."},{"name":"content_type","type":"String","description":"The content type of the body. Must be one of the following: `text/plain`, `text/xml`, or `application/json`."}]},{"name":"timeout","type":"Float64","description":"The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period.\nNotes: If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone's Challenge Passage time and you should not provide this value."}]},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"description","type":"String","description":"An informative summary of the firewall rule."},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"priority","type":"Float64","description":"The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related firewall rules."},{"name":"products","type":"List[String]"}]}]},"post /zones/{}/firewall/ua_rules":{"operationId":"user-agent-blocking-rules-create-a-user-agent-blocking-rule","declarations":[{"kind":"resource","name":"cloudflare_user_agent_blocking_rule","stainlessResource":"firewall.ua_rules","methodName":"create","snippet":"resource \"cloudflare_user_agent_blocking_rule\" \"example_user_agent_blocking_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n configuration = {\n target = \"ua\"\n value = \"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)\"\n }\n mode = \"challenge\"\n description = \"Prevent multiple login failures to mitigate brute force attacks\"\n paused = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"mode","type":"String","description":"The action to apply to a matched request."},{"name":"configuration","type":"Attributes","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ua` when specifying a user agent in the rule."},{"name":"value","type":"String","description":"the user agent to exactly match"}]}],"optional":[{"name":"description","type":"String","description":"An informative summary of the rule. This value is sanitized and any tags will be removed."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the User Agent Blocking rule."}]}]},"post /zones/{}/healthchecks":{"operationId":"health-checks-create-health-check","declarations":[{"kind":"resource","name":"cloudflare_healthcheck","stainlessResource":"healthchecks","methodName":"create","snippet":"resource \"cloudflare_healthcheck\" \"example_healthcheck\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n address = \"www.example.com\"\n name = \"server-1\"\n check_regions = [\"WEU\", \"ENAM\"]\n consecutive_fails = 0\n consecutive_successes = 0\n description = \"Health check for www.example.com\"\n http_config = {\n allow_insecure = true\n expected_body = \"success\"\n expected_codes = [\"2xx\", \"302\"]\n follow_redirects = true\n header = {\n Host = [\"example.com\"]\n X-App-ID = [\"abc123\"]\n }\n method = \"GET\"\n path = \"/health\"\n port = 0\n }\n interval = 0\n retries = 0\n suspended = true\n tcp_config = {\n method = \"connection_established\"\n port = 0\n }\n timeout = 0\n type = \"HTTPS\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"address","type":"String","description":"The hostname or IP address of the origin server to run health checks on."},{"name":"name","type":"String","description":"A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed."}],"optional":[{"name":"description","type":"String","description":"A human-readable description of the health check."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means Cloudflare will pick a default region."},{"name":"consecutive_fails","type":"Int64","description":"The number of consecutive fails required from a health check before changing the health to unhealthy."},{"name":"consecutive_successes","type":"Int64","description":"The number of consecutive successes required from a health check before changing the health to healthy."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"suspended","type":"Bool","description":"If suspended, no health checks are sent to the origin."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'."},{"name":"http_config","type":"Attributes","description":"Parameters specific to an HTTP or HTTPS health check.","children":[{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when the health check uses HTTPS."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy."},{"name":"expected_codes","type":"List[String]","description":"The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if the origin returns a 3xx status code."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden."},{"name":"method","type":"String","description":"The HTTP method to use for the health check."},{"name":"path","type":"String","description":"The endpoint path to health check against."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS."}]},{"name":"tcp_config","type":"Attributes","description":"Parameters specific to TCP health check.","children":[{"name":"method","type":"String","description":"The TCP connection method to use for the health check."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"failure_reason","type":"String","description":"The current failure reason if status is unhealthy."},{"name":"modified_on","type":"Time"},{"name":"status","type":"String","description":"The current status of the origin server according to the health check."}]}]},"post /zones/{}/hold":{"operationId":"zones-0-hold-post","declarations":[{"kind":"resource","name":"cloudflare_zone_hold","stainlessResource":"zones.holds","methodName":"create","snippet":"resource \"cloudflare_zone_hold\" \"example_zone_hold\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"hold_after","type":"String","description":"If `hold_after` is provided and future-dated, the hold will be temporarily disabled,\nthen automatically re-enabled by the system at the time specified\nin this RFC3339-formatted timestamp. A past-dated `hold_after` value will have\nno effect on an existing, enabled hold. Providing an empty string will set its value\nto the current time. Providing `null` will disable the hold indefinitely."},{"name":"include_subdomains","type":"Bool","description":"If `true`, the zone hold will extend to block any subdomain of the given zone, as well\nas SSL4SaaS Custom Hostnames. For example, a zone hold on a zone with the hostname\n'example.com' and include_subdomains=true will block 'example.com',\n'staging.example.com', 'api.staging.example.com', etc."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"hold","type":"Bool"}]}]},"post /zones/{}/keyless_certificates":{"operationId":"keyless-ssl-for-a-zone-create-keyless-ssl-configuration","declarations":[{"kind":"resource","name":"cloudflare_keyless_certificate","stainlessResource":"keyless_certificates","methodName":"create","snippet":"resource \"cloudflare_keyless_certificate\" \"example_keyless_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate = <This request has been rate-limited.\"\n content_type = \"text/xml\"\n }\n timeout = 86400\n }\n match = {\n headers = [{\n name = \"Cf-Cache-Status\"\n op = \"ne\"\n value = \"HIT\"\n }]\n request = {\n methods = [\"GET\", \"POST\"]\n schemes = [\"HTTP\", \"HTTPS\"]\n url = \"*.example.org/path*\"\n }\n response = {\n origin_traffic = true\n }\n }\n period = 900\n threshold = 60\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"period","type":"Float64","description":"The time in seconds (an integer value) to count matching traffic. If the count exceeds the configured threshold within this period, Cloudflare will perform the configured action."},{"name":"threshold","type":"Float64","description":"The threshold that will trigger the configured mitigation action. Configure this value along with the `period` property to establish a threshold per period."},{"name":"action","type":"Attributes","description":"The action to perform when the threshold of matched traffic within the configured period is exceeded.","children":[{"name":"mode","type":"String","description":"The action to perform."},{"name":"response","type":"Attributes","description":"A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional.\nNotes: If you omit this object, Cloudflare will use the default HTML error page. If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone challenge pages and you should not provide the \"response\" object.","children":[{"name":"body","type":"String","description":"The response body to return. The value must conform to the configured content type."},{"name":"content_type","type":"String","description":"The content type of the body. Must be one of the following: `text/plain`, `text/xml`, or `application/json`."}]},{"name":"timeout","type":"Float64","description":"The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period.\nNotes: If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone's Challenge Passage time and you should not provide this value."}]},{"name":"match","type":"Attributes","description":"Determines which traffic the rate limit counts towards the threshold.","children":[{"name":"headers","type":"List[Attributes]","children":[{"name":"name","type":"String","description":"The name of the response header to match."},{"name":"op","type":"String","description":"The operator used when matching: `eq` means \"equal\" and `ne` means \"not equal\"."},{"name":"value","type":"String","description":"The value of the response header, which must match exactly."}]},{"name":"request","type":"Attributes","children":[{"name":"methods","type":"List[String]","description":"The HTTP methods to match. You can specify a subset (for example, `['POST','PUT']`) or all methods (`['_ALL_']`). This field is optional when creating a rate limit."},{"name":"schemes","type":"List[String]","description":"The HTTP schemes to match. You can specify one scheme (`['HTTPS']`), both schemes (`['HTTP','HTTPS']`), or all schemes (`['_ALL_']`). This field is optional."},{"name":"url","type":"String","description":"The URL pattern to match, composed of a host and a path such as `example.org/path*`. Normalization is applied before the pattern is matched. `*` wildcards are expanded to match applicable traffic. Query strings are not matched. Set the value to `*` to match all traffic to your zone."}]},{"name":"response","type":"Attributes","children":[{"name":"origin_traffic","type":"Bool","description":"When true, only the uncached traffic served from your origin servers will count towards rate limiting. In this case, any cached traffic served by Cloudflare will not count towards rate limiting. This field is optional.\nNotes: This field is deprecated. Instead, use response headers and set \"origin_traffic\" to \"false\" to avoid legacy behaviour interacting with the \"response_headers\" property."}]}]}],"optional":[{"name":"rate_limit_id","type":"String","description":"Defines the unique identifier of the rate limit.","requiresReplace":true}],"computed":[]}]},"post /zones/{}/schema_validation/schemas":{"operationId":"schema-validation-create-schema","declarations":[{"kind":"resource","name":"cloudflare_schema_validation_schemas","stainlessResource":"schema_validation.schemas","methodName":"create","snippet":"resource \"cloudflare_schema_validation_schemas\" \"example_schema_validation_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"openapi_v3\"\n name = \"petstore schema\"\n source = \"\"\n validation_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"kind","type":"String","description":"The kind of the schema","requiresReplace":true},{"name":"name","type":"String","description":"A human-readable name for the schema","requiresReplace":true},{"name":"source","type":"String","description":"The raw schema, e.g., the OpenAPI schema, either as JSON or YAML","requiresReplace":true},{"name":"validation_enabled","type":"Bool","description":"An indicator if this schema is enabled"}],"optional":[],"computed":[{"name":"id","type":"String","description":"A unique identifier of this schema"},{"name":"schema_id","type":"String","description":"A unique identifier of this schema"},{"name":"created_at","type":"Time"}]}]},"post /zones/{}/secondary_dns/incoming":{"operationId":"secondary-dns-(-secondary-zone)-create-secondary-zone-configuration","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_incoming","stainlessResource":"dns.zone_transfers.incoming","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_incoming\" \"example_dns_zone_transfers_incoming\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n auto_refresh_seconds = 86400\n name = \"www.example.com.\"\n peers = [\"23ff594956f20c2a721606e94745a8aa\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"Zone name."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}],"optional":[{"name":"auto_refresh_seconds","type":"Float64","description":"How often should a secondary zone auto refresh regardless of DNS NOTIFY.\nNot applicable for primary zones."}],"computed":[{"name":"id","type":"String"},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"modified_time","type":"String","description":"The time for a specific event."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."}]}]},"post /zones/{}/secondary_dns/outgoing":{"operationId":"secondary-dns-(-primary-zone)-create-primary-zone-configuration","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_outgoing","stainlessResource":"dns.zone_transfers.outgoing","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_outgoing\" \"example_dns_zone_transfers_outgoing\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n name = \"www.example.com.\"\n peers = [\"23ff594956f20c2a721606e94745a8aa\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"Zone name."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"last_transferred_time","type":"String","description":"The time for a specific event."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."}]}]},"post /zones/{}/spectrum/apps":{"operationId":"spectrum-applications-create-spectrum-application-using-a-name-for-the-origin","declarations":[{"kind":"resource","name":"cloudflare_spectrum_application","stainlessResource":"spectrum.apps","methodName":"create","snippet":"resource \"cloudflare_spectrum_application\" \"example_spectrum_application\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns = {\n name = \"ssh.example.com\"\n type = \"CNAME\"\n }\n protocol = \"tcp/22\"\n traffic_type = \"direct\"\n argo_smart_routing = true\n edge_ips = {\n connectivity = \"all\"\n type = \"dynamic\"\n }\n ip_firewall = false\n origin_direct = [\"tcp://127.0.0.1:8080\"]\n origin_dns = {\n name = \"origin.example.com\"\n ttl = 600\n type = \"\"\n }\n origin_port = 22\n origin_worker_id = \"277b7815c871434b960b60729659000a\"\n proxy_protocol = \"off\"\n tls = \"off\"\n virtual_network_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier.","requiresReplace":true},{"name":"protocol","type":"String","description":"The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`."},{"name":"dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the application."},{"name":"type","type":"String","description":"The type of DNS record associated with the application."}]}],"optional":[{"name":"origin_worker_id","type":"String","description":"Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"."},{"name":"virtual_network_id","type":"String","description":"Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks."},{"name":"origin_direct","type":"List[String]","description":"List of origin IP addresses. Array may contain multiple IP addresses for load balancing."},{"name":"origin_dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the origin."},{"name":"ttl","type":"Int64","description":"The TTL of our resolution of your DNS record in seconds."},{"name":"type","type":"String","description":"The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records."}]},{"name":"origin_port","type":"Dynamic Int64 | String","description":"The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field."},{"name":"argo_smart_routing","type":"Bool","description":"Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"."},{"name":"ip_firewall","type":"Bool","description":"Enables IP Access Rules for this application.\nNotes: Only available for TCP applications."},{"name":"proxy_protocol","type":"String","description":"Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol."},{"name":"tls","type":"String","description":"The type of TLS termination associated with the application."},{"name":"traffic_type","type":"String","description":"Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`."},{"name":"edge_ips","type":"Attributes","description":"The anycast edge IP configuration for the hostname of this application.","children":[{"name":"connectivity","type":"String","description":"The IP versions supported for inbound connections on Spectrum anycast IPs."},{"name":"type","type":"String","description":"The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names."},{"name":"ips","type":"List[String]","description":"The array of customer owned IPs we broadcast via anycast for this hostname and application."}]}],"computed":[{"name":"id","type":"String","description":"App identifier."},{"name":"created_on","type":"Time","description":"When the Application was created."},{"name":"modified_on","type":"Time","description":"When the Application was last modified."}]}]},"post /zones/{}/speed_api/schedule/{}":{"operationId":"speed-create-scheduled-test","declarations":[{"kind":"resource","name":"cloudflare_observatory_scheduled_test","stainlessResource":"speed.schedule","methodName":"create","snippet":"resource \"cloudflare_observatory_scheduled_test\" \"example_observatory_scheduled_test\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n url = \"example.com\"\n}\n","required":[{"name":"url","type":"String","description":"A URL.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"A URL.","requiresReplace":true},{"name":"frequency","type":"String","description":"The frequency of the test."},{"name":"region","type":"String","description":"A test region."},{"name":"schedule","type":"Attributes","description":"The test schedule.","children":[{"name":"frequency","type":"String","description":"The frequency of the test."},{"name":"region","type":"String","description":"A test region."},{"name":"url","type":"String","description":"A URL."}]},{"name":"test","type":"Attributes","children":[{"name":"id","type":"String","description":"UUID."},{"name":"date","type":"Time"},{"name":"desktop_report","type":"Attributes","description":"The Lighthouse report.","children":[{"name":"cls","type":"Float64","description":"Cumulative Layout Shift."},{"name":"device_type","type":"String","description":"The type of device."},{"name":"error","type":"Attributes","children":[{"name":"code","type":"String","description":"The error code of the Lighthouse result."},{"name":"detail","type":"String","description":"Detailed error message."},{"name":"final_displayed_url","type":"String","description":"The final URL displayed to the user."}]},{"name":"fcp","type":"Float64","description":"First Contentful Paint."},{"name":"json_report_url","type":"String","description":"The URL to the full Lighthouse JSON report."},{"name":"lcp","type":"Float64","description":"Largest Contentful Paint."},{"name":"performance_score","type":"Float64","description":"The Lighthouse performance score."},{"name":"si","type":"Float64","description":"Speed Index."},{"name":"state","type":"String","description":"The state of the Lighthouse report."},{"name":"tbt","type":"Float64","description":"Total Blocking Time."},{"name":"ttfb","type":"Float64","description":"Time To First Byte."},{"name":"tti","type":"Float64","description":"Time To Interactive."}]},{"name":"mobile_report","type":"Attributes","description":"The Lighthouse report.","children":[{"name":"cls","type":"Float64","description":"Cumulative Layout Shift."},{"name":"device_type","type":"String","description":"The type of device."},{"name":"error","type":"Attributes","children":[{"name":"code","type":"String","description":"The error code of the Lighthouse result."},{"name":"detail","type":"String","description":"Detailed error message."},{"name":"final_displayed_url","type":"String","description":"The final URL displayed to the user."}]},{"name":"fcp","type":"Float64","description":"First Contentful Paint."},{"name":"json_report_url","type":"String","description":"The URL to the full Lighthouse JSON report."},{"name":"lcp","type":"Float64","description":"Largest Contentful Paint."},{"name":"performance_score","type":"Float64","description":"The Lighthouse performance score."},{"name":"si","type":"Float64","description":"Speed Index."},{"name":"state","type":"String","description":"The state of the Lighthouse report."},{"name":"tbt","type":"Float64","description":"Total Blocking Time."},{"name":"ttfb","type":"Float64","description":"Time To First Byte."},{"name":"tti","type":"Float64","description":"Time To Interactive."}]},{"name":"region","type":"Attributes","description":"A test region with a label.","children":[{"name":"label","type":"String"},{"name":"value","type":"String","description":"A test region."}]},{"name":"schedule_frequency","type":"String","description":"The frequency of the test."},{"name":"url","type":"String","description":"A URL."}]}]}]},"post /zones/{}/ssl/certificate_packs/order":{"operationId":"certificate-packs-order-advanced-certificate-manager-certificate-pack","declarations":[{"kind":"resource","name":"cloudflare_certificate_pack","stainlessResource":"ssl.certificate_packs","methodName":"create","snippet":"resource \"cloudflare_certificate_pack\" \"example_certificate_pack\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_authority = \"lets_encrypt\"\n hosts = [\"example.com\", \"*.example.com\", \"www.example.com\"]\n type = \"advanced\"\n validation_method = \"txt\"\n validity_days = 14\n cloudflare_branding = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"certificate_authority","type":"String","description":"Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities).","requiresReplace":true},{"name":"type","type":"String","description":"Type of certificate pack.","requiresReplace":true},{"name":"validation_method","type":"String","description":"Validation Method selected for the order.","requiresReplace":true},{"name":"validity_days","type":"Int64","description":"Validity Days selected for the order.","requiresReplace":true}],"optional":[{"name":"cloudflare_branding","type":"Bool","description":"Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true.","requiresReplace":true},{"name":"hosts","type":"Set[String]","description":"Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"The unique identifier for a certificate_pack.","requiresReplace":true},{"name":"primary_certificate","type":"String","description":"Identifier of the primary certificate in a pack."},{"name":"status","type":"String","description":"Status of certificate pack."},{"name":"certificates","type":"List[Attributes]","description":"Array of certificates in this pack.","children":[{"name":"id","type":"String","description":"Certificate identifier."},{"name":"hosts","type":"List[String]","description":"Hostnames covered by this certificate."},{"name":"status","type":"String","description":"Certificate status."},{"name":"bundle_method","type":"String","description":"Certificate bundle method."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally.","children":[{"name":"label","type":"String"}]},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"zone_id","type":"String","description":"Identifier."}]},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","description":"Certificates' validation records.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]}]}]},"post /zones/{}/subscription":{"operationId":"zone-subscription-create-zone-subscription","declarations":[{"kind":"resource","name":"cloudflare_zone_subscription","stainlessResource":"zones.subscriptions","methodName":"create","snippet":"resource \"cloudflare_zone_subscription\" \"example_zone_subscription\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n frequency = \"monthly\"\n rate_plan = {\n id = \"free\"\n currency = \"USD\"\n externally_managed = false\n is_contract = false\n public_name = \"Business Plan\"\n scope = \"zone\"\n sets = [\"string\"]\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier","requiresReplace":true}],"optional":[{"name":"frequency","type":"String","description":"How often the subscription is renewed automatically."},{"name":"rate_plan","type":"Attributes","description":"The rate plan applied to the subscription.","children":[{"name":"id","type":"String","description":"The ID of the rate plan."},{"name":"currency","type":"String","description":"The currency applied to the rate plan subscription."},{"name":"externally_managed","type":"Bool","description":"Whether this rate plan is managed externally from Cloudflare."},{"name":"is_contract","type":"Bool","description":"Whether a rate plan is enterprise-based (or newly adopted term contract)."},{"name":"public_name","type":"String","description":"The full name of the rate plan."},{"name":"scope","type":"String","description":"The scope that this rate plan applies to."},{"name":"sets","type":"List[String]","description":"The list of sets this rate plan applies to. Returns array of strings."}]}],"computed":[{"name":"id","type":"String","description":"Identifier","requiresReplace":true},{"name":"currency","type":"String","description":"The monetary unit in which pricing information is displayed."},{"name":"current_period_end","type":"Time","description":"The end of the current period and also when the next billing is due."},{"name":"current_period_start","type":"Time","description":"When the current billing period started. May match initial_period_start if this is the first period."},{"name":"price","type":"Float64","description":"The price of the subscription that will be billed, in US dollars."},{"name":"state","type":"String","description":"The state that the subscription is in."}]}]},"post /zones/{}/token_validation/config":{"operationId":"token-validation-config-create","declarations":[{"kind":"resource","name":"cloudflare_token_validation_config","stainlessResource":"token_validation.configuration","methodName":"create","snippet":"resource \"cloudflare_token_validation_config\" \"example_token_validation_config\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credentials = {\n keys = [{\n alg = \"RS256\"\n e = \"e\"\n kid = \"kid\"\n kty = \"RSA\"\n n = \"n\"\n }]\n }\n description = \"Long description for Token Validation Configuration\"\n title = \"Example Token Validation Configuration\"\n token_sources = [\"http.request.headers[\\\"x-auth\\\"][0]\", \"http.request.cookies[\\\"Authorization\\\"][0]\"]\n token_type = \"JWT\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"token_type","type":"String","requiresReplace":true},{"name":"credentials","type":"Attributes","description":"Request payload for create and PUT credentials operations. Provided keys define the complete stored key set. Key identities (`{alg,kid}`) must be unique.","requiresReplace":true,"children":[{"name":"keys","type":"List[Attributes]","children":[{"name":"alg","type":"String","description":"Algorithm"},{"name":"e","type":"String","description":"RSA exponent"},{"name":"kid","type":"String","description":"Key ID"},{"name":"kty","type":"String","description":"Key Type"},{"name":"n","type":"String","description":"RSA modulus"},{"name":"crv","type":"String","description":"Curve"},{"name":"x","type":"String","description":"X EC coordinate"},{"name":"y","type":"String","description":"Y EC coordinate"},{"name":"k","type":"String","description":"Symmetric key material. Required for create and PUT update requests."}]}]},{"name":"description","type":"String"},{"name":"title","type":"String"},{"name":"token_sources","type":"List[String]"}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"last_updated","type":"Time"}]}]},"post /zones/{}/token_validation/rules":{"operationId":"token-validation-rules-create","declarations":[{"kind":"resource","name":"cloudflare_token_validation_rules","stainlessResource":"token_validation.rules","methodName":"create","snippet":"resource \"cloudflare_token_validation_rules\" \"example_token_validation_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = \"log\"\n description = \"Long description for Token Validation Rule\"\n enabled = true\n expression = \"is_jwt_valid(\\\"52973293-cb04-4a97-8f55-e7d2ad1107dd\\\") or is_jwt_valid(\\\"46eab8d1-6376-45e3-968f-2c649d77d423\\\")\"\n selector = {\n exclude = [{\n operation_ids = [\"f9c5615e-fe15-48ce-bec6-cfc1946f1bec\", \"56828eae-035a-4396-ba07-51c66d680a04\"]\n }]\n include = [{\n host = [\"v1.example.com\", \"v2.example.com\"]\n }]\n }\n title = \"Example Token Validation Rule\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"description","type":"String","description":"A human-readable description that gives more details than `title`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"expression","type":"String","description":"Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n"},{"name":"title","type":"String","description":"A human-readable name for the rule."},{"name":"selector","type":"Attributes","description":"Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n","children":[{"name":"exclude","type":"List[Attributes]","description":"Ignore operations that were otherwise included by `include`.","children":[{"name":"operation_ids","type":"List[String]","description":"Excluded operation IDs."}]},{"name":"include","type":"List[Attributes]","description":"Select all matching operations.","children":[{"name":"host","type":"List[String]","description":"Included hostnames."}]}]}],"optional":[{"name":"position","type":"Attributes","description":"Update rule order among zone rules.","children":[{"name":"index","type":"Int64","description":"Move rule to this position"},{"name":"before","type":"String","description":"Move rule to before rule with this ID."},{"name":"after","type":"String","description":"Move rule to after rule with this ID."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"last_updated","type":"Time"}]}]},"post /zones/{}/waiting_rooms":{"operationId":"waiting-room-create-waiting-room","declarations":[{"kind":"resource","name":"cloudflare_waiting_room","stainlessResource":"waiting_rooms","methodName":"create","snippet":"resource \"cloudflare_waiting_room\" \"example_waiting_room\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n host = \"shop.example.com\"\n name = \"production_webinar\"\n new_users_per_minute = 200\n total_active_users = 200\n additional_routes = [{\n host = \"shop2.example.com\"\n path = \"/shop2/checkout\"\n }]\n cookie_attributes = {\n samesite = \"auto\"\n secure = \"auto\"\n }\n cookie_suffix = \"abcd\"\n custom_page_html = \"{{#waitTimeKnown}} {{waitTime}} mins {{/waitTimeKnown}} {{^waitTimeKnown}} Queue all enabled {{/waitTimeKnown}}\"\n default_template_language = \"es-ES\"\n description = \"Production - DO NOT MODIFY\"\n disable_session_renewal = false\n enabled_origin_commands = [\"revoke\"]\n json_response_enabled = false\n path = \"/shop/checkout\"\n queue_all = true\n queueing_method = \"fifo\"\n queueing_status_code = 202\n session_duration = 1\n suspended = true\n turnstile_action = \"log\"\n turnstile_mode = \"off\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"host","type":"String","description":"The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination must be unique."},{"name":"name","type":"String","description":"A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. So it is possible that there is a little more or little less traffic coming to the route based on the traffic patterns at that time around the world."},{"name":"total_active_users","type":"Int64","description":"Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available. This value is used as a baseline for the total number of active user sessions on the route. It is possible to have a situation where there are more or less active users sessions on the route based on the traffic patterns at that time around the world."}],"optional":[{"name":"cookie_suffix","type":"String","description":"Appends a '_' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(__cf_waitingroom). If `cookie_suffix` is \"abcd\", the cookie name will be `__cf_waitingroom_abcd`. This field is required if using `additional_routes`."},{"name":"custom_page_html","type":"String","description":"Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custom_page_html is provided, the default waiting room will be used. The template is based on mustache ( https://mustache.github.io/ ). There are several variables that are evaluated by the Cloudflare edge:\n1. {{`waitTimeKnown`}} Acts like a boolean value that indicates the behavior to take when wait time is not available, for instance when queue_all is **true**.\n2. {{`waitTimeFormatted`}} Estimated wait time for the user. For example, five minutes. Alternatively, you can use:\n3. {{`waitTime`}} Number of minutes of estimated wait for a user.\n4. {{`waitTimeHours`}} Number of hours of estimated wait for a user (`Math.floor(waitTime/60)`).\n5. {{`waitTimeHourMinutes`}} Number of minutes above the `waitTimeHours` value (`waitTime%60`).\n6. {{`queueIsFull`}} Changes to **true** when no more people can be added to the queue.\n\nTo view the full list of variables, look at the `cfWaitingRoom` object described under the `json_response_enabled` property in other Waiting Room API calls."},{"name":"default_template_language","type":"String","description":"The language of the default page template. If no default_template_language is provided, then `en-US` (English) will be used."},{"name":"description","type":"String","description":"A note that you can use to add more details about the waiting room."},{"name":"disable_session_renewal","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If `true`, an accepted user will have session_duration minutes to browse the site. After that, they will have to go through the waiting room again. If `false`, a user's session cookie will be automatically renewed on every request."},{"name":"json_response_enabled","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. If `true`, requests to the waiting room with the header `Accept: application/json` will receive a JSON response object with information on the user's status in the waiting room as opposed to the configured static HTML page. This JSON response object has one property `cfWaitingRoom` which is an object containing the following fields:\n1. `inWaitingRoom`: Boolean indicating if the user is in the waiting room (always **true**).\n2. `waitTimeKnown`: Boolean indicating if the current estimated wait times are accurate. If **false**, they are not available.\n3. `waitTime`: Valid only when `waitTimeKnown` is **true**. Integer indicating the current estimated time in minutes the user will wait in the waiting room. When `queueingMethod` is **random**, this is set to `waitTime50Percentile`.\n4. `waitTime25Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 25% of users that gain entry the fastest (25th percentile).\n5. `waitTime50Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 50% of users that gain entry the fastest (50th percentile). In other words, half of the queued users are expected to let into the origin website before `waitTime50Percentile` and half are expected to be let in after it.\n6. `waitTime75Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 75% of users that gain entry the fastest (75th percentile).\n7. `waitTimeFormatted`: String displaying the `waitTime` formatted in English for users. If `waitTimeKnown` is **false**, `waitTimeFormatted` will display **unavailable**.\n8. `queueIsFull`: Boolean indicating if the waiting room's queue is currently full and not accepting new users at the moment.\n9. `queueAll`: Boolean indicating if all users will be queued in the waiting room and no one will be let into the origin website.\n10. `lastUpdated`: String displaying the timestamp as an ISO 8601 string of the user's last attempt to leave the waiting room and be let into the origin website. The user is able to make another attempt after `refreshIntervalSeconds` past this time. If the user makes a request too soon, it will be ignored and `lastUpdated` will not change.\n11. `refreshIntervalSeconds`: Integer indicating the number of seconds after `lastUpdated` until the user is able to make another attempt to leave the waiting room and be let into the origin website. When the `queueingMethod` is `reject`, there is no specified refresh time —\\_it will always be **zero**.\n12. `queueingMethod`: The queueing method currently used by the waiting room. It is either **fifo**, **random**, **passthrough**, or **reject**.\n13. `isFIFOQueue`: Boolean indicating if the waiting room uses a FIFO (First-In-First-Out) queue.\n14. `isRandomQueue`: Boolean indicating if the waiting room uses a Random queue where users gain access randomly.\n15. `isPassthroughQueue`: Boolean indicating if the waiting room uses a passthrough queue. Keep in mind that when passthrough is enabled, this JSON response will only exist when `queueAll` is **true** or `isEventPrequeueing` is **true** because in all other cases requests will go directly to the origin.\n16. `isRejectQueue`: Boolean indicating if the waiting room uses a reject queue.\n17. `isEventActive`: Boolean indicating if an event is currently occurring. Events are able to change a waiting room's behavior during a specified period of time. For additional information, look at the event properties `prequeue_start_time`, `event_start_time`, and `event_end_time` in the documentation for creating waiting room events. Events are considered active between these start and end times, as well as during the prequeueing period if it exists.\n18. `isEventPrequeueing`: Valid only when `isEventActive` is **true**. Boolean indicating if an event is currently prequeueing users before it starts.\n19. `timeUntilEventStart`: Valid only when `isEventPrequeueing` is **true**. Integer indicating the number of minutes until the event starts.\n20. `timeUntilEventStartFormatted`: String displaying the `timeUntilEventStart` formatted in English for users. If `isEventPrequeueing` is **false**, `timeUntilEventStartFormatted` will display **unavailable**.\n21. `timeUntilEventEnd`: Valid only when `isEventActive` is **true**. Integer indicating the number of minutes until the event ends.\n22. `timeUntilEventEndFormatted`: String displaying the `timeUntilEventEnd` formatted in English for users. If `isEventActive` is **false**, `timeUntilEventEndFormatted` will display **unavailable**.\n23. `shuffleAtEventStart`: Valid only when `isEventActive` is **true**. Boolean indicating if the users in the prequeue are shuffled randomly when the event starts.\n24. `turnstile`: Empty when turnstile isn't enabled. String displaying an html tag to display the Turnstile widget. Please add the `{{{turnstile}}}` tag to the `custom_html` template to ensure the Turnstile widget appears.\n25. `infiniteQueue`: Boolean indicating whether the response is for a user in the infinite queue.\n\nAn example cURL to a waiting room could be:\n\n\tcurl -X GET \"https://example.com/waitingroom\" \\\n\t\t-H \"Accept: application/json\"\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **fifo** and no event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 0,\n\t\t\t\"waitTime50Percentile\": 0,\n\t\t\t\"waitTime75Percentile\": 0,\n\t\t\t\"waitTimeFormatted\": \"10 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"fifo\",\n\t\t\t\"isFIFOQueue\": true,\n\t\t\t\"isRandomQueue\": false,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": false,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 0,\n\t\t\t\"timeUntilEventEndFormatted\": \"unavailable\",\n\t\t\t\"shuffleAtEventStart\": false\n\t\t}\n\t}\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **random** and an event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 5,\n\t\t\t\"waitTime50Percentile\": 10,\n\t\t\t\"waitTime75Percentile\": 15,\n\t\t\t\"waitTimeFormatted\": \"5 minutes to 15 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"random\",\n\t\t\t\"isFIFOQueue\": false,\n\t\t\t\"isRandomQueue\": true,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": true,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 15,\n\t\t\t\"timeUntilEventEndFormatted\": \"15 minutes\",\n\t\t\t\"shuffleAtEventStart\": true\n\t\t}\n\t}"},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."},{"name":"queue_all","type":"Bool","description":"If queue_all is `true`, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and estimated time will become unavailable."},{"name":"queueing_method","type":"String","description":"Sets the queueing method used by the waiting room. Changing this parameter from the **default** queueing method is only available for the Waiting Room Advanced subscription. Regardless of the queueing method, if `queue_all` is enabled or an event is prequeueing, users in the waiting room will not be accepted to the origin. These users will always see a waiting room page that refreshes automatically. The valid queueing methods are:\n1. `fifo` **(default)**: First-In-First-Out queue where customers gain access in the order they arrived.\n2. `random`: Random queue where customers gain access randomly, regardless of arrival time.\n3. `passthrough`: Users will pass directly through the waiting room and into the origin website. As a result, any configured limits will not be respected while this is enabled. This method can be used as an alternative to disabling a waiting room (with `suspended`) so that analytics are still reported. This can be used if you wish to allow all traffic normally, but want to restrict traffic during a waiting room event, or vice versa.\n4. `reject`: Users will be immediately rejected from the waiting room. As a result, no users will reach the origin website while this is enabled. This can be used if you wish to reject all traffic while performing maintenance, block traffic during a specified period of time (an event), or block traffic while events are not occurring. Consider a waiting room used for vaccine distribution that only allows traffic during sign-up events, and otherwise blocks all traffic. For this case, the waiting room uses `reject`, and its events override this with `fifo`, `random`, or `passthrough`. When this queueing method is enabled and neither `queueAll` is enabled nor an event is prequeueing, the waiting room page **will not refresh automatically**."},{"name":"queueing_status_code","type":"Int64","description":"HTTP status code returned to a user while in the queue."},{"name":"session_duration","type":"Int64","description":"Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they will be treated as a new user that visits the route."},{"name":"suspended","type":"Bool","description":"Suspends or allows traffic going to the waiting room. If set to `true`, the traffic will not go to the waiting room."},{"name":"turnstile_action","type":"String","description":"Which action to take when a bot is detected using Turnstile. `log` will\nhave no impact on queueing behavior, simply keeping track of how many\nbots are detected in Waiting Room Analytics. `infinite_queue` will send\nbots to a false queueing state, where they will never reach your\norigin. `infinite_queue` requires Advanced Waiting Room.\n"},{"name":"turnstile_mode","type":"String","description":"Which Turnstile widget type to use for detecting bot traffic. See\n[the Turnstile documentation](https://developers.cloudflare.com/turnstile/concepts/widget/#widget-types)\nfor the definitions of these widget types. Set to `off` to disable the\nTurnstile integration entirely. Setting this to anything other than\n`off` or `invisible` requires Advanced Waiting Room.\n"},{"name":"enabled_origin_commands","type":"List[String]","description":"A list of enabled origin commands."},{"name":"additional_routes","type":"List[Attributes]","description":"Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an implied wildcard at the end of the path. The hostname and path combination must be unique to this and all other waiting rooms.","children":[{"name":"host","type":"String","description":"The hostname to which this waiting room will be applied (no wildcards). The hostname must be the primary domain, subdomain, or custom hostname (if using SSL for SaaS) of this zone. Please do not include the scheme (http:// or https://)."},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."}]},{"name":"cookie_attributes","type":"Attributes","description":"Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.","children":[{"name":"samesite","type":"String","description":"Configures the SameSite attribute on the waiting room cookie. Value `auto` will be translated to `lax` or `none` depending if **Always Use HTTPS** is enabled. Note that when using value `none`, the secure attribute cannot be set to `never`."},{"name":"secure","type":"String","description":"Configures the Secure attribute on the waiting room cookie. Value `always` indicates that the Secure attribute will be set in the Set-Cookie header, `never` indicates that the Secure attribute will not be set, and `auto` will set the Secure attribute depending if **Always Use HTTPS** is enabled."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"},{"name":"next_event_prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will begin queueing."},{"name":"next_event_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will start."}]}]},"post /zones/{}/waiting_rooms/{}/events":{"operationId":"waiting-room-create-event","declarations":[{"kind":"resource","name":"cloudflare_waiting_room_event","stainlessResource":"waiting_rooms.events","methodName":"create","snippet":"resource \"cloudflare_waiting_room_event\" \"example_waiting_room_event\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n event_end_time = \"2021-09-28T17:00:00Z\"\n event_start_time = \"2021-09-28T15:30:00Z\"\n name = \"production_webinar_event\"\n custom_page_html = \"{{#waitTimeKnown}} {{waitTime}} mins {{/waitTimeKnown}} {{^waitTimeKnown}} Event is prequeueing / Queue all enabled {{/waitTimeKnown}}\"\n description = \"Production event - DO NOT MODIFY\"\n disable_session_renewal = true\n new_users_per_minute = 200\n prequeue_start_time = \"2021-09-28T15:00:00Z\"\n queueing_method = \"random\"\n session_duration = 1\n shuffle_at_event_start = true\n suspended = true\n total_active_users = 200\n turnstile_action = \"log\"\n turnstile_mode = \"off\"\n}\n","required":[{"name":"waiting_room_id","type":"String","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"event_end_time","type":"String","description":"An ISO 8601 timestamp that marks the end of the event."},{"name":"event_start_time","type":"String","description":"An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`."},{"name":"name","type":"String","description":"A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed."}],"optional":[{"name":"custom_page_html","type":"String","description":"If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it."},{"name":"disable_session_renewal","type":"Bool","description":"If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it."},{"name":"new_users_per_minute","type":"Int64","description":"If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set."},{"name":"prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`."},{"name":"queueing_method","type":"String","description":"If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it."},{"name":"session_duration","type":"Int64","description":"If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it."},{"name":"total_active_users","type":"Int64","description":"If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set."},{"name":"turnstile_action","type":"String","description":"If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it."},{"name":"turnstile_mode","type":"String","description":"If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it."},{"name":"description","type":"String","description":"A note that you can use to add more details about the event."},{"name":"shuffle_at_event_start","type":"Bool","description":"If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary."},{"name":"suspended","type":"Bool","description":"Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration."}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]},"post /zones/{}/web3/hostnames":{"operationId":"web3-hostname-create-web3-hostname","declarations":[{"kind":"resource","name":"cloudflare_web3_hostname","stainlessResource":"web3.hostnames","methodName":"create","snippet":"resource \"cloudflare_web3_hostname\" \"example_web3_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"gateway.example.com\"\n target = \"ipfs\"\n description = \"This is my IPFS gateway.\"\n dnslink = \"/ipns/onboarding.ipfs.cloudflare.com\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the identifier of the hostname.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the hostname that points to the target gateway via CNAME.","requiresReplace":true},{"name":"target","type":"String","description":"Specify the target gateway of the hostname.","requiresReplace":true}],"optional":[{"name":"description","type":"String","description":"Specify an optional description of the hostname."},{"name":"dnslink","type":"String","description":"Specify the DNSLink value used if the target is ipfs."}],"computed":[{"name":"id","type":"String","description":"Specify the identifier of the hostname."},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"},{"name":"status","type":"String","description":"Specifies the status of the hostname's activation."}]}]},"post /zones/{}/workers/routes":{"operationId":"worker-routes-create-route","declarations":[{"kind":"resource","name":"cloudflare_workers_route","stainlessResource":"workers.routes","methodName":"create","snippet":"resource \"cloudflare_workers_route\" \"example_workers_route\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pattern = \"example.com/*\"\n script = \"my-workers-script\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."}],"optional":[{"name":"script","type":"String","description":"Name of the script to run if the route matches."}],"computed":[{"name":"id","type":"String","description":"Identifier."}]}]},"put /accounts/{}/access/keys":{"operationId":"access-key-configuration-update-the-access-key-configuration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_key_configuration","stainlessResource":"zero_trust.access.keys","methodName":"update","snippet":"resource \"cloudflare_zero_trust_access_key_configuration\" \"example_zero_trust_access_key_configuration\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n key_rotation_interval_days = 30\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"key_rotation_interval_days","type":"Float64","description":"The number of days between key rotations."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"days_until_next_rotation","type":"Float64","description":"The number of days until the next key rotation."},{"name":"last_key_rotation_at","type":"Time","description":"The timestamp of the previous key rotation."}]}]},"put /accounts/{}/cfd_tunnel/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-put-configuration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared_config","stainlessResource":"zero_trust.tunnels.cloudflared.configurations","methodName":"update","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared_config\" \"example_zero_trust_tunnel_cloudflared_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n config = {\n ingress = [{\n hostname = \"tunnel.example.com\"\n service = \"https://localhost:8001\"\n origin_request = {\n access = {\n aud_tag = [\"string\"]\n team_name = \"zero-trust-organization-name\"\n required = false\n }\n ca_pool = \"caPool\"\n connect_timeout = 10\n disable_chunked_encoding = true\n http2_origin = true\n http_host_header = \"httpHostHeader\"\n keep_alive_connections = 100\n keep_alive_timeout = 90\n match_sn_ito_host = false\n no_happy_eyeballs = false\n no_tls_verify = false\n origin_server_name = \"originServerName\"\n proxy_type = \"proxyType\"\n tcp_keep_alive = 30\n tls_timeout = 10\n }\n path = \"subpath\"\n }]\n origin_request = {\n access = {\n aud_tag = [\"string\"]\n team_name = \"zero-trust-organization-name\"\n required = false\n }\n ca_pool = \"caPool\"\n connect_timeout = 10\n disable_chunked_encoding = true\n http2_origin = true\n http_host_header = \"httpHostHeader\"\n keep_alive_connections = 100\n keep_alive_timeout = 90\n match_sn_ito_host = false\n no_happy_eyeballs = false\n no_tls_verify = false\n origin_server_name = \"originServerName\"\n proxy_type = \"proxyType\"\n tcp_keep_alive = 30\n tls_timeout = 10\n }\n }\n}\n","required":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"config","type":"Attributes","description":"The tunnel configuration and ingress rules.","children":[{"name":"ingress","type":"List[Attributes]","description":"List of public hostname definitions. At least one ingress rule needs to be defined for the tunnel.","children":[{"name":"hostname","type":"String","description":"Public hostname for this service."},{"name":"service","type":"String","description":"Protocol and address of destination server. Supported protocols: http://, https://, unix://, tcp://, ssh://, rdp://, unix+tls://, smb://. Alternatively can return a HTTP status code http_status:[code] e.g. 'http_status:404'.\n"},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"path","type":"String","description":"Requests with this path route to this public hostname."}]},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"warp_routing","type":"Attributes","description":"Enable private network access from WARP users to private network routes. This is enabled if the tunnel has an assigned route.","deprecated":"This field is ignored by cloudflared since version 2023.10.0.","children":[{"name":"enabled","type":"Bool"}]}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"created_at","type":"Time"},{"name":"source","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel's configuration on the Zero Trust dashboard."},{"name":"version","type":"Int64","description":"The version of the Tunnel Configuration."}]}]},"put /accounts/{}/devices/policy/{}/fallback_domains":{"operationId":"devices-set-local-domain-fallback-list-for-a-device-settings-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_custom_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.custom.fallback_domains","methodName":"update","snippet":"resource \"cloudflare_zero_trust_device_custom_profile_local_domain_fallback\" \"example_zero_trust_device_custom_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n domains = [{\n suffix = \"example.com\"\n description = \"Domain bypass for local development\"\n dns_server = [\"1.1.1.1\"]\n }]\n}\n","required":[{"name":"policy_id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/devices/policy/fallback_domains":{"operationId":"devices-set-local-domain-fallback-list","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_default_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.default.fallback_domains","methodName":"update","snippet":"resource \"cloudflare_zero_trust_device_default_profile_local_domain_fallback\" \"example_zero_trust_device_default_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n domains = [{\n suffix = \"example.com\"\n description = \"Domain bypass for local development\"\n dns_server = [\"1.1.1.1\"]\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/devices/settings":{"operationId":"zero-trust-accounts-update-device-settings-for-the-zero-trust-account","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_settings","stainlessResource":"zero_trust.devices.settings","methodName":"update","snippet":"resource \"cloudflare_zero_trust_device_settings\" \"example_zero_trust_device_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n disable_for_time = 0\n external_emergency_signal_enabled = true\n external_emergency_signal_fingerprint = \"abcd1234567890abcd1234567890abcd1234567890abcd1234567890abcd1234\"\n external_emergency_signal_interval = \"5m\"\n external_emergency_signal_url = \"https://192.0.2.1/signal\"\n gateway_proxy_enabled = true\n gateway_udp_proxy_enabled = true\n root_certificate_installation_enabled = true\n use_zt_virtual_ip = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"disable_for_time","type":"Float64","description":"Sets the time limit, in seconds, that a user can use an override code to bypass WARP."},{"name":"external_emergency_signal_enabled","type":"Bool","description":"Controls whether the external emergency disconnect feature is enabled."},{"name":"external_emergency_signal_fingerprint","type":"String","description":"The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external_emergency_signal_url. If provided, the WARP client will use this value to verify the server's identity. The device will ignore any response if the server's certificate fingerprint does not exactly match this value."},{"name":"external_emergency_signal_interval","type":"String","description":"The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., \"5m\", \"2m30s\", \"1h\"). Minimum 30 seconds."},{"name":"external_emergency_signal_url","type":"String","description":"The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host."},{"name":"gateway_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on TCP."},{"name":"gateway_udp_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on UDP."},{"name":"root_certificate_installation_enabled","type":"Bool","description":"Enable installation of cloudflare managed root certificate."},{"name":"use_zt_virtual_ip","type":"Bool","description":"Enable using CGNAT virtual IPv4."}],"computed":[]}]},"put /accounts/{}/dlp/profiles/predefined/{}/config":{"operationId":"dlp-profiles-update-predefined-profile-config","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_predefined_profile","stainlessResource":"zero_trust.dlp.profiles.predefined","methodName":"update","snippet":"resource \"cloudflare_zero_trust_dlp_predefined_profile\" \"example_zero_trust_dlp_predefined_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n ai_context_enabled = true\n allowed_match_count = 5\n confidence_threshold = \"confidence_threshold\"\n enabled_entries = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n entries = [{\n id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n enabled = true\n }]\n ocr_enabled = true\n}\n","required":[{"name":"profile_id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"enabled_entries","type":"List[String]"},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64"},{"name":"confidence_threshold","type":"String"},{"name":"ocr_enabled","type":"Bool"},{"name":"entries","type":"List[Attributes]","deprecated":"Deprecated.","children":[{"name":"id","type":"String"},{"name":"enabled","type":"Bool"}]}],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the predefined profile."},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."}]}]},"put /accounts/{}/dlp/sensitivity_groups/{}/level_order":{"operationId":"dlp-sensitivity-groups-put-level-order","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_sensitivity_level_order","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels.order","methodName":"update","snippet":"resource \"cloudflare_zero_trust_dlp_sensitivity_level_order\" \"example_zero_trust_dlp_sensitivity_level_order\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_ids = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n}\n","required":[{"name":"sensitivity_group_id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"level_ids","type":"List[String]"}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/dlp/settings":{"operationId":"dlp-settings-update","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_settings","stainlessResource":"zero_trust.dlp.settings","methodName":"update","snippet":"resource \"cloudflare_zero_trust_dlp_settings\" \"example_zero_trust_dlp_settings\" {\n account_id = \"account_id\"\n ai_context_analysis = true\n ocr = true\n payload_logging = {\n masking_level = \"full\"\n public_key = \"public_key\"\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"ai_context_analysis","type":"Bool","description":"Whether AI context analysis is enabled at the account level."},{"name":"ocr","type":"Bool","description":"Whether OCR is enabled at the account level."},{"name":"payload_logging","type":"Attributes","description":"Request model for payload log settings within the DLP settings endpoint.\nUnlike the legacy endpoint, null and missing are treated identically here\n(both mean \"not provided\" for PATCH, \"reset to default\" for PUT).","children":[{"name":"masking_level","type":"String","description":"Masking level for payload logs.\n\n- `full`: The entire payload is masked.\n- `partial`: Only partial payload content is masked.\n- `clear`: No masking is applied to the payload content.\n- `default`: DLP uses its default masking behavior."},{"name":"public_key","type":"String","description":"Base64-encoded public key for encrypting payload logs.\n\n- Set to a non-empty base64 string to enable payload logging with the given key.\n- Set to an empty string to disable payload logging.\n- Omit or set to null to leave unchanged (PATCH) or reset to disabled (PUT)."}]}],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/event_notifications/r2/{}/configuration/queues/{}":{"operationId":"r2-put-event-notification-config","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_event_notification","stainlessResource":"r2.buckets.event_notifications","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_event_notification\" \"example_r2_bucket_event_notification\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n queue_id = \"queue_id\"\n rules = [{\n actions = [\"PutObject\", \"CopyObject\"]\n description = \"Notifications from source bucket to queue\"\n prefix = \"img/\"\n suffix = \".jpeg\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"queue_id","type":"String","description":"ID of the Cloudflare Queue that receives notifications for matching R2 object events.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","description":"Array of rules to drive notifications.","children":[{"name":"actions","type":"List[String]","description":"Array of R2 object actions that will trigger notifications."},{"name":"description","type":"String","description":"A description that can be used to identify the event notification rule after creation."},{"name":"prefix","type":"String","description":"Notifications will be sent only for objects with this prefix."},{"name":"suffix","type":"String","description":"Notifications will be sent only for objects with this suffix."}]}],"optional":[],"computed":[{"name":"queue_name","type":"String","description":"Name of the queue."}]}]},"put /accounts/{}/field_extractors/{}":{"operationId":"updateFieldExtractor","declarations":[{"kind":"resource","name":"cloudflare_field_extractor","stainlessResource":"field_extractors","methodName":"update","snippet":"resource \"cloudflare_field_extractor\" \"example_field_extractor\" {\n account_id = \"123456\"\n extractor = \"llm_prompts\"\n rules = [{\n fields = [{\n expression = \"x\"\n name = \"x\"\n }]\n ref = \"x\"\n description = \"description\"\n }]\n}\n","required":[{"name":"extractor","type":"String","description":"Extractor type.","requiresReplace":true},{"name":"account_id","type":"String","description":"Cloudflare account ID.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"expression","type":"String"},{"name":"name","type":"String"}]},{"name":"ref","type":"String"},{"name":"description","type":"String"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Extractor type.","requiresReplace":true}]}]},"put /accounts/{}/gateway/configuration":{"operationId":"zero-trust-accounts-update-zero-trust-account-configuration.","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_settings","stainlessResource":"zero_trust.gateway.configurations","methodName":"update","snippet":"resource \"cloudflare_zero_trust_gateway_settings\" \"example_zero_trust_gateway_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n settings = {\n activity_log = {\n enabled = true\n }\n antivirus = {\n enabled_download_phase = false\n enabled_upload_phase = false\n fail_closed = false\n notification_settings = {\n enabled = true\n include_context = true\n msg = \"msg\"\n support_url = \"support_url\"\n }\n }\n block_page = {\n background_color = \"background_color\"\n enabled = true\n footer_text = \"--footer--\"\n header_text = \"--header--\"\n include_context = true\n logo_path = \"https://logos.com/a.png\"\n mailto_address = \"admin@example.com\"\n mailto_subject = \"Blocked User Inquiry\"\n mode = \"\"\n name = \"Cloudflare\"\n suppress_footer = false\n target_uri = \"https://example.com\"\n }\n body_scanning = {\n inspection_mode = \"deep\"\n }\n browser_isolation = {\n non_identity_enabled = true\n url_browser_isolation_enabled = true\n }\n certificate = {\n id = \"d1b364c5-1311-466e-a194-f0e943e0799f\"\n }\n custom_certificate = {\n enabled = true\n id = \"d1b364c5-1311-466e-a194-f0e943e0799f\"\n }\n extended_email_matching = {\n enabled = true\n }\n fips = {\n tls = true\n }\n host_selector = {\n enabled = false\n }\n inspection = {\n mode = \"static\"\n }\n max_ttl_secs = 3600\n protocol_detection = {\n enabled = true\n }\n sandbox = {\n enabled = true\n fallback_action = \"allow\"\n }\n tls_decrypt = {\n enabled = true\n }\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}],"optional":[{"name":"settings","type":"Attributes","description":"Specify account settings.","children":[{"name":"activity_log","type":"Attributes","description":"Specify activity log settings.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to log activity."}]},{"name":"antivirus","type":"Attributes","description":"Specify anti-virus settings.","children":[{"name":"enabled_download_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on downloads."},{"name":"enabled_upload_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on uploads."},{"name":"fail_closed","type":"Bool","description":"Specify whether to block requests for unscannable files."},{"name":"notification_settings","type":"Attributes","description":"Configure the message the user's device shows during an antivirus scan.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable notifications."},{"name":"include_context","type":"Bool","description":"Specify whether to include context information as query parameters."},{"name":"msg","type":"String","description":"Specify the message to show in the notification."},{"name":"support_url","type":"String","description":"Specify a URL that directs users to more information. If unset, the notification opens a block page."}]}]},{"name":"block_page","type":"Attributes","description":"Specify block page layout settings.","children":[{"name":"background_color","type":"String","description":"Specify the block page background color in `#rrggbb` format when the mode is customized_block_page."},{"name":"enabled","type":"Bool","description":"Specify whether to enable the custom block page."},{"name":"footer_text","type":"String","description":"Specify the block page footer text when the mode is customized_block_page."},{"name":"header_text","type":"String","description":"Specify the block page header text when the mode is customized_block_page."},{"name":"include_context","type":"Bool","description":"Specify whether to append context to target_uri as query parameters. This applies only when the mode is redirect_uri."},{"name":"logo_path","type":"String","description":"Specify the full URL to the logo file when the mode is customized_block_page."},{"name":"mailto_address","type":"String","description":"Specify the admin email for users to contact when the mode is customized_block_page."},{"name":"mailto_subject","type":"String","description":"Specify the subject line for emails created from the block page when the mode is customized_block_page."},{"name":"mode","type":"String","description":"Specify whether to redirect users to a Cloudflare-hosted block page or a customer-provided URI."},{"name":"name","type":"String","description":"Specify the block page title when the mode is customized_block_page."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"suppress_footer","type":"Bool","description":"Specify whether to suppress detailed information at the bottom of the block page when the mode is customized_block_page."},{"name":"target_uri","type":"String","description":"Specify the URI to redirect users to when the mode is redirect_uri."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"body_scanning","type":"Attributes","description":"Specify the DLP inspection mode.","children":[{"name":"inspection_mode","type":"String","description":"Specify the inspection mode as either `deep` or `shallow`."}]},{"name":"browser_isolation","type":"Attributes","description":"Specify Clientless Browser Isolation settings.","children":[{"name":"non_identity_enabled","type":"Bool","description":"Specify whether to enable non-identity onramp support for Browser Isolation."},{"name":"url_browser_isolation_enabled","type":"Bool","description":"Specify whether to enable Clientless Browser Isolation."}]},{"name":"certificate","type":"Attributes","description":"Specify certificate settings for Gateway TLS interception. If unset, the Cloudflare Root CA handles interception.","children":[{"name":"id","type":"String","description":"Specify the UUID of the certificate used for interception. Ensure the certificate is available at the edge(previously called 'active'). A nil UUID directs Cloudflare to use the Root CA."}]},{"name":"custom_certificate","type":"Attributes","description":"Specify custom certificate settings for BYO-PKI. This field is deprecated; use `certificate` instead.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable a custom certificate authority for signing Gateway traffic."},{"name":"id","type":"String","description":"Specify the UUID of the certificate (ID from MTLS certificate store)."},{"name":"binding_status","type":"String","description":"Indicate the internal certificate status."},{"name":"updated_at","type":"Time"}]},{"name":"extended_email_matching","type":"Attributes","description":"Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses `.` or `+` modifiers.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to match all variants of user emails (with + or . modifiers) used as criteria in Firewall policies."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"fips","type":"Attributes","description":"Specify FIPS settings.","children":[{"name":"tls","type":"Bool","description":"Enforce cipher suites and TLS versions compliant with FIPS 140-2."}]},{"name":"host_selector","type":"Attributes","description":"Enable host selection in egress policies.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable filtering via hosts for egress policies."}]},{"name":"inspection","type":"Attributes","description":"Define the proxy inspection mode.","children":[{"name":"mode","type":"String","description":"Define the proxy inspection mode. 1. static: Gateway applies static inspection to HTTP on TCP(80). With TLS decryption on, Gateway inspects HTTPS traffic on TCP(443) and UDP(443). 2. dynamic: Gateway applies protocol detection to inspect HTTP and HTTPS traffic on any port. TLS decryption must remain on to inspect HTTPS traffic."}]},{"name":"max_ttl_secs","type":"Int64","description":"Account-level cap on DNS response TTLs, in seconds. Gateway rewrites DNS responses so returned record TTLs do not exceed this value. Null means no cap. Each DNS location can inherit, override, or disable it through the location `max_ttl` setting."},{"name":"protocol_detection","type":"Attributes","description":"Specify whether to detect protocols from the initial bytes of client traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to detect protocols from the initial bytes of client traffic."}]},{"name":"sandbox","type":"Attributes","description":"Specify whether to enable the sandbox.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable the sandbox."},{"name":"fallback_action","type":"String","description":"Specify the action to take when the system cannot scan the file."}]},{"name":"tls_decrypt","type":"Attributes","description":"Specify whether to inspect encrypted HTTP traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to inspect encrypted HTTP traffic."}]}]}],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"put /accounts/{}/gateway/logging":{"operationId":"zero-trust-accounts-update-logging-settings-for-the-zero-trust-account","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_logging","stainlessResource":"zero_trust.gateway.logging","methodName":"update","snippet":"resource \"cloudflare_zero_trust_gateway_logging\" \"example_zero_trust_gateway_logging\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n redact_pii = true\n settings_by_rule_type = {\n dns = {\n log_all = false\n log_blocks = true\n }\n http = {\n log_all = false\n log_blocks = true\n }\n l4 = {\n log_all = false\n log_blocks = true\n }\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}],"optional":[{"name":"redact_pii","type":"Bool","description":"Indicate whether to redact personally identifiable information from activity logging (PII fields include source IP, user email, user ID, device ID, URL, referrer, and user agent)."},{"name":"settings_by_rule_type","type":"Attributes","description":"Configure logging settings for each rule type.","children":[{"name":"dns","type":"Attributes","description":"Configure logging settings for DNS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"http","type":"Attributes","description":"Configure logging settings for HTTP/HTTPS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"l4","type":"Attributes","description":"Configure logging settings for Network firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]}]}],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}]}]},"put /accounts/{}/r2/buckets/{}/cors":{"operationId":"r2-put-bucket-cors-policy","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_cors","stainlessResource":"r2.buckets.cors","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_cors\" \"example_r2_bucket_cors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n allowed = {\n methods = [\"GET\"]\n origins = [\"http://localhost:3000\"]\n headers = [\"x-requested-by\"]\n }\n id = \"Allow Local Development\"\n expose_headers = [\"Content-Encoding\"]\n max_age_seconds = 3600\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"rules","type":"List[Attributes]","children":[{"name":"allowed","type":"Attributes","description":"Object specifying allowed origins, methods and headers for this CORS rule.","children":[{"name":"methods","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Methods header R2 sets when requesting objects in a bucket from a browser."},{"name":"origins","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Origin header R2 sets when requesting objects in a bucket from a browser."},{"name":"headers","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Headers header R2 sets when requesting objects in this bucket from a browser. Cross-origin requests that include custom headers (e.g. x-user-id) should specify these headers as AllowedHeaders."}]},{"name":"id","type":"String","description":"Identifier for this rule."},{"name":"expose_headers","type":"List[String]","description":"Specifies the headers that can be exposed back, and accessed by, the JavaScript making the cross-origin request. If you need to access headers beyond the safelisted response headers, such as Content-Encoding or cf-cache-status, you must specify it here."},{"name":"max_age_seconds","type":"Float64","description":"Specifies the amount of time (in seconds) browsers are allowed to cache CORS preflight responses. Browsers may limit this to 2 hours or less, even if the maximum value (86400) is specified."}]}],"computed":[]}]},"put /accounts/{}/r2/buckets/{}/domains/managed":{"operationId":"r2-put-bucket-public-policy","declarations":[{"kind":"resource","name":"cloudflare_r2_managed_domain","stainlessResource":"r2.buckets.domains.managed","methodName":"update","snippet":"resource \"cloudflare_r2_managed_domain\" \"example_r2_managed_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n enabled = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether to enable public bucket access at the r2.dev domain."}],"optional":[],"computed":[{"name":"bucket_id","type":"String","description":"Bucket ID."},{"name":"domain","type":"String","description":"Domain name of the bucket's r2.dev domain."}]}]},"put /accounts/{}/r2/buckets/{}/lifecycle":{"operationId":"r2-put-bucket-lifecycle-configuration","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_lifecycle","stainlessResource":"r2.buckets.lifecycle","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_lifecycle\" \"example_r2_bucket_lifecycle\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n id = \"Expire all objects older than 24 hours\"\n conditions = {\n prefix = \"prefix\"\n }\n enabled = true\n abort_multipart_uploads_transition = {\n condition = {\n max_age = 0\n type = \"Age\"\n }\n }\n delete_objects_transition = {\n condition = {\n max_age = 0\n type = \"Age\"\n }\n }\n storage_class_transitions = [{\n condition = {\n max_age = 0\n type = \"Age\"\n }\n storage_class = \"InfrequentAccess\"\n }]\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"conditions","type":"Attributes","description":"Conditions that apply to all transitions of this rule.","children":[{"name":"prefix","type":"String","description":"Transitions will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"abort_multipart_uploads_transition","type":"Attributes","description":"Transition to abort ongoing multipart uploads.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"}]}]},{"name":"delete_objects_transition","type":"Attributes","description":"Transition to delete objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]}]},{"name":"storage_class_transitions","type":"List[Attributes]","description":"Transitions to change the storage class of objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"storage_class","type":"String"}]}]}],"computed":[]}]},"put /accounts/{}/r2/buckets/{}/lock":{"operationId":"r2-put-bucket-lock-configuration","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_lock","stainlessResource":"r2.buckets.locks","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_lock\" \"example_r2_bucket_lock\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n id = \"Lock all objects for 24 hours\"\n condition = {\n max_age_seconds = 100\n type = \"Age\"\n }\n enabled = true\n prefix = \"prefix\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"condition","type":"Attributes","description":"Condition to apply a lock rule to an object for how long in seconds.","children":[{"name":"max_age_seconds","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"prefix","type":"String","description":"Rule will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]}],"computed":[]}]},"put /accounts/{}/r2/buckets/{}/sippy":{"operationId":"r2-put-bucket-sippy-config","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_sippy","stainlessResource":"r2.buckets.sippy","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_sippy\" \"example_r2_bucket_sippy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n destination = {\n access_key_id = \"accessKeyId\"\n r2_bucket_sippy_provider = \"r2\"\n secret_access_key = \"secretAccessKey\"\n }\n source = {\n access_key_id = \"accessKeyId\"\n bucket = \"bucket\"\n r2_bucket_sippy_provider = \"aws\"\n region = \"region\"\n secret_access_key = \"secretAccessKey\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"destination","type":"Attributes","description":"R2 bucket to copy objects to.","children":[{"name":"access_key_id","type":"String","description":"ID of a Cloudflare API token.\nThis is the value labelled \"Access Key ID\" when creating an API.\ntoken from the [R2 dashboard](https://dash.cloudflare.com/?to=/:account/r2/api-tokens).\n\nSippy will use this token when writing objects to R2, so it is\nbest to scope this token to the bucket you're enabling Sippy for.\n"},{"name":"r2_bucket_sippy_provider","type":"String"},{"name":"secret_access_key","type":"String","description":"Value of a Cloudflare API token.\nThis is the value labelled \"Secret Access Key\" when creating an API.\ntoken from the [R2 dashboard](https://dash.cloudflare.com/?to=/:account/r2/api-tokens).\n\nSippy will use this token when writing objects to R2, so it is\nbest to scope this token to the bucket you're enabling Sippy for.\n","sensitive":true}]},{"name":"source","type":"Attributes","description":"AWS S3 bucket to copy objects from.","children":[{"name":"access_key_id","type":"String","description":"Access Key ID of an IAM credential (ideally scoped to a single S3 bucket)."},{"name":"bucket","type":"String","description":"Name of the AWS S3 bucket."},{"name":"r2_bucket_sippy_provider","type":"String"},{"name":"region","type":"String","description":"AWS region containing the source S3 bucket."},{"name":"secret_access_key","type":"String","description":"Secret Access Key of an IAM credential (ideally scoped to a single S3 bucket).","sensitive":true},{"name":"client_email","type":"String","description":"Client email of an IAM credential (ideally scoped to a single GCS bucket)."},{"name":"private_key","type":"String","description":"Private Key of an IAM credential (ideally scoped to a single GCS bucket).","sensitive":true},{"name":"bucket_url","type":"String","description":"URL to the S3-compatible API of the bucket."},{"name":"account_key","type":"String","description":"Access key for the Azure Storage account. Mutually exclusive with sasToken.","sensitive":true},{"name":"account_name","type":"String","description":"Name of the Azure Storage account."},{"name":"container","type":"String","description":"Name of the Azure Blob Storage container."},{"name":"sas_token","type":"String","description":"Shared Access Signature token for the Azure Storage account. Mutually exclusive with accountKey.","sensitive":true}]}],"computed":[{"name":"enabled","type":"Bool","description":"State of Sippy for this bucket."}]}]},"put /accounts/{}/registrar/domains/{}":{"operationId":"registrar-domains-update-domain","declarations":[{"kind":"resource","name":"cloudflare_registrar_domain","stainlessResource":"registrar.domains","methodName":"update","snippet":"resource \"cloudflare_registrar_domain\" \"example_registrar_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_name = \"example.com\"\n auto_renew = true\n locked = false\n privacy = true\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"domain_name","type":"String","description":"Provides a fully qualified domain name (FQDN), including the extension\n(e.g., `example.com`, `mybrand.app`). The domain name uniquely identifies\na registration. Cloudflare permits only one registration per domain, making\nthe domain name a natural idempotency key for registration requests.\n","requiresReplace":true}],"optional":[{"name":"auto_renew","type":"Bool","description":"Auto-renew controls whether subscription is automatically renewed upon domain expiration."},{"name":"locked","type":"Bool","description":"Shows whether a registrar lock is in place for a domain."},{"name":"privacy","type":"Bool","description":"Privacy option controls redacting WHOIS information."}],"computed":[]}]},"put /accounts/{}/storage/kv/namespaces/{}/values/{}":{"operationId":"workers-kv-namespace-write-key-value-pair-with-metadata","declarations":[{"kind":"resource","name":"cloudflare_workers_kv","stainlessResource":"kv.namespaces.values","methodName":"update","snippet":"resource \"cloudflare_workers_kv\" \"example_workers_kv\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n key_name = \"My-Key\"\n value = \"Some Value\"\n metadata = {\n\n }\n}\n","required":[{"name":"key_name","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL.","requiresReplace":true},{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces.","requiresReplace":true},{"name":"namespace_id","type":"String","description":"ID of the Workers KV namespace.","requiresReplace":true},{"name":"value","type":"String","description":"A byte sequence to be stored, up to 25 MiB in length."}],"optional":[{"name":"metadata","type":"unknown","description":"Associates arbitrary JSON data with a key/value pair."}],"computed":[{"name":"id","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL.","requiresReplace":true}]}]},"put /accounts/{}/stream/webhook":{"operationId":"stream-webhook-create-webhooks","declarations":[{"kind":"resource","name":"cloudflare_stream_webhook","stainlessResource":"stream.webhooks","methodName":"update","snippet":"resource \"cloudflare_stream_webhook\" \"example_stream_webhook\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n notification_url = \"https://example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"notification_url","type":"String","description":"The URL where webhooks will be sent."}],"computed":[{"name":"modified","type":"Time","description":"The date and time the webhook was last modified."},{"name":"secret","type":"String","description":"The secret used to verify webhook signatures.","sensitive":true}]}]},"put /accounts/{}/warp_connector/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-update-warp-connector-configuration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_warp_connector_config","stainlessResource":"zero_trust.tunnels.warp_connector.configurations","methodName":"update","snippet":"resource \"cloudflare_zero_trust_tunnel_warp_connector_config\" \"example_zero_trust_tunnel_warp_connector_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n ha_mode = \"aws\"\n config = {\n fnr_id = \"eni-0123456789abcdef0\"\n }\n}\n","required":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"ha_mode","type":"String","description":"High-availability mode for the Mesh node. `none` means HA is enabled but no provider is configured yet (newly created nodes default to this). `disabled` means HA is explicitly turned off. `aws` uses AWS ENI move for failover. `local` uses virtual IPs (VIPs) on the local interface."}],"optional":[{"name":"config","type":"Attributes","description":"Provider-specific configuration. Required shape depends on ha_mode. For `aws`, must contain `fnr_id`. For `local`, must contain `vips`. For `none` and `disabled`, must be empty or omitted.","children":[{"name":"fnr_id","type":"String","description":"Floating Network Resource ID — the secondary ENI that is moved between nodes on failover."},{"name":"vips","type":"List[Attributes]","description":"VIPs to assign on the CloudflareWARP interface.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]},{"name":"vips_previous","type":"List[Attributes]","description":"VIPs to clean up on demotion or version drift.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"configuration_version","type":"Int64","description":"Monotonically increasing configuration version, incremented on each PUT."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"updated_at","type":"Time","description":"Timestamp of the last update. Null if never updated."}]}]},"put /accounts/{}/workers/domains":{"operationId":"workers.domains.update","declarations":[{"kind":"resource","name":"cloudflare_workers_custom_domain","stainlessResource":"workers.domains","methodName":"update","snippet":"resource \"cloudflare_workers_custom_domain\" \"example_workers_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"app.example.com\"\n service = \"my-worker\"\n zone_id = \"593c9c94de529bbbfaac7c53ced0447d\"\n zone_name = \"example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"hostname","type":"String","description":"Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker.","requiresReplace":true},{"name":"service","type":"String","description":"Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker.","requiresReplace":true}],"optional":[{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname.","requiresReplace":true},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Immutable ID of the domain.","requiresReplace":true},{"name":"cert_id","type":"String","description":"ID of the TLS certificate issued for the domain."},{"name":"environment","type":"String","description":"Worker environment associated with the domain.","deprecated":"Deprecated."}]}]},"put /accounts/{}/workers/scripts/{}":{"operationId":"worker-script-upload-worker-module","declarations":[{"kind":"resource","name":"cloudflare_workers_script","stainlessResource":"workers.scripts","methodName":"update","snippet":"resource \"cloudflare_workers_script\" \"example_workers_script\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n metadata = {\n annotations = {\n workers_message = \"Fixed bug.\"\n workers_tag = \"v1.0.1\"\n }\n assets = {\n config = {\n headers = <Possible Content-Type(s) are: `application/javascript+module`, `text/javascript+module`, `application/javascript`, `text/javascript`, `text/x-python`, `text/x-python-requirement`, `application/wasm`, `text/plain`, `application/octet-stream`, `application/source-map`."}],"computed":[{"name":"id","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"entry_point","type":"String","description":"The entry point for the script."},{"name":"etag","type":"String","description":"Hashed script content, can be used in a If-None-Match header when updating."},{"name":"has_assets","type":"Bool","description":"Whether a Worker contains assets."},{"name":"has_modules","type":"Bool","description":"Whether a Worker contains modules."},{"name":"last_deployed_from","type":"String","description":"The client most recently used to deploy this Worker."},{"name":"logpush","type":"Bool","description":"Whether Logpush is turned on for the Worker."},{"name":"migration_tag","type":"String","description":"The tag of the Durable Object migration that was most recently applied for this Worker."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"placement_mode","type":"String","deprecated":"Deprecated."},{"name":"placement_status","type":"String","deprecated":"Deprecated."},{"name":"startup_time_ms","type":"Int64"},{"name":"tag","type":"String","description":"The immutable ID of the script."},{"name":"usage_model","type":"String","description":"Usage model for the Worker invocations."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the default export."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the Worker's most recent version,\nincluding Durable Object classes (with their `storage`\nbackend) and named Worker entrypoints. Tombstoned lifecycle\nentries are omitted, so only live exports (`created` and\n`expecting-transfer`) are returned.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"named_handlers","type":"List[Attributes]","description":"Named exports, such as Durable Object class implementations and named entrypoints.","children":[{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the named export."},{"name":"name","type":"String","description":"The name of the export."}]},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for incoming requests. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"last_analyzed_at","type":"Time","description":"The last time the script was analyzed for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"status","type":"String","description":"Status of [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"List of Workers that will consume logs from the attached Worker.","children":[{"name":"service","type":"String","description":"Name of Worker that is to be the consumer."},{"name":"environment","type":"String","description":"Optional environment if the Worker utilizes one."},{"name":"namespace","type":"String","description":"Optional dispatch namespace the script belongs to."}]}]}]},"put /accounts/{}/workers/scripts/{}/schedules":{"operationId":"worker-cron-trigger-update-cron-triggers","declarations":[{"kind":"resource","name":"cloudflare_workers_cron_trigger","stainlessResource":"workers.scripts.schedules","methodName":"update","snippet":"resource \"cloudflare_workers_cron_trigger\" \"example_workers_cron_trigger\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n body = [{\n cron = \"*/30 * * * *\"\n }]\n}\n","required":[{"name":"script_name","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"body","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}]}]},"put /accounts/{}/workflows/{}":{"operationId":"wor-create-or-modify-workflow","declarations":[{"kind":"resource","name":"cloudflare_workflow","stainlessResource":"workflows","methodName":"update","snippet":"resource \"cloudflare_workflow\" \"example_workflow\" {\n account_id = \"account_id\"\n workflow_name = \"x\"\n class_name = \"x\"\n script_name = \"x\"\n concurrency = {\n limit = 1\n }\n default_retention = {\n error_retention = \"5 minutes\"\n success_retention = \"5 minutes\"\n }\n limits = {\n steps = 1\n }\n schedules = [{\n cron = \"x\"\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"workflow_name","type":"String","requiresReplace":true},{"name":"class_name","type":"String"},{"name":"script_name","type":"String"}],"optional":[{"name":"concurrency","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Maximum number of instances of this workflow that can run concurrently. Additional instances are queued and started as running instances complete. Must not exceed the account concurrency limit."}]},{"name":"default_retention","type":"Attributes","description":"Default retention applied to instances of this version when they do not set their own retention.","children":[{"name":"error_retention","type":"Dynamic Int64 | String","description":"Specifies the duration in milliseconds or as a string like '5 minutes'."},{"name":"success_retention","type":"Dynamic Int64 | String","description":"Specifies the duration in milliseconds or as a string like '5 minutes'."}]},{"name":"limits","type":"Attributes","children":[{"name":"steps","type":"Int64"}]},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"name","type":"String"},{"name":"created_on","type":"Time"},{"name":"is_deleted","type":"Float64"},{"name":"modified_on","type":"Time"},{"name":"script_deleted","type":"Bool","description":"Whether the bound Worker was deleted, leaving this Workflow inactive."},{"name":"terminator_running","type":"Float64"},{"name":"triggered_on","type":"Time"},{"name":"version_id","type":"String"},{"name":"instances","type":"Map[Float64]"}]}]},"put /accounts/{}/zt_risk_scoring/behaviors":{"operationId":"dlp-risk-score-behaviors-put","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_risk_behavior","stainlessResource":"zero_trust.risk_scoring.behaviours","methodName":"update","snippet":"resource \"cloudflare_zero_trust_risk_behavior\" \"example_zero_trust_risk_behavior\" {\n account_id = \"account_id\"\n behaviors = {\n foo = {\n enabled = true\n risk_level = \"low\"\n }\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"behaviors","type":"Map[Attributes]","children":[{"name":"enabled","type":"Bool"},{"name":"risk_level","type":"String"}]}],"optional":[],"computed":[]}]},"put /organizations/{}/profile":{"operationId":"Organizations_modifyProfile","declarations":[{"kind":"resource","name":"cloudflare_organization_profile","stainlessResource":"organizations.organization_profile","methodName":"update","snippet":"resource \"cloudflare_organization_profile\" \"example_organization_profile\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n business_address = \"business_address\"\n business_email = \"business_email\"\n business_name = \"business_name\"\n business_phone = \"business_phone\"\n external_metadata = \"external_metadata\"\n}\n","required":[{"name":"organization_id","type":"String","requiresReplace":true},{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}],"optional":[],"computed":[]}]},"put /zones/{}/api_gateway/configuration":{"operationId":"api-shield-settings-set-configuration-properties","declarations":[{"kind":"resource","name":"cloudflare_api_shield","stainlessResource":"api_gateway.configurations","methodName":"update","snippet":"resource \"cloudflare_api_shield\" \"example_api_shield\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n auth_id_characteristics = [{\n name = \"authorization\"\n type = \"header\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"auth_id_characteristics","type":"List[Attributes]","children":[{"name":"name","type":"String","description":"The name of the characteristic field, i.e., the header or cookie name."},{"name":"type","type":"String","description":"The type of characteristic."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/api_gateway/operations/{}/schema_validation":{"operationId":"api-shield-schema-validation-update-operation-level-settings","declarations":[{"kind":"resource","name":"cloudflare_api_shield_operation_schema_validation_settings","stainlessResource":"api_gateway.operations.schema_validation","methodName":"update","snippet":"resource \"cloudflare_api_shield_operation_schema_validation_settings\" \"example_api_shield_operation_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n mitigation_action = \"block\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation\n\n - `log` log request when request does not conform to schema for this operation\n - `block` deny access to the site when request does not conform to schema for this operation\n - `none` will skip mitigation for this operation\n - `null` indicates that no operation level mitigation is in place, see Zone Level Schema Validation Settings for mitigation action that will be applied\n"}],"computed":[{"name":"id","type":"String","description":"UUID.","requiresReplace":true}]}]},"put /zones/{}/api_gateway/settings/schema_validation":{"operationId":"api-shield-schema-validation-update-zone-level-settings","declarations":[{"kind":"resource","name":"cloudflare_api_shield_schema_validation_settings","stainlessResource":"api_gateway.settings.schema_validation","methodName":"update","snippet":"resource \"cloudflare_api_shield_schema_validation_settings\" \"example_api_shield_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_default_mitigation_action = \"block\"\n validation_override_mitigation_action = \"none\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used when there is no mitigation action defined on the operation\n\nMitigation actions are as follows:\n\n * `log` - log request when request does not conform to schema\n * `block` - deny access to the site when request does not conform to schema\n\nA special value of of `none` will skip running schema validation entirely for the request when there is no mitigation action defined on the operation\n"}],"optional":[{"name":"validation_override_mitigation_action","type":"String","description":"When set, this overrides both zone level and operation level mitigation actions.\n\n - `none` will skip running schema validation entirely for the request\n - `null` indicates that no override is in place\n\nTo clear any override, use the special value `disable_override` or `null`\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/bot_management":{"operationId":"bot-management-for-a-zone-update-config","declarations":[{"kind":"resource","name":"cloudflare_bot_management","stainlessResource":"bot_management","methodName":"update","snippet":"resource \"cloudflare_bot_management\" \"example_bot_management\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ai_bots_migration_opt_out = false\n ai_bots_protection = \"block\"\n aisearch = \"block\"\n ai_training = \"disallow\"\n ai_user = \"only_on_ad_pages\"\n bot_preference_sync_enabled = true\n cf_robots_variant = \"policy_only\"\n content_bots_protection = \"disabled\"\n crawler_protection = \"enabled\"\n enable_js = true\n fight_mode = true\n is_robots_txt_managed = false\n jsd_api_results_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"ai_bots_migration_opt_out","type":"Bool","description":"Temporary migration flag tracking zones opted out of AI bots managed-rule updates."},{"name":"ai_bots_protection","type":"String","description":"Enable rule to block AI Scrapers and Crawlers."},{"name":"ai_training","type":"String","description":"Configure robots.txt policy for AI model training bots."},{"name":"ai_user","type":"String","description":"Configure robots.txt policy for AI assistant and agent bots."},{"name":"aisearch","type":"String","description":"Configure robots.txt policy for AI search bots."},{"name":"auto_update_model","type":"Bool","description":"Automatically update to the newest bot detection models created by Cloudflare as they are released. [Learn more.](https://developers.cloudflare.com/bots/reference/machine-learning-models#model-versions-and-release-notes)"},{"name":"bm_cookie_enabled","type":"Bool","description":"Indicates that the bot management cookie can be placed on end user devices accessing the site. Defaults to true"},{"name":"bot_preference_sync_enabled","type":"Bool","description":"Enable Bot Preference Sync for this zone. When enabled, Cloudflare can serve robots.txt content derived from the zone's AI Search, AI User, and AI Training preferences."},{"name":"cf_robots_variant","type":"String","description":"Specifies the Robots Access Control License variant to use."},{"name":"content_bots_protection","type":"String","description":"Enable rule to block content bots. When enabled, blocks automated traffic with low bot scores, excluding safe verified bot categories. Exceptions should be managed via skip rules."},{"name":"crawler_protection","type":"String","description":"Enable rule to punish AI Scrapers and Crawlers via a link maze."},{"name":"enable_js","type":"Bool","description":"Use lightweight, invisible JavaScript detections to improve Bot Management. [Learn more about JavaScript Detections](https://developers.cloudflare.com/bots/reference/javascript-detections/)."},{"name":"fight_mode","type":"Bool","description":"Whether to enable Bot Fight Mode."},{"name":"is_robots_txt_managed","type":"Bool","description":"Enable cloudflare managed robots.txt. If an existing robots.txt is detected, then managed robots.txt will be prepended to the existing robots.txt."},{"name":"jsd_api_results_enabled","type":"Bool","description":"Whether to use JavaScript Detection results submitted through the API for this zone."},{"name":"optimize_wordpress","type":"Bool","description":"Whether to optimize Super Bot Fight Mode protections for Wordpress."},{"name":"sbfm_definitely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on definitely automated requests."},{"name":"sbfm_likely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on likely automated requests."},{"name":"sbfm_static_resource_protection","type":"Bool","description":"Super Bot Fight Mode (SBFM) to enable static resource protection.\nEnable if static resources on your application need bot protection.\nNote: Static resource protection can also result in legitimate traffic being blocked.\n"},{"name":"sbfm_verified_bots","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on verified bots requests."},{"name":"suppress_session_score","type":"Bool","description":"Whether to disable tracking the highest bot score for a session in the Bot Management cookie."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"using_latest_model","type":"Bool","description":"A read-only field that indicates whether the zone currently is running the latest ML model.\n"},{"name":"stale_zone_configuration","type":"Attributes","description":"A read-only field that shows which unauthorized settings are currently active on the zone. These settings typically result from upgrades or downgrades.","children":[{"name":"optimize_wordpress","type":"Bool","description":"Indicates that the zone's wordpress optimization for SBFM is turned on."},{"name":"sbfm_definitely_automated","type":"String","description":"Indicates that the zone's definitely automated requests are being blocked or challenged."},{"name":"sbfm_likely_automated","type":"String","description":"Indicates that the zone's likely automated requests are being blocked or challenged."},{"name":"sbfm_static_resource_protection","type":"String","description":"Indicates that the zone's static resource protection is turned on."},{"name":"sbfm_verified_bots","type":"String","description":"Indicates that the zone's verified bot requests are being blocked."},{"name":"suppress_session_score","type":"Bool","description":"Indicates that the zone's session score tracking is disabled."},{"name":"fight_mode","type":"Bool","description":"Indicates that the zone's Bot Fight Mode is turned on."}]}]}]},"put /zones/{}/certificate_authorities/hostname_associations":{"operationId":"client-certificate-for-a-zone-put-hostname-associations","declarations":[{"kind":"resource","name":"cloudflare_certificate_authorities_hostname_associations","stainlessResource":"certificate_authorities.hostname_associations","methodName":"update","snippet":"resource \"cloudflare_certificate_authorities_hostname_associations\" \"example_certificate_authorities_hostname_associations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostnames = [\"api.example.com\"]\n mtls_certificate_id = \"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"mtls_certificate_id","type":"String","description":"The UUID for a certificate that was uploaded to the mTLS Certificate Management endpoint. If no mtls_certificate_id is given, the hostnames will be associated to your active Cloudflare Managed CA."},{"name":"hostnames","type":"List[String]"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/cloud_connector/rules":{"operationId":"zone-cloud-conenctor-rules-put","declarations":[{"kind":"resource","name":"cloudflare_cloud_connector_rules","stainlessResource":"cloud_connector.rules","methodName":"update","snippet":"resource \"cloudflare_cloud_connector_rules\" \"example_cloud_connector_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rules = [{\n id = \"95c365e17e1b46599cd99e5b231fac4e\"\n description = \"Rule description\"\n enabled = true\n expression = \"http.cookie eq \\\"a=b\\\"\"\n parameters = {\n host = \"examplebucket.s3.eu-north-1.amazonaws.com\"\n }\n cloud_connector_rules_provider = \"aws_s3\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String"},{"name":"parameters","type":"Attributes","description":"Parameters of Cloud Connector Rule","children":[{"name":"host","type":"String","description":"Host to perform Cloud Connection to"}]},{"name":"cloud_connector_rules_provider","type":"String","description":"Cloud Provider type"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/content-upload-scan/settings":{"operationId":"waf-content-scanning-update-settings","declarations":[{"kind":"resource","name":"cloudflare_content_scanning","stainlessResource":"content_scanning","methodName":"create","snippet":"resource \"cloudflare_content_scanning\" \"example_content_scanning\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"enabled\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"value","type":"String","description":"The status value for Content Scanning."}],"optional":[],"computed":[{"name":"modified","type":"String","description":"Defines the last modification date (ISO 8601) of the Content Scanning status."}]}]},"put /zones/{}/custom_hostnames/fallback_origin":{"operationId":"custom-hostname-fallback-origin-for-a-zone-update-fallback-origin-for-custom-hostnames","declarations":[{"kind":"resource","name":"cloudflare_custom_hostname_fallback_origin","stainlessResource":"custom_hostnames.fallback_origin","methodName":"update","snippet":"resource \"cloudflare_custom_hostname_fallback_origin\" \"example_custom_hostname_fallback_origin\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin = \"fallback.example.com\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"origin","type":"String","description":"Your origin hostname that requests to your custom hostnames will be sent to."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"created_at","type":"Time","description":"This is the time the fallback origin was created."},{"name":"status","type":"String","description":"Status of the fallback origin's activation."},{"name":"updated_at","type":"Time","description":"This is the time the fallback origin was updated."},{"name":"errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a fallback origin."}]}]},"put /zones/{}/email/routing/rules/catch_all":{"operationId":"email-routing-routing-rules-update-catch-all-rule","declarations":[{"kind":"resource","name":"cloudflare_email_routing_catch_all","stainlessResource":"email_routing.rules.catch_alls","methodName":"update","snippet":"resource \"cloudflare_email_routing_catch_all\" \"example_email_routing_catch_all\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n actions = [{\n type = \"forward\"\n value = [\"destinationaddress@example.net\"]\n }]\n matchers = [{\n type = \"all\"\n }]\n enabled = true\n name = \"Send to user@example.net rule.\"\n owner_worker_tag = \"a7e6fb77503c41d8a7f3113c6918f10c\"\n source = \"api\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"actions","type":"List[Attributes]","description":"List actions for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of action for catch-all rule."},{"name":"value","type":"List[String]","description":"List of values for the action. Currently limited to a single value."}]},{"name":"matchers","type":"List[Attributes]","description":"List of matchers for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of matcher. Default is 'all'."}]}],"optional":[{"name":"name","type":"String","description":"Routing rule name."},{"name":"owner_worker_tag","type":"String","description":"Public tag (script_tag) of the Worker that owns this rule. Required when\n`source` is `wrangler`.\n"},{"name":"enabled","type":"Bool","description":"Routing rule status."},{"name":"source","type":"String","description":"Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"tag","type":"String","description":"Routing rule tag. (Deprecated, replaced by routing rule identifier)","deprecated":"Deprecated."}]}]},"put /zones/{}/hostnames/settings/{}/{}":{"operationId":"per-hostname-tls-settings-put","declarations":[{"kind":"resource","name":"cloudflare_hostname_tls_setting","stainlessResource":"hostnames.settings.tls","methodName":"update","snippet":"resource \"cloudflare_hostname_tls_setting\" \"example_hostname_tls_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n hostname = \"app.example.com\"\n value = [\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]\n}\n","required":[{"name":"setting_id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.","requiresReplace":true},{"name":"hostname","type":"String","description":"The hostname for which the tls settings are set.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"String","description":"The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`)."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.","requiresReplace":true},{"name":"created_at","type":"Time","description":"This is the time the tls setting was originally created for this hostname."},{"name":"status","type":"String","description":"Deployment status for the given tls setting."},{"name":"updated_at","type":"Time","description":"This is the time the tls setting was updated."}]}]},"put /zones/{}/observability/tracing/rules":{"operationId":"zone.observability.tracing.rules.update","declarations":[{"kind":"resource","name":"cloudflare_zone_tracing_rules","stainlessResource":"zones.observability.tracing.rules","methodName":"update","snippet":"resource \"cloudflare_zone_tracing_rules\" \"example_zone_tracing_rules\" {\n zone_id = \"zone_id\"\n rules = [{\n action = \"set_trace_settings\"\n action_parameters = {\n sampling_ratio = 0\n }\n description = \"description\"\n enabled = true\n expression = \"x\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","description":"Trace rules in evaluation order.","children":[{"name":"action","type":"String"},{"name":"action_parameters","type":"Attributes","children":[{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."}]},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String","description":"A Rules language expression that selects requests."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the zone ID.","requiresReplace":true}]}]},"put /zones/{}/origin_tls_client_auth/settings":{"operationId":"zone-level-authenticated-origin-pulls-set-enablement-for-zone","declarations":[{"kind":"resource","name":"cloudflare_authenticated_origin_pulls_settings","stainlessResource":"origin_tls_client_auth.settings","methodName":"update","snippet":"resource \"cloudflare_authenticated_origin_pulls_settings\" \"example_authenticated_origin_pulls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Indicates whether zone-level authenticated origin pulls is enabled."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/origin/cloud_regions/{}":{"operationId":"origin-cloud-regions-v2-upsert","declarations":[{"kind":"resource","name":"cloudflare_origin_cloud_region","stainlessResource":"cache.origin_cloud_regions","methodName":"update","snippet":"resource \"cloudflare_origin_cloud_region\" \"example_origin_cloud_region\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin_ip = \"192.0.2.1\"\n region = \"us-east-1\"\n vendor = \"aws\"\n}\n","required":[{"name":"origin_ip","type":"String","description":"Origin IP address (IPv4 or IPv6). For the single PUT endpoint (`PUT /origin/cloud_regions/{origin_ip}`), this field must match the path parameter or the request will be rejected with a 400 error. For the batch PUT endpoint, this field identifies which mapping to upsert.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"region","type":"String","description":"Cloud vendor region identifier. Must be a valid region for the specified vendor as returned by the supported_regions endpoint."},{"name":"vendor","type":"String","description":"Cloud vendor hosting the origin. Must be one of the supported vendors."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Origin IP address (IPv4 or IPv6). For the single PUT endpoint (`PUT /origin/cloud_regions/{origin_ip}`), this field must match the path parameter or the request will be rejected with a 400 error. For the batch PUT endpoint, this field identifies which mapping to upsert.","requiresReplace":true},{"name":"modified_on","type":"Time","description":"Time this mapping was last modified."}]}]},"put /zones/{}/precursor":{"operationId":"precursor-for-a-zone-update-config","declarations":[{"kind":"resource","name":"cloudflare_precursor","stainlessResource":"precursor","methodName":"update","snippet":"resource \"cloudflare_precursor\" \"example_precursor\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n default_mode = \"min-friction\"\n enforcement_rules = [{\n expression = \"http.request.uri.path eq \\\"/login\\\"\"\n mode = \"max-security\"\n description = \"Ease friction on the login path\"\n enabled = true\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"default_mode","type":"String","description":"The zone-level Precursor enforcement mode applied to requests that do\nnot match a more specific enforcement rule.\n","deprecated":"Deprecated."},{"name":"enforcement_rules","type":"List[Attributes]","description":"The ordered list of enforcement rules for the zone.","deprecated":"Deprecated.","children":[{"name":"expression","type":"String","description":"The filter expression that determines which requests the rule matches."},{"name":"mode","type":"String","description":"The override mode Precursor applies to requests matching an enforcement\nrule. Unlike `default_mode`, this cannot be `off`.\n"},{"name":"id","type":"String","description":"The read-only identifier that Cloudflare assigns to the rule."},{"name":"description","type":"String","description":"An informative description of the rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is active."}]}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/schema_validation/settings":{"operationId":"schema-validation-update-settings","declarations":[{"kind":"resource","name":"cloudflare_schema_validation_settings","stainlessResource":"schema_validation.settings","methodName":"update","snippet":"resource \"cloudflare_schema_validation_settings\" \"example_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_default_mitigation_action = \"block\"\n validation_override_mitigation_action = \"none\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used\nMitigation actions are as follows:\n\n - `\"log\"` - log request when request does not conform to schema\n - `\"block\"` - deny access to the site when request does not conform to schema\n - `\"none\"` - skip running schema validation\n"}],"optional":[{"name":"validation_override_mitigation_action","type":"String","description":"When set, this overrides both zone level and operation level mitigation actions.\n\n - `\"none\"` - skip running schema validation entirely for the request\n - `null` - clears any existing override\n"}],"computed":[]}]},"put /zones/{}/schema_validation/settings/operations/{}":{"operationId":"schema-validation-update-per-operation-setting","declarations":[{"kind":"resource","name":"cloudflare_schema_validation_operation_settings","stainlessResource":"schema_validation.settings.operations","methodName":"update","snippet":"resource \"cloudflare_schema_validation_operation_settings\" \"example_schema_validation_operation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n mitigation_action = \"block\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\n - `null` - clears any mitigation action\n"}],"optional":[],"computed":[]}]},"put /zones/{}/settings/google-tag-gateway/config":{"operationId":"zone-settings-change-google-tag-gateway-config","declarations":[{"kind":"resource","name":"cloudflare_google_tag_gateway","stainlessResource":"google_tag_gateway.config","methodName":"update","snippet":"resource \"cloudflare_google_tag_gateway\" \"example_google_tag_gateway\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n endpoint = \"/metrics\"\n hide_original_ip = true\n measurement_id = \"GTM-P2F3N47Q\"\n set_up_tag = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Enables or disables Google Tag Gateway for this zone."},{"name":"endpoint","type":"String","description":"Specifies the endpoint path for proxying Google Tag Manager requests. Use an absolute path starting with '/', with no nested paths and alphanumeric characters only (e.g. /metrics)."},{"name":"hide_original_ip","type":"Bool","description":"Hides the original client IP address from Google when enabled."},{"name":"measurement_id","type":"String","description":"Specify the Google Tag Manager container or measurement ID (e.g. GTM-XXXXXXX or G-XXXXXXXXXX)."}],"optional":[{"name":"set_up_tag","type":"Bool","description":"Set up the associated Google Tag on the zone automatically when enabled."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/settings/origin_tls_compliance_modes":{"operationId":"zone-cache-settings-replace-origin-tls-compliance-modes-setting","declarations":[{"kind":"resource","name":"cloudflare_origin_tls_compliance_modes","stainlessResource":"origin_tls_compliance_modes","methodName":"update","snippet":"resource \"cloudflare_origin_tls_compliance_modes\" \"example_origin_tls_compliance_modes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = [\"fips\", \"pqh\"]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"List[String]","description":"List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone's origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"put /zones/{}/snippets/{}":{"operationId":"updateZoneSnippet","declarations":[{"kind":"resource","name":"cloudflare_snippet","stainlessResource":"snippets","methodName":"update","snippet":"resource \"cloudflare_snippet\" \"example_snippet\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n snippet_name = \"my_snippet\"\n metadata = {\n main_module = \"main.js\"\n }\n}\n","required":[{"name":"snippet_name","type":"String","description":"Identify the snippet.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone.","requiresReplace":true},{"name":"metadata","type":"Attributes","description":"Provide metadata about the snippet.","children":[{"name":"main_module","type":"String","description":"Specify the name of the file that contains the main module of the snippet."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identify the snippet.","requiresReplace":true},{"name":"created_on","type":"Time","description":"Indicates when the snippet was created."},{"name":"modified_on","type":"Time","description":"Indicates when the snippet was last modified."}]}]},"put /zones/{}/snippets/snippet_rules":{"operationId":"updateZoneSnippetRules","declarations":[{"kind":"resource","name":"cloudflare_snippet_rules","stainlessResource":"snippets.rules","methodName":"update","snippet":"resource \"cloudflare_snippet_rules\" \"example_snippet_rules\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n rules = [{\n expression = \"ip.src eq 1.1.1.1\"\n snippet_name = \"my_snippet\"\n description = \"Execute my_snippet when IP address is 1.1.1.1.\"\n enabled = true\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","description":"Lists snippet rules.","children":[{"name":"id","type":"String","description":"Specify the unique ID of the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Use this field to specify the unique ID of the zone.","requiresReplace":true},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."}]}]},"put /zones/{}/url_normalization":{"operationId":"updateUrlNormalization","declarations":[{"kind":"resource","name":"cloudflare_url_normalization_settings","stainlessResource":"url_normalization","methodName":"update","snippet":"resource \"cloudflare_url_normalization_settings\" \"example_url_normalization_settings\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n scope = \"incoming\"\n type = \"cloudflare\"\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone.","requiresReplace":true},{"name":"scope","type":"String","description":"The scope of the URL normalization."},{"name":"type","type":"String","description":"The type of URL normalization performed by Cloudflare."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone.","requiresReplace":true}]}]},"put /zones/{}/waiting_rooms/{}/rules":{"operationId":"waiting-room-replace-waiting-room-rules","declarations":[{"kind":"resource","name":"cloudflare_waiting_room_rules","stainlessResource":"waiting_rooms.rules","methodName":"update","snippet":"resource \"cloudflare_waiting_room_rules\" \"example_waiting_room_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n rules = [{\n action = \"bypass_waiting_room\"\n expression = \"ip.src in {10.20.30.40}\"\n description = \"allow all traffic from 10.20.30.40\"\n enabled = true\n }]\n}\n","required":[{"name":"waiting_room_id","type":"String","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","children":[{"name":"action","type":"String","description":"The action to take when the expression matches."},{"name":"expression","type":"String","description":"Criteria defining when there is a match for the current rule."},{"name":"description","type":"String","description":"The description of the rule."},{"name":"enabled","type":"Bool","description":"When set to true, the rule is enabled."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"The ID of the rule."}]}]},"put /zones/{}/waiting_rooms/settings":{"operationId":"waiting-room-update-zone-settings","declarations":[{"kind":"resource","name":"cloudflare_waiting_room_settings","stainlessResource":"waiting_rooms.settings","methodName":"update","snippet":"resource \"cloudflare_waiting_room_settings\" \"example_waiting_room_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n search_engine_crawler_bypass = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"search_engine_crawler_bypass","type":"Bool","description":"Whether to allow verified search engine crawlers to bypass all waiting rooms on this zone.\nVerified search engine crawlers will not be tracked or counted by the waiting room system,\nand will not appear in waiting room analytics.\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]}}} diff --git a/packages/docs-site/src/terraform-extension.ts b/packages/docs-site/src/terraform-extension.ts new file mode 100644 index 000000000..564fd5975 --- /dev/null +++ b/packages/docs-site/src/terraform-extension.ts @@ -0,0 +1,37 @@ +import { readFileSync } from 'node:fs'; +import { defineFernExtension } from 'astro-fern'; +import { + canonicalTerraformEndpoint, + generatedTerraformDocsSchema, + TERRAFORM_EXTENSION_NAME, + terraformOperationDataSchema, + type GeneratedTerraformDocs, + type TerraformOperationData, +} from './terraform.ts'; + +function loadTerraformDocs(): GeneratedTerraformDocs { + const file = new URL('./generated/terraform-docs.json', import.meta.url); + return generatedTerraformDocsSchema.parse(JSON.parse(readFileSync(file, 'utf8'))); +} + +const terraformDocs = loadTerraformDocs(); + +/** Build-only bridge from Stainless's Terraform model into operation artifacts. */ +export const cloudflareTerraformExtension = defineFernExtension< + TerraformOperationData, + GeneratedTerraformDocs['operations'] +>({ + name: TERRAFORM_EXTENSION_NAME, + schema: terraformOperationDataSchema, + prepare: () => terraformDocs.operations, + operation: ({ method, path, operation }, operations) => { + const entry = operations[canonicalTerraformEndpoint(method, path)]; + if (!entry) return undefined; + if (entry.operationId !== operation.operationId) { + throw new Error( + `generated Terraform mapping expected operationId "${entry.operationId}" for ${method.toUpperCase()} ${path}, received "${operation.operationId ?? ''}"`, + ); + } + return { data: { declarations: entry.declarations } }; + }, +}); diff --git a/packages/docs-site/src/terraform.test.ts b/packages/docs-site/src/terraform.test.ts new file mode 100644 index 000000000..abdae23b2 --- /dev/null +++ b/packages/docs-site/src/terraform.test.ts @@ -0,0 +1,82 @@ +import assert from 'node:assert/strict'; +import { readFile } from 'node:fs/promises'; +import test from 'node:test'; +import type { FernPageSchema } from 'astro-fern'; +import { + canonicalTerraformEndpoint, + generatedTerraformDocsSchema, + getTerraformOperationData, + TERRAFORM_EXTENSION_NAME, + terraformDeclarationLabel, + type TerraformDeclaration, + withTerraformTarget, +} from './terraform.ts'; + +const resource: TerraformDeclaration = { + kind: 'resource', + name: 'cloudflare_widget', + stainlessResource: 'widgets', + methodName: 'create', + snippet: 'resource "cloudflare_widget" "example" {}\n', + required: [], + optional: [], + computed: [], +}; + +const dataSource: TerraformDeclaration = { + ...resource, + kind: 'data-source', + name: 'cloudflare_widget_data', + snippet: 'data "cloudflare_widget" "example" {}\n', +}; + +function pageWith(declarations?: TerraformDeclaration[]): FernPageSchema { + return { + operation: { + extensions: declarations ? { [TERRAFORM_EXTENSION_NAME]: { declarations } } : {}, + }, + targets: [ + { id: 'curl', code: 'curl example', syntax: 'bash' }, + { id: 'terraform', code: null, syntax: 'hcl' }, + ], + } as FernPageSchema; +} + +test('canonical Terraform endpoints ignore parameter naming differences', () => { + assert.equal( + canonicalTerraformEndpoint('GET', '/{account_or_zone}/{account_or_zone_id}/widgets'), + 'get /{}/{}/widgets', + ); +}); + +test('Terraform operation data remains namespaced on the operation', () => { + assert.deepEqual(getTerraformOperationData(pageWith([resource]).operation)?.declarations, [resource]); + assert.equal(terraformDeclarationLabel(resource), 'resource cloudflare_widget'); + assert.equal(terraformDeclarationLabel(dataSource), 'data cloudflare_widget_data'); +}); + +test('withTerraformTarget preserves all declaration snippets for agent Markdown', () => { + const page = pageWith([resource, dataSource]); + const decorated = withTerraformTarget(page); + const code = decorated.targets.find((target) => target.id === 'terraform')?.code; + assert.match(code ?? '', /# resource cloudflare_widget/); + assert.match(code ?? '', /# data cloudflare_widget_data/); + assert.equal(page.targets.find((target) => target.id === 'terraform')?.code, null); +}); + +test('the generated index retains every declaration for shared DLP endpoints', async () => { + const source = await readFile(new URL('./generated/terraform-docs.json', import.meta.url), 'utf8'); + const generated = generatedTerraformDocsSchema.parse(JSON.parse(source)); + const dlp = generated.operations['get /accounts/{}/dlp/entries']; + assert.ok(dlp); + assert.equal(dlp.declarations.length, 4); + assert.deepEqual( + dlp.declarations.map((declaration) => declaration.name), + [ + 'cloudflare_zero_trust_dlp_custom_entries', + 'cloudflare_zero_trust_dlp_entries', + 'cloudflare_zero_trust_dlp_integration_entries', + 'cloudflare_zero_trust_dlp_predefined_entries', + ], + ); +}); diff --git a/packages/docs-site/src/terraform.ts b/packages/docs-site/src/terraform.ts new file mode 100644 index 000000000..8b9ad58dd --- /dev/null +++ b/packages/docs-site/src/terraform.ts @@ -0,0 +1,93 @@ +import { z } from 'astro/zod'; +import type { FernPageSchema } from 'astro-fern'; + +export interface TerraformAttribute { + name: string; + type: string; + description?: string; + deprecated?: string; + sensitive?: boolean; + requiresReplace?: boolean; + children?: TerraformAttribute[]; +} + +export const terraformAttributeSchema: z.ZodType = z.lazy(() => + z.object({ + name: z.string().min(1), + type: z.string().min(1), + description: z.string().optional(), + deprecated: z.string().optional(), + sensitive: z.boolean().optional(), + requiresReplace: z.boolean().optional(), + children: z.array(terraformAttributeSchema).optional(), + }), +); + +export const terraformDeclarationSchema = z.object({ + kind: z.enum(['resource', 'data-source', 'list-data-source']), + name: z.string().min(1), + stainlessResource: z.string().min(1), + methodName: z.string().min(1), + snippet: z.string().min(1).optional(), + required: z.array(terraformAttributeSchema), + optional: z.array(terraformAttributeSchema), + computed: z.array(terraformAttributeSchema), +}); +export type TerraformDeclaration = z.infer; + +export const terraformOperationDataSchema = z.object({ + declarations: z.array(terraformDeclarationSchema).min(1), +}); +export type TerraformOperationData = z.infer; + +export const generatedTerraformDocsSchema = z.object({ + format: z.literal(1), + operations: z.record( + z.string(), + z.object({ + operationId: z.string().min(1), + declarations: z.array(terraformDeclarationSchema).min(1), + }), + ), +}); +export type GeneratedTerraformDocs = z.infer; + +export const TERRAFORM_EXTENSION_NAME = 'cloudflare-terraform'; + +export function getTerraformOperationData( + operation: FernPageSchema['operation'], +): TerraformOperationData | undefined { + const value = operation.extensions[TERRAFORM_EXTENSION_NAME]; + return value === undefined ? undefined : terraformOperationDataSchema.parse(value); +} + +export function canonicalTerraformEndpoint(method: string, endpointPath: string): string { + return `${method.toLowerCase()} ${endpointPath.replaceAll(/\{[^}]+\}/g, '{}')}`; +} + +export function terraformDeclarationLabel(declaration: TerraformDeclaration): string { + return `${declaration.kind === 'resource' ? 'resource' : 'data'} ${declaration.name}`; +} + +function combinedTerraformSnippet(data: TerraformOperationData): string | undefined { + const snippets = data.declarations.flatMap((declaration) => + declaration.snippet ? [{ label: terraformDeclarationLabel(declaration), code: declaration.snippet.trimEnd() }] : [], + ); + if (snippets.length === 0) return undefined; + if (snippets.length === 1) return snippets[0]?.code; + return snippets.map(({ label, code }) => `# ${label}\n${code}`).join('\n\n'); +} + +/** Adds operation-owned Terraform HCL to the generic target for agent Markdown. */ +export function withTerraformTarget(page: FernPageSchema): FernPageSchema { + const data = getTerraformOperationData(page.operation); + if (!data) return page; + const code = combinedTerraformSnippet(data); + if (!code) return page; + return { + ...page, + targets: page.targets.map((target) => + target.id === 'terraform' ? { ...target, code, syntax: 'hcl' } : target, + ), + }; +} From 28afc9a28c85803f82a6c597c6a4449426e1cbf3 Mon Sep 17 00:00:00 2001 From: ematipico Date: Fri, 9 Oct 2026 11:00:23 +0100 Subject: [PATCH 2/2] refactor: from source now --- .github/workflows/sync-terraform-docs.yml | 215 + .oxfmtrc.json | 2 +- packages/docs-site/README.md | 33 + .../scripts/generate-terraform-docs.test.mjs | 389 +- .../scripts/generate-terraform-docs.ts | 429 +- packages/docs-site/scripts/source-tree.ts | 118 + .../docs-site/scripts/terraform-provider.ts | 392 + .../docs-site/src/components/CodeSample.astro | 20 +- .../components/TerraformDeclarations.astro | 19 +- .../src/components/TerraformFields.astro | 3 - .../src/generated/terraform-docs.json | 114043 ++++++++++++++- packages/docs-site/src/terraform-extension.ts | 53 +- packages/docs-site/src/terraform.test.ts | 109 +- packages/docs-site/src/terraform.ts | 172 +- 14 files changed, 115580 insertions(+), 417 deletions(-) create mode 100644 .github/workflows/sync-terraform-docs.yml create mode 100644 packages/docs-site/scripts/source-tree.ts create mode 100644 packages/docs-site/scripts/terraform-provider.ts diff --git a/.github/workflows/sync-terraform-docs.yml b/.github/workflows/sync-terraform-docs.yml new file mode 100644 index 000000000..7434f702e --- /dev/null +++ b/.github/workflows/sync-terraform-docs.yml @@ -0,0 +1,215 @@ +# Keeps packages/docs-site/src/generated/terraform-docs.json in sync with the latest stable +# Cloudflare Terraform provider. +# +# Security model: +# - `generate` handles untrusted third-party sources. It has read-only permissions, no secrets and +# no persisted git credentials. It clones the provider and the cloudflare-go modules its go.mod +# requires as plain git data at release tags, and runs the offline generator. The generator +# doesn't download or execute anything, and it refuses symlinks and paths outside each checkout. +# Only the generated JSON leaves the job, as an artifact. +# - `pull-request` never sees third-party sources. It commits only the generated file to a bot +# branch, opens or updates a PR, and merges it only once every check on it has passed. The +# generated file is data that the site renders as escaped text, and the recorded commit SHAs +# keep every merged update traceable to its sources. +# - Third-party actions are pinned to commit SHAs. Inputs reach shell scripts only through `env` +# and are validated. +name: Sync Terraform docs + +on: + schedule: + - cron: '17 6 * * *' # every day at 06:17 UTC + workflow_dispatch: + inputs: + provider_version: + description: Provider version (x.y.z). Defaults to the latest stable version on the Terraform registry. + required: false + type: string + +permissions: {} + +concurrency: + group: sync-terraform-docs + cancel-in-progress: false + +env: + OUTPUT: packages/docs-site/src/generated/terraform-docs.json + +jobs: + generate: + runs-on: ubuntu-latest + timeout-minutes: 15 + permissions: + contents: read + outputs: + changed: ${{ steps.versions.outputs.changed }} + current: ${{ steps.versions.outputs.current }} + target: ${{ steps.versions.outputs.target }} + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Resolve versions + id: versions + env: + INPUT_PROVIDER: ${{ inputs.provider_version }} + run: | + set -euo pipefail + current="$(jq -r '.source.provider.version // empty' "$OUTPUT")" + # The registry, not GitHub tags: a tag can exist days before the release is published. + target="${INPUT_PROVIDER:-$( + curl -fsSL --proto '=https' https://registry.terraform.io/v1/providers/cloudflare/cloudflare/versions \ + | jq -r '.versions[].version' | grep -E '^[0-9]+\.[0-9]+\.[0-9]+$' | sort -V | tail -n1 + )}" + if ! [[ "$target" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then + echo "::error::Invalid provider version: $target"; exit 1 + fi + echo "current=$current" >> "$GITHUB_OUTPUT" + echo "target=$target" >> "$GITHUB_OUTPUT" + echo "changed=$([ "$current" != "$target" ] && echo true || echo false)" >> "$GITHUB_OUTPUT" + echo "::notice::Terraform provider $current -> $target" + + - name: Fetch pinned sources (data only) + if: steps.versions.outputs.changed == 'true' + env: + TARGET: ${{ steps.versions.outputs.target }} + run: | + set -euo pipefail + sources="$RUNNER_TEMP/terraform-sources" + mkdir -p "$sources" + clone() { # + git -c advice.detachedHead=false -c core.symlinks=false \ + clone --quiet --depth 1 --no-tags --branch "$2" "https://github.com/cloudflare/$1" "$3" + echo "::notice::$1 $2 = $(git -C "$3" rev-parse HEAD)" + } + clone terraform-provider-cloudflare "v$TARGET" "$sources/provider" + args=(--provider-dir "$sources/provider") + while read -r module version; do + [[ "$module" =~ ^github\.com/cloudflare/cloudflare-go/v[0-9]+$ ]] || { echo "::error::Unexpected module $module"; exit 1; } + [[ "$version" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]] || { echo "::error::Unsupported version $module $version"; exit 1; } + clone cloudflare-go "$version" "$sources/${module##*/}" + args+=(--sdk-dir "$module=$sources/${module##*/}") + done < <(grep -E '^\s*github\.com/cloudflare/cloudflare-go/v[0-9]+ ' "$sources/provider/go.mod" | awk '{print $1, $2}') + printf '%s\n' "${args[@]}" > "$RUNNER_TEMP/generator-args" + + - uses: ./.github/actions/setup-workspace + if: steps.versions.outputs.changed == 'true' + + - name: Generate + if: steps.versions.outputs.changed == 'true' + run: | + set -euo pipefail + mapfile -t args < "$RUNNER_TEMP/generator-args" + pnpm --filter docs-site generate:terraform-docs "${args[@]}" + + - name: Test + if: steps.versions.outputs.changed == 'true' + run: pnpm --filter docs-site test + + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + if: steps.versions.outputs.changed == 'true' + with: + name: terraform-docs + path: ${{ env.OUTPUT }} + if-no-files-found: error + retention-days: 7 + + pull-request: + needs: generate + if: needs.generate.outputs.changed == 'true' + runs-on: ubuntu-latest + timeout-minutes: 60 + permissions: + contents: write + pull-requests: write + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 + with: + name: terraform-docs + path: ${{ runner.temp }}/terraform-docs + + - name: Apply artifact + run: | + set -euo pipefail + jq -e '.format == 2' "$RUNNER_TEMP/terraform-docs/terraform-docs.json" > /dev/null + cp "$RUNNER_TEMP/terraform-docs/terraform-docs.json" "$OUTPUT" + + - name: Open or update pull request + id: pr + env: + # PRs opened with GITHUB_TOKEN don't trigger CI; set DOCS_SYNC_TOKEN (GitHub App or + # fine-grained PAT limited to this repository) so checks run on the bot PR. + GH_TOKEN: ${{ secrets.DOCS_SYNC_TOKEN || github.token }} + BASE: ${{ github.event.repository.default_branch }} + BRANCH: bot/sync-terraform-docs + CURRENT: ${{ needs.generate.outputs.current }} + TARGET: ${{ needs.generate.outputs.target }} + run: | + set -euo pipefail + if git diff --quiet -- "$OUTPUT"; then + echo "::notice::$OUTPUT is already up to date" + exit 0 + fi + + # Only the generated file is committed; the branch is rebuilt from the base every run. + gh auth setup-git + git config user.name 'github-actions[bot]' + git config user.email '41898282+github-actions[bot]@users.noreply.github.com' + git switch --create "$BRANCH" + git add -- "$OUTPUT" + git commit --quiet --message "chore(docs): sync Terraform docs to provider v$TARGET" + git push --force --quiet origin "$BRANCH" + + title="chore(docs): sync Terraform docs (provider v$TARGET)" + body="$(cat <> "$GITHUB_OUTPUT" + echo "head=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" + + # Merges only when every check on the PR's head commit has passed. Nothing is merged if any + # check fails, if no checks ever appear (e.g. the PR was opened with GITHUB_TOKEN, which doesn't + # trigger CI), or if the branch moved after the checks ran. + - name: Merge when all checks pass + if: steps.pr.outputs.number != '' + timeout-minutes: 50 + env: + GH_TOKEN: ${{ secrets.DOCS_SYNC_TOKEN || github.token }} + NUMBER: ${{ steps.pr.outputs.number }} + HEAD_SHA: ${{ steps.pr.outputs.head }} + run: | + set -euo pipefail + checks() { gh pr view "$NUMBER" --json statusCheckRollup --jq '.statusCheckRollup | length'; } + count=0 + for _ in $(seq 1 20); do + count="$(checks)" + [ "$count" -gt 0 ] && break + sleep 15 + done + if [ "$count" -eq 0 ]; then + echo "::warning::No checks reported on #$NUMBER; leaving it open for manual review" + exit 0 + fi + sleep 30 # let workflows that register later attach their checks too + + # Exits non-zero on the first failing check, which fails this job and leaves the PR open. + gh pr checks "$NUMBER" --watch --fail-fast --interval 30 + gh pr merge "$NUMBER" --squash --match-head-commit "$HEAD_SHA" diff --git a/.oxfmtrc.json b/.oxfmtrc.json index 09814f57a..7c4b83b6e 100644 --- a/.oxfmtrc.json +++ b/.oxfmtrc.json @@ -7,5 +7,5 @@ "tabWidth": 2, "useTabs": false, "endOfLine": "lf", - "ignorePatterns": ["**/_generated/**", "dist", ".wrangler"] + "ignorePatterns": ["**/_generated/**", "packages/docs-site/src/generated", "dist", ".wrangler"] } diff --git a/packages/docs-site/README.md b/packages/docs-site/README.md index b66bd8957..6b7d0b769 100644 --- a/packages/docs-site/README.md +++ b/packages/docs-site/README.md @@ -36,6 +36,39 @@ and method metadata defines each public product, resource hierarchy, and method route. OpenAPI tags remain internal ownership metadata and do not appear in SDK-backed URLs. +### Terraform + +The Terraform target is built from `src/generated/terraform-docs.json`. That file is generated +from local checkouts of the released Cloudflare Terraform provider and the cloudflare-go modules +it imports: + +```sh +git clone --depth 1 --branch v5.27.0 https://github.com/cloudflare/terraform-provider-cloudflare /tmp/tf/provider +git clone --depth 1 --branch v7.12.0 https://github.com/cloudflare/cloudflare-go /tmp/tf/sdk-v7 # versions from the provider's go.mod +git clone --depth 1 --branch v6.10.0 https://github.com/cloudflare/cloudflare-go /tmp/tf/sdk-v6 + +pnpm generate:terraform-docs --provider-dir /tmp/tf/provider \ + --sdk-dir github.com/cloudflare/cloudflare-go/v7=/tmp/tf/sdk-v7 \ + --sdk-dir github.com/cloudflare/cloudflare-go/v6=/tmp/tf/sdk-v6 # add --check to verify instead +``` + +The generator is offline and read-only. It doesn't download, spawn or execute anything (a test +enforces this). It reads checkouts through `scripts/source-tree.ts`, which refuses symbolic links +and paths outside each checkout. It reads: + +- `docs/{resources,data-sources}/*.md` (tfplugindocs output, the same content as the Terraform + Registry) for descriptions and Required / Optional / Read-only attributes; +- `examples/` for HCL and import syntax; +- `internal/services/*` client calls plus cloudflare-go `api.md` to link each declaration to the + API operations it calls (create, read, update, delete, import); +- `internal/version.go` and `.git/HEAD` to record the versions and commits used. + +The parsers are strict. Unexpected Markdown fails with `file:line`, and so does an SDK call that +can't be resolved. `.github/workflows/sync-terraform-docs.yml` runs daily and opens a PR when a new +provider release is published. Untrusted sources are only handled in a job with read-only +permissions and no secrets. `src/terraform-extension.ts` attaches declarations to OpenAPI +operations and warns during builds about declarations that match no operation. + ## Project ownership - `src/content.config.ts` selects OpenAPI sources, discovers SDK products and ownership sections, configures snapshots and execution targets, and registers the canonical, route-neutral API collection. diff --git a/packages/docs-site/scripts/generate-terraform-docs.test.mjs b/packages/docs-site/scripts/generate-terraform-docs.test.mjs index 5a1b6464c..aff4fd271 100644 --- a/packages/docs-site/scripts/generate-terraform-docs.test.mjs +++ b/packages/docs-site/scripts/generate-terraform-docs.test.mjs @@ -1,81 +1,328 @@ import assert from 'node:assert/strict'; +import { mkdir, mkdtemp, readFile, rm, symlink, writeFile } from 'node:fs/promises'; +import os from 'node:os'; +import path from 'node:path'; import test from 'node:test'; -import { canonicalTerraformEndpoint, extractTerraformDocs } from './generate-terraform-docs.ts'; +import { parsePackageVersion, parseSdkRequirements } from './generate-terraform-docs.ts'; +import { SourceTree } from './source-tree.ts'; +import { + buildTerraformDocs, + declarationFiles, + parseDeclarationMarkdown, + parseSdkApiMarkdown, + parseServiceSource, +} from './terraform-provider.ts'; -test('canonicalTerraformEndpoint ignores path parameter names', () => { - assert.equal( - canonicalTerraformEndpoint('POST', '/accounts/{account_id}/widgets/{widget_id}'), - 'post /accounts/{}/widgets/{}', - ); +const API_MD = ` +## Widgets +- client.Widgets.New(ctx context.Context) (\\*widgets.Widget, error) +- client.Widgets.Get(ctx, widgetID) (\\*widgets.Widget, error) +- client.Widgets.List(ctx) (\\*pagination.Page, error) +- client.Widgets.Delete(ctx, widgetID) error +`; + +const RESOURCE_GO = `package widget + +import ( + "github.com/cloudflare/cloudflare-go/v7" + "github.com/cloudflare/cloudflare-go/v7/option" +) + +func (r *WidgetResource) Metadata(ctx context.Context, req resource.MetadataRequest, resp *resource.MetadataResponse) { + resp.TypeName = req.ProviderTypeName + "_widget" +} + +func (r *WidgetResource) Create(ctx context.Context, req resource.CreateRequest, resp *resource.CreateResponse) { + _, err = r.client.Widgets.New(ctx, option.WithRequestBody("application/json", dataBytes)) +} + +func (r *WidgetResource) Read(ctx context.Context, req resource.ReadRequest, resp *resource.ReadResponse) { + _, err := r.client.Widgets.Get(ctx, data.ID.ValueString()) +} + +func (r *WidgetResource) Delete(ctx context.Context, req resource.DeleteRequest, resp *resource.DeleteResponse) { + _, err := r.client.Widgets.Delete(ctx, data.ID.ValueString()) +} + +func (r *WidgetResource) ImportState(ctx context.Context, req resource.ImportStateRequest, resp *resource.ImportStateResponse) { + _, err := r.client.Widgets.Get(ctx, path_widget_id) +} +`; + +const LIST_GO = `package widget +import "github.com/cloudflare/cloudflare-go/v7" +func (d *WidgetsDataSource) Metadata(ctx context.Context, req datasource.MetadataRequest, resp *datasource.MetadataResponse) { + resp.TypeName = req.ProviderTypeName + "_widgets" +} +func (d *WidgetsDataSource) Read(ctx context.Context, req datasource.ReadRequest, resp *datasource.ReadResponse) { + page, err := d.client.Widgets.ListAutoPaging(ctx, params) + other := d.client.Widgets.Rename(ctx) +} +`; + +const WIDGET_MD = `--- +page_title: "cloudflare_widget Resource - Cloudflare" +subcategory: "" +description: |- + Manages a widget. +--- + +# cloudflare_widget (Resource) + +Manages a widget. + +- \`Widget Write\` + +## Example Usage + +\`\`\`terraform +resource "cloudflare_widget" "example" {} +\`\`\` + + +## Schema + +### Required + +- \`name\` (String) Widget name. +Available values: "a", "b". +- \`account_id\` (String) + +### Optional + +- \`secret\` (String, Sensitive) A secret. +- \`token\` (String, Sensitive, [Write-only](https://developer.hashicorp.com/terraform/language/resources/ephemeral#write-only-arguments)) Write-only token. +- \`settings\` (Attributes) Widget settings. (see [below for nested schema](#nestedatt--settings)) + +### Read-Only + +- \`id\` (String) The ID of this resource. +- \`tags\` (List of String) + + +### Nested Schema for \`settings\` + +Optional: + +- \`mode\` (Attributes) Mode. (see [below for nested schema](#nestedatt--settings--mode)) + +Read-Only: + +- \`enabled\` (Boolean, Deprecated) Whether it is enabled. + + +### Nested Schema for \`settings.mode\` + +Required: + +- \`value\` (Number) + +## Import + +\`\`\`shell +$ terraform import cloudflare_widget.example '' +\`\`\` +`; + +const WIDGETS_MD = `# cloudflare_widgets (Data Source) + + +## Schema + +### Required + +- \`account_id\` (String) +`; + +test('parseSdkApiMarkdown maps SDK accessors to documented endpoints', () => { + const endpoints = parseSdkApiMarkdown(API_MD); + assert.equal(endpoints.get('Widgets.New'), 'post /accounts/{account_id}/widgets'); + assert.equal(endpoints.get('Widgets.Delete'), 'delete /accounts/{account_id}/widgets/{widget_id}'); + assert.equal(endpoints.size, 4); }); -test('extractTerraformDocs resolves fields and joins declarations to Forge operations', () => { - const servicePath = '(resource) widgets'; - const sourcePath = `${servicePath} > (terraform resource)`; - const namePath = `${sourcePath} > (attribute) name`; - const settingsPath = `${sourcePath} > (attribute) settings`; - const enabledPath = `${settingsPath} > (attribute) enabled`; - const sdkJson = { - resources: { - widgets: { - stainlessPath: servicePath, - methods: { create: { endpoint: 'post /accounts/{account_id}/widgets' } }, - subresources: {}, - }, - }, - decls: { - terraform: { - [servicePath]: { kind: 'TerraformDeclServiceNode', resource: sourcePath }, - [sourcePath]: { - kind: 'TerraformDeclSource', - type: 'resource', - name: 'cloudflare_widget', - methodName: 'create', - required: [namePath], - optional: [settingsPath], - computed: [], - }, - [namePath]: { - kind: 'TerraformDeclAttribute', - name: 'name', - type: { category: 'primitive', type: 'String' }, - children: [], - }, - [settingsPath]: { - kind: 'TerraformDeclAttribute', - name: 'settings', - type: { category: 'nested', type: 'SingleNested' }, - children: [enabledPath], - }, - [enabledPath]: { - kind: 'TerraformDeclAttribute', - name: 'enabled', - type: { category: 'primitive', type: 'Bool' }, - children: [], - }, - }, - }, - snippets: { - 'terraform.default': { - [sourcePath]: { default: { content: 'resource "cloudflare_widget" "example" {}\n' } }, - }, - }, - metadata: { terraform: { version: '1.0.0' } }, - }; - const openapi = { - paths: { - '/accounts/{account}/widgets': { - post: { operationId: 'widgets_create' }, - }, - }, - }; - const result = extractTerraformDocs(sdkJson, openapi); +test('parseServiceSource records the type name, SDK module and lifecycle role of each call', () => { + const resource = parseServiceSource(RESOURCE_GO, 'resource'); + assert.equal(resource?.name, 'cloudflare_widget'); + assert.equal(resource?.sdkModule, 'github.com/cloudflare/cloudflare-go/v7'); + assert.deepEqual(resource?.calls, [ + { call: 'Widgets.New', role: 'create' }, + { call: 'Widgets.Get', role: 'read' }, + { call: 'Widgets.Delete', role: 'delete' }, + { call: 'Widgets.Get', role: 'import' }, + ]); + const list = parseServiceSource(LIST_GO, 'list-data-source'); + assert.deepEqual(list?.calls[0], { call: 'Widgets.List', role: 'read' }); + assert.equal(parseServiceSource('package nothing', 'resource'), undefined); +}); - assert.deepEqual(result.stats, { operations: 1, declarations: 1, missingSnippets: 0, unmatched: 0 }); - assert.equal(result.operations['post /accounts/{}/widgets'].operationId, 'widgets_create'); - assert.deepEqual(result.operations['post /accounts/{}/widgets'].declarations[0].optional[0], { +test('parseDeclarationMarkdown reads tfplugindocs groups, flags and nested schemas', () => { + const doc = parseDeclarationMarkdown(WIDGET_MD, 'docs/resources/widget.md'); + assert.equal(doc.name, 'cloudflare_widget'); + assert.equal(doc.description, 'Manages a widget.\n\n- `Widget Write`'); + assert.deepEqual(doc.required, [ + { name: 'account_id', type: 'String' }, + { name: 'name', type: 'String', description: 'Widget name.\nAvailable values: "a", "b".' }, + ]); + assert.deepEqual( + doc.optional.map(({ name, sensitive }) => [name, sensitive ?? false]), + [ + ['secret', true], + ['settings', false], + ['token', true], + ], + ); + assert.deepEqual(doc.optional[1], { name: 'settings', type: 'Attributes', - children: [{ name: 'enabled', type: 'Bool' }], + description: 'Widget settings.', + children: [ + { name: 'enabled', type: 'Boolean', description: 'Whether it is enabled.', deprecated: 'Deprecated.' }, + { name: 'mode', type: 'Attributes', description: 'Mode.', children: [{ name: 'value', type: 'Number' }] }, + ], + }); + assert.deepEqual( + doc.computed.map(({ name, type }) => [name, type]), + [ + ['id', 'String'], + ['tags', 'List of String'], + ], + ); +}); + +test('parseDeclarationMarkdown fails with file:line on anything unexpected', () => { + const file = 'docs/resources/widget.md'; + const lineOf = (needle) => WIDGET_MD.split('\n').findIndex((line) => line.includes(needle)) + 1; + const cases = [ + [WIDGET_MD.replace('(String, Sensitive) A secret', '(String, Secret) A secret'), /unknown attribute flag "Secret"/], + [WIDGET_MD.replace('(#nestedatt--settings--mode)', '(#nestedatt--nope)'), /references missing nested schema/], + [WIDGET_MD.replace('', ''), /missing `'; +const TITLE = /^# (\S+) \((Resource|Data Source)\)$/; +const ROOT_GROUP = /^### (Required|Optional|Read-Only)$/; +const NESTED_GROUP = /^(Required|Optional|Read-Only):$/; +const ANCHOR = /^<\/a>$/; +const NESTED_TITLE = /^### Nested Schema for `([\w.]+)`$/; +const ITEM = /^- `(\w+)` \(/; +const NESTED_REFERENCE = /\s*\(see \[below for nested (?:schema|block)\]\(#(nested[\w-]+)\)\)$/; +const WRITE_ONLY_FLAG = /^\[Write-only\]\([^)\s]+\)$/; +const GROUP_NAMES: Readonly> = { + Required: 'required', + Optional: 'optional', + 'Read-Only': 'computed', +}; + +interface RawItem { + line: number; + group: AttributeGroup; + name: string; + spec: string; + text: string[]; +} + +/** Returns the index just past the parenthesis that closes the one at `open`, or -1. */ +function closingParenthesis(text: string, open: number): number { + let depth = 0; + for (let index = open; index < text.length; index += 1) { + if (text[index] === '(') depth += 1; + else if (text[index] === ')' && --depth === 0) return index + 1; + } + return -1; +} + +/** + * Parses one tfplugindocs page. The layout is generated by `tfplugindocs` (`schemamd`), so anything + * that does not fit it fails with `file:line` instead of being silently skipped. + */ +export function parseDeclarationMarkdown(markdown: string, file: string): ParsedDeclarationDoc { + const lines = markdown.replaceAll('\r\n', '\n').split('\n'); + const fail = (index: number, message: string): never => { + throw new Error(`${file}:${index + 1}: ${message}`); + }; + + let titleIndex = lines.findIndex((line) => TITLE.test(line)); + if (titleIndex < 0) fail(0, 'missing `# (Resource|Data Source)` heading'); + const name = lines[titleIndex]!.match(TITLE)![1]!; + const markerIndex = lines.indexOf(SCHEMA_MARKER); + if (markerIndex < 0) fail(titleIndex, `missing \`${SCHEMA_MARKER}\``); + + const descriptionEnd = lines.findIndex((line, index) => index > titleIndex && line.startsWith('## ')); + const description = lines + .slice(titleIndex + 1, descriptionEnd < 0 || descriptionEnd > markerIndex ? markerIndex : descriptionEnd) + .join('\n') + .trim(); + + let index = markerIndex + 1; + while (lines[index]?.trim() === '') index += 1; + if (lines[index] !== '## Schema') fail(index, 'expected `## Schema` after the tfplugindocs marker'); + titleIndex = index; + + const root: RawItem[] = []; + const sections = new Map(); + let items = root; + let inRoot = true; + let group: AttributeGroup | undefined; + let item: RawItem | undefined; + + for (index = titleIndex + 1; index < lines.length; index += 1) { + const line = lines[index]!; + if (line.startsWith('## ')) break; // e.g. `## Import` + const anchor = line.match(ANCHOR)?.[1]; + const rootGroup = line.match(ROOT_GROUP)?.[1]; + const nestedGroup = line.match(NESTED_GROUP)?.[1]; + const itemStart = line.match(ITEM); + + if (anchor) { + let next = index + 1; + while (lines[next]?.trim() === '') next += 1; + if (!NESTED_TITLE.test(lines[next] ?? '')) + fail(next, `expected \`### Nested Schema for\` after anchor ${anchor}`); + if (sections.has(anchor)) fail(index, `duplicate anchor ${anchor}`); + items = []; + sections.set(anchor, { line: index, items }); + inRoot = false; + group = undefined; + item = undefined; + index = next; + } else if (rootGroup || nestedGroup) { + if (rootGroup && !inRoot) fail(index, `\`### ${rootGroup}\` inside a nested schema`); + if (nestedGroup && inRoot) fail(index, `\`${nestedGroup}:\` outside a nested schema`); + group = GROUP_NAMES[(rootGroup ?? nestedGroup)!]; + item = undefined; + } else if (itemStart) { + if (!group) fail(index, 'attribute before any Required/Optional/Read-Only group'); + const open = itemStart[0].length - 1; + const close = closingParenthesis(line, open); + if (close < 0) fail(index, 'unbalanced parentheses in attribute type'); + item = { + line: index, + group: group!, + name: itemStart[1]!, + spec: line.slice(open + 1, close - 1), + text: [line.slice(close).trim()], + }; + items.push(item); + } else if (item) { + item.text.push(line); // multi-line description + } else if (line.trim() !== '') { + fail(index, `unexpected line in schema: ${JSON.stringify(line.slice(0, 80))}`); + } + } + + const used = new Set(); + const convert = (raw: RawItem, ancestors: readonly string[]): TerraformAttribute => { + const [type, ...flags] = raw.spec.split(', '); + if (!type) fail(raw.line, `missing type for ${raw.name}`); + for (const flag of flags) { + if (flag !== 'Sensitive' && flag !== 'Deprecated' && !WRITE_ONLY_FLAG.test(flag)) { + fail(raw.line, `unknown attribute flag ${JSON.stringify(flag)}`); + } + } + let text = raw.text.join('\n').trim(); + const reference = text.match(NESTED_REFERENCE)?.[1]; + if (reference) text = text.slice(0, text.length - text.match(NESTED_REFERENCE)![0].length).trim(); + let children: TerraformAttribute[] = []; + if (reference) { + const section = sections.get(reference); + if (!section) fail(raw.line, `${raw.name} references missing nested schema #${reference}`); + if (ancestors.includes(reference)) fail(raw.line, `nested schema cycle at #${reference}`); + used.add(reference); + children = section!.items + .map((child) => convert(child, [...ancestors, reference])) + .sort((left, right) => left.name.localeCompare(right.name)); + } + return { + name: raw.name, + type: type!, + ...(text ? { description: text } : {}), + ...(flags.includes('Deprecated') ? { deprecated: 'Deprecated.' } : {}), + ...(flags.includes('Sensitive') ? { sensitive: true } : {}), + ...(children.length > 0 ? { children } : {}), + }; + }; + + const groups: Record = { required: [], optional: [], computed: [] }; + for (const raw of root) groups[raw.group].push(convert(raw, [])); + for (const [anchor, section] of sections) { + if (!used.has(anchor)) fail(section.line, `nested schema #${anchor} is not referenced by any attribute`); + } + for (const group of Object.values(groups)) group.sort((left, right) => left.name.localeCompare(right.name)); + return { name, description: description || undefined, ...groups }; +} + +// --------------------------------------------------------------------------- +// Assembly +// --------------------------------------------------------------------------- + +export function declarationKey(kind: TerraformDeclarationKind, name: string): string { + return `${kind}:${name}`; +} + +export interface BuildTerraformDocsInput { + provider: GeneratedTerraformDocs['source']['provider']; + sdks: GeneratedTerraformDocs['source']['sdks']; + services: ServiceSource[]; + /** SDK module path -> (`Service.Method` -> endpoint). */ + sdkEndpoints: ReadonlyMap>; + /** Reads a file from the provider checkout (e.g. `docs/resources/x.md`), or undefined when missing. */ + readProviderFile: (relativePath: string) => string | undefined; + providerTypeName?: string; +} + +/** Provider-relative paths of a declaration's documentation and examples (tfplugindocs layout). */ +export function declarationFiles(kind: TerraformDeclarationKind, name: string, providerTypeName = 'cloudflare') { + const shortName = name.slice(providerTypeName.length + 1); + return kind === 'resource' + ? { + doc: `docs/resources/${shortName}.md`, + example: `examples/resources/${name}/resource.tf`, + importExample: `examples/resources/${name}/import.sh`, + } + : { doc: `docs/data-sources/${shortName}.md`, example: `examples/data-sources/${name}/data-source.tf` }; +} + +export function buildTerraformDocs(input: BuildTerraformDocsInput): GeneratedTerraformDocs { + const declarations: Record = {}; + const endpoints = new Map>>(); + const unresolvedCalls: GeneratedTerraformDocs['unresolvedCalls'] = []; + const unlinked: string[] = []; + const undocumented: string[] = []; + const sorted = [...input.services].sort( + (left, right) => left.name.localeCompare(right.name) || left.kind.localeCompare(right.kind), + ); + + for (const service of sorted) { + const key = declarationKey(service.kind, service.name); + if (declarations[key]) throw new Error(`Duplicate Terraform declaration ${key}`); + const files = declarationFiles(service.kind, service.name, input.providerTypeName); + const markdown = input.readProviderFile(files.doc); + // tfplugindocs documents every registered declaration; service code without a page is not shipped. + if (markdown === undefined) { + undocumented.push(key); + continue; + } + const doc = parseDeclarationMarkdown(markdown, files.doc); + if (doc.name !== service.name) { + throw new Error(`${files.doc}: documents ${doc.name}, expected ${service.name}`); + } + const example = input.readProviderFile(files.example)?.trimEnd(); + const importExample = files.importExample ? input.readProviderFile(files.importExample)?.trimEnd() : undefined; + declarations[key] = { + kind: service.kind, + name: service.name, + ...(doc.description ? { description: doc.description } : {}), + ...(example ? { example } : {}), + ...(importExample ? { importExample } : {}), + required: doc.required, + optional: doc.optional, + computed: doc.computed, + }; + + const methods = service.sdkModule ? input.sdkEndpoints.get(service.sdkModule) : undefined; + let linked = false; + for (const { call, role } of service.calls) { + const endpoint = methods?.get(call); + if (!endpoint) { + unresolvedCalls.push({ declaration: key, call: `${service.sdkModule ?? ''} ${call}` }); + continue; + } + linked = true; + const links = endpoints.get(endpoint) ?? new Map>(); + links.set(key, (links.get(key) ?? new Set()).add(role)); + endpoints.set(endpoint, links); + } + if (!linked) unlinked.push(key); + } + + const endpointRecord = Object.fromEntries( + [...endpoints] + .sort(([left], [right]) => left.localeCompare(right)) + .map(([endpoint, links]) => [ + endpoint, + [...links] + .sort(([left], [right]) => left.localeCompare(right)) + .map(([declaration, roles]) => ({ + declaration, + roles: terraformRoleSchema.options.filter((role) => roles.has(role)), + })), + ]), + ); + const declarationCount = Object.keys(declarations).length; + // Validate against the contract the docs build reads, so a bad file never gets written. + return parseWith( + generatedTerraformDocsSchema, + { + format: 2, + source: { provider: input.provider, sdks: input.sdks }, + stats: { + declarations: declarationCount, + linkedDeclarations: declarationCount - unlinked.length, + endpoints: Object.keys(endpointRecord).length, + unresolvedCalls: unresolvedCalls.length, + }, + unlinked, + undocumented, + unresolvedCalls, + declarations, + endpoints: endpointRecord, + }, + 'Generated Terraform docs', + ); +} diff --git a/packages/docs-site/src/components/CodeSample.astro b/packages/docs-site/src/components/CodeSample.astro index 471d84aa7..40cd5b1e6 100644 --- a/packages/docs-site/src/components/CodeSample.astro +++ b/packages/docs-site/src/components/CodeSample.astro @@ -222,15 +222,25 @@ function codeSampleSyntax(sample: OperationCodeSampleSchema): string { {terraform.declarations.map((declaration) => (

{terraformDeclarationLabel(declaration)}

- {declaration.snippet ? ( + {declaration.example ? ( ) : ( -

No generated HCL example is available for this declaration.

+

No HCL example is available for this declaration.

)} + {declaration.importExample ? ( + <> +

Import

+ + + ) : null}
))}
@@ -748,6 +758,10 @@ function codeSampleSyntax(sample: OperationCodeSampleSchema): string { border-top: 1px solid var(--cf-border); } + .forge-terraform-sample * + h3 { + border-top: 1px solid var(--cf-border); + } + .forge-terraform-sample h3 { margin: 0; border-bottom: 1px solid var(--cf-border); diff --git a/packages/docs-site/src/components/TerraformDeclarations.astro b/packages/docs-site/src/components/TerraformDeclarations.astro index f202e3cfe..668b297f2 100644 --- a/packages/docs-site/src/components/TerraformDeclarations.astro +++ b/packages/docs-site/src/components/TerraformDeclarations.astro @@ -1,6 +1,6 @@ --- import AnchorHeading from '@astrojs/starlight/components/AnchorHeading.astro'; -import type { TerraformOperationData } from '../terraform.ts'; +import { terraformRolesSummary, type TerraformOperationData } from '../terraform.ts'; import TerraformFields from './TerraformFields.astro'; interface Props { @@ -12,7 +12,7 @@ const { operation, declarationOffset = 0 } = Astro.props; const groups = [ { id: 'required', label: 'Required', fields: 'required' as const }, { id: 'optional', label: 'Optional', fields: 'optional' as const }, - { id: 'computed', label: 'Computed', fields: 'computed' as const }, + { id: 'computed', label: 'Read-only', fields: 'computed' as const }, ]; const declarationKindLabels = { @@ -29,7 +29,9 @@ const declarationKindLabels = {
{declarationKindLabels[declaration.kind]}

{declaration.name}

+

{terraformRolesSummary(declaration)}

+ {declaration.description ?

{declaration.description}

: null} {groups.map((group) => declaration[group.fields].length > 0 ? (
@@ -87,6 +89,19 @@ const declarationKindLabels = { text-transform: uppercase; } + .forge-terraform-roles, + .forge-terraform-summary { + margin: 0; + color: var(--cf-muted-foreground); + font-size: 0.8125rem; + line-height: 1.6; + } + + .forge-terraform-summary { + margin-top: 0.75rem; + white-space: pre-wrap; + } + .forge-terraform-unavailable p { margin: 0.5rem 0 0; color: var(--cf-muted-foreground); diff --git a/packages/docs-site/src/components/TerraformFields.astro b/packages/docs-site/src/components/TerraformFields.astro index 6c65719e1..b15849e13 100644 --- a/packages/docs-site/src/components/TerraformFields.astro +++ b/packages/docs-site/src/components/TerraformFields.astro @@ -16,7 +16,6 @@ const { fields } = Astro.props;
{field.name} {field.type} - {field.requiresReplace ? forces replacement : null} {field.sensitive ? sensitive : null} {field.deprecated ? deprecated : null}
@@ -74,7 +73,6 @@ const { fields } = Astro.props; font-size: 0.75rem; } - .forge-terraform-replace, .forge-terraform-sensitive, .forge-terraform-deprecated { font-size: 0.7rem; @@ -83,7 +81,6 @@ const { fields } = Astro.props; letter-spacing: 0.04em; } - .forge-terraform-replace, .forge-terraform-sensitive { color: var(--cf-muted-foreground); } diff --git a/packages/docs-site/src/generated/terraform-docs.json b/packages/docs-site/src/generated/terraform-docs.json index d3b818deb..d3d0f1def 100644 --- a/packages/docs-site/src/generated/terraform-docs.json +++ b/packages/docs-site/src/generated/terraform-docs.json @@ -1 +1,114042 @@ -{"format":1,"source":{"terraform":{"repo_url":"https://www.github.com/cloudflare/terraform-provider-cloudflare","code_url":"https://github.com/cloudflare/terraform-provider-cloudflare/tree/main","package_title":"Cloudflare Terraform","version":"0.0.1","install":"cloudflare = { source = \"cloudflare/cloudflare\" }"}},"stats":{"operations":664,"declarations":673,"missingSnippets":4,"unmatched":48},"unmatched":[{"kind":"resource","name":"cloudflare_account_subscription","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/subscriptions"},{"kind":"data-source","name":"cloudflare_account_subscription","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/subscriptions"},{"kind":"resource","name":"cloudflare_custom_csr","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/custom_csrs"},{"kind":"data-source","name":"cloudflare_custom_csr","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_csrs/{custom_csr_id}"},{"kind":"list-data-source","name":"cloudflare_custom_csrs","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_csrs"},{"kind":"resource","name":"cloudflare_custom_pages","endpoint":"put /{accounts_or_zones}/{account_or_zone_id}/custom_pages/{identifier}"},{"kind":"data-source","name":"cloudflare_custom_pages","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/{identifier}"},{"kind":"list-data-source","name":"cloudflare_custom_pages_list","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages"},{"kind":"resource","name":"cloudflare_custom_page_asset","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets"},{"kind":"data-source","name":"cloudflare_custom_page_asset","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets/{asset_name}"},{"kind":"list-data-source","name":"cloudflare_custom_page_assets","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets"},{"kind":"resource","name":"cloudflare_account_dns_settings","endpoint":"patch /accounts/{account_id}/dns_settings"},{"kind":"data-source","name":"cloudflare_account_dns_settings","endpoint":"get /accounts/{account_id}/dns_settings"},{"kind":"resource","name":"cloudflare_zone_dns_settings","endpoint":"patch /zones/{zone_id}/dns_settings"},{"kind":"data-source","name":"cloudflare_zone_dns_settings","endpoint":"get /zones/{zone_id}/dns_settings"},{"kind":"list-data-source","name":"cloudflare_email_routing_rules","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/email/routing/rules"},{"kind":"resource","name":"cloudflare_access_rule","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules"},{"kind":"data-source","name":"cloudflare_access_rule","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules/{rule_id}"},{"kind":"list-data-source","name":"cloudflare_access_rules","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules"},{"kind":"resource","name":"cloudflare_load_balancer","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/load_balancers"},{"kind":"data-source","name":"cloudflare_load_balancer","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/load_balancers/{load_balancer_id}"},{"kind":"list-data-source","name":"cloudflare_load_balancers","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/load_balancers"},{"kind":"data-source","name":"cloudflare_logpush_dataset_field","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/datasets/{dataset_id}/fields"},{"kind":"data-source","name":"cloudflare_logpush_dataset_job","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/datasets/{dataset_id}/jobs"},{"kind":"resource","name":"cloudflare_logpush_job","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs"},{"kind":"data-source","name":"cloudflare_logpush_job","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs/{job_id}"},{"kind":"list-data-source","name":"cloudflare_logpush_jobs","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs"},{"kind":"resource","name":"cloudflare_logpush_ownership_challenge","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/logpush/ownership"},{"kind":"list-data-source","name":"cloudflare_waiting_rooms","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/waiting_rooms"},{"kind":"resource","name":"cloudflare_zero_trust_access_short_lived_certificate","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}/ca"},{"kind":"data-source","name":"cloudflare_zero_trust_access_short_lived_certificate","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}/ca"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_short_lived_certificates","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/apps/ca"},{"kind":"resource","name":"cloudflare_zero_trust_access_mtls_certificate","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/certificates"},{"kind":"data-source","name":"cloudflare_zero_trust_access_mtls_certificate","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/certificates/{certificate_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_mtls_certificates","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/certificates"},{"kind":"resource","name":"cloudflare_zero_trust_access_mtls_hostname_settings","endpoint":"put /{accounts_or_zones}/{account_or_zone_id}/access/certificates/settings"},{"kind":"data-source","name":"cloudflare_zero_trust_access_mtls_hostname_settings","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/certificates/settings"},{"kind":"resource","name":"cloudflare_zero_trust_access_group","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/groups"},{"kind":"data-source","name":"cloudflare_zero_trust_access_group","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/groups/{group_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_groups","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/groups"},{"kind":"resource","name":"cloudflare_zero_trust_access_service_token","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens"},{"kind":"data-source","name":"cloudflare_zero_trust_access_service_token","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens/{service_token_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_service_tokens","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens"},{"kind":"resource","name":"cloudflare_zero_trust_access_identity_provider","endpoint":"post /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers"},{"kind":"data-source","name":"cloudflare_zero_trust_access_identity_provider","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers/{identity_provider_id}"},{"kind":"list-data-source","name":"cloudflare_zero_trust_access_identity_providers","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers"},{"kind":"resource","name":"cloudflare_zero_trust_organization","endpoint":"put /{accounts_or_zones}/{account_or_zone_id}/access/organizations"},{"kind":"data-source","name":"cloudflare_zero_trust_organization","endpoint":"get /{accounts_or_zones}/{account_or_zone_id}/access/organizations"}],"operations":{"get /accounts":{"operationId":"accounts-list-accounts","declarations":[{"kind":"list-data-source","name":"cloudflare_accounts","stainlessResource":"accounts","methodName":"list","snippet":"data \"cloudflare_accounts\" \"example_accounts\" {\n direction = \"desc\"\n name = \"example.com\"\n}\n","required":[],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"name","type":"String","description":"Name of the account."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Account name"},{"name":"type","type":"String"},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the account"},{"name":"managed_by","type":"Attributes","description":"Parent container details","children":[{"name":"parent_org_id","type":"String","description":"ID of the parent Organization, if one exists"},{"name":"parent_org_name","type":"String","description":"Name of the parent Organization, if one exists"}]},{"name":"settings","type":"Attributes","description":"Account settings","children":[{"name":"abuse_contact_email","type":"String","description":"Sets an abuse contact email to notify for abuse reports."},{"name":"enforce_twofactor","type":"Bool","description":"Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled"}]}]}]}]},"get /accounts/{}":{"operationId":"accounts-account-details","declarations":[{"kind":"data-source","name":"cloudflare_account","stainlessResource":"accounts","methodName":"get","snippet":"data \"cloudflare_account\" \"example_account\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[],"optional":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"name","type":"String","description":"Name of the account."}]}],"computed":[{"name":"id","type":"String","description":"Account identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the account"},{"name":"name","type":"String","description":"Account name"},{"name":"type","type":"String"},{"name":"managed_by","type":"Attributes","description":"Parent container details","children":[{"name":"parent_org_id","type":"String","description":"ID of the parent Organization, if one exists"},{"name":"parent_org_name","type":"String","description":"Name of the parent Organization, if one exists"}]},{"name":"settings","type":"Attributes","description":"Account settings","children":[{"name":"abuse_contact_email","type":"String","description":"Sets an abuse contact email to notify for abuse reports."},{"name":"enforce_twofactor","type":"Bool","description":"Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled"}]}]}]},"get /accounts/{}/access/ai-controls/mcp/portals":{"operationId":"mcp-portals-api-list-portals","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_portals","stainlessResource":"zero_trust.access.ai_controls.mcp.portals","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_portals\" \"example_zero_trust_access_ai_controls_mcp_portals\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search by id, name, hostname"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP portal."},{"name":"hostname","type":"String","description":"Hostname where the MCP portal is available."},{"name":"name","type":"String","description":"Display name for the MCP portal."},{"name":"servers","type":"Set[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"server_id","type":"String","description":"Unique identifier for the MCP server."},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"default_disabled","type":"Bool","description":"Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated_tools or updated_prompts."},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"on_behalf","type":"Bool"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"updated_prompts","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]},{"name":"updated_tools","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]}]},{"name":"allow_code_mode","type":"Bool","description":"Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.","deprecated":"Deprecated."},{"name":"code_mode","type":"String","description":"Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP portal."},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound MCP traffic through Zero Trust Secure Web Gateway."}]}]}]},"get /accounts/{}/access/ai-controls/mcp/portals/{}":{"operationId":"mcp-portals-api-fetch-gateways","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_portal","stainlessResource":"zero_trust.access.ai_controls.mcp.portals","methodName":"read","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_portal\" \"example_zero_trust_access_ai_controls_mcp_portal\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-portal\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String","description":"Unique identifier for the MCP portal."},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Search by id, name, hostname"}]}],"computed":[{"name":"allow_code_mode","type":"Bool","description":"Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.","deprecated":"Deprecated."},{"name":"code_mode","type":"String","description":"Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP portal."},{"name":"hostname","type":"String","description":"Hostname where the MCP portal is available."},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"name","type":"String","description":"Display name for the MCP portal."},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound MCP traffic through Zero Trust Secure Web Gateway."},{"name":"servers","type":"Set[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"server_id","type":"String","description":"Unique identifier for the MCP server."},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"default_disabled","type":"Bool","description":"Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated_tools or updated_prompts."},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"on_behalf","type":"Bool"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"updated_prompts","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]},{"name":"updated_tools","type":"List[Attributes]","children":[{"name":"name","type":"String"},{"name":"enabled","type":"Bool"},{"name":"portal_alias","type":"String"},{"name":"portal_description","type":"String"},{"name":"server_alias","type":"String"},{"name":"server_description","type":"String"}]}]}]}]},"get /accounts/{}/access/ai-controls/mcp/servers":{"operationId":"mcp-portals-api-list-servers","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_servers","stainlessResource":"zero_trust.access.ai_controls.mcp.servers","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_servers\" \"example_zero_trust_access_ai_controls_mcp_servers\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search by id, name"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"updated_prompts","type":"List[Attributes]","description":"Server-wide prompt capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Server-wide tool capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]}]}]}]},"get /accounts/{}/access/ai-controls/mcp/servers/{}":{"operationId":"mcp-portals-api-fetch-servers","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_ai_controls_mcp_server","stainlessResource":"zero_trust.access.ai_controls.mcp.servers","methodName":"read","snippet":"data \"cloudflare_zero_trust_access_ai_controls_mcp_server\" \"example_zero_trust_access_ai_controls_mcp_server\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-server\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String","description":"Unique identifier for the MCP server."},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Search by id, name"}]}],"computed":[{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server."},{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"error","type":"String"},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint."},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"name","type":"String","description":"Display name for the MCP server."},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]},{"name":"updated_prompts","type":"List[Attributes]","description":"Server-wide prompt capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Server-wide tool capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]}]}]},"get /accounts/{}/access/custom_pages":{"operationId":"access-custom-pages-list-custom-pages","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_custom_pages","stainlessResource":"zero_trust.access.custom_pages","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_custom_pages\" \"example_zero_trust_access_custom_pages\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"name","type":"String","description":"Custom page name."},{"name":"type","type":"String","description":"Custom page type."},{"name":"app_count","type":"Int64","description":"Number of apps the custom page is assigned to."},{"name":"contract_version","type":"Int64","description":"Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim."},{"name":"created_at","type":"Time"},{"name":"uid","type":"String","description":"UUID."},{"name":"updated_at","type":"Time"},{"name":"warnings","type":"List[Attributes]","description":"Advisory validation findings returned when creating or updating a template. Omitted when empty.","children":[{"name":"message","type":"String","description":"Human-readable description of the finding."},{"name":"tier","type":"String","description":"The validation tier that produced the finding (e.g. html, liquid)."},{"name":"ref","type":"String","description":"Optional pointer to the part of the template the finding refers to."}]}]}]}]},"get /accounts/{}/access/custom_pages/{}":{"operationId":"access-custom-pages-get-a-custom-page","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_custom_page","stainlessResource":"zero_trust.access.custom_pages","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_custom_page\" \"example_zero_trust_access_custom_page\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_page_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"custom_page_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"app_count","type":"Int64","description":"Number of apps the custom page is assigned to."},{"name":"contract_version","type":"Int64","description":"Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim."},{"name":"created_at","type":"Time"},{"name":"custom_html","type":"String","description":"Custom page HTML."},{"name":"name","type":"String","description":"Custom page name."},{"name":"type","type":"String","description":"Custom page type."},{"name":"uid","type":"String","description":"UUID."},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/access/keys":{"operationId":"access-key-configuration-get-the-access-key-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_key_configuration","stainlessResource":"zero_trust.access.keys","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_key_configuration\" \"example_zero_trust_access_key_configuration\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"days_until_next_rotation","type":"Float64","description":"The number of days until the next key rotation."},{"name":"key_rotation_interval_days","type":"Float64","description":"The number of days between key rotations."},{"name":"last_key_rotation_at","type":"Time","description":"The timestamp of the previous key rotation."}]}]},"get /accounts/{}/access/policies":{"operationId":"access-policies-list-access-reusable-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_policies","stainlessResource":"zero_trust.access.policies","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_policies\" \"example_zero_trust_access_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The UUID of the policy"},{"name":"account_id","type":"String","description":"Identifier."},{"name":"app_count","type":"Int64","description":"Number of access applications currently using this policy."},{"name":"approval_groups","type":"Set[Attributes]","description":"Administrators who can approve a temporary authentication request.","children":[{"name":"approvals_needed","type":"Float64","description":"The number of approvals needed to obtain access."},{"name":"email_addresses","type":"List[String]","description":"A list of emails that can approve the access request."},{"name":"email_list_uuid","type":"String","description":"The UUID of an re-usable email list."}]},{"name":"approval_required","type":"Bool","description":"Requires the user to request access from an administrator at the start of each session."},{"name":"connection_rules","type":"Attributes","description":"The rules that define how users may connect to targets secured by your application.","children":[{"name":"rdp","type":"Attributes","description":"The RDP-specific rules that define clipboard behavior for RDP connections.","children":[{"name":"allowed_clipboard_local_to_remote_formats","type":"List[String]","description":"Clipboard formats allowed when copying from local machine to remote RDP session."},{"name":"allowed_clipboard_remote_to_local_formats","type":"List[String]","description":"Clipboard formats allowed when copying from remote RDP session to local machine."}]}]},{"name":"created_at","type":"Time"},{"name":"decision","type":"String","description":"The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action."},{"name":"exclude","type":"Set[Attributes]","description":"Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"include","type":"Set[Attributes]","description":"Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"isolation_required","type":"Bool","description":"Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature."},{"name":"mfa_config","type":"Attributes","description":"Configures multi-factor authentication (MFA) settings.","children":[{"name":"allowed_authenticators","type":"List[String]","description":"Lists the MFA methods that users can authenticate with."},{"name":"mfa_disabled","type":"Bool","description":"Indicates whether to disable MFA for this resource. This option is available at the application and policy level."},{"name":"session_duration","type":"String","description":"Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`."}]},{"name":"name","type":"String","description":"The name of the Access policy."},{"name":"purpose_justification_prompt","type":"String","description":"A custom message that will appear on the purpose justification screen."},{"name":"purpose_justification_required","type":"Bool","description":"Require users to enter a justification when they log in to the application."},{"name":"require","type":"Set[Attributes]","description":"Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"reusable","type":"Bool"},{"name":"session_duration","type":"String","description":"The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h."},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/access/policies/{}":{"operationId":"access-policies-get-an-access-reusable-policy","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_policy","stainlessResource":"zero_trust.access.policies","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_policy\" \"example_zero_trust_access_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"policy_id","type":"String","description":"The UUID of the policy"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The UUID of the policy"},{"name":"app_count","type":"Int64","description":"Number of access applications currently using this policy."},{"name":"approval_required","type":"Bool","description":"Requires the user to request access from an administrator at the start of each session."},{"name":"created_at","type":"Time"},{"name":"decision","type":"String","description":"The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action."},{"name":"isolation_required","type":"Bool","description":"Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature."},{"name":"name","type":"String","description":"The name of the Access policy."},{"name":"purpose_justification_prompt","type":"String","description":"A custom message that will appear on the purpose justification screen."},{"name":"purpose_justification_required","type":"Bool","description":"Require users to enter a justification when they log in to the application."},{"name":"reusable","type":"Bool"},{"name":"session_duration","type":"String","description":"The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h."},{"name":"updated_at","type":"Time"},{"name":"approval_groups","type":"Set[Attributes]","description":"Administrators who can approve a temporary authentication request.","children":[{"name":"approvals_needed","type":"Float64","description":"The number of approvals needed to obtain access."},{"name":"email_addresses","type":"List[String]","description":"A list of emails that can approve the access request."},{"name":"email_list_uuid","type":"String","description":"The UUID of an re-usable email list."}]},{"name":"connection_rules","type":"Attributes","description":"The rules that define how users may connect to targets secured by your application.","children":[{"name":"rdp","type":"Attributes","description":"The RDP-specific rules that define clipboard behavior for RDP connections.","children":[{"name":"allowed_clipboard_local_to_remote_formats","type":"List[String]","description":"Clipboard formats allowed when copying from local machine to remote RDP session."},{"name":"allowed_clipboard_remote_to_local_formats","type":"List[String]","description":"Clipboard formats allowed when copying from remote RDP session to local machine."}]}]},{"name":"exclude","type":"Set[Attributes]","description":"Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"include","type":"Set[Attributes]","description":"Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"mfa_config","type":"Attributes","description":"Configures multi-factor authentication (MFA) settings.","children":[{"name":"allowed_authenticators","type":"List[String]","description":"Lists the MFA methods that users can authenticate with."},{"name":"mfa_disabled","type":"Bool","description":"Indicates whether to disable MFA for this resource. This option is available at the application and policy level."},{"name":"session_duration","type":"String","description":"Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`."}]},{"name":"require","type":"Set[Attributes]","description":"Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]}]}]},"get /accounts/{}/access/tags":{"operationId":"access-tags-list-tags","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_tags","stainlessResource":"zero_trust.access.tags","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_tags\" \"example_zero_trust_access_tags\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The name of the tag"},{"name":"name","type":"String","description":"The name of the tag"},{"name":"app_count","type":"Int64","description":"The number of applications that have this tag"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/access/tags/{}":{"operationId":"access-tags-get-a-tag","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_tag","stainlessResource":"zero_trust.access.tags","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_tag\" \"example_zero_trust_access_tag\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tag_name = \"engineers\"\n}\n","required":[{"name":"tag_name","type":"String","description":"The name of the tag"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The name of the tag"},{"name":"app_count","type":"Int64","description":"The number of applications that have this tag"},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"The name of the tag"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/addressing/address_maps":{"operationId":"ip-address-management-address-maps-list-address-maps","declarations":[{"kind":"list-data-source","name":"cloudflare_address_maps","stainlessResource":"addressing.address_maps","methodName":"list","snippet":"data \"cloudflare_address_maps\" \"example_address_maps\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of an Address Map."},{"name":"can_delete","type":"Bool","description":"If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps."},{"name":"can_modify_ips","type":"Bool","description":"If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps."},{"name":"created_at","type":"Time"},{"name":"default_sni","type":"String","description":"If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account."},{"name":"description","type":"String","description":"An optional description field which may be used to describe the types of IPs or zones on the map."},{"name":"enabled","type":"Bool","description":"Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled."},{"name":"modified_at","type":"Time"}]}]}]},"get /accounts/{}/addressing/address_maps/{}":{"operationId":"ip-address-management-address-maps-address-map-details","declarations":[{"kind":"data-source","name":"cloudflare_address_map","stainlessResource":"addressing.address_maps","methodName":"get","snippet":"data \"cloudflare_address_map\" \"example_address_map\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n address_map_id = \"055817b111884e0227e1be16a0be6ee0\"\n}\n","required":[{"name":"address_map_id","type":"String","description":"Identifier of an Address Map."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of an Address Map."},{"name":"can_delete","type":"Bool","description":"If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps."},{"name":"can_modify_ips","type":"Bool","description":"If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps."},{"name":"created_at","type":"Time"},{"name":"default_sni","type":"String","description":"If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account."},{"name":"description","type":"String","description":"An optional description field which may be used to describe the types of IPs or zones on the map."},{"name":"enabled","type":"Bool","description":"Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled."},{"name":"modified_at","type":"Time"},{"name":"ips","type":"List[Attributes]","description":"The set of IPs on the Address Map.","children":[{"name":"created_at","type":"Time"},{"name":"ip","type":"String","description":"An IPv4 or IPv6 address."}]},{"name":"memberships","type":"List[Attributes]","description":"Zones and Accounts which will be assigned IPs on this Address Map. A zone membership will take priority over an account membership.","children":[{"name":"can_delete","type":"Bool","description":"Controls whether the membership can be deleted via the API or not."},{"name":"created_at","type":"Time"},{"name":"identifier","type":"String","description":"The identifier for the membership (eg. a zone or account tag)."},{"name":"kind","type":"String","description":"The type of the membership."}]}]}]},"get /accounts/{}/addressing/prefixes":{"operationId":"ip-address-management-prefixes-list-prefixes","declarations":[{"kind":"list-data-source","name":"cloudflare_byo_ip_prefixes","stainlessResource":"addressing.prefixes","methodName":"list","snippet":"data \"cloudflare_byo_ip_prefixes\" \"example_byo_ip_prefixes\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of an IP Prefix."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."},{"name":"advertised","type":"Bool","description":"Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"advertised_modified_at","type":"Time","description":"Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"approved","type":"String","description":"Approval state of the prefix (P = pending, V = active)."},{"name":"asn","type":"Int64","description":"Autonomous System Number (ASN) the prefix will be advertised under."},{"name":"cidr","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"created_at","type":"Time"},{"name":"delegate_loa_creation","type":"Bool","description":"Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner."},{"name":"description","type":"String","description":"Description of the prefix."},{"name":"irr_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"loa_document_id","type":"String","description":"Identifier for the uploaded LOA document."},{"name":"modified_at","type":"Time"},{"name":"on_demand_enabled","type":"Bool","description":"Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"on_demand_locked","type":"Bool","description":"Whether advertisement status of the prefix is locked, meaning it cannot be changed.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"ownership_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"ownership_validation_token","type":"String","description":"Token provided to demonstrate ownership of the prefix."},{"name":"rpki_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."}]}]}]},"get /accounts/{}/addressing/prefixes/{}":{"operationId":"ip-address-management-prefixes-prefix-details","declarations":[{"kind":"data-source","name":"cloudflare_byo_ip_prefix","stainlessResource":"addressing.prefixes","methodName":"get","snippet":"data \"cloudflare_byo_ip_prefix\" \"example_byo_ip_prefix\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n prefix_id = \"2af39739cc4e3b5910c918468bb89828\"\n}\n","required":[{"name":"prefix_id","type":"String","description":"Identifier of an IP Prefix."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of an IP Prefix."},{"name":"advertised","type":"Bool","description":"Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"advertised_modified_at","type":"Time","description":"Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"approved","type":"String","description":"Approval state of the prefix (P = pending, V = active)."},{"name":"asn","type":"Int64","description":"Autonomous System Number (ASN) the prefix will be advertised under."},{"name":"cidr","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"created_at","type":"Time"},{"name":"delegate_loa_creation","type":"Bool","description":"Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner."},{"name":"description","type":"String","description":"Description of the prefix."},{"name":"irr_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"loa_document_id","type":"String","description":"Identifier for the uploaded LOA document."},{"name":"modified_at","type":"Time"},{"name":"on_demand_enabled","type":"Bool","description":"Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"on_demand_locked","type":"Bool","description":"Whether advertisement status of the prefix is locked, meaning it cannot be changed.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"ownership_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"ownership_validation_token","type":"String","description":"Token provided to demonstrate ownership of the prefix."},{"name":"rpki_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."}]}]},"get /accounts/{}/ai-gateway/gateways":{"operationId":"aig-config-list-gateway","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_gateways","stainlessResource":"ai_gateway","methodName":"list","snippet":"data \"cloudflare_ai_gateways\" \"example_ai_gateways\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search by id"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier of the AI Gateway within the account."},{"name":"cache_invalidate_on_update","type":"Bool"},{"name":"cache_ttl","type":"Int64"},{"name":"collect_logs","type":"Bool"},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"rate_limiting_interval","type":"Int64"},{"name":"rate_limiting_limit","type":"Int64"},{"name":"authentication","type":"Bool"},{"name":"byok_only","type":"Bool","description":"Requires customer-provided provider credentials and prevents fallback to Unified Billing."},{"name":"dlp","type":"Attributes","children":[{"name":"action","type":"String"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"},{"name":"policies","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"action","type":"String"},{"name":"check","type":"List[String]"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"}]}]},{"name":"guardrails","type":"Attributes","children":[{"name":"prompt","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]},{"name":"response","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]}]},{"name":"is_default","type":"Bool"},{"name":"log_classification","type":"Bool"},{"name":"log_management","type":"Int64"},{"name":"log_management_strategy","type":"String"},{"name":"logpush","type":"Bool"},{"name":"logpush_public_key","type":"String"},{"name":"otel","type":"List[Attributes]","children":[{"name":"headers","type":"Map[String]"},{"name":"url","type":"String"},{"name":"authorization","type":"String"},{"name":"content_type","type":"String"}]},{"name":"rate_limiting_technique","type":"String"},{"name":"retry_backoff","type":"String","description":"Backoff strategy for retry delays"},{"name":"retry_delay","type":"Int64","description":"Delay between retry attempts in milliseconds (0-60000)"},{"name":"retry_max_attempts","type":"Int64","description":"Maximum number of retry attempts for failed requests (1-5)"},{"name":"spend_limits","type":"Attributes","children":[{"name":"enabled","type":"Bool"},{"name":"rules","type":"List[Attributes]","children":[{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Int64"},{"name":"id","type":"String"},{"name":"enabled","type":"Bool"},{"name":"metadata","type":"Map[Attributes]","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"model","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"ai_gateway_provider","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"technique","type":"String"}]}]},{"name":"store_id","type":"String"},{"name":"stripe","type":"Attributes","children":[{"name":"authorization","type":"String"},{"name":"usage_events","type":"List[Attributes]","children":[{"name":"payload","type":"String"}]}]},{"name":"workers_ai_billing_mode","type":"String","description":"Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway."},{"name":"zdr","type":"Bool"}]}]}]},"get /accounts/{}/ai-gateway/gateways/{}":{"operationId":"aig-config-fetch-gateway","declarations":[{"kind":"data-source","name":"cloudflare_ai_gateway","stainlessResource":"ai_gateway","methodName":"get","snippet":"data \"cloudflare_ai_gateway\" \"example_ai_gateway\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n id = \"my-gateway\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String","description":"Unique identifier of the AI Gateway within the account."},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Search by id"}]}],"computed":[{"name":"authentication","type":"Bool"},{"name":"byok_only","type":"Bool","description":"Requires customer-provided provider credentials and prevents fallback to Unified Billing."},{"name":"cache_invalidate_on_update","type":"Bool"},{"name":"cache_ttl","type":"Int64"},{"name":"collect_logs","type":"Bool"},{"name":"created_at","type":"Time"},{"name":"is_default","type":"Bool"},{"name":"log_classification","type":"Bool"},{"name":"log_management","type":"Int64"},{"name":"log_management_strategy","type":"String"},{"name":"logpush","type":"Bool"},{"name":"logpush_public_key","type":"String"},{"name":"modified_at","type":"Time"},{"name":"rate_limiting_interval","type":"Int64"},{"name":"rate_limiting_limit","type":"Int64"},{"name":"rate_limiting_technique","type":"String"},{"name":"retry_backoff","type":"String","description":"Backoff strategy for retry delays"},{"name":"retry_delay","type":"Int64","description":"Delay between retry attempts in milliseconds (0-60000)"},{"name":"retry_max_attempts","type":"Int64","description":"Maximum number of retry attempts for failed requests (1-5)"},{"name":"store_id","type":"String"},{"name":"workers_ai_billing_mode","type":"String","description":"Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway."},{"name":"zdr","type":"Bool"},{"name":"dlp","type":"Attributes","children":[{"name":"action","type":"String"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"},{"name":"policies","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"action","type":"String"},{"name":"check","type":"List[String]"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"}]}]},{"name":"guardrails","type":"Attributes","children":[{"name":"prompt","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]},{"name":"response","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]}]},{"name":"otel","type":"List[Attributes]","children":[{"name":"headers","type":"Map[String]"},{"name":"url","type":"String"},{"name":"authorization","type":"String"},{"name":"content_type","type":"String"}]},{"name":"spend_limits","type":"Attributes","children":[{"name":"enabled","type":"Bool"},{"name":"rules","type":"List[Attributes]","children":[{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Int64"},{"name":"id","type":"String"},{"name":"enabled","type":"Bool"},{"name":"metadata","type":"Map[Attributes]","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"model","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"ai_gateway_provider","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"technique","type":"String"}]}]},{"name":"stripe","type":"Attributes","children":[{"name":"authorization","type":"String"},{"name":"usage_events","type":"List[Attributes]","children":[{"name":"payload","type":"String"}]}]}]}]},"get /accounts/{}/ai-gateway/gateways/{}/routes/{}":{"operationId":"aig-config-get-gateway-dynamic-route","declarations":[{"kind":"data-source","name":"cloudflare_ai_gateway_dynamic_routing","stainlessResource":"ai_gateway.dynamic_routing","methodName":"get","snippet":"data \"cloudflare_ai_gateway_dynamic_routing\" \"example_ai_gateway_dynamic_routing\" {\n account_id = \"0d37909e38d3e99c29fa2cd343ac421a\"\n gateway_id = \"54442216\"\n id = \"54442216\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"gateway_id","type":"String"},{"name":"id","type":"String"}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String"},{"name":"deployment","type":"Attributes","children":[{"name":"created_at","type":"String"},{"name":"deployment_id","type":"String"},{"name":"version_id","type":"String"}]},{"name":"elements","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"outputs","type":"Attributes","children":[{"name":"next","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"false","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"true","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"element_id","type":"String"},{"name":"fallback","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"success","type":"Attributes","children":[{"name":"element_id","type":"String"}]}]},{"name":"type","type":"String"},{"name":"properties","type":"Attributes","children":[{"name":"conditions","type":"unknown"},{"name":"key","type":"String"},{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Float64"},{"name":"model","type":"String"},{"name":"ai_gateway_dynamic_routing_provider","type":"String"},{"name":"retries","type":"Float64"},{"name":"timeout","type":"Float64"}]}]},{"name":"version","type":"Attributes","children":[{"name":"active","type":"String"},{"name":"created_at","type":"String"},{"name":"data","type":"String"},{"name":"version_id","type":"String"},{"name":"is_valid","type":"Bool"}]}]}]},"get /accounts/{}/ai-search/instances":{"operationId":"ai-search-list-instances","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_search_instances","stainlessResource":"ai_search.instances","methodName":"list","snippet":"data \"cloudflare_ai_search_instances\" \"example_ai_search_instances\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n hostname = \"x\"\n namespace = \"namespace\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"hostname","type":"String","description":"Filter by exact Search for Agents hostname (case-insensitive)."},{"name":"namespace","type":"String","description":"Filter by namespace."},{"name":"search","type":"String","description":"Filter instances whose id contains this string (case-insensitive)."},{"name":"order_by","type":"String","description":"Field to order results by."},{"name":"order_by_direction","type":"String","description":"Order direction."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"ai_gateway_id","type":"String"},{"name":"aisearch_model","type":"String"},{"name":"cache","type":"Bool"},{"name":"cache_threshold","type":"String"},{"name":"cache_ttl","type":"Float64"},{"name":"chunk","type":"Bool"},{"name":"chunk_overlap","type":"Float64"},{"name":"chunk_size","type":"Float64"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"custom_metadata","type":"List[Attributes]","children":[{"name":"data_type","type":"String"},{"name":"field_name","type":"String"}]},{"name":"embedding_model","type":"String"},{"name":"enable","type":"Bool"},{"name":"engine_version","type":"Float64"},{"name":"fusion_method","type":"String"},{"name":"hybrid_search_enabled","type":"Bool"},{"name":"index_method","type":"Attributes","children":[{"name":"keyword","type":"Bool"},{"name":"vector","type":"Bool"}]},{"name":"indexing_options","type":"Attributes","children":[{"name":"keyword_tokenizer","type":"String"},{"name":"use_ocr","type":"Bool"}]},{"name":"last_activity","type":"Time"},{"name":"max_num_results","type":"Float64"},{"name":"metadata","type":"Attributes","children":[{"name":"created_from_aisearch_wizard","type":"Bool"},{"name":"worker_domain","type":"String"}]},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"namespace","type":"String"},{"name":"paused","type":"Bool"},{"name":"public_endpoint_id","type":"String"},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool"}]},{"name":"custom_domains","type":"List[String]"},{"name":"default_domain_enabled","type":"Bool"},{"name":"enabled","type":"Bool"},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool"}]}]},{"name":"reranking","type":"Bool"},{"name":"reranking_model","type":"String"},{"name":"retrieval_options","type":"Attributes","children":[{"name":"boost_by","type":"List[Attributes]","children":[{"name":"field","type":"String"},{"name":"data_type","type":"String"},{"name":"direction","type":"String"}]},{"name":"keyword_match_mode","type":"String"}]},{"name":"rewrite_model","type":"String"},{"name":"rewrite_query","type":"Bool"},{"name":"score_threshold","type":"Float64"},{"name":"source","type":"String"},{"name":"source_params","type":"Attributes","children":[{"name":"exclude_items","type":"List[String]"},{"name":"include_items","type":"List[String]"},{"name":"prefix","type":"String"},{"name":"r2_jurisdiction","type":"String"},{"name":"web_crawler","type":"Attributes","children":[{"name":"discover_options","type":"Attributes","children":[{"name":"depth","type":"Float64"},{"name":"include_external_links","type":"Bool"},{"name":"include_subdomains","type":"Bool"},{"name":"limit","type":"Float64","description":"Maximum number of pages to crawl. New values are capped at 100000; instances configured before that cap may report a higher stored value, which the crawler clamps at run time."},{"name":"max_age","type":"Float64"},{"name":"source","type":"String"}]},{"name":"parse_options","type":"Attributes","children":[{"name":"content_selector","type":"List[Attributes]","children":[{"name":"path","type":"String"},{"name":"selector","type":"String"}]},{"name":"include_headers","type":"Map[String]"},{"name":"include_images","type":"Bool"},{"name":"specific_sitemaps","type":"List[String]"},{"name":"use_browser_rendering","type":"Bool"}]},{"name":"parse_type","type":"String"}]}]},{"name":"status","type":"String"},{"name":"summarization","type":"Bool"},{"name":"summarization_model","type":"String"},{"name":"sync_interval","type":"Float64"},{"name":"system_prompt_aisearch","type":"String"},{"name":"system_prompt_index_summarization","type":"String"},{"name":"system_prompt_rewrite_query","type":"String"},{"name":"token_id","type":"String"},{"name":"type","type":"String"}]}]}]},"get /accounts/{}/ai-search/instances/{}":{"operationId":"ai-search-fetch-instance","declarations":[{"kind":"data-source","name":"cloudflare_ai_search_instance","stainlessResource":"ai_search.instances","methodName":"read","snippet":"data \"cloudflare_ai_search_instance\" \"example_ai_search_instance\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n id = \"my-ai-search\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"hostname","type":"String","description":"Filter by exact Search for Agents hostname (case-insensitive)."},{"name":"namespace","type":"String","description":"Filter by namespace."},{"name":"order_by","type":"String","description":"Field to order results by."},{"name":"order_by_direction","type":"String","description":"Order direction."},{"name":"search","type":"String","description":"Filter instances whose id contains this string (case-insensitive)."}]}],"computed":[{"name":"ai_gateway_id","type":"String"},{"name":"aisearch_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"cache","type":"Bool"},{"name":"cache_threshold","type":"String"},{"name":"cache_ttl","type":"Float64","description":"Cache entry TTL in seconds. Allowed values: 600 (10min), 1800 (30min), 3600 (1h), 7200 (2h), 21600 (6h), 43200 (12h), 86400 (24h), 172800 (48h), 259200 (72h), 518400 (6d)."},{"name":"chunk_overlap","type":"Int64"},{"name":"chunk_size","type":"Int64"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"embedding_model","type":"String"},{"name":"enable","type":"Bool"},{"name":"engine_version","type":"Float64"},{"name":"fusion_method","type":"String"},{"name":"hybrid_search_enabled","type":"Bool","description":"Deprecated — use index_method instead. Defaults to true for new instances; set false to create a vector-only instance.","deprecated":"Deprecated."},{"name":"last_activity","type":"Time"},{"name":"max_num_results","type":"Int64"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"namespace","type":"String"},{"name":"paused","type":"Bool"},{"name":"public_endpoint_id","type":"String"},{"name":"reranking","type":"Bool"},{"name":"reranking_model","type":"String"},{"name":"rewrite_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"rewrite_query","type":"Bool"},{"name":"score_threshold","type":"Float64"},{"name":"source","type":"String"},{"name":"status","type":"String"},{"name":"sync_interval","type":"Float64","description":"Interval between automatic syncs, in seconds. Allowed values: 900 (15min), 1800 (30min), 3600 (1h), 7200 (2h), 14400 (4h), 21600 (6h), 43200 (12h), 86400 (24h)."},{"name":"token_id","type":"String"},{"name":"type","type":"String","description":"Source type. When omitted or null with a non-blank source, HTTP(S) URLs infer web-crawler and existing R2 bucket names infer r2. A missing or blank source without a type uses managed upload-only storage."},{"name":"custom_metadata","type":"List[Attributes]","children":[{"name":"data_type","type":"String"},{"name":"field_name","type":"String"}]},{"name":"index_method","type":"Attributes","description":"Controls which storage backends are used during indexing. Defaults to vector and keyword indexing for new instances.","children":[{"name":"keyword","type":"Bool","description":"Enable keyword (BM25) storage backend."},{"name":"vector","type":"Bool","description":"Enable vector (embedding) storage backend."}]},{"name":"indexing_options","type":"Attributes","children":[{"name":"keyword_tokenizer","type":"String","description":"Tokenizer used for keyword search indexing. porter provides word-level tokenization with Porter stemming (good for natural language queries). trigram enables character-level substring matching (good for partial matches, code, identifiers). Changing this triggers a full re-index. Defaults to porter."},{"name":"use_ocr","type":"Bool","description":"Enables OCR ingestion for PDFs and images. Changing this triggers a full re-index. Defaults to false."}]},{"name":"metadata","type":"Attributes","children":[{"name":"created_from_aisearch_wizard","type":"Bool"},{"name":"worker_domain","type":"String"}]},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]},{"name":"retrieval_options","type":"Attributes","children":[{"name":"boost_by","type":"List[Attributes]","description":"Metadata fields to boost search results by. Each entry specifies a metadata field and an optional direction. Direction defaults to 'asc' for numeric/datetime fields and 'exists' for text/boolean fields. Fields must match 'timestamp' or a defined custom_metadata field.","children":[{"name":"field","type":"String","description":"Metadata field name to boost by. Use 'timestamp' for document freshness, or any custom_metadata field. Numeric and datetime fields support all four directions (asc, desc, exists, not_exists); text/boolean fields only support exists/not_exists."},{"name":"direction","type":"String","description":"Boost direction. 'desc' = higher values rank higher (e.g. newer timestamps). 'asc' = lower values rank higher. 'exists' = boost chunks that have the field. 'not_exists' = boost chunks that lack the field. Optional — defaults to 'asc' for numeric/datetime fields, 'exists' for text/boolean fields."}]},{"name":"keyword_match_mode","type":"String","description":"Controls which documents are candidates for BM25 scoring. 'and' restricts candidates to documents containing all query terms; 'or' includes any document containing at least one term, ranked by BM25 relevance. When omitted on an update, the existing stored value is preserved; when never set, search falls back to 'and'."}]},{"name":"source_params","type":"Attributes","children":[{"name":"exclude_items","type":"List[String]","description":"List of path patterns to exclude. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /admin/** matches /admin/users and /admin/settings/advanced). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"include_items","type":"List[String]","description":"List of path patterns to include. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /blog/** matches /blog/post and /blog/2024/post). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"prefix","type":"String"},{"name":"r2_jurisdiction","type":"String"},{"name":"web_crawler","type":"Attributes","children":[{"name":"discover_options","type":"Attributes","description":"Options for parse_type 'discover', where Browser Run discovers URLs by link following and sitemaps. Ignored for 'sitemap'.","children":[{"name":"depth","type":"Float64","description":"Maximum link-follow depth from the seed URL."},{"name":"include_external_links","type":"Bool","description":"Follow links that point outside the source domain. Must stay `false` — discover crawls are restricted to the zone you own."},{"name":"include_subdomains","type":"Bool","description":"Follow links to subdomains of the source host."},{"name":"limit","type":"Float64","description":"Maximum number of pages to crawl (1-100000)."},{"name":"max_age","type":"Float64","description":"Maximum content age in seconds to accept (0–604800)."},{"name":"source","type":"String","description":"Where the crawler looks for URLs: 'sitemaps' reads sitemap XML only, 'links' follows page links only, 'all' does both."}]},{"name":"parse_options","type":"Attributes","children":[{"name":"content_selector","type":"List[Attributes]","description":"List of path-to-selector mappings for extracting specific content from crawled pages. Each entry pairs a URL glob pattern with a CSS selector. The first matching path wins. Only the matched HTML fragment is stored and indexed. Omit the field to disable content selection — empty arrays are rejected.","children":[{"name":"path","type":"String","description":"Glob pattern to match against the page URL path. Uses standard glob syntax: * matches within a segment, ** crosses directories."},{"name":"selector","type":"String","description":"CSS selector to extract content from pages matching the path pattern. Must not contain disallowed characters (;, `, $, {, }, \\). Must target a single element; if multiple elements match, the selector is ignored and the full page is used."}]},{"name":"include_headers","type":"Map[String]","description":"Up to 5 custom HTTP headers sent with each crawl request. Names must be RFC-7230 token characters (no spaces, colons, or control characters); values must be HTAB + printable ASCII (no CR/LF)."},{"name":"include_images","type":"Bool"},{"name":"specific_sitemaps","type":"List[String]","description":"List of specific sitemap URLs to use for crawling. Only valid when parse_type is 'sitemap'."},{"name":"use_browser_rendering","type":"Bool"}]},{"name":"parse_type","type":"String","description":"How URLs are discovered. 'sitemap' reads XML sitemaps; 'discover' follows links recursively and requires the source to be a Verified zone on this account."}]}]}]}]},"get /accounts/{}/ai-search/namespaces":{"operationId":"ai-search-list-namespaces","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_search_namespaces","stainlessResource":"ai_search.namespaces","methodName":"list","snippet":"data \"cloudflare_ai_search_namespaces\" \"example_ai_search_namespaces\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n search = \"prod\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Filter namespaces whose name or description contains this string (case-insensitive)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"description","type":"String","description":"Optional description for the namespace. Max 256 characters."},{"name":"public_endpoint_id","type":"String"},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"instances_allowed","type":"List[String]","description":"Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit."},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]}]}]}]},"get /accounts/{}/ai-search/namespaces/{}":{"operationId":"ai-search-fetch-namespace","declarations":[{"kind":"data-source","name":"cloudflare_ai_search_namespace","stainlessResource":"ai_search.namespaces","methodName":"read","snippet":"data \"cloudflare_ai_search_namespace\" \"example_ai_search_namespace\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n name = \"production\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"name","type":"String"}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Optional description for the namespace. Max 256 characters."},{"name":"public_endpoint_id","type":"String"},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"instances_allowed","type":"List[String]","description":"Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit."},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]}]}]},"get /accounts/{}/ai-search/tokens":{"operationId":"ai-search-list-tokens","declarations":[{"kind":"list-data-source","name":"cloudflare_ai_search_tokens","stainlessResource":"ai_search.tokens","methodName":"list","snippet":"data \"cloudflare_ai_search_tokens\" \"example_ai_search_tokens\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n search = \"my-token\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Filter tokens whose name contains this string (case-insensitive)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"cf_api_id","type":"String"},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String"},{"name":"created_by","type":"String"},{"name":"enabled","type":"Bool"},{"name":"legacy","type":"Bool"},{"name":"modified_by","type":"String"}]}]}]},"get /accounts/{}/ai-search/tokens/{}":{"operationId":"ai-search-fetch-tokens","declarations":[{"kind":"data-source","name":"cloudflare_ai_search_token","stainlessResource":"ai_search.tokens","methodName":"read","snippet":"data \"cloudflare_ai_search_token\" \"example_ai_search_token\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n id = \"62af0db3-c410-40b2-9ee3-0e93f6dd1de0\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Filter tokens whose name contains this string (case-insensitive)."}]}],"computed":[{"name":"cf_api_id","type":"String"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"enabled","type":"Bool"},{"name":"legacy","type":"Bool"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"name","type":"String"}]}]},"get /accounts/{}/alerting/v3/destinations/webhooks":{"operationId":"notification-webhooks-list-webhooks","declarations":[{"kind":"list-data-source","name":"cloudflare_notification_policy_webhooks_list","stainlessResource":"alerting.destinations.webhooks","methodName":"list","snippet":"data \"cloudflare_notification_policy_webhooks_list\" \"example_notification_policy_webhooks_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account id"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of a webhook"},{"name":"created_at","type":"Time","description":"Timestamp of when the webhook destination was created."},{"name":"last_failure","type":"Time","description":"Timestamp of the last time an attempt to dispatch a notification to this webhook failed."},{"name":"last_success","type":"Time","description":"Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook."},{"name":"name","type":"String","description":"The name of the webhook destination. This will be included in the request body when you receive a webhook notification."},{"name":"secret","type":"String","description":"Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.","sensitive":true},{"name":"type","type":"String","description":"Type of webhook endpoint."},{"name":"url","type":"String","description":"The POST endpoint to call when dispatching a notification."}]}]}]},"get /accounts/{}/alerting/v3/destinations/webhooks/{}":{"operationId":"notification-webhooks-get-a-webhook","declarations":[{"kind":"data-source","name":"cloudflare_notification_policy_webhooks","stainlessResource":"alerting.destinations.webhooks","methodName":"get","snippet":"data \"cloudflare_notification_policy_webhooks\" \"example_notification_policy_webhooks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n webhook_id = \"b115d5ec15c641ee8b7692c449b5227b\"\n}\n","required":[{"name":"webhook_id","type":"String","description":"The unique identifier of a webhook"},{"name":"account_id","type":"String","description":"The account id"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique identifier of a webhook"},{"name":"created_at","type":"Time","description":"Timestamp of when the webhook destination was created."},{"name":"last_failure","type":"Time","description":"Timestamp of the last time an attempt to dispatch a notification to this webhook failed."},{"name":"last_success","type":"Time","description":"Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook."},{"name":"name","type":"String","description":"The name of the webhook destination. This will be included in the request body when you receive a webhook notification."},{"name":"secret","type":"String","description":"Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.","sensitive":true},{"name":"type","type":"String","description":"Type of webhook endpoint."},{"name":"url","type":"String","description":"The POST endpoint to call when dispatching a notification."}]}]},"get /accounts/{}/alerting/v3/policies":{"operationId":"notification-policies-list-notification-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_notification_policies","stainlessResource":"alerting.policies","methodName":"list","snippet":"data \"cloudflare_notification_policies\" \"example_notification_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account id"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of a notification policy"},{"name":"alert_interval","type":"String","description":"Optional specification of how often to re-alert from the same incident, not support on all alert types."},{"name":"alert_type","type":"String","description":"Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values."},{"name":"created","type":"Time"},{"name":"description","type":"String","description":"Optional description for the Notification policy."},{"name":"enabled","type":"Bool","description":"Whether or not the Notification policy is enabled."},{"name":"filters","type":"Attributes","description":"Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.","children":[{"name":"actions","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"affected_asns","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"affected_components","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"affected_locations","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"airport_code","type":"List[String]","description":"Used for configuring maintenance_event_notification"},{"name":"alert_trigger_preferences","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"alert_trigger_preferences_value","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"enabled","type":"List[String]","description":"Used for configuring load_balancing_pool_enablement_alert"},{"name":"environment","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event_source","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"event_type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"group_by","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"health_check_id","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"incident_impact","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"input_id","type":"List[String]","description":"Used for configuring stream_live_notifications"},{"name":"insight_class","type":"List[String]","description":"Used for configuring security_insights_alert"},{"name":"limit","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"logo_tag","type":"List[String]","description":"Used for configuring logo_match_alert"},{"name":"megabits_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"new_health","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"new_status","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"packets_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"pool_id","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"pop_names","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"product","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"project_id","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"protocol","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"query_tag","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"requests_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"selectors","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"services","type":"List[String]","description":"Used for configuring clickhouse_alert_fw_ent_anomaly"},{"name":"slo","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"status","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"target_hostname","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"target_ip","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"target_zone_name","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"token_id","type":"List[String]","description":"Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens."},{"name":"traffic_exclusions","type":"List[String]","description":"Used for configuring traffic_anomalies_alert"},{"name":"tunnel_id","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"tunnel_name","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"where","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"zones","type":"List[String]","description":"Usage depends on specific alert type"}]},{"name":"mechanisms","type":"Attributes","description":"List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.","children":[{"name":"email","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The email address"}]},{"name":"pagerduty","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]},{"name":"webhooks","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]}]},{"name":"modified","type":"Time"},{"name":"name","type":"String","description":"Name of the policy."}]}]}]},"get /accounts/{}/alerting/v3/policies/{}":{"operationId":"notification-policies-get-a-notification-policy","declarations":[{"kind":"data-source","name":"cloudflare_notification_policy","stainlessResource":"alerting.policies","methodName":"get","snippet":"data \"cloudflare_notification_policy\" \"example_notification_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"0da2b59ef118439d8097bdfb215203c9\"\n}\n","required":[{"name":"policy_id","type":"String","description":"The unique identifier of a notification policy"},{"name":"account_id","type":"String","description":"The account id"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique identifier of a notification policy"},{"name":"alert_interval","type":"String","description":"Optional specification of how often to re-alert from the same incident, not support on all alert types."},{"name":"alert_type","type":"String","description":"Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values."},{"name":"created","type":"Time"},{"name":"description","type":"String","description":"Optional description for the Notification policy."},{"name":"enabled","type":"Bool","description":"Whether or not the Notification policy is enabled."},{"name":"modified","type":"Time"},{"name":"name","type":"String","description":"Name of the policy."},{"name":"filters","type":"Attributes","description":"Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.","children":[{"name":"actions","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"affected_asns","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"affected_components","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"affected_locations","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"airport_code","type":"List[String]","description":"Used for configuring maintenance_event_notification"},{"name":"alert_trigger_preferences","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"alert_trigger_preferences_value","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"enabled","type":"List[String]","description":"Used for configuring load_balancing_pool_enablement_alert"},{"name":"environment","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event_source","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"event_type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"group_by","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"health_check_id","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"incident_impact","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"input_id","type":"List[String]","description":"Used for configuring stream_live_notifications"},{"name":"insight_class","type":"List[String]","description":"Used for configuring security_insights_alert"},{"name":"limit","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"logo_tag","type":"List[String]","description":"Used for configuring logo_match_alert"},{"name":"megabits_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"new_health","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"new_status","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"packets_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"pool_id","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"pop_names","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"product","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"project_id","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"protocol","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"query_tag","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"requests_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"selectors","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"services","type":"List[String]","description":"Used for configuring clickhouse_alert_fw_ent_anomaly"},{"name":"slo","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"status","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"target_hostname","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"target_ip","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"target_zone_name","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"token_id","type":"List[String]","description":"Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens."},{"name":"traffic_exclusions","type":"List[String]","description":"Used for configuring traffic_anomalies_alert"},{"name":"tunnel_id","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"tunnel_name","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"where","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"zones","type":"List[String]","description":"Usage depends on specific alert type"}]},{"name":"mechanisms","type":"Attributes","description":"List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.","children":[{"name":"email","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The email address"}]},{"name":"pagerduty","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]},{"name":"webhooks","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]}]}]}]},"get /accounts/{}/botnet_feed/configs/asn":{"operationId":"botnet-threat-feed-list-asn","declarations":[{"kind":"data-source","name":"cloudflare_botnet_feed_config_asn","stainlessResource":"botnet_feed.configs.asn","methodName":"get","snippet":"data \"cloudflare_botnet_feed_config_asn\" \"example_botnet_feed_config_asn\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"asn","type":"Int64"}]}]},"get /accounts/{}/calls/apps":{"operationId":"calls-apps-list","declarations":[{"kind":"list-data-source","name":"cloudflare_calls_sfu_apps","stainlessResource":"calls.sfu","methodName":"list","snippet":"data \"cloudflare_calls_sfu_apps\" \"example_calls_sfu_apps\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]}]},"get /accounts/{}/calls/apps/{}":{"operationId":"calls-apps-retrieve-app-details","declarations":[{"kind":"data-source","name":"cloudflare_calls_sfu_app","stainlessResource":"calls.sfu","methodName":"get","snippet":"data \"cloudflare_calls_sfu_app\" \"example_calls_sfu_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n app_id = \"2a95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"app_id","type":"String","description":"A Cloudflare-generated unique identifier for a item."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"get /accounts/{}/calls/turn_keys":{"operationId":"calls-turn-key-list","declarations":[{"kind":"list-data-source","name":"cloudflare_calls_turn_apps","stainlessResource":"calls.turn","methodName":"list","snippet":"data \"cloudflare_calls_turn_apps\" \"example_calls_turn_apps\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]}]},"get /accounts/{}/calls/turn_keys/{}":{"operationId":"calls-retrieve-turn-key-details","declarations":[{"kind":"data-source","name":"cloudflare_calls_turn_app","stainlessResource":"calls.turn","methodName":"get","snippet":"data \"cloudflare_calls_turn_app\" \"example_calls_turn_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n key_id = \"2a95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"key_id","type":"String","description":"A Cloudflare-generated unique identifier for a item."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"get /accounts/{}/cfd_tunnel":{"operationId":"cloudflare-tunnel-list-cloudflare-tunnels","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_cloudflareds","stainlessResource":"zero_trust.tunnels.cloudflared","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflareds\" \"example_zero_trust_tunnel_cloudflareds\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n exclude_prefix = \"vpc1-\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n include_prefix = \"vpc1-\"\n is_deleted = true\n name = \"blog\"\n status = \"healthy\"\n uuid = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n was_active_at = \"2009-11-10T23:00:00Z\"\n was_inactive_at = \"2009-11-10T23:00:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"config_src","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"remote_config","type":"Bool","description":"If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.","deprecated":"Use the config_src field instead."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."}]}]}]},"get /accounts/{}/cfd_tunnel/{}":{"operationId":"cloudflare-tunnel-get-a-cloudflare-tunnel","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared","stainlessResource":"zero_trust.tunnels.cloudflared","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared\" \"example_zero_trust_tunnel_cloudflared\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"filter","type":"Attributes","children":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"config_src","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard."},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"remote_config","type":"Bool","description":"If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.","deprecated":"Use the config_src field instead."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"get /accounts/{}/cfd_tunnel/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-get-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_config","stainlessResource":"zero_trust.tunnels.cloudflared.configurations","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_config\" \"example_zero_trust_tunnel_cloudflared_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"source","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel's configuration on the Zero Trust dashboard."},{"name":"version","type":"Int64","description":"The version of the Tunnel Configuration."},{"name":"config","type":"Attributes","description":"The tunnel configuration and ingress rules.","children":[{"name":"ingress","type":"List[Attributes]","description":"List of public hostname definitions. At least one ingress rule needs to be defined for the tunnel.","children":[{"name":"hostname","type":"String","description":"Public hostname for this service."},{"name":"service","type":"String","description":"Protocol and address of destination server. Supported protocols: http://, https://, unix://, tcp://, ssh://, rdp://, unix+tls://, smb://. Alternatively can return a HTTP status code http_status:[code] e.g. 'http_status:404'.\n"},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"path","type":"String","description":"Requests with this path route to this public hostname."}]},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"warp_routing","type":"Attributes","description":"Enable private network access from WARP users to private network routes. This is enabled if the tunnel has an assigned route.","deprecated":"This field is ignored by cloudflared since version 2023.10.0.","children":[{"name":"enabled","type":"Bool"}]}]}]}]},"get /accounts/{}/cfd_tunnel/{}/token":{"operationId":"cloudflare-tunnel-get-a-cloudflare-tunnel-token","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_token","stainlessResource":"zero_trust.tunnels.cloudflared.token","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_token\" \"example_zero_trust_tunnel_cloudflared_token\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"token","type":"String","description":"The Tunnel Token is used as a mechanism to authenticate the operation of a tunnel.","sensitive":true}]}]},"get /accounts/{}/challenges/widgets":{"operationId":"accounts-turnstile-widgets-list","declarations":[{"kind":"list-data-source","name":"cloudflare_turnstile_widgets","stainlessResource":"turnstile.widgets","methodName":"list","snippet":"data \"cloudflare_turnstile_widgets\" \"example_turnstile_widgets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n filter = \"name:my-widget\"\n order = \"id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"Direction to order widgets."},{"name":"filter","type":"String","description":"Filter widgets by field. The `name` field uses case-insensitive\nsubstring matching; `sitekey` uses exact matching.\nFormat: `field:value`\n\nSupported fields:\n- `name` - Filter by widget name (e.g., `filter=name:login-form`)\n- `sitekey` - Filter by sitekey (e.g., `filter=sitekey:0x4AAA`)\n\nReturns 400 Bad Request if the field is unsupported or format is invalid.\nAn empty filter value returns all results.\n"},{"name":"order","type":"String","description":"Field to order widgets by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"bot_fight_mode","type":"Bool","description":"If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only).\n"},{"name":"clearance_level","type":"String","description":"If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\n"},{"name":"created_on","type":"Time","description":"When the widget was created."},{"name":"domains","type":"List[String]"},{"name":"ephemeral_id","type":"Bool","description":"Return the Ephemeral ID in /siteverify (ENT only).\n"},{"name":"mode","type":"String","description":"Widget Mode"},{"name":"modified_on","type":"Time","description":"When the widget was modified."},{"name":"name","type":"String","description":"Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used.\n"},{"name":"offlabel","type":"Bool","description":"Do not show any Cloudflare branding on the widget (ENT only).\n"},{"name":"region","type":"String","description":"Region where this widget can be used. This cannot be changed after creation.\n"},{"name":"sitekey","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"deployed_via","type":"String","description":"Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\n"},{"name":"last_modified_via","type":"String","description":"Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\n"}]}]}]},"get /accounts/{}/challenges/widgets/{}":{"operationId":"accounts-turnstile-widget-get","declarations":[{"kind":"data-source","name":"cloudflare_turnstile_widget","stainlessResource":"turnstile.widgets","methodName":"get","snippet":"data \"cloudflare_turnstile_widget\" \"example_turnstile_widget\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n sitekey = \"0x4AAF00AAAABn0R22HWm-YUc\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"sitekey","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order widgets."},{"name":"filter","type":"String","description":"Filter widgets by field. The `name` field uses case-insensitive\nsubstring matching; `sitekey` uses exact matching.\nFormat: `field:value`\n\nSupported fields:\n- `name` - Filter by widget name (e.g., `filter=name:login-form`)\n- `sitekey` - Filter by sitekey (e.g., `filter=sitekey:0x4AAA`)\n\nReturns 400 Bad Request if the field is unsupported or format is invalid.\nAn empty filter value returns all results.\n"},{"name":"order","type":"String","description":"Field to order widgets by."}]}],"computed":[{"name":"id","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"bot_fight_mode","type":"Bool","description":"If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only).\n"},{"name":"clearance_level","type":"String","description":"If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\n"},{"name":"created_on","type":"Time","description":"When the widget was created."},{"name":"deployed_via","type":"String","description":"Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\n"},{"name":"ephemeral_id","type":"Bool","description":"Return the Ephemeral ID in /siteverify (ENT only).\n"},{"name":"last_modified_via","type":"String","description":"Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\n"},{"name":"mode","type":"String","description":"Widget Mode"},{"name":"modified_on","type":"Time","description":"When the widget was modified."},{"name":"name","type":"String","description":"Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used.\n"},{"name":"offlabel","type":"Bool","description":"Do not show any Cloudflare branding on the widget (ENT only).\n"},{"name":"region","type":"String","description":"Region where this widget can be used. This cannot be changed after creation.\n"},{"name":"secret","type":"String","description":"Secret key for this widget.","sensitive":true},{"name":"domains","type":"List[String]"}]}]},"get /accounts/{}/cloudforce-one/requests/{}":{"operationId":"cloudforce-one-request-get","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request","stainlessResource":"cloudforce_one.requests","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request\" \"example_cloudforce_one_request\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"request_id","type":"String","description":"UUID."},{"name":"filter","type":"Attributes","children":[{"name":"page","type":"Int64","description":"Page number of results."},{"name":"per_page","type":"Int64","description":"Number of results per page."},{"name":"completed_after","type":"Time","description":"Retrieve requests completed after this time."},{"name":"completed_before","type":"Time","description":"Retrieve requests completed before this time."},{"name":"created_after","type":"Time","description":"Retrieve requests created after this time."},{"name":"created_before","type":"Time","description":"Retrieve requests created before this time."},{"name":"request_type","type":"String","description":"Requested information from request."},{"name":"sort_by","type":"String","description":"Field to sort results by."},{"name":"sort_order","type":"String","description":"Sort order (asc or desc)."},{"name":"status","type":"String","description":"Request Status."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"content","type":"String","description":"Request content."},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"priority","type":"Time"},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"get /accounts/{}/cloudforce-one/requests/{}/asset/{}":{"operationId":"cloudforce-one-request-asset-get","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request_asset","stainlessResource":"cloudforce_one.requests.assets","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request_asset\" \"example_cloudforce_one_request_asset\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n asset_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"asset_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"request_id","type":"String","description":"UUID."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created","type":"Time","description":"Defines the asset creation time."},{"name":"description","type":"String","description":"Asset description."},{"name":"file_type","type":"String","description":"Asset file type."},{"name":"name","type":"String","description":"Asset name."}]}]},"get /accounts/{}/cloudforce-one/requests/priority/{}":{"operationId":"cloudforce-one-priority-get","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request_priority","stainlessResource":"cloudforce_one.requests.priority","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request_priority\" \"example_cloudforce_one_request_priority\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n priority_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"priority_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"content","type":"String","description":"Request content."},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"priority","type":"Time"},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"get /accounts/{}/connectivity/directory/services":{"operationId":"connectivity-services-list","declarations":[{"kind":"list-data-source","name":"cloudflare_connectivity_directory_services","stainlessResource":"connectivity.directory.services","methodName":"list","snippet":"data \"cloudflare_connectivity_directory_services\" \"example_connectivity_directory_services\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n type = \"tcp\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier"}],"optional":[{"name":"type","type":"String"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"host","type":"Attributes","children":[{"name":"ipv4","type":"String"},{"name":"network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"}]},{"name":"ipv6","type":"String"},{"name":"hostname","type":"String"},{"name":"resolver_network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"},{"name":"resolver_ips","type":"List[String]"}]}]},{"name":"name","type":"String"},{"name":"type","type":"String"},{"name":"created_at","type":"Time"},{"name":"http_port","type":"Int64"},{"name":"https_port","type":"Int64"},{"name":"service_id","type":"String"},{"name":"tls_settings","type":"Attributes","description":"TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.","children":[{"name":"cert_verification_mode","type":"String","description":"TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all"}]},{"name":"updated_at","type":"Time"},{"name":"app_protocol","type":"String"},{"name":"tcp_port","type":"Int64"}]}]}]},"get /accounts/{}/connectivity/directory/services/{}":{"operationId":"connectivity-services-get","declarations":[{"kind":"data-source","name":"cloudflare_connectivity_directory_service","stainlessResource":"connectivity.directory.services","methodName":"get","snippet":"data \"cloudflare_connectivity_directory_service\" \"example_connectivity_directory_service\" {\n account_id = \"account_id\"\n service_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"service_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"type","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"app_protocol","type":"String"},{"name":"created_at","type":"Time"},{"name":"http_port","type":"Int64"},{"name":"https_port","type":"Int64"},{"name":"name","type":"String"},{"name":"tcp_port","type":"Int64"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"host","type":"Attributes","children":[{"name":"ipv4","type":"String"},{"name":"network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"}]},{"name":"ipv6","type":"String"},{"name":"hostname","type":"String"},{"name":"resolver_network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"},{"name":"resolver_ips","type":"List[String]"}]}]},{"name":"tls_settings","type":"Attributes","description":"TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.","children":[{"name":"cert_verification_mode","type":"String","description":"TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all"}]}]}]},"get /accounts/{}/d1/database":{"operationId":"d1-list-databases","declarations":[{"kind":"list-data-source","name":"cloudflare_d1_databases","stainlessResource":"d1.database","methodName":"list","snippet":"data \"cloudflare_d1_databases\" \"example_d1_databases\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"name\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"name","type":"String","description":"a database name to search for."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"D1 database identifier (UUID)."},{"name":"created_at","type":"Time","description":"Specifies the timestamp the resource was created as an ISO8601 string."},{"name":"jurisdiction","type":"String","description":"Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored."},{"name":"name","type":"String","description":"D1 database name."},{"name":"uuid","type":"String","description":"D1 database identifier (UUID)."},{"name":"version","type":"String"}]}]}]},"get /accounts/{}/d1/database/{}":{"operationId":"d1-get-database","declarations":[{"kind":"data-source","name":"cloudflare_d1_database","stainlessResource":"d1.database","methodName":"get","snippet":"data \"cloudflare_d1_database\" \"example_d1_database\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n database_id = \"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx\"\n fields = [\"uuid\"]\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"database_id","type":"String","description":"D1 database identifier (UUID)."},{"name":"fields","type":"List[String]","description":"Comma-separated list of fields to include in the response. When omitted,\nall fields are returned.\n"},{"name":"filter","type":"Attributes","children":[{"name":"name","type":"String","description":"a database name to search for."}]}],"computed":[{"name":"id","type":"String","description":"D1 database identifier (UUID)."},{"name":"created_at","type":"Time","description":"Specifies the timestamp the resource was created as an ISO8601 string."},{"name":"file_size","type":"Float64","description":"The D1 database's size, in bytes."},{"name":"jurisdiction","type":"String","description":"Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored."},{"name":"name","type":"String","description":"D1 database name."},{"name":"num_tables","type":"Float64","description":"The number of tables in the D1 database. This count is no longer accurate and should not be relied upon.","deprecated":"Deprecated."},{"name":"uuid","type":"String","description":"D1 database identifier (UUID)."},{"name":"version","type":"String"},{"name":"read_replication","type":"Attributes","description":"Configuration for D1 read replication.","children":[{"name":"mode","type":"String","description":"The read replication mode for the database. Mode 'auto' denotes that D1 creates replicas and automatically places them around the world. Mode 'disabled' denotes that no database replicas are used."}]}]}]},"get /accounts/{}/data-security/posture/policies":{"operationId":"ListPolicies","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_casb_policies","stainlessResource":"zero_trust.casb.posture.policies","methodName":"list","snippet":"data \"cloudflare_zero_trust_casb_policies\" \"example_zero_trust_casb_policies\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the policy configuration."},{"name":"actions","type":"Attributes","description":"The actions configured for this policy.","children":[{"name":"remediation_types","type":"List[Attributes]","description":"List of remediation types that will be executed.","children":[{"name":"display_name","type":"String","description":"Display name/label of the remediation type."},{"name":"remediation_type","type":"String","description":"The system name of the remediation type."},{"name":"remediation_type_id","type":"String","description":"Unique identifier for the remediation type."}]},{"name":"webhook_configs","type":"List[Attributes]","description":"List of webhook configurations that will be triggered.","children":[{"name":"display_name","type":"String","description":"Display name/label of the webhook configuration."},{"name":"webhook_config_id","type":"String","description":"Unique identifier for the webhook configuration."}]}]},{"name":"applies_to_all_integrations","type":"Bool","description":"When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids."},{"name":"created_at","type":"Time","description":"Timestamp when the policy was created."},{"name":"description","type":"String","description":"User-set description of what this policy does. Limited to 1000 characters."},{"name":"display_name","type":"String","description":"Display name for the policy configuration. Limited to 255 characters."},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset)."},{"name":"finding_type_id","type":"String","description":"The finding type this policy is associated with. Immutable after creation; changing it replaces the policy."},{"name":"integration_ids","type":"List[String]","description":"The integrations this policy applies to."},{"name":"updated_at","type":"Time","description":"Timestamp when the policy was last updated."},{"name":"disabled_at","type":"Time","description":"Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled."},{"name":"last_triggered_at","type":"Time","description":"Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints."}]}]}]},"get /accounts/{}/data-security/posture/policies/{}":{"operationId":"GetPolicyByID","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_casb_policy","stainlessResource":"zero_trust.casb.posture.policies","methodName":"get","snippet":"data \"cloudflare_zero_trust_casb_policy\" \"example_zero_trust_casb_policy\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n policy_id = \"497f6eca-6276-4993-bfeb-53cbbbba6f08\"\n}\n","required":[{"name":"policy_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"applies_to_all_integrations","type":"Bool","description":"When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids."},{"name":"created_at","type":"Time","description":"Timestamp when the policy was created."},{"name":"description","type":"String","description":"User-set description of what this policy does. Limited to 1000 characters."},{"name":"disabled_at","type":"Time","description":"Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled."},{"name":"display_name","type":"String","description":"Display name for the policy configuration. Limited to 255 characters."},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset)."},{"name":"finding_type_id","type":"String","description":"The finding type this policy is associated with. Immutable after creation; changing it replaces the policy."},{"name":"last_triggered_at","type":"Time","description":"Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints."},{"name":"updated_at","type":"Time","description":"Timestamp when the policy was last updated."},{"name":"integration_ids","type":"List[String]","description":"The integrations this policy applies to."},{"name":"actions","type":"Attributes","description":"The actions configured for this policy.","children":[{"name":"remediation_types","type":"List[Attributes]","description":"List of remediation types that will be executed.","children":[{"name":"display_name","type":"String","description":"Display name/label of the remediation type."},{"name":"remediation_type","type":"String","description":"The system name of the remediation type."},{"name":"remediation_type_id","type":"String","description":"Unique identifier for the remediation type."}]},{"name":"webhook_configs","type":"List[Attributes]","description":"List of webhook configurations that will be triggered.","children":[{"name":"display_name","type":"String","description":"Display name/label of the webhook configuration."},{"name":"webhook_config_id","type":"String","description":"Unique identifier for the webhook configuration."}]}]}]}]},"get /accounts/{}/data-security/posture/webhooks":{"operationId":"ListWebhooks","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_casb_webhooks","stainlessResource":"zero_trust.casb.posture.webhooks","methodName":"list","snippet":"data \"cloudflare_zero_trust_casb_webhooks\" \"example_zero_trust_casb_webhooks\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the specific webhook configuration."},{"name":"authentication_type","type":"String","description":"Type of authentication used for the webhook."},{"name":"created_at","type":"Time","description":"Timestamp when the webhook configuration was created."},{"name":"destination_url","type":"String","description":"Target URL for the webhook configuration. Where resulting data will be sent."},{"name":"label","type":"String","description":"Account-specified display label for the webhook configuration."},{"name":"status","type":"String","description":"Current status of the webhook configuration. If disabled, data cannot be sent through this configuration."},{"name":"updated_at","type":"Time","description":"Timestamp when the webhook configuration was last updated."},{"name":"version","type":"Int64","description":"Version number of the configuration."},{"name":"headers","type":"List[Attributes]","description":"List of header keys configured for this webhook. Values are not included for security reasons.","children":[{"name":"key","type":"String","description":"Header key name (lowercase)."},{"name":"value","type":"String","description":"Header value. This field is never returned in API responses for security reasons.","sensitive":true}]}]}]}]},"get /accounts/{}/data-security/posture/webhooks/{}":{"operationId":"GetWebhookConfigByID","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_casb_webhook","stainlessResource":"zero_trust.casb.posture.webhooks","methodName":"get","snippet":"data \"cloudflare_zero_trust_casb_webhook\" \"example_zero_trust_casb_webhook\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n webhook_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"webhook_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"authentication_type","type":"String","description":"Type of authentication used for the webhook."},{"name":"created_at","type":"Time","description":"Timestamp when the webhook configuration was created."},{"name":"destination_url","type":"String","description":"Target URL for the webhook configuration. Where resulting data will be sent."},{"name":"label","type":"String","description":"Account-specified display label for the webhook configuration."},{"name":"status","type":"String","description":"Current status of the webhook configuration. If disabled, data cannot be sent through this configuration."},{"name":"updated_at","type":"Time","description":"Timestamp when the webhook configuration was last updated."},{"name":"version","type":"Int64","description":"Version number of the configuration."},{"name":"headers","type":"List[Attributes]","description":"List of header keys configured for this webhook. Values are not included for security reasons.","children":[{"name":"key","type":"String","description":"Header key name (lowercase)."},{"name":"value","type":"String","description":"Header value. This field is never returned in API responses for security reasons.","sensitive":true}]}]}]},"get /accounts/{}/devices/deployment-groups":{"operationId":"list-deployment-groups","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_deployment_groups_list","stainlessResource":"zero_trust.devices.deployment_groups","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_deployment_groups_list\" \"example_zero_trust_device_deployment_groups_list\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the deployment group."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was created."},{"name":"name","type":"String","description":"A user-friendly name for the deployment group."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was last updated."},{"name":"version_config","type":"List[Attributes]","description":"Contains version configurations for different target environments.","children":[{"name":"target_environment","type":"String","description":"The target environment for the client version (e.g., windows, macos)."},{"name":"version","type":"String","description":"The specific client version to deploy."}]},{"name":"policy_ids","type":"List[String]","description":"Contains a list of policy IDs assigned to this deployment group."}]}]}]},"get /accounts/{}/devices/deployment-groups/{}":{"operationId":"get-deployment-group","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_deployment_groups","stainlessResource":"zero_trust.devices.deployment_groups","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_deployment_groups\" \"example_zero_trust_device_deployment_groups\" {\n account_id = \"account_id\"\n group_id = \"group_id\"\n}\n","required":[{"name":"group_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was created."},{"name":"name","type":"String","description":"A user-friendly name for the deployment group."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was last updated."},{"name":"policy_ids","type":"List[String]","description":"Contains a list of policy IDs assigned to this deployment group."},{"name":"version_config","type":"List[Attributes]","description":"Contains version configurations for different target environments.","children":[{"name":"target_environment","type":"String","description":"The target environment for the client version (e.g., windows, macos)."},{"name":"version","type":"String","description":"The specific client version to deploy."}]}]}]},"get /accounts/{}/devices/ip-profiles":{"operationId":"list-ip-profiles","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_ip_profiles","stainlessResource":"zero_trust.devices.ip_profiles","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_ip_profiles\" \"example_zero_trust_device_ip_profiles\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the Device IP profile."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was created."},{"name":"description","type":"String","description":"An optional description of the Device IP profile."},{"name":"enabled","type":"Bool","description":"Whether the Device IP profile is enabled."},{"name":"match","type":"String","description":"The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"."},{"name":"name","type":"String","description":"A user-friendly name for the Device IP profile."},{"name":"precedence","type":"Int64","description":"The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field."},{"name":"subnet_id","type":"String","description":"The ID of the Subnet."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was last updated."}]}]}]},"get /accounts/{}/devices/ip-profiles/{}":{"operationId":"get-ip-profile","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_ip_profile","stainlessResource":"zero_trust.devices.ip_profiles","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_ip_profile\" \"example_zero_trust_device_ip_profile\" {\n account_id = \"account_id\"\n profile_id = \"profile_id\"\n}\n","required":[{"name":"profile_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was created."},{"name":"description","type":"String","description":"An optional description of the Device IP profile."},{"name":"enabled","type":"Bool","description":"Whether the Device IP profile is enabled."},{"name":"match","type":"String","description":"The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"."},{"name":"name","type":"String","description":"A user-friendly name for the Device IP profile."},{"name":"precedence","type":"Int64","description":"The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field."},{"name":"subnet_id","type":"String","description":"The ID of the Subnet."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was last updated."}]}]},"get /accounts/{}/devices/networks":{"operationId":"device-managed-networks-list-device-managed-networks","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_managed_networks_list","stainlessResource":"zero_trust.devices.networks","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_managed_networks_list\" \"example_zero_trust_device_managed_networks_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"API UUID."},{"name":"config","type":"Attributes","description":"The configuration object containing information for the WARP client to detect the managed network.","children":[{"name":"tls_sockaddr","type":"String","description":"A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host."},{"name":"sha256","type":"String","description":"The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate."}]},{"name":"name","type":"String","description":"The name of the device managed network. This name must be unique."},{"name":"network_id","type":"String","description":"API UUID."},{"name":"type","type":"String","description":"The type of device managed network."}]}]}]},"get /accounts/{}/devices/networks/{}":{"operationId":"device-managed-networks-device-managed-network-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_managed_networks","stainlessResource":"zero_trust.devices.networks","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_managed_networks\" \"example_zero_trust_device_managed_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n network_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"network_id","type":"String","description":"API UUID."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"name","type":"String","description":"The name of the device managed network. This name must be unique."},{"name":"type","type":"String","description":"The type of device managed network."},{"name":"config","type":"Attributes","description":"The configuration object containing information for the WARP client to detect the managed network.","children":[{"name":"tls_sockaddr","type":"String","description":"A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host."},{"name":"sha256","type":"String","description":"The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate."}]}]}]},"get /accounts/{}/devices/policies":{"operationId":"devices-list-device-settings-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_custom_profiles","stainlessResource":"zero_trust.devices.policies.custom","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_custom_profiles\" \"example_zero_trust_device_custom_profiles\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"profile_type","type":"String","description":"Filter profiles by client type. When omitted, only WARP profiles are returned."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"browser_extension_config","type":"Attributes","description":"Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.","children":[{"name":"proxy_control","type":"String","description":"Whether the user may disable the browser extension proxy."},{"name":"proxy_enabled","type":"Bool","description":"Whether the browser extension proxy is active."}]},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy is the account default. WARP group profiles cannot set this field."},{"name":"description","type":"String","description":"A description of the policy."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"gateway_unique_id","type":"String"},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"match","type":"String","description":"The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"."},{"name":"name","type":"String","description":"The name of the device settings profile."},{"name":"policy_id","type":"String"},{"name":"precedence","type":"Float64","description":"The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field."},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"target_tests","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The id of the DEX test targeting this policy."},{"name":"name","type":"String","description":"The name of the DEX test targeting this policy."}]},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]}]}]}]},"get /accounts/{}/devices/policy":{"operationId":"devices-get-default-device-settings-policy","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_default_profile","stainlessResource":"zero_trust.devices.policies.default","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_default_profile\" \"example_zero_trust_device_default_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"gateway_unique_id","type":"String"},{"name":"policy_id","type":"String"},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]}]}]},"get /accounts/{}/devices/policy/{}":{"operationId":"devices-get-device-settings-policy-by-id","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_custom_profile","stainlessResource":"zero_trust.devices.policies.custom","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_custom_profile\" \"example_zero_trust_device_custom_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"policy_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"profile_type","type":"String","description":"Filter profiles by client type. When omitted, only WARP profiles are returned."}]}],"computed":[{"name":"id","type":"String"},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy is the account default. WARP group profiles cannot set this field."},{"name":"description","type":"String","description":"A description of the policy."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"gateway_unique_id","type":"String"},{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"match","type":"String","description":"The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"."},{"name":"name","type":"String","description":"The name of the device settings profile."},{"name":"precedence","type":"Float64","description":"The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field."},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"browser_extension_config","type":"Attributes","description":"Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.","children":[{"name":"proxy_control","type":"String","description":"Whether the user may disable the browser extension proxy."},{"name":"proxy_enabled","type":"Bool","description":"Whether the browser extension proxy is active."}]},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]},{"name":"target_tests","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The id of the DEX test targeting this policy."},{"name":"name","type":"String","description":"The name of the DEX test targeting this policy."}]},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]}]}]},"get /accounts/{}/devices/policy/{}/fallback_domains":{"operationId":"devices-get-local-domain-fallback-list-for-a-device-settings-policy","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_custom_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.custom.fallback_domains","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_custom_profile_local_domain_fallback\" \"example_zero_trust_device_custom_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"policy_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}]},"get /accounts/{}/devices/policy/fallback_domains":{"operationId":"devices-get-local-domain-fallback-list","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_default_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.default.fallback_domains","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_default_profile_local_domain_fallback\" \"example_zero_trust_device_default_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}]},"get /accounts/{}/devices/posture":{"operationId":"device-posture-rules-list-device-posture-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_posture_rules","stainlessResource":"zero_trust.devices.posture","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_posture_rules\" \"example_zero_trust_device_posture_rules\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"API UUID."},{"name":"description","type":"String","description":"The description of the device posture rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise."},{"name":"expiration","type":"String","description":"Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client."},{"name":"input","type":"Attributes","description":"The value to be checked against.","children":[{"name":"operating_system","type":"String","description":"Operating system."},{"name":"path","type":"String","description":"File path."},{"name":"exists","type":"Bool","description":"Whether or not file exists."},{"name":"sha256","type":"String","description":"SHA-256."},{"name":"thumbprint","type":"String","description":"Signing certificate thumbprint."},{"name":"id","type":"String","description":"List ID."},{"name":"domain","type":"String","description":"Domain."},{"name":"operator","type":"String","description":"Operator."},{"name":"version","type":"String","description":"Version of OS."},{"name":"os_distro_name","type":"String","description":"Operating System Distribution Name (linux only)."},{"name":"os_distro_revision","type":"String","description":"Version of OS Distribution (linux only)."},{"name":"os_version_extra","type":"String","description":"Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version."},{"name":"enabled","type":"Bool","description":"Enabled."},{"name":"check_disks","type":"List[String]","description":"List of volume names to be checked for encryption."},{"name":"require_all","type":"Bool","description":"Whether to check all disks for encryption."},{"name":"certificate_id","type":"String","description":"UUID of Cloudflare managed certificate."},{"name":"cn","type":"String","description":"Common Name that is protected by the certificate."},{"name":"check_private_key","type":"Bool","description":"Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key."},{"name":"extended_key_usage","type":"List[String]","description":"List of values indicating purposes for which the certificate public key can be used."},{"name":"locations","type":"Attributes","children":[{"name":"paths","type":"List[String]","description":"List of paths to check for client certificate on linux."},{"name":"trust_stores","type":"List[String]","description":"List of trust stores to check for client certificate."}]},{"name":"subject_alternative_names","type":"List[String]","description":"List of certificate Subject Alternative Names."},{"name":"update_window_days","type":"Float64","description":"Number of days that the antivirus should be updated within."},{"name":"compliance_status","type":"String","description":"Compliance Status."},{"name":"connection_id","type":"String","description":"Posture Integration ID."},{"name":"last_seen","type":"String","description":"For more details on last seen, please refer to the Crowdstrike documentation."},{"name":"os","type":"String","description":"Os Version."},{"name":"overall","type":"String","description":"Overall."},{"name":"sensor_config","type":"String","description":"SensorConfig."},{"name":"state","type":"String","description":"For more details on state, please refer to the Crowdstrike documentation."},{"name":"version_operator","type":"String","description":"Version Operator."},{"name":"auth_state","type":"List[String]","description":"The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states."},{"name":"count_operator","type":"String","description":"Count Operator."},{"name":"issue_count","type":"String","description":"The Number of Issues."},{"name":"eid_last_seen","type":"String","description":"For more details on eid last seen, refer to the Tanium documentation."},{"name":"risk_level","type":"String","description":"For more details on risk level, refer to the Tanium documentation."},{"name":"score_operator","type":"String","description":"Score Operator."},{"name":"total_score","type":"Float64","description":"For more details on total score, refer to the Tanium documentation."},{"name":"active_threats","type":"Float64","description":"The Number of active threats."},{"name":"infected","type":"Bool","description":"Whether device is infected."},{"name":"is_active","type":"Bool","description":"Whether device is active."},{"name":"network_status","type":"String","description":"Network status of device."},{"name":"operational_state","type":"String","description":"Agent operational state."},{"name":"score","type":"Float64","description":"A value between 0-100 assigned to devices set by the 3rd party posture provider."}]},{"name":"match","type":"List[Attributes]","description":"The conditions that the client must match to run the rule.","children":[{"name":"platform","type":"String"}]},{"name":"name","type":"String","description":"The name of the device posture rule."},{"name":"schedule","type":"String","description":"Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`."},{"name":"type","type":"String","description":"The type of device posture rule."}]}]}]},"get /accounts/{}/devices/posture/{}":{"operationId":"device-posture-rules-device-posture-rules-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_posture_rule","stainlessResource":"zero_trust.devices.posture","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_posture_rule\" \"example_zero_trust_device_posture_rule\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"rule_id","type":"String","description":"API UUID."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"description","type":"String","description":"The description of the device posture rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise."},{"name":"expiration","type":"String","description":"Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client."},{"name":"name","type":"String","description":"The name of the device posture rule."},{"name":"schedule","type":"String","description":"Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`."},{"name":"type","type":"String","description":"The type of device posture rule."},{"name":"input","type":"Attributes","description":"The value to be checked against.","children":[{"name":"operating_system","type":"String","description":"Operating system."},{"name":"path","type":"String","description":"File path."},{"name":"exists","type":"Bool","description":"Whether or not file exists."},{"name":"sha256","type":"String","description":"SHA-256."},{"name":"thumbprint","type":"String","description":"Signing certificate thumbprint."},{"name":"id","type":"String","description":"List ID."},{"name":"domain","type":"String","description":"Domain."},{"name":"operator","type":"String","description":"Operator."},{"name":"version","type":"String","description":"Version of OS."},{"name":"os_distro_name","type":"String","description":"Operating System Distribution Name (linux only)."},{"name":"os_distro_revision","type":"String","description":"Version of OS Distribution (linux only)."},{"name":"os_version_extra","type":"String","description":"Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version."},{"name":"enabled","type":"Bool","description":"Enabled."},{"name":"check_disks","type":"List[String]","description":"List of volume names to be checked for encryption."},{"name":"require_all","type":"Bool","description":"Whether to check all disks for encryption."},{"name":"certificate_id","type":"String","description":"UUID of Cloudflare managed certificate."},{"name":"cn","type":"String","description":"Common Name that is protected by the certificate."},{"name":"check_private_key","type":"Bool","description":"Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key."},{"name":"extended_key_usage","type":"List[String]","description":"List of values indicating purposes for which the certificate public key can be used."},{"name":"locations","type":"Attributes","children":[{"name":"paths","type":"List[String]","description":"List of paths to check for client certificate on linux."},{"name":"trust_stores","type":"List[String]","description":"List of trust stores to check for client certificate."}]},{"name":"subject_alternative_names","type":"List[String]","description":"List of certificate Subject Alternative Names."},{"name":"update_window_days","type":"Float64","description":"Number of days that the antivirus should be updated within."},{"name":"compliance_status","type":"String","description":"Compliance Status."},{"name":"connection_id","type":"String","description":"Posture Integration ID."},{"name":"last_seen","type":"String","description":"For more details on last seen, please refer to the Crowdstrike documentation."},{"name":"os","type":"String","description":"Os Version."},{"name":"overall","type":"String","description":"Overall."},{"name":"sensor_config","type":"String","description":"SensorConfig."},{"name":"state","type":"String","description":"For more details on state, please refer to the Crowdstrike documentation."},{"name":"version_operator","type":"String","description":"Version Operator."},{"name":"auth_state","type":"List[String]","description":"The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states."},{"name":"count_operator","type":"String","description":"Count Operator."},{"name":"issue_count","type":"String","description":"The Number of Issues."},{"name":"eid_last_seen","type":"String","description":"For more details on eid last seen, refer to the Tanium documentation."},{"name":"risk_level","type":"String","description":"For more details on risk level, refer to the Tanium documentation."},{"name":"score_operator","type":"String","description":"Score Operator."},{"name":"total_score","type":"Float64","description":"For more details on total score, refer to the Tanium documentation."},{"name":"active_threats","type":"Float64","description":"The Number of active threats."},{"name":"infected","type":"Bool","description":"Whether device is infected."},{"name":"is_active","type":"Bool","description":"Whether device is active."},{"name":"network_status","type":"String","description":"Network status of device."},{"name":"operational_state","type":"String","description":"Agent operational state."},{"name":"score","type":"Float64","description":"A value between 0-100 assigned to devices set by the 3rd party posture provider."}]},{"name":"match","type":"List[Attributes]","description":"The conditions that the client must match to run the rule.","children":[{"name":"platform","type":"String"}]}]}]},"get /accounts/{}/devices/posture/integration":{"operationId":"device-posture-integrations-list-device-posture-integrations","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_device_posture_integrations","stainlessResource":"zero_trust.devices.posture.integrations","methodName":"list","snippet":"data \"cloudflare_zero_trust_device_posture_integrations\" \"example_zero_trust_device_posture_integrations\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"API UUID."},{"name":"config","type":"Attributes","description":"The configuration object containing third-party integration information.","children":[{"name":"api_url","type":"String","description":"The Workspace One API URL provided in the Workspace One Admin Dashboard."},{"name":"auth_url","type":"String","description":"The Workspace One Authorization URL depending on your region."},{"name":"client_id","type":"String","description":"The Workspace One client ID provided in the Workspace One Admin Dashboard."}]},{"name":"interval","type":"String","description":"The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)."},{"name":"name","type":"String","description":"The name of the device posture integration."},{"name":"type","type":"String","description":"The type of device posture integration."}]}]}]},"get /accounts/{}/devices/posture/integration/{}":{"operationId":"device-posture-integrations-device-posture-integration-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_posture_integration","stainlessResource":"zero_trust.devices.posture.integrations","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_posture_integration\" \"example_zero_trust_device_posture_integration\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n integration_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"integration_id","type":"String","description":"API UUID."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"interval","type":"String","description":"The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)."},{"name":"name","type":"String","description":"The name of the device posture integration."},{"name":"type","type":"String","description":"The type of device posture integration."},{"name":"config","type":"Attributes","description":"The configuration object containing third-party integration information.","children":[{"name":"api_url","type":"String","description":"The Workspace One API URL provided in the Workspace One Admin Dashboard."},{"name":"auth_url","type":"String","description":"The Workspace One Authorization URL depending on your region."},{"name":"client_id","type":"String","description":"The Workspace One client ID provided in the Workspace One Admin Dashboard."}]}]}]},"get /accounts/{}/devices/settings":{"operationId":"zero-trust-accounts-get-device-settings-for-zero-trust-account","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_settings","stainlessResource":"zero_trust.devices.settings","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_settings\" \"example_zero_trust_device_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"disable_for_time","type":"Float64","description":"Sets the time limit, in seconds, that a user can use an override code to bypass WARP."},{"name":"external_emergency_signal_enabled","type":"Bool","description":"Controls whether the external emergency disconnect feature is enabled."},{"name":"external_emergency_signal_fingerprint","type":"String","description":"The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external_emergency_signal_url. If provided, the WARP client will use this value to verify the server's identity. The device will ignore any response if the server's certificate fingerprint does not exactly match this value."},{"name":"external_emergency_signal_interval","type":"String","description":"The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., \"5m\", \"2m30s\", \"1h\"). Minimum 30 seconds."},{"name":"external_emergency_signal_url","type":"String","description":"The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host."},{"name":"gateway_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on TCP."},{"name":"gateway_udp_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on UDP."},{"name":"root_certificate_installation_enabled","type":"Bool","description":"Enable installation of cloudflare managed root certificate."},{"name":"use_zt_virtual_ip","type":"Bool","description":"Enable using CGNAT virtual IPv4."}]}]},"get /accounts/{}/dex/devices/dex_tests":{"operationId":"device-dex-test-details","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dex_tests","stainlessResource":"zero_trust.devices.dex_tests","methodName":"list","snippet":"data \"cloudflare_zero_trust_dex_tests\" \"example_zero_trust_dex_tests\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n kind = \"http\"\n test_name = \"testName\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[{"name":"kind","type":"String","description":"Filter by test type."},{"name":"test_name","type":"String","description":"Filter by test name."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier for the test."},{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool","description":"Determines whether or not the test is active."},{"name":"interval","type":"String","description":"How often the test will run."},{"name":"name","type":"String","description":"The name of the DEX test. Must be unique."},{"name":"created","type":"Time","description":"Date the test was created, in RFC 3339 format."},{"name":"description","type":"String","description":"Additional details about the test."},{"name":"target_policies","type":"List[Attributes]","description":"DEX rules targeted by this test","children":[{"name":"id","type":"String","description":"The id of the DEX rule."},{"name":"default","type":"Bool","description":"Whether the DEX rule is the account default."},{"name":"name","type":"String","description":"The name of the DEX rule."}]},{"name":"targeted","type":"Bool"},{"name":"test_id","type":"String","description":"The unique identifier for the test."},{"name":"updated","type":"Time","description":"Date the test was last updated, in RFC 3339 format."}]}]}]},"get /accounts/{}/dex/devices/dex_tests/{}":{"operationId":"device-dex-test-get-device-dex-test","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dex_test","stainlessResource":"zero_trust.devices.dex_tests","methodName":"get","snippet":"data \"cloudflare_zero_trust_dex_test\" \"example_zero_trust_dex_test\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n dex_test_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[{"name":"dex_test_id","type":"String","description":"The unique identifier for the test."},{"name":"filter","type":"Attributes","children":[{"name":"kind","type":"String","description":"Filter by test type."},{"name":"test_name","type":"String","description":"Filter by test name."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier for the test."},{"name":"created","type":"Time","description":"Date the test was created, in RFC 3339 format."},{"name":"description","type":"String","description":"Additional details about the test."},{"name":"enabled","type":"Bool","description":"Determines whether or not the test is active."},{"name":"interval","type":"String","description":"How often the test will run."},{"name":"name","type":"String","description":"The name of the DEX test. Must be unique."},{"name":"targeted","type":"Bool"},{"name":"test_id","type":"String","description":"The unique identifier for the test."},{"name":"updated","type":"Time","description":"Date the test was last updated, in RFC 3339 format."},{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"target_policies","type":"List[Attributes]","description":"DEX rules targeted by this test","children":[{"name":"id","type":"String","description":"The id of the DEX rule."},{"name":"default","type":"Bool","description":"Whether the DEX rule is the account default."},{"name":"name","type":"String","description":"The name of the DEX rule."}]}]}]},"get /accounts/{}/dex/rules":{"operationId":"list-dex-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dex_rules","stainlessResource":"zero_trust.dex.rules","methodName":"list","snippet":"data \"cloudflare_zero_trust_dex_rules\" \"example_zero_trust_dex_rules\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n name = \"name\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[{"name":"name","type":"String","description":"Filter results by rule name."},{"name":"sort_by","type":"String","description":"Which property to sort results by."},{"name":"sort_order","type":"String","description":"Sort direction for sort_by property."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"API Resource UUID tag."},{"name":"created_at","type":"String"},{"name":"match","type":"String"},{"name":"name","type":"String"},{"name":"description","type":"String"},{"name":"targeted_tests","type":"List[Attributes]","children":[{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"test_id","type":"String"}]},{"name":"updated_at","type":"String"}]}]}]}]},"get /accounts/{}/dex/rules/{}":{"operationId":"get-dex-rule","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dex_rule","stainlessResource":"zero_trust.dex.rules","methodName":"get","snippet":"data \"cloudflare_zero_trust_dex_rule\" \"example_zero_trust_dex_rule\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"rule_id","type":"String","description":"API Resource UUID tag."},{"name":"account_id","type":"String","description":"Unique identifier linked to an account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"API Resource UUID tag."},{"name":"created_at","type":"String"},{"name":"description","type":"String"},{"name":"match","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"String"},{"name":"targeted_tests","type":"List[Attributes]","children":[{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"test_id","type":"String"}]}]}]},"get /accounts/{}/dlp/custom_prompt_topics":{"operationId":"dlp-custom-prompt-topics-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_custom_prompt_topics","stainlessResource":"zero_trust.dlp.custom_prompt_topics","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_custom_prompt_topics\" \"example_zero_trust_dlp_custom_prompt_topics\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool","deprecated":"Deprecated."},{"name":"name","type":"String"},{"name":"topic","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String","deprecated":"Deprecated."}]}]}]},"get /accounts/{}/dlp/custom_prompt_topics/{}":{"operationId":"dlp-custom-prompt-topics-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_custom_prompt_topic","stainlessResource":"zero_trust.dlp.custom_prompt_topics","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_custom_prompt_topic\" \"example_zero_trust_dlp_custom_prompt_topic\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"entry_id","type":"String"}],"optional":[],"computed":[{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"enabled","type":"Bool","deprecated":"Deprecated."},{"name":"id","type":"String"},{"name":"name","type":"String"},{"name":"profile_id","type":"String","deprecated":"Deprecated."},{"name":"topic","type":"String"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/dlp/data_classes":{"operationId":"dlp-data-classes-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_data_classes","stainlessResource":"zero_trust.dlp.data_classes","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_data_classes\" \"example_zero_trust_dlp_data_classes\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"data_tags","type":"List[String]"},{"name":"expression","type":"String"},{"name":"name","type":"String"},{"name":"sensitivity_levels","type":"List[Attributes]","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/data_classes/{}":{"operationId":"dlp-data-classes-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_data_class","stainlessResource":"zero_trust.dlp.data_classes","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_data_class\" \"example_zero_trust_dlp_data_class\" {\n account_id = \"account_id\"\n data_class_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"data_class_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"expression","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"data_tags","type":"List[String]"},{"name":"sensitivity_levels","type":"List[Attributes]","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories":{"operationId":"dlp-data-tag-categories-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_data_tag_categories","stainlessResource":"zero_trust.dlp.data_tag_categories","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_data_tag_categories\" \"example_zero_trust_dlp_data_tag_categories\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"tags","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"template_id","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories/{}":{"operationId":"dlp-data-tag-categories-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_data_tag_category","stainlessResource":"zero_trust.dlp.data_tag_categories","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_data_tag_category\" \"example_zero_trust_dlp_data_tag_category\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"category_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"template_id","type":"String"},{"name":"updated_at","type":"Time"},{"name":"tags","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories/{}/data_tags":{"operationId":"dlp-data-tags-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_data_tags","stainlessResource":"zero_trust.dlp.data_tag_categories.data_tags","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_data_tags\" \"example_zero_trust_dlp_data_tags\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"category_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/data_tag_categories/{}/data_tags/{}":{"operationId":"dlp-data-tags-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_data_tag","stainlessResource":"zero_trust.dlp.data_tag_categories.data_tags","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_data_tag\" \"example_zero_trust_dlp_data_tag\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n tag_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"tag_id","type":"String"},{"name":"account_id","type":"String"},{"name":"category_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/dlp/datasets":{"operationId":"dlp-datasets-read-all","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_datasets","stainlessResource":"zero_trust.dlp.datasets","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_datasets\" \"example_zero_trust_dlp_datasets\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"created_at","type":"Time"},{"name":"encoding_version","type":"Int64"},{"name":"name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"secret","type":"Bool"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]},{"name":"case_sensitive","type":"Bool"},{"name":"description","type":"String","description":"The description of the dataset."}]}]}]},"get /accounts/{}/dlp/datasets/{}":{"operationId":"dlp-datasets-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_dataset","stainlessResource":"zero_trust.dlp.datasets","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_dataset\" \"example_zero_trust_dlp_dataset\" {\n account_id = \"account_id\"\n dataset_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"dataset_id","type":"String"}],"optional":[],"computed":[{"name":"case_sensitive","type":"Bool"},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"The description of the dataset."},{"name":"encoding_version","type":"Int64"},{"name":"id","type":"String"},{"name":"name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"secret","type":"Bool"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]}]}]},"get /accounts/{}/dlp/entries":{"operationId":"dlp-entries-list-all-entries","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_custom_entries","stainlessResource":"zero_trust.dlp.entries.custom","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_custom_entries\" \"example_zero_trust_dlp_custom_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]},{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_entries","stainlessResource":"zero_trust.dlp.entries","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_entries\" \"example_zero_trust_dlp_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]},{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_integration_entries","stainlessResource":"zero_trust.dlp.entries.integration","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_integration_entries\" \"example_zero_trust_dlp_integration_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]},{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_predefined_entries","stainlessResource":"zero_trust.dlp.entries.predefined","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_predefined_entries\" \"example_zero_trust_dlp_predefined_entries\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"upload_status","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]}]},"get /accounts/{}/dlp/entries/{}":{"operationId":"dlp-entries-get-dlp-entry","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_custom_entry","stainlessResource":"zero_trust.dlp.entries.custom","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_custom_entry\" \"example_zero_trust_dlp_custom_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"data-source","name":"cloudflare_zero_trust_dlp_entry","stainlessResource":"zero_trust.dlp.entries","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_entry\" \"example_zero_trust_dlp_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"data-source","name":"cloudflare_zero_trust_dlp_integration_entry","stainlessResource":"zero_trust.dlp.entries.integration","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_integration_entry\" \"example_zero_trust_dlp_integration_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"data-source","name":"cloudflare_zero_trust_dlp_predefined_entry","stainlessResource":"zero_trust.dlp.entries.predefined","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_predefined_entry\" \"example_zero_trust_dlp_predefined_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"entry_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"profile_id","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"get /accounts/{}/dlp/profiles/custom/{}":{"operationId":"dlp-profiles-get-custom-profile","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_custom_profile","stainlessResource":"zero_trust.dlp.profiles.custom","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_custom_profile\" \"example_zero_trust_dlp_custom_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"profile_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64","description":"Related DLP policies will trigger when the match count exceeds the number set."},{"name":"confidence_threshold","type":"String"},{"name":"created_at","type":"Time","description":"When the profile was created."},{"name":"description","type":"String","description":"The description of the profile."},{"name":"integration_id","type":"String"},{"name":"name","type":"String","description":"The name of the profile."},{"name":"ocr_enabled","type":"Bool"},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."},{"name":"type","type":"String"},{"name":"updated_at","type":"Time","description":"When the profile was lasted updated."},{"name":"data_classes","type":"List[String]","description":"Data classes associated with this profile."},{"name":"data_tags","type":"List[String]","description":"Data tags associated with this profile."},{"name":"context_awareness","type":"Attributes","description":"Scan the context of predefined entries to only return matches surrounded by keywords.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"If true, scan the context of predefined entries to only return matches surrounded by keywords."},{"name":"skip","type":"Attributes","description":"Content types to exclude from context analysis and return all matches.","children":[{"name":"files","type":"Bool","description":"If the content type is a file, skip context analysis and return all matches."}]}]},{"name":"entries","type":"List[Attributes]","deprecated":"Deprecated.","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]},{"name":"sensitivity_levels","type":"List[Attributes]","description":"Sensitivity levels associated with this profile.","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]},{"name":"shared_entries","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]}]},"get /accounts/{}/dlp/profiles/predefined/{}/config":{"operationId":"dlp-profiles-get-predefined-profile-config","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_predefined_profile","stainlessResource":"zero_trust.dlp.profiles.predefined","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_predefined_profile\" \"example_zero_trust_dlp_predefined_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"profile_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64"},{"name":"confidence_threshold","type":"String"},{"name":"name","type":"String","description":"The name of the predefined profile."},{"name":"ocr_enabled","type":"Bool"},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."},{"name":"enabled_entries","type":"List[String]","description":"Entries to enable for this predefined profile. Any entries not provided will be disabled."},{"name":"entries","type":"List[Attributes]","description":"This field has been deprecated for `enabled_entries`.","deprecated":"Deprecated.","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"profile_id","type":"String"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"secret","type":"Bool"},{"name":"word_list","type":"List[String]"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups":{"operationId":"dlp-sensitivity-groups-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_sensitivity_groups","stainlessResource":"zero_trust.dlp.sensitivity_groups","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_groups\" \"example_zero_trust_dlp_sensitivity_groups\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"levels","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"},{"name":"template_id","type":"String"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}":{"operationId":"dlp-sensitivity-groups-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_sensitivity_group","stainlessResource":"zero_trust.dlp.sensitivity_groups","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_group\" \"example_zero_trust_dlp_sensitivity_group\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"sensitivity_group_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"template_id","type":"String"},{"name":"updated_at","type":"Time"},{"name":"levels","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}/level_order":{"operationId":"dlp-sensitivity-groups-get-level-order","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_sensitivity_level_order","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels.order","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_level_order\" \"example_zero_trust_dlp_sensitivity_level_order\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"sensitivity_group_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"level_ids","type":"List[String]"}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}/levels":{"operationId":"dlp-sensitivity-levels-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dlp_sensitivity_levels","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels","methodName":"list","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_levels\" \"example_zero_trust_dlp_sensitivity_levels\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"sensitivity_group_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"},{"name":"description","type":"String"}]}]}]},"get /accounts/{}/dlp/sensitivity_groups/{}/levels/{}":{"operationId":"dlp-sensitivity-levels-read","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_sensitivity_level","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_sensitivity_level\" \"example_zero_trust_dlp_sensitivity_level\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n sensitivity_level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"sensitivity_level_id","type":"String"},{"name":"account_id","type":"String"},{"name":"sensitivity_group_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"Time"}]}]},"get /accounts/{}/dlp/settings":{"operationId":"dlp-settings-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dlp_settings","stainlessResource":"zero_trust.dlp.settings","methodName":"get","snippet":"data \"cloudflare_zero_trust_dlp_settings\" \"example_zero_trust_dlp_settings\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ai_context_analysis","type":"Bool","description":"Whether AI context analysis is enabled at the account level."},{"name":"ocr","type":"Bool","description":"Whether OCR is enabled at the account level."},{"name":"payload_logging","type":"Attributes","children":[{"name":"updated_at","type":"Time"},{"name":"masking_level","type":"String","description":"Masking level for payload logs.\n\n- `full`: The entire payload is masked.\n- `partial`: Only partial payload content is masked.\n- `clear`: No masking is applied to the payload content.\n- `default`: DLP uses its default masking behavior."},{"name":"public_key","type":"String","description":"Base64-encoded public key for encrypting payload logs. Null when payload logging is disabled."}]}]}]},"get /accounts/{}/dls/regional_services/prefix_bindings":{"operationId":"publicListPrefixBindings","declarations":[{"kind":"list-data-source","name":"cloudflare_dls_prefix_bindings","stainlessResource":"dls.regional_services.prefix_bindings","methodName":"list","snippet":"data \"cloudflare_dls_prefix_bindings\" \"example_dls_prefix_bindings\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the binding."},{"name":"cidr","type":"String","description":"The CIDR that is bound."},{"name":"prefix_id","type":"String","description":"The ID of the parent prefix."},{"name":"region_key","type":"String","description":"The region key used for the binding."}]}]}]},"get /accounts/{}/dls/regional_services/prefix_bindings/{}":{"operationId":"publicGetPrefixBinding","declarations":[{"kind":"data-source","name":"cloudflare_dls_prefix_binding","stainlessResource":"dls.regional_services.prefix_bindings","methodName":"get","snippet":"data \"cloudflare_dls_prefix_binding\" \"example_dls_prefix_binding\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n binding_id = \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}\n","required":[{"name":"binding_id","type":"String","description":"Unique identifier for the prefix binding."},{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Unique identifier for the prefix binding."},{"name":"cidr","type":"String","description":"The CIDR that is bound."},{"name":"prefix_id","type":"String","description":"The ID of the parent prefix."},{"name":"region_key","type":"String","description":"The region key used for the binding."}]}]},"get /accounts/{}/dns_firewall":{"operationId":"dns-firewall-list-dns-firewall-clusters","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_firewalls","stainlessResource":"dns_firewall","methodName":"list","snippet":"data \"cloudflare_dns_firewalls\" \"example_dns_firewalls\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"deprecate_any_requests","type":"Bool","description":"Whether to refuse to answer queries for the ANY type"},{"name":"dns_firewall_ips","type":"Set[String]"},{"name":"ecs_fallback","type":"Bool","description":"Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent"},{"name":"maximum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"minimum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons.\n"},{"name":"modified_on","type":"Time","description":"Last modification of DNS Firewall cluster"},{"name":"name","type":"String","description":"DNS Firewall cluster name"},{"name":"negative_cache_ttl","type":"Float64","description":"This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"ratelimit","type":"Float64","description":"Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting."},{"name":"retries","type":"Float64","description":"Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)"},{"name":"upstream_ips","type":"Set[String]"},{"name":"attack_mitigation","type":"Attributes","description":"Attack mitigation settings","children":[{"name":"enabled","type":"Bool","description":"When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers"},{"name":"only_when_upstream_unhealthy","type":"Bool","description":"Only mitigate attacks when upstream servers seem unhealthy"}]}]}]}]},"get /accounts/{}/dns_firewall/{}":{"operationId":"dns-firewall-dns-firewall-cluster-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_firewall","stainlessResource":"dns_firewall","methodName":"get","snippet":"data \"cloudflare_dns_firewall\" \"example_dns_firewall\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns_firewall_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"dns_firewall_id","type":"String","description":"Identifier."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"deprecate_any_requests","type":"Bool","description":"Whether to refuse to answer queries for the ANY type"},{"name":"ecs_fallback","type":"Bool","description":"Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent"},{"name":"maximum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"minimum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons.\n"},{"name":"modified_on","type":"Time","description":"Last modification of DNS Firewall cluster"},{"name":"name","type":"String","description":"DNS Firewall cluster name"},{"name":"negative_cache_ttl","type":"Float64","description":"This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"ratelimit","type":"Float64","description":"Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting."},{"name":"retries","type":"Float64","description":"Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)"},{"name":"dns_firewall_ips","type":"Set[String]"},{"name":"upstream_ips","type":"Set[String]"},{"name":"attack_mitigation","type":"Attributes","description":"Attack mitigation settings","children":[{"name":"enabled","type":"Bool","description":"When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers"},{"name":"only_when_upstream_unhealthy","type":"Bool","description":"Only mitigate attacks when upstream servers seem unhealthy"}]}]}]},"get /accounts/{}/dns_settings/views":{"operationId":"dns-views-for-an-account-list-internal-dns-views","declarations":[{"kind":"list-data-source","name":"cloudflare_account_dns_settings_internal_views","stainlessResource":"dns.settings.account.views","methodName":"list","snippet":"data \"cloudflare_account_dns_settings_internal_views\" \"example_account_dns_settings_internal_views\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = {\n contains = \"view\"\n endswith = \"ew\"\n exact = \"my view\"\n startswith = \"my\"\n }\n order = \"name\"\n zone_id = \"ae29bea30e2e427ba9cd8d78b628177b\"\n zone_name = \"www.example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"order","type":"String","description":"Field to order DNS views by."},{"name":"zone_id","type":"String","description":"A zone ID that exists in the zones list for the view.\n"},{"name":"zone_name","type":"String","description":"A zone name that exists in the zones list for the view.\n"},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS view name.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS view name.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS view name.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS view name.\n"}]},{"name":"direction","type":"String","description":"Direction to order DNS views in."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_time","type":"Time","description":"When the view was created."},{"name":"modified_time","type":"Time","description":"When the view was last modified."},{"name":"name","type":"String","description":"The name of the view."},{"name":"zones","type":"Set[String]","description":"The list of zones linked to this view."}]}]}]},"get /accounts/{}/dns_settings/views/{}":{"operationId":"dns-views-for-an-account-get-internal-dns-view","declarations":[{"kind":"data-source","name":"cloudflare_account_dns_settings_internal_view","stainlessResource":"dns.settings.account.views","methodName":"get","snippet":"data \"cloudflare_account_dns_settings_internal_view\" \"example_account_dns_settings_internal_view\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n view_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"view_id","type":"String","description":"Identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order DNS views in."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead.\n"},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS view name.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS view name.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS view name.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS view name.\n"}]},{"name":"order","type":"String","description":"Field to order DNS views by."},{"name":"zone_id","type":"String","description":"A zone ID that exists in the zones list for the view.\n"},{"name":"zone_name","type":"String","description":"A zone name that exists in the zones list for the view.\n"}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_time","type":"Time","description":"When the view was created."},{"name":"modified_time","type":"Time","description":"When the view was last modified."},{"name":"name","type":"String","description":"The name of the view."},{"name":"zones","type":"Set[String]","description":"The list of zones linked to this view."}]}]},"get /accounts/{}/email-security/settings/allow_policies":{"operationId":"email_security_list_allow_policies","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_allow_policies","stainlessResource":"email_security.settings.allow_policies","methodName":"list","snippet":"data \"cloudflare_email_security_allow_policies\" \"example_email_security_allow_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n is_acceptable_sender = true\n is_exempt_recipient = true\n is_trusted_sender = true\n order = \"pattern\"\n pattern = \"pattern\"\n pattern_type = \"EMAIL\"\n search = \"search\"\n verify_sender = true\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_acceptable_sender","type":"Bool","description":"Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious)."},{"name":"is_exempt_recipient","type":"Bool","description":"Filter to show only policies where messages to the recipient bypass all detections."},{"name":"is_trusted_sender","type":"Bool","description":"Filter to show only policies where messages from the sender bypass all detections and link following."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by exact pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"verify_sender","type":"Bool","description":"Filter to show only policies that enforce DMARC, SPF, or DKIM authentication."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Allow policy identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"comments","type":"String"},{"name":"is_acceptable_sender","type":"Bool","description":"Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply."},{"name":"is_exempt_recipient","type":"Bool","description":"Bypasses all detections for messages to this recipient."},{"name":"is_recipient","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.","deprecated":"Use `is_exempt_recipient` instead."},{"name":"is_regex","type":"Bool"},{"name":"is_sender","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_trusted_sender` instead."},{"name":"is_spoof","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_acceptable_sender` instead."},{"name":"is_trusted_sender","type":"Bool","description":"Bypasses all detections and link following for messages from this sender."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"},{"name":"verify_sender","type":"Bool","description":"Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication."}]}]}]},"get /accounts/{}/email-security/settings/allow_policies/{}":{"operationId":"email_security_get_allow_policy","declarations":[{"kind":"data-source","name":"cloudflare_email_security_allow_policy","stainlessResource":"email_security.settings.allow_policies","methodName":"get","snippet":"data \"cloudflare_email_security_allow_policy\" \"example_email_security_allow_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"policy_id","type":"String","description":"Allow policy identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_acceptable_sender","type":"Bool","description":"Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious)."},{"name":"is_exempt_recipient","type":"Bool","description":"Filter to show only policies where messages to the recipient bypass all detections."},{"name":"is_trusted_sender","type":"Bool","description":"Filter to show only policies where messages from the sender bypass all detections and link following."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by exact pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"verify_sender","type":"Bool","description":"Filter to show only policies that enforce DMARC, SPF, or DKIM authentication."}]}],"computed":[{"name":"id","type":"String","description":"Allow policy identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_acceptable_sender","type":"Bool","description":"Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply."},{"name":"is_exempt_recipient","type":"Bool","description":"Bypasses all detections for messages to this recipient."},{"name":"is_recipient","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.","deprecated":"Use `is_exempt_recipient` instead."},{"name":"is_regex","type":"Bool"},{"name":"is_sender","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_trusted_sender` instead."},{"name":"is_spoof","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_acceptable_sender` instead."},{"name":"is_trusted_sender","type":"Bool","description":"Bypasses all detections and link following for messages from this sender."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"},{"name":"verify_sender","type":"Bool","description":"Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication."}]}]},"get /accounts/{}/email-security/settings/block_senders":{"operationId":"email_security_list_blocked_senders","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_block_senders","stainlessResource":"email_security.settings.block_senders","methodName":"list","snippet":"data \"cloudflare_email_security_block_senders\" \"example_email_security_block_senders\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"pattern\"\n pattern = \"pattern\"\n pattern_type = \"EMAIL\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Blocked sender pattern identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal value."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"}]}]}]},"get /accounts/{}/email-security/settings/block_senders/{}":{"operationId":"email_security_get_blocked_sender","declarations":[{"kind":"data-source","name":"cloudflare_email_security_block_sender","stainlessResource":"email_security.settings.block_senders","methodName":"get","snippet":"data \"cloudflare_email_security_block_sender\" \"example_email_security_block_sender\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pattern_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"pattern_id","type":"String","description":"Blocked sender pattern identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String","description":"Filter by pattern value."},{"name":"pattern_type","type":"String","description":"Filter by pattern type."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."}]}],"computed":[{"name":"id","type":"String","description":"Blocked sender pattern identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal value."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"}]}]},"get /accounts/{}/email-security/settings/domains":{"operationId":"email_security_list_domains","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_domains","stainlessResource":"email_security.settings.domains","methodName":"list","snippet":"data \"cloudflare_email_security_domains\" \"example_email_security_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n active_delivery_mode = \"DIRECT\"\n allowed_delivery_mode = \"DIRECT\"\n direction = \"asc\"\n domain = [\"string\"]\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n order = \"domain\"\n search = \"search\"\n status = \"PENDING\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"active_delivery_mode","type":"String","description":"Currently active delivery mode to filter by."},{"name":"allowed_delivery_mode","type":"String","description":"Delivery mode to filter by."},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"integration_id","type":"String","description":"Integration ID to filter by."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"status","type":"String","description":"Filters response to domains with the provided status."},{"name":"domain","type":"List[String]","description":"Domain names to filter by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"allowed_delivery_modes","type":"Set[String]"},{"name":"authorization","type":"Attributes","children":[{"name":"authorized","type":"Bool"},{"name":"timestamp","type":"Time"},{"name":"status_message","type":"String"}]},{"name":"created_at","type":"Time"},{"name":"dmarc_status","type":"String"},{"name":"domain","type":"String"},{"name":"drop_dispositions","type":"Set[String]"},{"name":"emails_processed","type":"Attributes","children":[{"name":"timestamp","type":"Time"},{"name":"total_emails_processed","type":"Int64"},{"name":"total_emails_processed_previous","type":"Int64"}]},{"name":"folder","type":"String","description":"The mailbox folder to scan, for API-scanning domains."},{"name":"inbox_provider","type":"String"},{"name":"integration_id","type":"String"},{"name":"ip_restrictions","type":"Set[String]"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"lookback_hops","type":"Int64"},{"name":"modified_at","type":"Time"},{"name":"o365_tenant_id","type":"String"},{"name":"regions","type":"Set[String]"},{"name":"require_tls_inbound","type":"Bool"},{"name":"require_tls_outbound","type":"Bool"},{"name":"spf_status","type":"String"},{"name":"status","type":"String"},{"name":"transport","type":"String"}]}]}]},"get /accounts/{}/email-security/settings/domains/{}":{"operationId":"email_security_get_domain","declarations":[{"kind":"data-source","name":"cloudflare_email_security_domain","stainlessResource":"email_security.settings.domains","methodName":"get","snippet":"data \"cloudflare_email_security_domain\" \"example_email_security_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"domain_id","type":"String","description":"Domain identifier."},{"name":"filter","type":"Attributes","children":[{"name":"active_delivery_mode","type":"String","description":"Currently active delivery mode to filter by."},{"name":"allowed_delivery_mode","type":"String","description":"Delivery mode to filter by."},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"domain","type":"List[String]","description":"Domain names to filter by."},{"name":"integration_id","type":"String","description":"Integration ID to filter by."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"status","type":"String","description":"Filters response to domains with the provided status."}]}],"computed":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"created_at","type":"Time"},{"name":"dmarc_status","type":"String"},{"name":"domain","type":"String"},{"name":"folder","type":"String","description":"The mailbox folder to scan, for API-scanning domains."},{"name":"inbox_provider","type":"String"},{"name":"integration_id","type":"String"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"lookback_hops","type":"Int64"},{"name":"modified_at","type":"Time"},{"name":"o365_tenant_id","type":"String"},{"name":"require_tls_inbound","type":"Bool"},{"name":"require_tls_outbound","type":"Bool"},{"name":"spf_status","type":"String"},{"name":"status","type":"String"},{"name":"transport","type":"String"},{"name":"allowed_delivery_modes","type":"Set[String]"},{"name":"drop_dispositions","type":"Set[String]"},{"name":"ip_restrictions","type":"Set[String]"},{"name":"regions","type":"Set[String]"},{"name":"authorization","type":"Attributes","children":[{"name":"authorized","type":"Bool"},{"name":"timestamp","type":"Time"},{"name":"status_message","type":"String"}]},{"name":"emails_processed","type":"Attributes","children":[{"name":"timestamp","type":"Time"},{"name":"total_emails_processed","type":"Int64"},{"name":"total_emails_processed_previous","type":"Int64"}]}]}]},"get /accounts/{}/email-security/settings/impersonation_registry":{"operationId":"email_security_list_impersonation_registry","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_impersonation_registries","stainlessResource":"email_security.settings.impersonation_registry","methodName":"list","snippet":"data \"cloudflare_email_security_impersonation_registries\" \"example_email_security_impersonation_registries\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"name\"\n provenance = \"A1S_INTERNAL\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"provenance","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Impersonation registry entry identifier."},{"name":"comments","type":"String","description":"Optional note describing the entry."},{"name":"created_at","type":"Time"},{"name":"directory_id","type":"Int64","description":"Identifier of the directory the entry was synced from, when directory-synced."},{"name":"directory_node_id","type":"Int64","description":"Identifier of the directory node the entry was synced from, when directory-synced."},{"name":"email","type":"String","description":"Email address (or pattern) of the protected identity."},{"name":"external_directory_node_id","type":"String","description":"Deprecated. External identifier of the directory node.","deprecated":"This field is deprecated."},{"name":"is_email_regex","type":"Bool","description":"Whether `email` is a regular expression instead of a literal address."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Display name of the protected identity."},{"name":"provenance","type":"String","description":"Source the entry was created from."}]}]}]},"get /accounts/{}/email-security/settings/impersonation_registry/{}":{"operationId":"email_security_get_impersonation_registry","declarations":[{"kind":"data-source","name":"cloudflare_email_security_impersonation_registry","stainlessResource":"email_security.settings.impersonation_registry","methodName":"get","snippet":"data \"cloudflare_email_security_impersonation_registry\" \"example_email_security_impersonation_registry\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n impersonation_registry_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"impersonation_registry_id","type":"String","description":"Impersonation registry entry identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"provenance","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."}]}],"computed":[{"name":"id","type":"String","description":"Impersonation registry entry identifier."},{"name":"comments","type":"String","description":"Optional note describing the entry."},{"name":"created_at","type":"Time"},{"name":"directory_id","type":"Int64","description":"Identifier of the directory the entry was synced from, when directory-synced."},{"name":"directory_node_id","type":"Int64","description":"Identifier of the directory node the entry was synced from, when directory-synced."},{"name":"email","type":"String","description":"Email address (or pattern) of the protected identity."},{"name":"external_directory_node_id","type":"String","description":"Deprecated. External identifier of the directory node.","deprecated":"This field is deprecated."},{"name":"is_email_regex","type":"Bool","description":"Whether `email` is a regular expression instead of a literal address."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Display name of the protected identity."},{"name":"provenance","type":"String","description":"Source the entry was created from."}]}]},"get /accounts/{}/email-security/settings/trusted_domains":{"operationId":"email_security_list_trusted_domains","declarations":[{"kind":"list-data-source","name":"cloudflare_email_security_trusted_domains_list","stainlessResource":"email_security.settings.trusted_domains","methodName":"list","snippet":"data \"cloudflare_email_security_trusted_domains_list\" \"example_email_security_trusted_domains_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n is_recent = true\n is_similarity = true\n order = \"pattern\"\n pattern = \"pattern\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_recent","type":"Bool","description":"Filter to show only recently registered domains that are trusted to prevent triggering Suspicious or Malicious dispositions."},{"name":"is_similarity","type":"Bool","description":"Filter to show only proximity domains (partner or approved domains with similar spelling to connected domains) that prevent Spoof dispositions."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Trusted domain identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_recent","type":"Bool","description":"Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition."},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal domain."},{"name":"is_similarity","type":"Bool","description":"Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The domain pattern to trust, e.g. `example.com`."}]}]}]},"get /accounts/{}/email-security/settings/trusted_domains/{}":{"operationId":"email_security_get_trusted_domain","declarations":[{"kind":"data-source","name":"cloudflare_email_security_trusted_domains","stainlessResource":"email_security.settings.trusted_domains","methodName":"get","snippet":"data \"cloudflare_email_security_trusted_domains\" \"example_email_security_trusted_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n trusted_domain_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"trusted_domain_id","type":"String","description":"Trusted domain identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"The sorting direction."},{"name":"is_recent","type":"Bool","description":"Filter to show only recently registered domains that are trusted to prevent triggering Suspicious or Malicious dispositions."},{"name":"is_similarity","type":"Bool","description":"Filter to show only proximity domains (partner or approved domains with similar spelling to connected domains) that prevent Spoof dispositions."},{"name":"order","type":"String","description":"Field to sort by."},{"name":"pattern","type":"String"},{"name":"search","type":"String","description":"Search term for filtering records. Behavior may change."}]}],"computed":[{"name":"id","type":"String","description":"Trusted domain identifier."},{"name":"comments","type":"String"},{"name":"created_at","type":"Time"},{"name":"is_recent","type":"Bool","description":"Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition."},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal domain."},{"name":"is_similarity","type":"Bool","description":"Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition."},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"pattern","type":"String","description":"The domain pattern to trust, e.g. `example.com`."}]}]},"get /accounts/{}/email/routing/addresses":{"operationId":"email-routing-destination-addresses-list-destination-addresses","declarations":[{"kind":"list-data-source","name":"cloudflare_email_routing_addresses","stainlessResource":"email_routing.addresses","methodName":"list","snippet":"data \"cloudflare_email_routing_addresses\" \"example_email_routing_addresses\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"Sorts results in an ascending or descending order."},{"name":"verified","type":"Bool","description":"Filter by verified destination addresses."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Destination address identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"tag","type":"String","description":"Destination address tag. (Deprecated, replaced by destination address identifier)","deprecated":"Deprecated."},{"name":"verified","type":"Time","description":"The date and time the destination address has been verified. Null means not verified yet."}]}]}]},"get /accounts/{}/email/routing/addresses/{}":{"operationId":"email-routing-destination-addresses-get-a-destination-address","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_address","stainlessResource":"email_routing.addresses","methodName":"get","snippet":"data \"cloudflare_email_routing_address\" \"example_email_routing_address\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n destination_address_identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"destination_address_identifier","type":"String","description":"Destination address identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sorts results in an ascending or descending order."},{"name":"verified","type":"Bool","description":"Filter by verified destination addresses."}]}],"computed":[{"name":"id","type":"String","description":"Destination address identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"tag","type":"String","description":"Destination address tag. (Deprecated, replaced by destination address identifier)","deprecated":"Deprecated."},{"name":"verified","type":"Time","description":"The date and time the destination address has been verified. Null means not verified yet."}]}]},"get /accounts/{}/event_notifications/r2/{}/configuration/queues/{}":{"operationId":"r2-get-event-notification-config","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_event_notification","stainlessResource":"r2.buckets.event_notifications","methodName":"get","snippet":"data \"cloudflare_r2_bucket_event_notification\" \"example_r2_bucket_event_notification\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n queue_id = \"queue_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."},{"name":"queue_id","type":"String","description":"ID of the Cloudflare Queue that receives notifications for matching R2 object events."}],"optional":[],"computed":[{"name":"queue_name","type":"String","description":"Name of the queue."},{"name":"rules","type":"List[Attributes]","children":[{"name":"actions","type":"List[String]","description":"Array of R2 object actions that will trigger notifications."},{"name":"created_at","type":"String","description":"Timestamp when the rule was created."},{"name":"description","type":"String","description":"A description that can be used to identify the event notification rule after creation."},{"name":"prefix","type":"String","description":"Notifications will be sent only for objects with this prefix."},{"name":"rule_id","type":"String","description":"Rule ID."},{"name":"suffix","type":"String","description":"Notifications will be sent only for objects with this suffix."}]}]}]},"get /accounts/{}/field_extractors/{}":{"operationId":"getFieldExtractor","declarations":[{"kind":"data-source","name":"cloudflare_field_extractor","stainlessResource":"field_extractors","methodName":"get","snippet":"data \"cloudflare_field_extractor\" \"example_field_extractor\" {\n account_id = \"123456\"\n extractor = \"llm_prompts\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID."},{"name":"extractor","type":"String","description":"Extractor type."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"expression","type":"String","description":"Wirefilter value expression."},{"name":"name","type":"String","description":"Field name."}]},{"name":"ref","type":"String","description":"Stable rule identifier."},{"name":"description","type":"String","description":"Human-readable rule description."}]}]}]},"get /accounts/{}/flagship/apps":{"operationId":"flagship_list_apps","declarations":[{"kind":"list-data-source","name":"cloudflare_flagship_apps","stainlessResource":"flagship.apps","methodName":"list","snippet":"data \"cloudflare_flagship_apps\" \"example_flagship_apps\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String","description":"Email of the actor who last modified the app, or `unknown` when unavailable."}]}]}]},"get /accounts/{}/flagship/apps/{}":{"operationId":"flagship_get_app","declarations":[{"kind":"data-source","name":"cloudflare_flagship_app","stainlessResource":"flagship.apps","methodName":"get","snippet":"data \"cloudflare_flagship_app\" \"example_flagship_app\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n}\n","required":[{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created."},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Flagship app ID returned when the app was created."},{"name":"created_at","type":"String"},{"name":"name","type":"String"},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String","description":"Email of the actor who last modified the app, or `unknown` when unavailable."}]}]},"get /accounts/{}/flagship/apps/{}/flags":{"operationId":"flagship_list_flags","declarations":[{"kind":"list-data-source","name":"cloudflare_flagship_flags","stainlessResource":"flagship.apps.flags","methodName":"list","snippet":"data \"cloudflare_flagship_flags\" \"example_flagship_flags\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n limit = 1\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."},{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created."}],"optional":[{"name":"limit","type":"Int64","description":"Max items to return (1–200)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls."},{"name":"default_variation","type":"String","description":"Variation the API serves when the flag is off, or when it's on but no rule matches the context. Must be a key in `variations`."},{"name":"enabled","type":"Bool","description":"When false, the flag bypasses all rules and always serves `default_variation`."},{"name":"key","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls."},{"name":"rules","type":"List[Attributes]","description":"Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.","children":[{"name":"conditions","type":"List[Attributes]","description":"Conditions the context must satisfy for this rule to match. An empty array matches all contexts.","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[String]"},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"priority","type":"Int64","description":"Evaluation order: the API evaluates rules with lower numbers first. Must be unique across the flag's rules."},{"name":"serve_variation","type":"String","description":"Variation the API serves when this rule matches. Must be a key in `variations`."},{"name":"rollout","type":"Attributes","children":[{"name":"percentage","type":"Float64","description":"Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)."},{"name":"attribute","type":"String","description":"Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request."}]}]},{"name":"type","type":"String","description":"Server-inferred value type shared by all of the flag's variations."},{"name":"variations","type":"Map[String]","description":"Map of variation name to value. All values share the same type (boolean, string, number, or JSON object/array), and each serialized value stays within 10KB."},{"name":"description","type":"String","description":"Optional operator-facing description. It does not affect flag evaluation."},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String"}]}]}]},"get /accounts/{}/flagship/apps/{}/flags/{}":{"operationId":"flagship_get_flag","declarations":[{"kind":"data-source","name":"cloudflare_flagship_flag","stainlessResource":"flagship.apps.flags","methodName":"get","snippet":"data \"cloudflare_flagship_flag\" \"example_flagship_flag\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n flag_key = \"flag_key\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app."},{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created."}],"optional":[{"name":"flag_key","type":"String","description":"Case-sensitive key identifying the flag within the app."},{"name":"filter","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Max items to return (1–200)."}]}],"computed":[{"name":"id","type":"String","description":"Case-sensitive key identifying the flag within the app."},{"name":"default_variation","type":"String","description":"Variation the API serves when the flag is off, or when it's on but no rule matches the context. Must be a key in `variations`."},{"name":"description","type":"String","description":"Optional operator-facing description. It does not affect flag evaluation."},{"name":"enabled","type":"Bool","description":"When false, the flag bypasses all rules and always serves `default_variation`."},{"name":"key","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls."},{"name":"type","type":"String","description":"Server-inferred value type shared by all of the flag's variations."},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String"},{"name":"variations","type":"Map[String]","description":"Map of variation name to value. All values share the same type (boolean, string, number, or JSON object/array), and each serialized value stays within 10KB."},{"name":"rules","type":"List[Attributes]","description":"Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.","children":[{"name":"conditions","type":"List[Attributes]","description":"Conditions the context must satisfy for this rule to match. An empty array matches all contexts.","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[String]"},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"priority","type":"Int64","description":"Evaluation order: the API evaluates rules with lower numbers first. Must be unique across the flag's rules."},{"name":"serve_variation","type":"String","description":"Variation the API serves when this rule matches. Must be a key in `variations`."},{"name":"rollout","type":"Attributes","children":[{"name":"percentage","type":"Float64","description":"Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)."},{"name":"attribute","type":"String","description":"Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request."}]}]}]}]},"get /accounts/{}/gateway/app_types":{"operationId":"zero-trust-gateway-application-and-application-type-mappings-list-application-and-application-type-mappings","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_app_types_list","stainlessResource":"zero_trust.gateway.app_types","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_app_types_list\" \"example_zero_trust_gateway_app_types_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Provide the identifier string."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Identify this application. Only one application per ID."},{"name":"application_type_id","type":"Int64","description":"Identify the type of this application. Multiple applications can share the same type. Refers to the `id` of a returned application type."},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"Specify the name of the application or application type."},{"name":"description","type":"String","description":"Provide a short summary of applications with this type."}]}]}]},"get /accounts/{}/gateway/categories":{"operationId":"zero-trust-gateway-categories-list-categories","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_categories_list","stainlessResource":"zero_trust.gateway.categories","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_categories_list\" \"example_zero_trust_gateway_categories_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Provide the identifier string."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Identify this category. Only one category per ID."},{"name":"beta","type":"Bool","description":"Indicate whether the category is in beta and subject to change."},{"name":"class","type":"String","description":"Specify which account types can create policies for this category. `blocked` Blocks unconditionally for all accounts. `removalPending` Allows removal from policies but disables addition. `noBlock` Prevents blocking."},{"name":"description","type":"String","description":"Provide a short summary of domains in the category."},{"name":"name","type":"String","description":"Specify the category name."},{"name":"subcategories","type":"List[Attributes]","description":"Provide all subcategories for this category.","children":[{"name":"id","type":"Int64","description":"Identify this category. Only one category per ID."},{"name":"beta","type":"Bool","description":"Indicate whether the category is in beta and subject to change."},{"name":"class","type":"String","description":"Specify which account types can create policies for this category. `blocked` Blocks unconditionally for all accounts. `removalPending` Allows removal from policies but disables addition. `noBlock` Prevents blocking."},{"name":"description","type":"String","description":"Provide a short summary of domains in the category."},{"name":"name","type":"String","description":"Specify the category name."}]}]}]}]},"get /accounts/{}/gateway/certificates":{"operationId":"zero-trust-certificates-list-zero-trust-certificates","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_certificates","stainlessResource":"zero_trust.gateway.certificates","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_certificates\" \"example_zero_trust_gateway_certificates\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identify the certificate with a UUID."},{"name":"binding_status","type":"String","description":"Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state."},{"name":"certificate","type":"String","description":"Provide the CA certificate (read-only)."},{"name":"created_at","type":"Time"},{"name":"expires_on","type":"Time"},{"name":"fingerprint","type":"String","description":"Provide the SHA256 fingerprint of the certificate (read-only)."},{"name":"in_use","type":"Bool","description":"Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)."},{"name":"issuer_org","type":"String","description":"Indicate the organization that issued the certificate (read-only)."},{"name":"issuer_raw","type":"String","description":"Provide the entire issuer field of the certificate (read-only)."},{"name":"type","type":"String","description":"Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed."},{"name":"updated_at","type":"Time"},{"name":"uploaded_on","type":"Time"}]}]}]},"get /accounts/{}/gateway/certificates/{}":{"operationId":"zero-trust-certificates-zero-trust-certificate-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_certificate","stainlessResource":"zero_trust.gateway.certificates","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_certificate\" \"example_zero_trust_gateway_certificate\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n certificate_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"certificate_id","type":"String","description":"Identify the certificate with a UUID."},{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identify the certificate with a UUID."},{"name":"binding_status","type":"String","description":"Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state."},{"name":"certificate","type":"String","description":"Provide the CA certificate (read-only)."},{"name":"created_at","type":"Time"},{"name":"expires_on","type":"Time"},{"name":"fingerprint","type":"String","description":"Provide the SHA256 fingerprint of the certificate (read-only)."},{"name":"in_use","type":"Bool","description":"Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)."},{"name":"issuer_org","type":"String","description":"Indicate the organization that issued the certificate (read-only)."},{"name":"issuer_raw","type":"String","description":"Provide the entire issuer field of the certificate (read-only)."},{"name":"type","type":"String","description":"Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed."},{"name":"updated_at","type":"Time"},{"name":"uploaded_on","type":"Time"}]}]},"get /accounts/{}/gateway/configuration":{"operationId":"zero-trust-accounts-get-zero-trust-account-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_settings","stainlessResource":"zero_trust.gateway.configurations","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_settings\" \"example_zero_trust_gateway_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier."},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"},{"name":"settings","type":"Attributes","description":"Specify account settings.","children":[{"name":"activity_log","type":"Attributes","description":"Specify activity log settings.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to log activity."}]},{"name":"antivirus","type":"Attributes","description":"Specify anti-virus settings.","children":[{"name":"enabled_download_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on downloads."},{"name":"enabled_upload_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on uploads."},{"name":"fail_closed","type":"Bool","description":"Specify whether to block requests for unscannable files."},{"name":"notification_settings","type":"Attributes","description":"Configure the message the user's device shows during an antivirus scan.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable notifications."},{"name":"include_context","type":"Bool","description":"Specify whether to include context information as query parameters."},{"name":"msg","type":"String","description":"Specify the message to show in the notification."},{"name":"support_url","type":"String","description":"Specify a URL that directs users to more information. If unset, the notification opens a block page."}]}]},{"name":"block_page","type":"Attributes","description":"Specify block page layout settings.","children":[{"name":"background_color","type":"String","description":"Specify the block page background color in `#rrggbb` format when the mode is customized_block_page."},{"name":"enabled","type":"Bool","description":"Specify whether to enable the custom block page."},{"name":"footer_text","type":"String","description":"Specify the block page footer text when the mode is customized_block_page."},{"name":"header_text","type":"String","description":"Specify the block page header text when the mode is customized_block_page."},{"name":"include_context","type":"Bool","description":"Specify whether to append context to target_uri as query parameters. This applies only when the mode is redirect_uri."},{"name":"logo_path","type":"String","description":"Specify the full URL to the logo file when the mode is customized_block_page."},{"name":"mailto_address","type":"String","description":"Specify the admin email for users to contact when the mode is customized_block_page."},{"name":"mailto_subject","type":"String","description":"Specify the subject line for emails created from the block page when the mode is customized_block_page."},{"name":"mode","type":"String","description":"Specify whether to redirect users to a Cloudflare-hosted block page or a customer-provided URI."},{"name":"name","type":"String","description":"Specify the block page title when the mode is customized_block_page."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"suppress_footer","type":"Bool","description":"Specify whether to suppress detailed information at the bottom of the block page when the mode is customized_block_page."},{"name":"target_uri","type":"String","description":"Specify the URI to redirect users to when the mode is redirect_uri."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"body_scanning","type":"Attributes","description":"Specify the DLP inspection mode.","children":[{"name":"inspection_mode","type":"String","description":"Specify the inspection mode as either `deep` or `shallow`."}]},{"name":"browser_isolation","type":"Attributes","description":"Specify Clientless Browser Isolation settings.","children":[{"name":"non_identity_enabled","type":"Bool","description":"Specify whether to enable non-identity onramp support for Browser Isolation."},{"name":"url_browser_isolation_enabled","type":"Bool","description":"Specify whether to enable Clientless Browser Isolation."}]},{"name":"certificate","type":"Attributes","description":"Specify certificate settings for Gateway TLS interception. If unset, the Cloudflare Root CA handles interception.","children":[{"name":"id","type":"String","description":"Specify the UUID of the certificate used for interception. Ensure the certificate is available at the edge(previously called 'active'). A nil UUID directs Cloudflare to use the Root CA."}]},{"name":"custom_certificate","type":"Attributes","description":"Specify custom certificate settings for BYO-PKI. This field is deprecated; use `certificate` instead.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable a custom certificate authority for signing Gateway traffic."},{"name":"id","type":"String","description":"Specify the UUID of the certificate (ID from MTLS certificate store)."},{"name":"binding_status","type":"String","description":"Indicate the internal certificate status."},{"name":"updated_at","type":"Time"}]},{"name":"extended_email_matching","type":"Attributes","description":"Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses `.` or `+` modifiers.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to match all variants of user emails (with + or . modifiers) used as criteria in Firewall policies."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"fips","type":"Attributes","description":"Specify FIPS settings.","children":[{"name":"tls","type":"Bool","description":"Enforce cipher suites and TLS versions compliant with FIPS 140-2."}]},{"name":"host_selector","type":"Attributes","description":"Enable host selection in egress policies.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable filtering via hosts for egress policies."}]},{"name":"inspection","type":"Attributes","description":"Define the proxy inspection mode.","children":[{"name":"mode","type":"String","description":"Define the proxy inspection mode. 1. static: Gateway applies static inspection to HTTP on TCP(80). With TLS decryption on, Gateway inspects HTTPS traffic on TCP(443) and UDP(443). 2. dynamic: Gateway applies protocol detection to inspect HTTP and HTTPS traffic on any port. TLS decryption must remain on to inspect HTTPS traffic."}]},{"name":"max_ttl_secs","type":"Int64","description":"Account-level cap on DNS response TTLs, in seconds. Gateway rewrites DNS responses so returned record TTLs do not exceed this value. Null means no cap. Each DNS location can inherit, override, or disable it through the location `max_ttl` setting."},{"name":"protocol_detection","type":"Attributes","description":"Specify whether to detect protocols from the initial bytes of client traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to detect protocols from the initial bytes of client traffic."}]},{"name":"sandbox","type":"Attributes","description":"Specify whether to enable the sandbox.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable the sandbox."},{"name":"fallback_action","type":"String","description":"Specify the action to take when the system cannot scan the file."}]},{"name":"tls_decrypt","type":"Attributes","description":"Specify whether to inspect encrypted HTTP traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to inspect encrypted HTTP traffic."}]}]}]}]},"get /accounts/{}/gateway/lists":{"operationId":"zero-trust-lists-list-zero-trust-lists","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_lists","stainlessResource":"zero_trust.gateway.lists","methodName":"list","snippet":"data \"cloudflare_zero_trust_lists\" \"example_zero_trust_lists\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n type = \"SERIAL\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. Applies to the field named in `order_by`; when `order_by`\nis omitted it applies to the default `created_at` ordering. When\n`direction` is omitted the default is field-specific: explicitly choosing\n`created_at` or `updated_at` defaults to descending (newest first); `name`\nand `item_count` default to ascending; and the default `created_at`\nordering used when `order_by` is omitted is ascending (for backwards\ncompatibility).\n * `asc` — ascending.\n * `desc` — descending."},{"name":"order_by","type":"String","description":"Field to sort the returned lists by. When omitted, results are ordered by\n`created_at` in ascending order (i.e. creation order) for backwards\ncompatibility. Supported values:\n * `name` — sort alphabetically by list name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\n * `item_count` — sort by number of items in the list."},{"name":"search","type":"String","description":"Case-insensitive substring match on the list name or description. When\ncombined with `filter`, both must match (logical AND)."},{"name":"type","type":"String","description":"Specify the list type."},{"name":"filter","type":"List[String]","description":"Filter the returned lists by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a list must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the list name.\n * `id` — substring match on the list ID (UUID), with or without dashes.\n * `type` — exact match on the list type. Supersedes the legacy `type` query\n parameter when both are supplied. Must be one of the valid type values.\n * `item_count` — exact integer match on the number of items in the list.\n\nEach entry must match one of the per-field patterns below: the field must be\none of `name`, `id`, `type`, or `item_count`; `name`/`id` accept any value,\n`type` is restricted to the valid list type values, and `item_count` must be\na non-negative integer."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"list_count","type":"Float64","description":"Indicate the number of items in the list."},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list description."},{"name":"items","type":"Set[Attributes]","description":"Provide the list items.","children":[{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list item description (optional)."},{"name":"value","type":"String","description":"Specify the item value."}]},{"name":"name","type":"String","description":"Specify the list name."},{"name":"type","type":"String","description":"Specify the list type."},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/gateway/lists/{}":{"operationId":"zero-trust-lists-zero-trust-list-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_list","stainlessResource":"zero_trust.gateway.lists","methodName":"get","snippet":"data \"cloudflare_zero_trust_list\" \"example_zero_trust_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n list_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"list_id","type":"String","description":"Identify the API resource with a UUID."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. Applies to the field named in `order_by`; when `order_by`\nis omitted it applies to the default `created_at` ordering. When\n`direction` is omitted the default is field-specific: explicitly choosing\n`created_at` or `updated_at` defaults to descending (newest first); `name`\nand `item_count` default to ascending; and the default `created_at`\nordering used when `order_by` is omitted is ascending (for backwards\ncompatibility).\n * `asc` — ascending.\n * `desc` — descending."},{"name":"filter","type":"List[String]","description":"Filter the returned lists by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a list must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the list name.\n * `id` — substring match on the list ID (UUID), with or without dashes.\n * `type` — exact match on the list type. Supersedes the legacy `type` query\n parameter when both are supplied. Must be one of the valid type values.\n * `item_count` — exact integer match on the number of items in the list.\n\nEach entry must match one of the per-field patterns below: the field must be\none of `name`, `id`, `type`, or `item_count`; `name`/`id` accept any value,\n`type` is restricted to the valid list type values, and `item_count` must be\na non-negative integer."},{"name":"order_by","type":"String","description":"Field to sort the returned lists by. When omitted, results are ordered by\n`created_at` in ascending order (i.e. creation order) for backwards\ncompatibility. Supported values:\n * `name` — sort alphabetically by list name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\n * `item_count` — sort by number of items in the list."},{"name":"search","type":"String","description":"Case-insensitive substring match on the list name or description. When\ncombined with `filter`, both must match (logical AND)."},{"name":"type","type":"String","description":"Specify the list type."}]}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list description."},{"name":"list_count","type":"Float64","description":"Indicate the number of items in the list."},{"name":"name","type":"String","description":"Specify the list name."},{"name":"type","type":"String","description":"Specify the list type."},{"name":"updated_at","type":"Time"},{"name":"items","type":"Set[Attributes]","description":"Provide the list items.","children":[{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Provide the list item description (optional)."},{"name":"value","type":"String","description":"Specify the item value."}]}]}]},"get /accounts/{}/gateway/locations":{"operationId":"zero-trust-gateway-locations-list-zero-trust-gateway-locations","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_dns_locations","stainlessResource":"zero_trust.gateway.locations","methodName":"list","snippet":"data \"cloudflare_zero_trust_dns_locations\" \"example_zero_trust_dns_locations\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"order_by","type":"String","description":"Field to sort the returned locations by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by location name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the location name. When combined\nwith `filter`, both must match (logical AND)."},{"name":"filter","type":"List[String]","description":"Filter the returned locations by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a location must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the location name.\n * `id` — substring match on the location ID (UUID), with or without dashes.\n * `is_default` — whether it is the default for the account.\n\nEach entry must match one of the per-field patterns below:\n * the field must be one of `name`, `id`, or `is_default`;\n * `name`/`id` accept any value;\n * `is_default` only accepts `true` or `false`; any other value returns `400`"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"client_default","type":"Bool","description":"Indicate whether this location is the default location."},{"name":"created_at","type":"Time"},{"name":"dns_destination_ips_id","type":"String","description":"Indicate the identifier of the pair of IPv4 addresses assigned to this location."},{"name":"dns_destination_ipv6_block_id","type":"String","description":"Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block."},{"name":"doh_subdomain","type":"String","description":"Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value."},{"name":"ecs_support","type":"Bool","description":"Indicate whether the location must resolve EDNS queries."},{"name":"endpoints","type":"Attributes","description":"Configure the destination endpoints for this location.","children":[{"name":"doh","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOH endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]},{"name":"require_token","type":"Bool","description":"Specify whether the DOH endpoint requires user identity authentication."}]},{"name":"dot","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOT endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]}]},{"name":"ipv4","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPv4 endpoint is enabled for this location."}]},{"name":"ipv6","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPV6 endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv6 address or IPv6 CIDR."}]}]}]},{"name":"ip","type":"String","description":"Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location."},{"name":"ipv4_destination","type":"String","description":"Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"ipv4_destination_backup","type":"String","description":"Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"max_ttl","type":"Attributes","description":"Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.","children":[{"name":"mode","type":"String","description":"`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged."},{"name":"ttl_secs","type":"Int64","description":"Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`."}]},{"name":"name","type":"String","description":"Specify the location name."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24."}]},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/gateway/locations/{}":{"operationId":"zero-trust-gateway-locations-zero-trust-gateway-location-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_dns_location","stainlessResource":"zero_trust.gateway.locations","methodName":"get","snippet":"data \"cloudflare_zero_trust_dns_location\" \"example_zero_trust_dns_location\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n location_id = \"ed35569b41ce4d1facfe683550f54086\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"location_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"filter","type":"List[String]","description":"Filter the returned locations by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a location must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the location name.\n * `id` — substring match on the location ID (UUID), with or without dashes.\n * `is_default` — whether it is the default for the account.\n\nEach entry must match one of the per-field patterns below:\n * the field must be one of `name`, `id`, or `is_default`;\n * `name`/`id` accept any value;\n * `is_default` only accepts `true` or `false`; any other value returns `400`"},{"name":"order_by","type":"String","description":"Field to sort the returned locations by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by location name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the location name. When combined\nwith `filter`, both must match (logical AND)."}]}],"computed":[{"name":"id","type":"String"},{"name":"client_default","type":"Bool","description":"Indicate whether this location is the default location."},{"name":"created_at","type":"Time"},{"name":"dns_destination_ips_id","type":"String","description":"Indicate the identifier of the pair of IPv4 addresses assigned to this location."},{"name":"dns_destination_ipv6_block_id","type":"String","description":"Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block."},{"name":"doh_subdomain","type":"String","description":"Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value."},{"name":"ecs_support","type":"Bool","description":"Indicate whether the location must resolve EDNS queries."},{"name":"ip","type":"String","description":"Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location."},{"name":"ipv4_destination","type":"String","description":"Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"ipv4_destination_backup","type":"String","description":"Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"name","type":"String","description":"Specify the location name."},{"name":"updated_at","type":"Time"},{"name":"endpoints","type":"Attributes","description":"Configure the destination endpoints for this location.","children":[{"name":"doh","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOH endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]},{"name":"require_token","type":"Bool","description":"Specify whether the DOH endpoint requires user identity authentication."}]},{"name":"dot","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOT endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]}]},{"name":"ipv4","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPv4 endpoint is enabled for this location."}]},{"name":"ipv6","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPV6 endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv6 address or IPv6 CIDR."}]}]}]},{"name":"max_ttl","type":"Attributes","description":"Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.","children":[{"name":"mode","type":"String","description":"`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged."},{"name":"ttl_secs","type":"Int64","description":"Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`."}]},{"name":"networks","type":"List[Attributes]","description":"Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24."}]}]}]},"get /accounts/{}/gateway/logging":{"operationId":"zero-trust-accounts-get-logging-settings-for-the-zero-trust-account","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_logging","stainlessResource":"zero_trust.gateway.logging","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_logging\" \"example_zero_trust_gateway_logging\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier."},{"name":"redact_pii","type":"Bool","description":"Indicate whether to redact personally identifiable information from activity logging (PII fields include source IP, user email, user ID, device ID, URL, referrer, and user agent)."},{"name":"settings_by_rule_type","type":"Attributes","description":"Configure logging settings for each rule type.","children":[{"name":"dns","type":"Attributes","description":"Configure logging settings for DNS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"http","type":"Attributes","description":"Configure logging settings for HTTP/HTTPS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"l4","type":"Attributes","description":"Configure logging settings for Network firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]}]}]}]},"get /accounts/{}/gateway/pacfiles":{"operationId":"zero-trust-gateway-pacfiles-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_pacfiles","stainlessResource":"zero_trust.gateway.pacfiles","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_pacfiles\" \"example_zero_trust_gateway_pacfiles\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Detailed description of the PAC file."},{"name":"name","type":"String","description":"Name of the PAC file."},{"name":"slug","type":"String","description":"URL-friendly version of the PAC file name."},{"name":"updated_at","type":"Time"},{"name":"url","type":"String","description":"Unique URL to download the PAC file."}]}]}]},"get /accounts/{}/gateway/pacfiles/{}":{"operationId":"zero-trust-gateway-pacfiles-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_pacfile","stainlessResource":"zero_trust.gateway.pacfiles","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_pacfile\" \"example_zero_trust_gateway_pacfile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n pacfile_id = \"ed35569b41ce4d1facfe683550f54086\"\n}\n","required":[{"name":"pacfile_id","type":"String"},{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"contents","type":"String","description":"Actual contents of the PAC file"},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"Detailed description of the PAC file."},{"name":"name","type":"String","description":"Name of the PAC file."},{"name":"slug","type":"String","description":"URL-friendly version of the PAC file name."},{"name":"updated_at","type":"Time"},{"name":"url","type":"String","description":"Unique URL to download the PAC file."}]}]},"get /accounts/{}/gateway/proxy_endpoints":{"operationId":"zero-trust-gateway-proxy-endpoints-list-proxy-endpoints","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_proxy_endpoints","stainlessResource":"zero_trust.gateway.proxy_endpoints","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_proxy_endpoints\" \"example_zero_trust_gateway_proxy_endpoints\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"order_by","type":"String","description":"Field to sort the returned endpoints by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by endpoint name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the endpoint name. When combined\nwith `filter`, both must match (logical AND)."},{"name":"filter","type":"List[String]","description":"Filter the returned proxy endpoints by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (an endpoint must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the endpoint name.\n * `id` — substring match on the endpoint ID (UUID), with or without dashes.\n * `kind` — exact match on the endpoint kind. The value must be `ip` or `identity`; any other value returns `400`.\n\nEach entry must match one of the per-field patterns below: the field\nmust be one of `name`, `id`, or `kind`; `name`/`id` accept any value,\nwhile `kind` only accepts `ip` or `identity`."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"ips","type":"List[String]","description":"Specify the list of CIDRs to restrict ingress connections."},{"name":"name","type":"String","description":"Specify the name of the proxy endpoint."},{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The proxy endpoint kind"},{"name":"subdomain","type":"String","description":"Specify the subdomain to use as the destination in the proxy client."},{"name":"updated_at","type":"Time"}]}]}]},"get /accounts/{}/gateway/proxy_endpoints/{}":{"operationId":"zero-trust-gateway-proxy-endpoints-proxy-endpoint-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_proxy_endpoint","stainlessResource":"zero_trust.gateway.proxy_endpoints","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_proxy_endpoint\" \"example_zero_trust_gateway_proxy_endpoint\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n proxy_endpoint_id = \"ed35569b41ce4d1facfe683550f54086\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"proxy_endpoint_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending."},{"name":"filter","type":"List[String]","description":"Filter the returned proxy endpoints by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (an endpoint must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the endpoint name.\n * `id` — substring match on the endpoint ID (UUID), with or without dashes.\n * `kind` — exact match on the endpoint kind. The value must be `ip` or `identity`; any other value returns `400`.\n\nEach entry must match one of the per-field patterns below: the field\nmust be one of `name`, `id`, or `kind`; `name`/`id` accept any value,\nwhile `kind` only accepts `ip` or `identity`."},{"name":"order_by","type":"String","description":"Field to sort the returned endpoints by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by endpoint name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set."},{"name":"search","type":"String","description":"Case-insensitive substring match on the endpoint name. When combined\nwith `filter`, both must match (logical AND)."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The proxy endpoint kind"},{"name":"name","type":"String","description":"Specify the name of the proxy endpoint."},{"name":"subdomain","type":"String","description":"Specify the subdomain to use as the destination in the proxy client."},{"name":"updated_at","type":"Time"},{"name":"ips","type":"List[String]","description":"Specify the list of CIDRs to restrict ingress connections."}]}]},"get /accounts/{}/gateway/rules":{"operationId":"zero-trust-gateway-rules-list-zero-trust-gateway-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_gateway_policies","stainlessResource":"zero_trust.gateway.rules","methodName":"list","snippet":"data \"cloudflare_zero_trust_gateway_policies\" \"example_zero_trust_gateway_policies\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"direction","type":"String","description":"Sort direction. When `order_by` is omitted, this controls the direction\nof the existing precedence ordering. Shared rules remain first in either\ndirection. Accepted values are `asc` and `desc`."},{"name":"order_by","type":"String","description":"Field to sort the returned rules by. Supported values are `name`,\n`created_at`, `updated_at`, and `precedence`."},{"name":"search","type":"String","description":"Case-insensitive substring search across rule name and description."},{"name":"filter","type":"List[String]","description":"Filter the returned rules by one or more `field:value` pairs. Repeat the\nparameter to combine filters with logical AND.\n\nSupported fields are `name`, `id`, `action`, `enabled`, `source_account`,\n`is_shared`, `filters`, and `expression` (max 1024 bytes). The `source_account`\nvalue is matched as a normalized UUID substring. The `filters` value must\nbe one of the rule filter names and matches a member of the rule's `filters`\narray. The `expression` filter performs a case-insensitive literal\nsubstring match across traffic, identity, and device posture expressions."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"action","type":"String","description":"Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`."},{"name":"enabled","type":"Bool","description":"Specify whether the rule is enabled."},{"name":"filters","type":"List[String]","description":"Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value."},{"name":"name","type":"String","description":"Specify the rule name."},{"name":"precedence","type":"Int64","description":"Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform."},{"name":"traffic","type":"String","description":"Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"deleted_at","type":"Time","description":"Indicate the date of deletion, if any."},{"name":"description","type":"String","description":"Specify the rule description."},{"name":"device_posture","type":"String","description":"Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"expiration","type":"Attributes","description":"Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.","children":[{"name":"expires_at","type":"Time","description":"Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time."},{"name":"duration","type":"Int64","description":"Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule."},{"name":"expired","type":"Bool","description":"Indicates whether the policy is expired."}]},{"name":"identity","type":"String","description":"Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"read_only","type":"Bool","description":"Indicate that this rule is shared via the Orgs API and read only."},{"name":"rule_settings","type":"Attributes","description":"Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.","children":[{"name":"add_headers","type":"Map[List[String]]","description":"Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"allow_child_bypass","type":"Bool","description":"Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules."},{"name":"audit_ssh","type":"Attributes","description":"Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.","children":[{"name":"command_logging","type":"Bool","description":"Enable SSH command logging."}]},{"name":"biso_admin_controls","type":"Attributes","description":"Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.","children":[{"name":"copy","type":"String","description":"Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\"."},{"name":"dcp","type":"Bool","description":"Set to false to enable copy-pasting. Only applies when `version == \"v1\"`."},{"name":"dd","type":"Bool","description":"Set to false to enable downloading. Only applies when `version == \"v1\"`."},{"name":"dk","type":"Bool","description":"Set to false to enable keyboard usage. Only applies when `version == \"v1\"`."},{"name":"download","type":"String","description":"Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\"."},{"name":"dp","type":"Bool","description":"Set to false to enable printing. Only applies when `version == \"v1\"`."},{"name":"du","type":"Bool","description":"Set to false to enable uploading. Only applies when `version == \"v1\"`."},{"name":"keyboard","type":"String","description":"Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\"."},{"name":"paste","type":"String","description":"Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\"."},{"name":"printing","type":"String","description":"Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\"."},{"name":"upload","type":"String","description":"Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\"."},{"name":"version","type":"String","description":"Indicate which version of the browser isolation controls should apply."},{"name":"wm_id","type":"String","description":"Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser."}]},{"name":"block_page","type":"Attributes","description":"Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."}]},{"name":"block_page_enabled","type":"Bool","description":"Enable the custom block page. Settable only for `dns` rules with action `block`."},{"name":"block_reason","type":"String","description":"Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`."},{"name":"bypass_parent_rule","type":"Bool","description":"Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules."},{"name":"check_session","type":"Attributes","description":"Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.","children":[{"name":"duration","type":"String","description":"Sets the required session freshness threshold. The API returns a normalized version of this value."},{"name":"enforce","type":"Bool","description":"Enable session enforcement."}]},{"name":"delete_headers","type":"List[String]","description":"Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`."},{"name":"dns_resolvers","type":"Attributes","description":"Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"ipv4","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv4 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]},{"name":"ipv6","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv6 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]}]},{"name":"egress","type":"Attributes","description":"Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.","children":[{"name":"ipv4","type":"String","description":"Specify the IPv4 address to use for egress."},{"name":"ipv4_fallback","type":"String","description":"Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs."},{"name":"ipv6","type":"String","description":"Specify the IPv6 range to use for egress."}]},{"name":"forensic_copy","type":"Attributes","description":"Configure whether a copy of the HTTP request will be sent to storage when the rule matches.","children":[{"name":"enabled","type":"Bool","description":"Enable sending the copy to storage."}]},{"name":"ignore_cname_category_matches","type":"Bool","description":"Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules."},{"name":"insecure_disable_dnssec_validation","type":"Bool","description":"Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules."},{"name":"ip_categories","type":"Bool","description":"Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules."},{"name":"ip_indicator_feeds","type":"Bool","description":"Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules."},{"name":"l4override","type":"Attributes","description":"Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.","children":[{"name":"ip","type":"String","description":"Defines the IPv4 or IPv6 address."},{"name":"port","type":"Int64","description":"Defines a port number to use for TCP/UDP overrides."}]},{"name":"notification_settings","type":"Attributes","description":"Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.","children":[{"name":"enabled","type":"Bool","description":"Enable notification."},{"name":"include_context","type":"Bool","description":"Indicates whether to pass the context information as query parameters."},{"name":"msg","type":"String","description":"Customize the message shown in the notification."},{"name":"support_url","type":"String","description":"Defines an optional URL to direct users to additional information. If unset, the notification opens a block page."}]},{"name":"override_host","type":"String","description":"Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"override_ips","type":"List[String]","description":"Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"payload_log","type":"Attributes","description":"Configure DLP payload logging. Settable only for `http` rules.","children":[{"name":"enabled","type":"Bool","description":"Enable DLP payload logging for this rule."}]},{"name":"quarantine","type":"Attributes","description":"Configure settings that apply to quarantine rules. Settable only for `http` rules.","children":[{"name":"file_types","type":"List[String]","description":"Specify the types of files to sandbox."}]},{"name":"redirect","type":"Attributes","description":"Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."},{"name":"preserve_path_and_query","type":"Bool","description":"Specify whether to append the path and query parameters from the original request to target_uri."}]},{"name":"resolve_dns_internally","type":"Attributes","description":"Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"fallback","type":"String","description":"Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries."},{"name":"view_id","type":"String","description":"Specify the internal DNS view identifier to pass to the internal DNS service."}]},{"name":"resolve_dns_through_cloudflare","type":"Bool","description":"Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules."},{"name":"set_headers","type":"Map[List[String]]","description":"Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"untrusted_cert","type":"Attributes","description":"Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.","children":[{"name":"action","type":"String","description":"Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526."}]}]},{"name":"schedule","type":"Attributes","description":"Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.","children":[{"name":"fri","type":"String","description":"Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"mon","type":"String","description":"Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sat","type":"String","description":"Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sun","type":"String","description":"Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"thu","type":"String","description":"Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"time_zone","type":"String","description":"Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location."},{"name":"tue","type":"String","description":"Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"wed","type":"String","description":"Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."}]},{"name":"sharable","type":"Bool","description":"Indicate that this rule is sharable via the Orgs API."},{"name":"source_account","type":"String","description":"Provide the account tag of the account that created the rule."},{"name":"updated_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicate the version number of the rule(read-only)."},{"name":"warning_status","type":"String","description":"Indicate a warning for a misconfigured rule, if any."}]}]}]},"get /accounts/{}/gateway/rules/{}":{"operationId":"zero-trust-gateway-rules-zero-trust-gateway-rule-details","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_gateway_policy","stainlessResource":"zero_trust.gateway.rules","methodName":"get","snippet":"data \"cloudflare_zero_trust_gateway_policy\" \"example_zero_trust_gateway_policy\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier."}],"optional":[{"name":"rule_id","type":"String","description":"Identify the API resource with a UUID."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort direction. When `order_by` is omitted, this controls the direction\nof the existing precedence ordering. Shared rules remain first in either\ndirection. Accepted values are `asc` and `desc`."},{"name":"filter","type":"List[String]","description":"Filter the returned rules by one or more `field:value` pairs. Repeat the\nparameter to combine filters with logical AND.\n\nSupported fields are `name`, `id`, `action`, `enabled`, `source_account`,\n`is_shared`, `filters`, and `expression` (max 1024 bytes). The `source_account`\nvalue is matched as a normalized UUID substring. The `filters` value must\nbe one of the rule filter names and matches a member of the rule's `filters`\narray. The `expression` filter performs a case-insensitive literal\nsubstring match across traffic, identity, and device posture expressions."},{"name":"order_by","type":"String","description":"Field to sort the returned rules by. Supported values are `name`,\n`created_at`, `updated_at`, and `precedence`."},{"name":"search","type":"String","description":"Case-insensitive substring search across rule name and description."}]}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"action","type":"String","description":"Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`."},{"name":"created_at","type":"Time"},{"name":"deleted_at","type":"Time","description":"Indicate the date of deletion, if any."},{"name":"description","type":"String","description":"Specify the rule description."},{"name":"device_posture","type":"String","description":"Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"enabled","type":"Bool","description":"Specify whether the rule is enabled."},{"name":"identity","type":"String","description":"Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"name","type":"String","description":"Specify the rule name."},{"name":"precedence","type":"Int64","description":"Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform."},{"name":"read_only","type":"Bool","description":"Indicate that this rule is shared via the Orgs API and read only."},{"name":"sharable","type":"Bool","description":"Indicate that this rule is sharable via the Orgs API."},{"name":"source_account","type":"String","description":"Provide the account tag of the account that created the rule."},{"name":"traffic","type":"String","description":"Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"updated_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicate the version number of the rule(read-only)."},{"name":"warning_status","type":"String","description":"Indicate a warning for a misconfigured rule, if any."},{"name":"filters","type":"List[String]","description":"Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value."},{"name":"expiration","type":"Attributes","description":"Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.","children":[{"name":"expires_at","type":"Time","description":"Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time."},{"name":"duration","type":"Int64","description":"Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule."},{"name":"expired","type":"Bool","description":"Indicates whether the policy is expired."}]},{"name":"rule_settings","type":"Attributes","description":"Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.","children":[{"name":"add_headers","type":"Map[List[String]]","description":"Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"allow_child_bypass","type":"Bool","description":"Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules."},{"name":"audit_ssh","type":"Attributes","description":"Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.","children":[{"name":"command_logging","type":"Bool","description":"Enable SSH command logging."}]},{"name":"biso_admin_controls","type":"Attributes","description":"Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.","children":[{"name":"copy","type":"String","description":"Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\"."},{"name":"dcp","type":"Bool","description":"Set to false to enable copy-pasting. Only applies when `version == \"v1\"`."},{"name":"dd","type":"Bool","description":"Set to false to enable downloading. Only applies when `version == \"v1\"`."},{"name":"dk","type":"Bool","description":"Set to false to enable keyboard usage. Only applies when `version == \"v1\"`."},{"name":"download","type":"String","description":"Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\"."},{"name":"dp","type":"Bool","description":"Set to false to enable printing. Only applies when `version == \"v1\"`."},{"name":"du","type":"Bool","description":"Set to false to enable uploading. Only applies when `version == \"v1\"`."},{"name":"keyboard","type":"String","description":"Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\"."},{"name":"paste","type":"String","description":"Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\"."},{"name":"printing","type":"String","description":"Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\"."},{"name":"upload","type":"String","description":"Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\"."},{"name":"version","type":"String","description":"Indicate which version of the browser isolation controls should apply."},{"name":"wm_id","type":"String","description":"Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser."}]},{"name":"block_page","type":"Attributes","description":"Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."}]},{"name":"block_page_enabled","type":"Bool","description":"Enable the custom block page. Settable only for `dns` rules with action `block`."},{"name":"block_reason","type":"String","description":"Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`."},{"name":"bypass_parent_rule","type":"Bool","description":"Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules."},{"name":"check_session","type":"Attributes","description":"Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.","children":[{"name":"duration","type":"String","description":"Sets the required session freshness threshold. The API returns a normalized version of this value."},{"name":"enforce","type":"Bool","description":"Enable session enforcement."}]},{"name":"delete_headers","type":"List[String]","description":"Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`."},{"name":"dns_resolvers","type":"Attributes","description":"Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"ipv4","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv4 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]},{"name":"ipv6","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv6 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]}]},{"name":"egress","type":"Attributes","description":"Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.","children":[{"name":"ipv4","type":"String","description":"Specify the IPv4 address to use for egress."},{"name":"ipv4_fallback","type":"String","description":"Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs."},{"name":"ipv6","type":"String","description":"Specify the IPv6 range to use for egress."}]},{"name":"forensic_copy","type":"Attributes","description":"Configure whether a copy of the HTTP request will be sent to storage when the rule matches.","children":[{"name":"enabled","type":"Bool","description":"Enable sending the copy to storage."}]},{"name":"ignore_cname_category_matches","type":"Bool","description":"Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules."},{"name":"insecure_disable_dnssec_validation","type":"Bool","description":"Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules."},{"name":"ip_categories","type":"Bool","description":"Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules."},{"name":"ip_indicator_feeds","type":"Bool","description":"Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules."},{"name":"l4override","type":"Attributes","description":"Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.","children":[{"name":"ip","type":"String","description":"Defines the IPv4 or IPv6 address."},{"name":"port","type":"Int64","description":"Defines a port number to use for TCP/UDP overrides."}]},{"name":"notification_settings","type":"Attributes","description":"Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.","children":[{"name":"enabled","type":"Bool","description":"Enable notification."},{"name":"include_context","type":"Bool","description":"Indicates whether to pass the context information as query parameters."},{"name":"msg","type":"String","description":"Customize the message shown in the notification."},{"name":"support_url","type":"String","description":"Defines an optional URL to direct users to additional information. If unset, the notification opens a block page."}]},{"name":"override_host","type":"String","description":"Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"override_ips","type":"List[String]","description":"Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"payload_log","type":"Attributes","description":"Configure DLP payload logging. Settable only for `http` rules.","children":[{"name":"enabled","type":"Bool","description":"Enable DLP payload logging for this rule."}]},{"name":"quarantine","type":"Attributes","description":"Configure settings that apply to quarantine rules. Settable only for `http` rules.","children":[{"name":"file_types","type":"List[String]","description":"Specify the types of files to sandbox."}]},{"name":"redirect","type":"Attributes","description":"Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."},{"name":"preserve_path_and_query","type":"Bool","description":"Specify whether to append the path and query parameters from the original request to target_uri."}]},{"name":"resolve_dns_internally","type":"Attributes","description":"Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"fallback","type":"String","description":"Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries."},{"name":"view_id","type":"String","description":"Specify the internal DNS view identifier to pass to the internal DNS service."}]},{"name":"resolve_dns_through_cloudflare","type":"Bool","description":"Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules."},{"name":"set_headers","type":"Map[List[String]]","description":"Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"untrusted_cert","type":"Attributes","description":"Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.","children":[{"name":"action","type":"String","description":"Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526."}]}]},{"name":"schedule","type":"Attributes","description":"Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.","children":[{"name":"fri","type":"String","description":"Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"mon","type":"String","description":"Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sat","type":"String","description":"Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sun","type":"String","description":"Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"thu","type":"String","description":"Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"time_zone","type":"String","description":"Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location."},{"name":"tue","type":"String","description":"Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"wed","type":"String","description":"Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."}]}]}]},"get /accounts/{}/hyperdrive/configs":{"operationId":"list-hyperdrive","declarations":[{"kind":"list-data-source","name":"cloudflare_hyperdrive_configs","stainlessResource":"hyperdrive.configs","methodName":"list","snippet":"data \"cloudflare_hyperdrive_configs\" \"example_hyperdrive_configs\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Define configurations using a unique string identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"caching","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Defines whether caching is disabled."},{"name":"max_age","type":"Int64","description":"Defines the maximum duration (in seconds) items persist in the cache."},{"name":"stale_while_revalidate","type":"Int64","description":"Defines the number of seconds the cache may serve a stale response."}]},{"name":"name","type":"String","description":"The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API."},{"name":"origin","type":"Attributes","description":"Combines database connection fields with exactly one supported network location.","children":[{"name":"database","type":"String","description":"Set the name of your origin database."},{"name":"host","type":"String","description":"Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed."},{"name":"password","type":"String","description":"Set the password needed to access your origin database. The API never returns this write-only value.","sensitive":true},{"name":"port","type":"Int64","description":"Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"user","type":"String","description":"Set the user of your origin database."},{"name":"access_client_id","type":"String","description":"Defines the Client ID of the Access token to use when connecting to the origin database."},{"name":"access_client_secret","type":"String","description":"Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.","sensitive":true},{"name":"service_id","type":"String","description":"The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database."}]},{"name":"created_on","type":"Time","description":"Defines the creation time of the Hyperdrive configuration."},{"name":"integration","type":"Attributes","description":"Connects to a PlanetScale database using credentials managed by Cloudflare. The Cloudflare account must already be linked to PlanetScale in the Hyperdrive dashboard.","children":[{"name":"database_branch_name","type":"String","description":"The name of the PlanetScale database branch."},{"name":"database_name","type":"String","description":"The name of the PlanetScale database."},{"name":"organization_name","type":"String","description":"The name of the PlanetScale organization."},{"name":"hyperdrive_config_provider","type":"String","description":"The database integration provider used by this operation."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"custom_database_name","type":"String","description":"The database name to use when connecting. Defaults to `postgres` for PostgreSQL and `mysql` for MySQL."}]},{"name":"modified_on","type":"Time","description":"Defines the last modified time of the Hyperdrive configuration."},{"name":"mtls","type":"Attributes","description":"mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.","children":[{"name":"ca_certificate_id","type":"String","description":"Define CA certificate ID obtained after uploading CA cert."},{"name":"mtls_certificate_id","type":"String","description":"Define mTLS certificate ID obtained after uploading client cert."},{"name":"sslmode","type":"String","description":"PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate."}]},{"name":"origin_connection_limit","type":"Int64","description":"The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit.\n"},{"name":"restarted_on","type":"Time","description":"Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted."}]}]}]},"get /accounts/{}/hyperdrive/configs/{}":{"operationId":"get-hyperdrive","declarations":[{"kind":"data-source","name":"cloudflare_hyperdrive_config","stainlessResource":"hyperdrive.configs","methodName":"get","snippet":"data \"cloudflare_hyperdrive_config\" \"example_hyperdrive_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hyperdrive_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"hyperdrive_id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"account_id","type":"String","description":"Define configurations using a unique string identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"created_on","type":"Time","description":"Defines the creation time of the Hyperdrive configuration."},{"name":"modified_on","type":"Time","description":"Defines the last modified time of the Hyperdrive configuration."},{"name":"name","type":"String","description":"The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API."},{"name":"origin_connection_limit","type":"Int64","description":"The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit.\n"},{"name":"restarted_on","type":"Time","description":"Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted."},{"name":"caching","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Defines whether caching is disabled."},{"name":"max_age","type":"Int64","description":"Defines the maximum duration (in seconds) items persist in the cache."},{"name":"stale_while_revalidate","type":"Int64","description":"Defines the number of seconds the cache may serve a stale response."}]},{"name":"integration","type":"Attributes","description":"Connects to a PlanetScale database using credentials managed by Cloudflare. The Cloudflare account must already be linked to PlanetScale in the Hyperdrive dashboard.","children":[{"name":"database_branch_name","type":"String","description":"The name of the PlanetScale database branch."},{"name":"database_name","type":"String","description":"The name of the PlanetScale database."},{"name":"organization_name","type":"String","description":"The name of the PlanetScale organization."},{"name":"hyperdrive_config_provider","type":"String","description":"The database integration provider used by this operation."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"custom_database_name","type":"String","description":"The database name to use when connecting. Defaults to `postgres` for PostgreSQL and `mysql` for MySQL."}]},{"name":"mtls","type":"Attributes","description":"mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.","children":[{"name":"ca_certificate_id","type":"String","description":"Define CA certificate ID obtained after uploading CA cert."},{"name":"mtls_certificate_id","type":"String","description":"Define mTLS certificate ID obtained after uploading client cert."},{"name":"sslmode","type":"String","description":"PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate."}]},{"name":"origin","type":"Attributes","description":"Combines database connection fields with exactly one supported network location.","children":[{"name":"database","type":"String","description":"Set the name of your origin database."},{"name":"host","type":"String","description":"Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed."},{"name":"password","type":"String","description":"Set the password needed to access your origin database. The API never returns this write-only value.","sensitive":true},{"name":"port","type":"Int64","description":"Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"user","type":"String","description":"Set the user of your origin database."},{"name":"access_client_id","type":"String","description":"Defines the Client ID of the Access token to use when connecting to the origin database."},{"name":"access_client_secret","type":"String","description":"Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.","sensitive":true},{"name":"service_id","type":"String","description":"The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database."}]}]}]},"get /accounts/{}/iam/permission_groups":{"operationId":"account-permission-group-list","declarations":[{"kind":"list-data-source","name":"cloudflare_account_permission_groups","stainlessResource":"iam.permission_groups","methodName":"list","snippet":"data \"cloudflare_account_permission_groups\" \"example_account_permission_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"6d7f2f5f5b1d4a0e9081fdc98d432fd1\"\n label = \"labelOfThePermissionGroup\"\n name = \"NameOfThePermissionGroup\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"id","type":"String","description":"ID of the permission group to be fetched."},{"name":"label","type":"String","description":"Label of the permission group to be fetched."},{"name":"name","type":"String","description":"Name of the permission group to be fetched."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]}]}]},"get /accounts/{}/iam/permission_groups/{}":{"operationId":"account-permission-group-details","declarations":[{"kind":"data-source","name":"cloudflare_account_permission_group","stainlessResource":"iam.permission_groups","methodName":"get","snippet":"data \"cloudflare_account_permission_group\" \"example_account_permission_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n permission_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"permission_group_id","type":"String","description":"Permission Group identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"name","type":"String","description":"Name of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]}]}]},"get /accounts/{}/iam/resource_groups":{"operationId":"account-resource-group-list","declarations":[{"kind":"list-data-source","name":"cloudflare_resource_groups","stainlessResource":"iam.resource_groups","methodName":"list","snippet":"data \"cloudflare_resource_groups\" \"example_resource_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"NameOfTheResourceGroup\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"id","type":"String","description":"ID of the resource group to be fetched."},{"name":"name","type":"String","description":"Name of the resource group to be fetched."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]}]},"get /accounts/{}/iam/resource_groups/{}":{"operationId":"account-resource-group-details","declarations":[{"kind":"data-source","name":"cloudflare_resource_group","stainlessResource":"iam.resource_groups","methodName":"get","snippet":"data \"cloudflare_resource_group\" \"example_resource_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"resource_group_id","type":"String","description":"Resource Group identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"name","type":"String","description":"Name of the resource group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]}]}]},"get /accounts/{}/iam/user_groups":{"operationId":"account-user-group-list","declarations":[{"kind":"list-data-source","name":"cloudflare_user_groups","stainlessResource":"iam.user_groups","methodName":"list","snippet":"data \"cloudflare_user_groups\" \"example_user_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n fuzzy_name = \"Foo\"\n name = \"NameOfTheUserGroup\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"fuzzy_name","type":"String","description":"A string used for searching for user groups containing that substring."},{"name":"id","type":"String","description":"ID of the user group to be fetched."},{"name":"name","type":"String","description":"Name of the user group to be fetched."},{"name":"direction","type":"String","description":"The sort order of returned user groups by name (ascending or descending)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the user group"},{"name":"modified_on","type":"Time","description":"Last time the user group was modified."},{"name":"name","type":"String","description":"Name of the user group."},{"name":"policies","type":"List[Attributes]","description":"Policies attached to the User group","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]}]}]}]},"get /accounts/{}/iam/user_groups/{}":{"operationId":"account-user-group-details","declarations":[{"kind":"data-source","name":"cloudflare_user_group","stainlessResource":"iam.user_groups","methodName":"get","snippet":"data \"cloudflare_user_group\" \"example_user_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"user_group_id","type":"String","description":"User Group identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"ID of the user group to be fetched."},{"name":"direction","type":"String","description":"The sort order of returned user groups by name (ascending or descending)."},{"name":"fuzzy_name","type":"String","description":"A string used for searching for user groups containing that substring."},{"name":"name","type":"String","description":"Name of the user group to be fetched."}]}],"computed":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the user group"},{"name":"modified_on","type":"Time","description":"Last time the user group was modified."},{"name":"name","type":"String","description":"Name of the user group."},{"name":"policies","type":"List[Attributes]","description":"Policies attached to the User group","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]}]}]},"get /accounts/{}/iam/user_groups/{}/members":{"operationId":"account-user-group-member-list","declarations":[{"kind":"data-source","name":"cloudflare_user_group_members","stainlessResource":"iam.user_groups.members","methodName":"list","snippet":"data \"cloudflare_user_group_members\" \"example_user_group_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n fuzzy_email = \"user@\"\n}\n","required":[{"name":"user_group_id","type":"String","description":"User Group identifier tag."},{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"fuzzy_email","type":"String","description":"A string used for filtering members by partial email match."},{"name":"direction","type":"String","description":"The sort order of returned user group members by email."}],"computed":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"status","type":"String","description":"The member's status in the account."}]}]},"get /accounts/{}/images/v1":{"operationId":"cloudflare-images-list-images","declarations":[{"kind":"list-data-source","name":"cloudflare_images","stainlessResource":"images.v1","methodName":"list","snippet":"data \"cloudflare_images\" \"example_images\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n creator = \"creator\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"creator","type":"String","description":"Internal user ID set within the creator field. Setting to empty string \"\" will return images where creator field is not set"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"images","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Image unique identifier."},{"name":"creator","type":"String","description":"Can set the creator field with an internal user ID."},{"name":"filename","type":"String","description":"Image file name."},{"name":"meta","type":"unknown","description":"User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the image can be a accessed only using it's UID. If set to true, a signed token needs to be generated with a signing key to view the image."},{"name":"uploaded","type":"Time","description":"When the media item was uploaded."},{"name":"variants","type":"List[String]","description":"Object specifying available variants for an image."}]}]}]}]},"get /accounts/{}/images/v1/{}":{"operationId":"cloudflare-images-image-details","declarations":[{"kind":"data-source","name":"cloudflare_image","stainlessResource":"images.v1","methodName":"get","snippet":"data \"cloudflare_image\" \"example_image\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n image_id = \"image_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"image_id","type":"String","description":"Image unique identifier."}],"optional":[],"computed":[{"name":"creator","type":"String","description":"Can set the creator field with an internal user ID."},{"name":"filename","type":"String","description":"Image file name."},{"name":"id","type":"String","description":"Image unique identifier."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the image can be a accessed only using it's UID. If set to true, a signed token needs to be generated with a signing key to view the image."},{"name":"uploaded","type":"Time","description":"When the media item was uploaded."},{"name":"variants","type":"List[String]","description":"Object specifying available variants for an image."},{"name":"meta","type":"unknown","description":"User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes."}]}]},"get /accounts/{}/images/v1/variants/{}":{"operationId":"cloudflare-images-variants-variant-details","declarations":[{"kind":"data-source","name":"cloudflare_image_variant","stainlessResource":"images.v1.variants","methodName":"get","snippet":"data \"cloudflare_image_variant\" \"example_image_variant\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n variant_id = \"hero\"\n}\n","required":[{"name":"variant_id","type":"String"},{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"variant","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"options","type":"Attributes","description":"Allows you to define image resizing sizes for different use cases.","children":[{"name":"fit","type":"String","description":"The fit property describes how the width and height dimensions should be interpreted."},{"name":"height","type":"Float64","description":"Maximum height in image pixels."},{"name":"metadata","type":"String","description":"What EXIF data should be preserved in the output image."},{"name":"width","type":"Float64","description":"Maximum width in image pixels."}]},{"name":"never_require_signed_urls","type":"Bool","description":"Indicates whether the variant can access an image without a signature, regardless of image access control."}]}]}]},"get /accounts/{}/infrastructure/targets":{"operationId":"infra-targets-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_access_infrastructure_targets","stainlessResource":"zero_trust.access.infrastructure.targets","methodName":"list","snippet":"data \"cloudflare_zero_trust_access_infrastructure_targets\" \"example_zero_trust_access_infrastructure_targets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_after = \"2019-12-27T18:11:19.117Z\"\n created_before = \"2019-12-27T18:11:19.117Z\"\n direction = \"asc\"\n hostname = \"hostname\"\n hostname_contains = \"hostname_contains\"\n ip_like = \"ip_like\"\n ip_v4 = \"ip_v4\"\n ip_v6 = \"ip_v6\"\n ips = [\"string\"]\n ipv4_end = \"ipv4_end\"\n ipv4_start = \"ipv4_start\"\n ipv6_end = \"ipv6_end\"\n ipv6_start = \"ipv6_start\"\n modified_after = \"2019-12-27T18:11:19.117Z\"\n modified_before = \"2019-12-27T18:11:19.117Z\"\n order = \"hostname\"\n tag = [\"string\"]\n target_ids = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n virtual_network_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier"}],"optional":[{"name":"created_after","type":"Time","description":"Date and time at which the target was created after (inclusive)"},{"name":"created_before","type":"Time","description":"Date and time at which the target was created before (inclusive)"},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"hostname","type":"String","description":"Hostname of a target"},{"name":"hostname_contains","type":"String","description":"Partial match to the hostname of a target"},{"name":"ip_like","type":"String","description":"Filters for targets whose IP addresses look like the specified string.\nSupports `*` as a wildcard character"},{"name":"ip_v4","type":"String","description":"IPv4 address of the target"},{"name":"ip_v6","type":"String","description":"IPv6 address of the target"},{"name":"ipv4_end","type":"String","description":"Defines an IPv4 filter range's ending value (inclusive). Requires\n`ipv4_start` to be specified as well."},{"name":"ipv4_start","type":"String","description":"Defines an IPv4 filter range's starting value (inclusive). Requires\n`ipv4_end` to be specified as well."},{"name":"ipv6_end","type":"String","description":"Defines an IPv6 filter range's ending value (inclusive). Requires\n`ipv6_start` to be specified as well."},{"name":"ipv6_start","type":"String","description":"Defines an IPv6 filter range's starting value (inclusive). Requires\n`ipv6_end` to be specified as well."},{"name":"modified_after","type":"Time","description":"Date and time at which the target was modified after (inclusive)"},{"name":"modified_before","type":"Time","description":"Date and time at which the target was modified before (inclusive)"},{"name":"order","type":"String","description":"The field to sort by."},{"name":"virtual_network_id","type":"String","description":"Private virtual network identifier of the target"},{"name":"ips","type":"List[String]","description":"Filters for targets that have any of the following IP addresses. Specify\n`ips` multiple times in query parameter to build list of candidates."},{"name":"tag","type":"List[String]","description":"Filter by tag key:value pairs. Multiple `tag` params are AND'd.\nFormat: `tag=key:value` (e.g., `tag=environment:production`).\nKey and value must both be non-empty; `tag=:value` and `tag=key:` return 400."},{"name":"target_ids","type":"List[String]","description":"Filters for targets that have any of the following UUIDs. Specify\n`target_ids` multiple times in query parameter to build list of\ncandidates."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Target identifier"},{"name":"created_at","type":"Time","description":"Date and time at which the target was created"},{"name":"hostname","type":"String","description":"A non-unique field that refers to a target"},{"name":"ip","type":"Attributes","description":"The IPv4/IPv6 address that identifies where to reach a target","children":[{"name":"ipv4","type":"Attributes","description":"The target's IPv4 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]},{"name":"ipv6","type":"Attributes","description":"The target's IPv6 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]}]},{"name":"modified_at","type":"Time","description":"Date and time at which the target was modified"},{"name":"tags","type":"Map[String]","description":"Tags assigned to the target. Empty when no tags are assigned."}]}]}]},"get /accounts/{}/infrastructure/targets/{}":{"operationId":"infra-targets-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_access_infrastructure_target","stainlessResource":"zero_trust.access.infrastructure.targets","methodName":"get","snippet":"data \"cloudflare_zero_trust_access_infrastructure_target\" \"example_zero_trust_access_infrastructure_target\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n target_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier"}],"optional":[{"name":"target_id","type":"String","description":"Target identifier"},{"name":"filter","type":"Attributes","children":[{"name":"created_after","type":"Time","description":"Date and time at which the target was created after (inclusive)"},{"name":"created_before","type":"Time","description":"Date and time at which the target was created before (inclusive)"},{"name":"direction","type":"String","description":"The sorting direction."},{"name":"hostname","type":"String","description":"Hostname of a target"},{"name":"hostname_contains","type":"String","description":"Partial match to the hostname of a target"},{"name":"ip_like","type":"String","description":"Filters for targets whose IP addresses look like the specified string.\nSupports `*` as a wildcard character"},{"name":"ip_v4","type":"String","description":"IPv4 address of the target"},{"name":"ip_v6","type":"String","description":"IPv6 address of the target"},{"name":"ips","type":"List[String]","description":"Filters for targets that have any of the following IP addresses. Specify\n`ips` multiple times in query parameter to build list of candidates."},{"name":"ipv4_end","type":"String","description":"Defines an IPv4 filter range's ending value (inclusive). Requires\n`ipv4_start` to be specified as well."},{"name":"ipv4_start","type":"String","description":"Defines an IPv4 filter range's starting value (inclusive). Requires\n`ipv4_end` to be specified as well."},{"name":"ipv6_end","type":"String","description":"Defines an IPv6 filter range's ending value (inclusive). Requires\n`ipv6_start` to be specified as well."},{"name":"ipv6_start","type":"String","description":"Defines an IPv6 filter range's starting value (inclusive). Requires\n`ipv6_end` to be specified as well."},{"name":"modified_after","type":"Time","description":"Date and time at which the target was modified after (inclusive)"},{"name":"modified_before","type":"Time","description":"Date and time at which the target was modified before (inclusive)"},{"name":"order","type":"String","description":"The field to sort by."},{"name":"tag","type":"List[String]","description":"Filter by tag key:value pairs. Multiple `tag` params are AND'd.\nFormat: `tag=key:value` (e.g., `tag=environment:production`).\nKey and value must both be non-empty; `tag=:value` and `tag=key:` return 400."},{"name":"target_ids","type":"List[String]","description":"Filters for targets that have any of the following UUIDs. Specify\n`target_ids` multiple times in query parameter to build list of\ncandidates."},{"name":"virtual_network_id","type":"String","description":"Private virtual network identifier of the target"}]}],"computed":[{"name":"id","type":"String","description":"Target identifier"},{"name":"created_at","type":"Time","description":"Date and time at which the target was created"},{"name":"hostname","type":"String","description":"A non-unique field that refers to a target"},{"name":"modified_at","type":"Time","description":"Date and time at which the target was modified"},{"name":"tags","type":"Map[String]","description":"Tags assigned to the target. Empty when no tags are assigned."},{"name":"ip","type":"Attributes","description":"The IPv4/IPv6 address that identifies where to reach a target","children":[{"name":"ipv4","type":"Attributes","description":"The target's IPv4 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]},{"name":"ipv6","type":"Attributes","description":"The target's IPv6 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]}]}]}]},"get /accounts/{}/load_balancers/monitor_groups":{"operationId":"account-load-balancer-monitor-groups-list-monitor-groups","declarations":[{"kind":"list-data-source","name":"cloudflare_load_balancer_monitor_groups","stainlessResource":"load_balancers.monitor_groups","methodName":"list","snippet":"data \"cloudflare_load_balancer_monitor_groups\" \"example_load_balancer_monitor_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"description","type":"String","description":"A short description of the monitor group"},{"name":"members","type":"Set[Attributes]","description":"List of monitors in this group","children":[{"name":"enabled","type":"Bool","description":"Whether this monitor is enabled in the group"},{"name":"monitor_id","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitoring_only","type":"Bool","description":"Whether this monitor is used for monitoring only (does not affect pool health)"},{"name":"must_be_healthy","type":"Bool","description":"Whether this monitor must be healthy for the pool to be considered healthy"},{"name":"created_at","type":"Time","description":"The timestamp of when the monitor was added to the group"},{"name":"updated_at","type":"Time","description":"The timestamp of when the monitor group member was last updated"}]},{"name":"created_on","type":"Time","description":"The timestamp of when the monitor group was created"},{"name":"modified_on","type":"Time","description":"The timestamp of when the monitor group was last updated"}]}]}]},"get /accounts/{}/load_balancers/monitor_groups/{}":{"operationId":"account-load-balancer-monitor-groups-monitor-group-details","declarations":[{"kind":"data-source","name":"cloudflare_load_balancer_monitor_group","stainlessResource":"load_balancers.monitor_groups","methodName":"get","snippet":"data \"cloudflare_load_balancer_monitor_group\" \"example_load_balancer_monitor_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor_group_id = \"17b5962d775c646f3f9725cbc7a53df4\"\n}\n","required":[{"name":"monitor_group_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time","description":"The timestamp of when the monitor group was created"},{"name":"description","type":"String","description":"A short description of the monitor group"},{"name":"modified_on","type":"Time","description":"The timestamp of when the monitor group was last updated"},{"name":"members","type":"Set[Attributes]","description":"List of monitors in this group","children":[{"name":"enabled","type":"Bool","description":"Whether this monitor is enabled in the group"},{"name":"monitor_id","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitoring_only","type":"Bool","description":"Whether this monitor is used for monitoring only (does not affect pool health)"},{"name":"must_be_healthy","type":"Bool","description":"Whether this monitor must be healthy for the pool to be considered healthy"},{"name":"created_at","type":"Time","description":"The timestamp of when the monitor was added to the group"},{"name":"updated_at","type":"Time","description":"The timestamp of when the monitor group member was last updated"}]}]}]},"get /accounts/{}/load_balancers/monitors":{"operationId":"account-load-balancer-monitors-list-monitors","declarations":[{"kind":"list-data-source","name":"cloudflare_load_balancer_monitors","stainlessResource":"load_balancers.monitors","methodName":"list","snippet":"data \"cloudflare_load_balancer_monitors\" \"example_load_balancer_monitors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors."},{"name":"consecutive_down","type":"Int64","description":"To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times."},{"name":"consecutive_up","type":"Int64","description":"To be marked healthy the monitored origin must pass this healthcheck N consecutive times."},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"Object description."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"expected_codes","type":"String","description":"The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations."},{"name":"method","type":"String","description":"The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks."},{"name":"modified_on","type":"String"},{"name":"path","type":"String","description":"The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"port","type":"Int64","description":"The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)."},{"name":"probe_zone","type":"String","description":"Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'."}]}]}]},"get /accounts/{}/load_balancers/monitors/{}":{"operationId":"account-load-balancer-monitors-monitor-details","declarations":[{"kind":"data-source","name":"cloudflare_load_balancer_monitor","stainlessResource":"load_balancers.monitors","methodName":"get","snippet":"data \"cloudflare_load_balancer_monitor\" \"example_load_balancer_monitor\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor_id = \"f1aba936b94213e5b8dca0c0dbf1f9cc\"\n}\n","required":[{"name":"monitor_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors."},{"name":"consecutive_down","type":"Int64","description":"To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times."},{"name":"consecutive_up","type":"Int64","description":"To be marked healthy the monitored origin must pass this healthcheck N consecutive times."},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"Object description."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"expected_codes","type":"String","description":"The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations."},{"name":"method","type":"String","description":"The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks."},{"name":"modified_on","type":"String"},{"name":"path","type":"String","description":"The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"port","type":"Int64","description":"The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)."},{"name":"probe_zone","type":"String","description":"Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors."}]}]},"get /accounts/{}/load_balancers/pools":{"operationId":"account-load-balancer-pools-list-pools","declarations":[{"kind":"list-data-source","name":"cloudflare_load_balancer_pools","stainlessResource":"load_balancers.pools","methodName":"list","snippet":"data \"cloudflare_load_balancer_pools\" \"example_load_balancer_pools\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor = \"monitor\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means every Cloudflare data center."},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"A human-readable description of the pool."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)."},{"name":"health_sources","type":"List[String]","description":"A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions."},{"name":"latitude","type":"Float64","description":"The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set."},{"name":"load_shedding","type":"Attributes","description":"Configures load shedding policies and percentages for the pool.","children":[{"name":"default_percent","type":"Float64","description":"The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity."},{"name":"default_policy","type":"String","description":"The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs."},{"name":"session_percent","type":"Float64","description":"The percent of existing sessions to shed from the pool, according to the session policy."},{"name":"session_policy","type":"String","description":"Only the hash policy is supported for existing sessions (to avoid exponential decay)."}]},{"name":"longitude","type":"Float64","description":"The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set."},{"name":"minimum_origins","type":"Int64","description":"The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool."},{"name":"modified_on","type":"String"},{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitor_group","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"name","type":"String","description":"A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed."},{"name":"networks","type":"List[String]","description":"List of networks where Load Balancer or Pool is enabled."},{"name":"notification_email","type":"String","description":"This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list."},{"name":"notification_filter","type":"Attributes","description":"Filter pool and origin health notifications by resource type or health status. Use null to reset.","children":[{"name":"origin","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]},{"name":"pool","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]}]},{"name":"origin_steering","type":"Attributes","description":"Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.","children":[{"name":"policy","type":"String","description":"The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections."}]},{"name":"origins","type":"Set[Attributes]","description":"The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.","children":[{"name":"address","type":"String","description":"The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the origin is disabled. This field is set with the time the origin was disabled."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool."},{"name":"flatten_cname","type":"Bool","description":"Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting."},{"name":"header","type":"Attributes","description":"The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.","children":[{"name":"host","type":"List[String]","description":"The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin."}]},{"name":"name","type":"String","description":"A human-identifiable name for the origin."},{"name":"port","type":"Int64","description":"The port for upstream connections. A value of 0 means the default port for the protocol will be used."},{"name":"virtual_network_id","type":"String","description":"The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account."},{"name":"weight","type":"Float64","description":"The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections."}]}]}]}]},"get /accounts/{}/load_balancers/pools/{}":{"operationId":"account-load-balancer-pools-pool-details","declarations":[{"kind":"data-source","name":"cloudflare_load_balancer_pool","stainlessResource":"load_balancers.pools","methodName":"get","snippet":"data \"cloudflare_load_balancer_pool\" \"example_load_balancer_pool\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pool_id = \"17b5962d775c646f3f9725cbc7a53df4\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"pool_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"String"},{"name":"description","type":"String","description":"A human-readable description of the pool."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)."},{"name":"latitude","type":"Float64","description":"The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set."},{"name":"longitude","type":"Float64","description":"The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set."},{"name":"minimum_origins","type":"Int64","description":"The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool."},{"name":"modified_on","type":"String"},{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitor_group","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"name","type":"String","description":"A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed."},{"name":"notification_email","type":"String","description":"This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means every Cloudflare data center."},{"name":"health_sources","type":"List[String]","description":"A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions."},{"name":"networks","type":"List[String]","description":"List of networks where Load Balancer or Pool is enabled."},{"name":"load_shedding","type":"Attributes","description":"Configures load shedding policies and percentages for the pool.","children":[{"name":"default_percent","type":"Float64","description":"The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity."},{"name":"default_policy","type":"String","description":"The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs."},{"name":"session_percent","type":"Float64","description":"The percent of existing sessions to shed from the pool, according to the session policy."},{"name":"session_policy","type":"String","description":"Only the hash policy is supported for existing sessions (to avoid exponential decay)."}]},{"name":"notification_filter","type":"Attributes","description":"Filter pool and origin health notifications by resource type or health status. Use null to reset.","children":[{"name":"origin","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]},{"name":"pool","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]}]},{"name":"origin_steering","type":"Attributes","description":"Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.","children":[{"name":"policy","type":"String","description":"The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections."}]},{"name":"origins","type":"Set[Attributes]","description":"The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.","children":[{"name":"address","type":"String","description":"The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the origin is disabled. This field is set with the time the origin was disabled."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool."},{"name":"flatten_cname","type":"Bool","description":"Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting."},{"name":"header","type":"Attributes","description":"The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.","children":[{"name":"host","type":"List[String]","description":"The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin."}]},{"name":"name","type":"String","description":"A human-identifiable name for the origin."},{"name":"port","type":"Int64","description":"The port for upstream connections. A value of 0 means the default port for the protocol will be used."},{"name":"virtual_network_id","type":"String","description":"The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account."},{"name":"weight","type":"Float64","description":"The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections."}]}]}]},"get /accounts/{}/magic/bgp/filter_profiles":{"operationId":"magic-bgp-list-filter-profiles","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_wan_bgp_filter_profiles","stainlessResource":"magic_transit.bgp_filter_profiles","methodName":"list","snippet":"data \"cloudflare_magic_wan_bgp_filter_profiles\" \"example_magic_wan_bgp_filter_profiles\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"description","type":"String","description":"Description of the filter profile"},{"name":"match_action","type":"String","description":"Action to take when a route matches one of the targets in this profile"},{"name":"name","type":"String","description":"Friendly name for the filter profile"},{"name":"targets","type":"List[String]","description":"List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N."},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]}]},"get /accounts/{}/magic/bgp/filter_profiles/{}":{"operationId":"magic-bgp-get-filter-profile","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_bgp_filter_profile","stainlessResource":"magic_transit.bgp_filter_profiles","methodName":"get","snippet":"data \"cloudflare_magic_wan_bgp_filter_profile\" \"example_magic_wan_bgp_filter_profile\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n profile_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"profile_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"Description of the filter profile"},{"name":"match_action","type":"String","description":"Action to take when a route matches one of the targets in this profile"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"Friendly name for the filter profile"},{"name":"targets","type":"List[String]","description":"List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N."}]}]},"get /accounts/{}/magic/cf1_sites":{"operationId":"magic-cf1-sites-list-cf1-sites","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_cf1_sites","stainlessResource":"magic_transit.cf1_sites","methodName":"list","snippet":"data \"cloudflare_magic_transit_cf1_sites\" \"example_magic_transit_cf1_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]},{"name":"modified_on","type":"Time"}]}]}]},"get /accounts/{}/magic/cf1_sites/{}":{"operationId":"magic-cf1-sites-get-cf1-site","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_cf1_site","stainlessResource":"magic_transit.cf1_sites","methodName":"get","snippet":"data \"cloudflare_magic_transit_cf1_site\" \"example_magic_transit_cf1_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cf1_site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"cf1_site_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]}]}]},"get /accounts/{}/magic/connectors":{"operationId":"mconn-connectors-list","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_connectors","stainlessResource":"magic_transit.connectors","methodName":"list","snippet":"data \"cloudflare_magic_transit_connectors\" \"example_magic_transit_connectors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n device_type = \"MANAGED\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"device_type","type":"String","description":"Filter connectors by device type."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"activated","type":"Bool"},{"name":"interrupt_window_days_of_week","type":"List[String]","description":"Allowed days of the week for upgrades. Default is all days."},{"name":"interrupt_window_duration_hours","type":"Float64"},{"name":"interrupt_window_embargo_dates","type":"List[String]","description":"List of dates (YYYY-MM-DD) when upgrades are blocked."},{"name":"interrupt_window_hour_of_day","type":"Float64"},{"name":"last_updated","type":"String"},{"name":"notes","type":"String"},{"name":"timezone","type":"String"},{"name":"device","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"serial_number","type":"String"},{"name":"type","type":"String"}]},{"name":"last_heartbeat","type":"String"},{"name":"last_seen_version","type":"String"},{"name":"license_key","type":"String"}]}]}]},"get /accounts/{}/magic/connectors/{}":{"operationId":"mconn-connectors-get","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_connector","stainlessResource":"magic_transit.connectors","methodName":"get","snippet":"data \"cloudflare_magic_transit_connector\" \"example_magic_transit_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connector_id = \"connector_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"connector_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"device_type","type":"String","description":"Filter connectors by device type."}]}],"computed":[{"name":"id","type":"String"},{"name":"activated","type":"Bool"},{"name":"interrupt_window_duration_hours","type":"Float64"},{"name":"interrupt_window_hour_of_day","type":"Float64"},{"name":"last_heartbeat","type":"String"},{"name":"last_seen_version","type":"String"},{"name":"last_updated","type":"String"},{"name":"license_key","type":"String"},{"name":"notes","type":"String"},{"name":"timezone","type":"String"},{"name":"interrupt_window_days_of_week","type":"List[String]","description":"Allowed days of the week for upgrades. Default is all days."},{"name":"interrupt_window_embargo_dates","type":"List[String]","description":"List of dates (YYYY-MM-DD) when upgrades are blocked."},{"name":"device","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"serial_number","type":"String"},{"name":"type","type":"String"}]}]}]},"get /accounts/{}/magic/gre_tunnels/{}":{"operationId":"magic-gre-tunnels-list-gre-tunnel-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_gre_tunnel","stainlessResource":"magic_transit.gre_tunnels","methodName":"get","snippet":"data \"cloudflare_magic_wan_gre_tunnel\" \"example_magic_wan_gre_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n gre_tunnel_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"gre_tunnel_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"gre_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."}]}]}]},"get /accounts/{}/magic/ipsec_tunnels/{}":{"operationId":"magic-ipsec-tunnels-list-ipsec-tunnel-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_ipsec_tunnel","stainlessResource":"magic_transit.ipsec_tunnels","methodName":"get","snippet":"data \"cloudflare_magic_wan_ipsec_tunnel\" \"example_magic_wan_ipsec_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ipsec_tunnel_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"ipsec_tunnel_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"ipsec_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."}]}]}]},"get /accounts/{}/magic/routes/{}":{"operationId":"magic-static-routes-route-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_wan_static_route","stainlessResource":"magic_transit.routes","methodName":"get","snippet":"data \"cloudflare_magic_wan_static_route\" \"example_magic_wan_static_route\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n route_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"route_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"route","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."}]}]}]},"get /accounts/{}/magic/sites":{"operationId":"magic-sites-list-sites","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_sites","stainlessResource":"magic_transit.sites","methodName":"list","snippet":"data \"cloudflare_magic_transit_sites\" \"example_magic_transit_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connectorid = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"connectorid","type":"String","description":"Identifier"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"connector_id","type":"String","description":"Magic Connector identifier tag."},{"name":"description","type":"String"},{"name":"ha_mode","type":"Bool","description":"Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode."},{"name":"location","type":"Attributes","description":"Location of site in latitude and longitude.","children":[{"name":"lat","type":"String","description":"Latitude"},{"name":"lon","type":"String","description":"Longitude"}]},{"name":"name","type":"String","description":"The name of the site."},{"name":"secondary_connector_id","type":"String","description":"Magic Connector identifier tag. Used when high availability mode is on."}]}]}]},"get /accounts/{}/magic/sites/{}":{"operationId":"magic-sites-site-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site","stainlessResource":"magic_transit.sites","methodName":"get","snippet":"data \"cloudflare_magic_transit_site\" \"example_magic_transit_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"}],"optional":[{"name":"site_id","type":"String","description":"Identifier"},{"name":"filter","type":"Attributes","children":[{"name":"connectorid","type":"String","description":"Identifier"}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"connector_id","type":"String","description":"Magic Connector identifier tag."},{"name":"description","type":"String"},{"name":"ha_mode","type":"Bool","description":"Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode."},{"name":"name","type":"String","description":"The name of the site."},{"name":"secondary_connector_id","type":"String","description":"Magic Connector identifier tag. Used when high availability mode is on."},{"name":"location","type":"Attributes","description":"Location of site in latitude and longitude.","children":[{"name":"lat","type":"String","description":"Latitude"},{"name":"lon","type":"String","description":"Longitude"}]}]}]},"get /accounts/{}/magic/sites/{}/acls":{"operationId":"magic-site-acls-list-acls","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_site_acls","stainlessResource":"magic_transit.sites.acls","methodName":"list","snippet":"data \"cloudflare_magic_transit_site_acls\" \"example_magic_transit_site_acls\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"description","type":"String","description":"Description for the ACL."},{"name":"forward_locally","type":"Bool","description":"The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false."},{"name":"lan_1","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"lan_2","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"name","type":"String","description":"The name of the ACL."},{"name":"protocols","type":"List[String]"},{"name":"unidirectional","type":"Bool","description":"The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false."}]}]}]},"get /accounts/{}/magic/sites/{}/acls/{}":{"operationId":"magic-site-acls-acl-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site_acl","stainlessResource":"magic_transit.sites.acls","methodName":"get","snippet":"data \"cloudflare_magic_transit_site_acl\" \"example_magic_transit_site_acl\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n acl_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"acl_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"description","type":"String","description":"Description for the ACL."},{"name":"forward_locally","type":"Bool","description":"The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false."},{"name":"name","type":"String","description":"The name of the ACL."},{"name":"unidirectional","type":"Bool","description":"The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false."},{"name":"protocols","type":"List[String]"},{"name":"lan_1","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"lan_2","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]}]}]},"get /accounts/{}/magic/sites/{}/lans":{"operationId":"magic-site-lans-list-lans","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_site_lans","stainlessResource":"magic_transit.sites.lans","methodName":"list","snippet":"data \"cloudflare_magic_transit_site_lans\" \"example_magic_transit_site_lans\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"bond_id","type":"Int64"},{"name":"ha_link","type":"Bool","description":"mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link."},{"name":"is_breakout","type":"Bool","description":"mark true to use this LAN for source-based breakout traffic"},{"name":"is_prioritized","type":"Bool","description":"mark true to use this LAN for source-based prioritized traffic"},{"name":"name","type":"String"},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"physport","type":"Int64"},{"name":"routed_subnets","type":"List[Attributes]","children":[{"name":"next_hop","type":"String","description":"A valid IPv4 address."},{"name":"prefix","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]}]},{"name":"site_id","type":"String","description":"Identifier"},{"name":"static_addressing","type":"Attributes","description":"If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"dhcp_relay","type":"Attributes","children":[{"name":"server_addresses","type":"List[String]","description":"List of DHCP server IPs."}]},{"name":"dhcp_server","type":"Attributes","children":[{"name":"dhcp_options","type":"List[Attributes]","description":"Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.","children":[{"name":"code","type":"Int64","description":"DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration."},{"name":"type","type":"String","description":"The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\n"},{"name":"value","type":"String","description":"The option value, interpreted according to the type field."}]},{"name":"dhcp_pool_end","type":"String","description":"A valid IPv4 address."},{"name":"dhcp_pool_start","type":"String","description":"A valid IPv4 address."},{"name":"dns_server","type":"String","description":"A valid IPv4 address.","deprecated":"Deprecated."},{"name":"dns_servers","type":"List[String]"},{"name":"reservations","type":"Map[String]","description":"Mapping of MAC addresses to IP addresses"}]},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"virtual_address","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."}]}]}]},"get /accounts/{}/magic/sites/{}/lans/{}":{"operationId":"magic-site-lans-lan-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site_lan","stainlessResource":"magic_transit.sites.lans","methodName":"get","snippet":"data \"cloudflare_magic_transit_site_lan\" \"example_magic_transit_site_lan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lan_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"lan_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"bond_id","type":"Int64"},{"name":"ha_link","type":"Bool","description":"mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link."},{"name":"is_breakout","type":"Bool","description":"mark true to use this LAN for source-based breakout traffic"},{"name":"is_prioritized","type":"Bool","description":"mark true to use this LAN for source-based prioritized traffic"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"routed_subnets","type":"List[Attributes]","children":[{"name":"next_hop","type":"String","description":"A valid IPv4 address."},{"name":"prefix","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]}]},{"name":"static_addressing","type":"Attributes","description":"If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"dhcp_relay","type":"Attributes","children":[{"name":"server_addresses","type":"List[String]","description":"List of DHCP server IPs."}]},{"name":"dhcp_server","type":"Attributes","children":[{"name":"dhcp_options","type":"List[Attributes]","description":"Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.","children":[{"name":"code","type":"Int64","description":"DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration."},{"name":"type","type":"String","description":"The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\n"},{"name":"value","type":"String","description":"The option value, interpreted according to the type field."}]},{"name":"dhcp_pool_end","type":"String","description":"A valid IPv4 address."},{"name":"dhcp_pool_start","type":"String","description":"A valid IPv4 address."},{"name":"dns_server","type":"String","description":"A valid IPv4 address.","deprecated":"Deprecated."},{"name":"dns_servers","type":"List[String]"},{"name":"reservations","type":"Map[String]","description":"Mapping of MAC addresses to IP addresses"}]},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"virtual_address","type":"String","description":"A valid CIDR notation representing an IP range."}]}]}]},"get /accounts/{}/magic/sites/{}/wans":{"operationId":"magic-site-wans-list-wans","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_transit_site_wans","stainlessResource":"magic_transit.sites.wans","methodName":"list","snippet":"data \"cloudflare_magic_transit_site_wans\" \"example_magic_transit_site_wans\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"health_check_rate","type":"String","description":"Magic WAN health check rate for tunnels created on this link. The default value is `mid`."},{"name":"load_balance_inner_flows","type":"Bool"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"priority","type":"Int64","description":"Priority of WAN for traffic loadbalancing."},{"name":"site_id","type":"String","description":"Identifier"},{"name":"static_addressing","type":"Attributes","description":"(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"gateway_address","type":"String","description":"A valid IPv4 address."},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."}]}]}]},"get /accounts/{}/magic/sites/{}/wans/{}":{"operationId":"magic-site-wans-wan-details","declarations":[{"kind":"data-source","name":"cloudflare_magic_transit_site_wan","stainlessResource":"magic_transit.sites.wans","methodName":"get","snippet":"data \"cloudflare_magic_transit_site_wan\" \"example_magic_transit_site_wan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n wan_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"wan_id","type":"String","description":"Identifier"},{"name":"account_id","type":"String","description":"Identifier"},{"name":"site_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"health_check_rate","type":"String","description":"Magic WAN health check rate for tunnels created on this link. The default value is `mid`."},{"name":"load_balance_inner_flows","type":"Bool"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"priority","type":"Int64","description":"Priority of WAN for traffic loadbalancing."},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"static_addressing","type":"Attributes","description":"(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"gateway_address","type":"String","description":"A valid IPv4 address."},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."}]}]}]},"get /accounts/{}/members":{"operationId":"account-members-list-members","declarations":[{"kind":"list-data-source","name":"cloudflare_account_members","stainlessResource":"accounts.members","methodName":"list","snippet":"data \"cloudflare_account_members\" \"example_account_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n order = \"status\"\n status = \"accepted\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"order","type":"String","description":"Field to order results by."},{"name":"status","type":"String","description":"A member's status in the account."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Membership identifier tag."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"policies","type":"List[Attributes]","description":"Access policy for the membership","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]},{"name":"roles","type":"List[Attributes]","description":"Roles assigned to this Member.","children":[{"name":"id","type":"String","description":"Role identifier tag."},{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]},{"name":"status","type":"String","description":"A member's status in the account."},{"name":"user","type":"Attributes","description":"Details of the user associated to the membership.","children":[{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"id","type":"String","description":"Identifier"},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."}]}]}]}]},"get /accounts/{}/members/{}":{"operationId":"account-members-member-details","declarations":[{"kind":"data-source","name":"cloudflare_account_member","stainlessResource":"accounts.members","methodName":"get","snippet":"data \"cloudflare_account_member\" \"example_account_member\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n member_id = \"4536bcfad5faccb111b47003c79917fa\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"member_id","type":"String","description":"Membership identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"order","type":"String","description":"Field to order results by."},{"name":"status","type":"String","description":"A member's status in the account."}]}],"computed":[{"name":"id","type":"String","description":"Membership identifier tag."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"status","type":"String","description":"A member's status in the account."},{"name":"policies","type":"List[Attributes]","description":"Access policy for the membership","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the resource group."},{"name":"scope","type":"Attributes","description":"A scope is a combination of scope objects which provides additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Account ID etc.)"},{"name":"objects","type":"List[Attributes]","description":"A list of scope objects for additional context.","children":[{"name":"key","type":"String","description":"This is a combination of pre-defined resource name and identifier (like Zone ID etc.)"}]}]},{"name":"meta","type":"Attributes","description":"Attributes associated to the resource group.","children":[{"name":"key","type":"String"},{"name":"value","type":"String"}]},{"name":"name","type":"String","description":"Name of the resource group."}]}]},{"name":"roles","type":"List[Attributes]","description":"Roles assigned to this Member.","children":[{"name":"id","type":"String","description":"Role identifier tag."},{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]},{"name":"user","type":"Attributes","description":"Details of the user associated to the membership.","children":[{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"id","type":"String","description":"Identifier"},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."}]}]}]},"get /accounts/{}/mnm/config":{"operationId":"magic-network-monitoring-configuration-list-account-configuration","declarations":[{"kind":"data-source","name":"cloudflare_magic_network_monitoring_configuration","stainlessResource":"magic_network_monitoring.configs","methodName":"get","snippet":"data \"cloudflare_magic_network_monitoring_configuration\" \"example_magic_network_monitoring_configuration\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"default_sampling","type":"Float64","description":"Fallback sampling rate of flow messages being sent in packets per second. This should match the packet sampling rate configured on the router."},{"name":"name","type":"String","description":"The account name."},{"name":"router_ips","type":"List[String]"},{"name":"warp_devices","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the warp device."},{"name":"name","type":"String","description":"Name of the warp device."},{"name":"router_ip","type":"String","description":"IPv4 CIDR of the router sourcing flow data associated with this warp device. Only /32 addresses are currently supported."}]}]}]},"get /accounts/{}/mnm/rules":{"operationId":"magic-network-monitoring-rules-list-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_magic_network_monitoring_rules","stainlessResource":"magic_network_monitoring.rules","methodName":"list","snippet":"data \"cloudflare_magic_network_monitoring_rules\" \"example_magic_network_monitoring_rules\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The id of the rule. Must be unique."},{"name":"automatic_advertisement","type":"Bool","description":"Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit."},{"name":"name","type":"String","description":"The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters."},{"name":"prefixes","type":"List[String]"},{"name":"type","type":"String","description":"MNM rule type."},{"name":"bandwidth_threshold","type":"Float64","description":"The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"duration","type":"String","description":"The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"]."},{"name":"packet_threshold","type":"Float64","description":"The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"prefix_match","type":"String","description":"Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule."},{"name":"zscore_sensitivity","type":"String","description":"Level of sensitivity set for zscore rules."},{"name":"zscore_target","type":"String","description":"Target of the zscore rule analysis."}]}]}]},"get /accounts/{}/mnm/rules/{}":{"operationId":"magic-network-monitoring-rules-get-rule","declarations":[{"kind":"data-source","name":"cloudflare_magic_network_monitoring_rule","stainlessResource":"magic_network_monitoring.rules","methodName":"get","snippet":"data \"cloudflare_magic_network_monitoring_rule\" \"example_magic_network_monitoring_rule\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n rule_id = \"2890e6fa406311ed9b5a23f70f6fb8cf\"\n}\n","required":[{"name":"rule_id","type":"String","description":"The id of the rule. Must be unique."},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The id of the rule. Must be unique."},{"name":"automatic_advertisement","type":"Bool","description":"Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit."},{"name":"bandwidth_threshold","type":"Float64","description":"The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"duration","type":"String","description":"The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"]."},{"name":"name","type":"String","description":"The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters."},{"name":"packet_threshold","type":"Float64","description":"The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"prefix_match","type":"String","description":"Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule."},{"name":"type","type":"String","description":"MNM rule type."},{"name":"zscore_sensitivity","type":"String","description":"Level of sensitivity set for zscore rules."},{"name":"zscore_target","type":"String","description":"Target of the zscore rule analysis."},{"name":"prefixes","type":"List[String]"}]}]},"get /accounts/{}/moq/relays":{"operationId":"moq-relays-list","declarations":[{"kind":"list-data-source","name":"cloudflare_moq_relays","stainlessResource":"moq.relays","methodName":"list","snippet":"data \"cloudflare_moq_relays\" \"example_moq_relays\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_after = \"2026-03-27T15:00:00Z\"\n created_before = \"2026-03-27T15:00:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account identifier."}],"optional":[{"name":"created_after","type":"Time","description":"Cursor for pagination. Returns relays created strictly after this\nRFC 3339 timestamp (typically the `created` value of the last item\non the current page, to fetch the next page).\n"},{"name":"created_before","type":"Time","description":"Cursor for pagination. Returns relays created strictly before this\nRFC 3339 timestamp (typically the `created` value of the first item\non the current page, to fetch the previous page).\n"},{"name":"asc","type":"Bool","description":"Sort order by `created`. When true, results are returned oldest-first\n(ascending); otherwise newest-first (descending, the default).\n"},{"name":"per_page","type":"Int64","description":"Maximum number of relays to return per page. Values above the maximum are\nclamped to it rather than rejected.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created","type":"Time"},{"name":"modified","type":"Time"},{"name":"name","type":"String"},{"name":"uid","type":"String"}]}]}]},"get /accounts/{}/moq/relays/{}":{"operationId":"moq-relays-get","declarations":[{"kind":"data-source","name":"cloudflare_moq_relay","stainlessResource":"moq.relays","methodName":"get","snippet":"data \"cloudflare_moq_relay\" \"example_moq_relay\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n relay_id = \"a1b2c3d4e5f67890a1b2c3d4e5f67890\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account identifier."}],"optional":[{"name":"relay_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"asc","type":"Bool","description":"Sort order by `created`. When true, results are returned oldest-first\n(ascending); otherwise newest-first (descending, the default).\n"},{"name":"created_after","type":"Time","description":"Cursor for pagination. Returns relays created strictly after this\nRFC 3339 timestamp (typically the `created` value of the last item\non the current page, to fetch the next page).\n"},{"name":"created_before","type":"Time","description":"Cursor for pagination. Returns relays created strictly before this\nRFC 3339 timestamp (typically the `created` value of the first item\non the current page, to fetch the previous page).\n"},{"name":"per_page","type":"Int64","description":"Maximum number of relays to return per page. Values above the maximum are\nclamped to it rather than rejected.\n"}]}],"computed":[{"name":"id","type":"String"},{"name":"created","type":"Time"},{"name":"modified","type":"Time"},{"name":"name","type":"String"},{"name":"status","type":"String","description":"\"connected\" when active, omitted otherwise."},{"name":"uid","type":"String"},{"name":"config","type":"Attributes","children":[{"name":"upstreams","type":"Attributes","description":"Upstreams are external MOQT server publishers that a relay falls back\nto when it has no local publisher for a requested namespace/track.\n","children":[{"name":"enabled","type":"Bool"},{"name":"upstreams","type":"List[Attributes]","description":"Ordered list of upstream MOQT server publishers. Each entry is an\nobject (not a bare string) so per-upstream configuration can be\nadded in the future without another breaking change.\n","children":[{"name":"url","type":"String","description":"Upstream MOQT server publisher URL. Must be an absolute URL with a\nhost and a scheme the relay can dial: moqt:// (raw QUIC) or https://\n(WebTransport). Validated on update (PUT); rejected with 21013.\n"}]}]}]}]}]},"get /accounts/{}/mtls_certificates/{}/associations":{"operationId":"m-tls-certificate-management-list-m-tls-certificate-associations","declarations":[{"kind":"data-source","name":"cloudflare_mtls_certificate_associations","stainlessResource":"mtls_certificates.associations","methodName":"get","snippet":"data \"cloudflare_mtls_certificate_associations\" \"example_mtls_certificate_associations\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n mtls_certificate_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"mtls_certificate_id","type":"String","description":"Certificate identifier tag."}],"optional":[],"computed":[{"name":"service","type":"String","description":"The service using the certificate."},{"name":"status","type":"String","description":"Certificate deployment status for the given service."}]}]},"get /accounts/{}/oauth_clients":{"operationId":"oauth-clients-list","declarations":[{"kind":"list-data-source","name":"cloudflare_oauth_clients","stainlessResource":"iam.oauth_clients","methodName":"list","snippet":"data \"cloudflare_oauth_clients\" \"example_oauth_clients\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"client_id","type":"String","description":"The unique identifier for an OAuth client."},{"name":"visibility","type":"String","description":"Visibility of the OAuth client."},{"name":"allowed_cors_origins","type":"List[String]","description":"Array of allowed CORS origins."},{"name":"client_name","type":"String","description":"Human-readable name of the OAuth client."},{"name":"client_uri","type":"String","description":"URL of the home page of the client."},{"name":"client_uri_verification","type":"Attributes","description":"Client URI domain control verification state.","children":[{"name":"status","type":"String","description":"Current verification status for the client URI host."},{"name":"text","type":"String","description":"Exact TXT record value that must be added to DNS to prove ownership of the client URI host."}]},{"name":"created_at","type":"Time","description":"Timestamp when the OAuth client was created."},{"name":"grant_types","type":"List[String]","description":"Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally."},{"name":"has_rotated_secret","type":"Bool","description":"Indicates whether the client has a rotated secret that has not yet been deleted."},{"name":"logo_uri","type":"String","description":"URL of the client's logo."},{"name":"optional_scopes","type":"List[String]","description":"Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional."},{"name":"policy_uri","type":"String","description":"URL that points to a privacy policy document."},{"name":"post_logout_redirect_uris","type":"List[String]","description":"Array of allowed post-logout redirect URIs."},{"name":"promoted_at","type":"Time","description":"Timestamp when the OAuth client was promoted to public visibility."},{"name":"redirect_uris","type":"List[String]","description":"Array of allowed redirect URIs for the client."},{"name":"response_types","type":"List[String]","description":"Array of OAuth response types the client is allowed to use."},{"name":"scopes","type":"List[String]","description":"Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`."},{"name":"token_endpoint_auth_method","type":"String","description":"The authentication method the client uses at the token endpoint."},{"name":"tos_uri","type":"String","description":"URL that points to a terms of service document."},{"name":"updated_at","type":"Time","description":"Timestamp when the OAuth client was last updated."}]}]}]},"get /accounts/{}/oauth_clients/{}":{"operationId":"oauth-clients-get","declarations":[{"kind":"data-source","name":"cloudflare_oauth_client","stainlessResource":"iam.oauth_clients","methodName":"get","snippet":"data \"cloudflare_oauth_client\" \"example_oauth_client\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n oauth_client_id = \"a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"oauth_client_id","type":"String","description":"The unique identifier for an OAuth client."}],"optional":[],"computed":[{"name":"client_id","type":"String","description":"The unique identifier for an OAuth client."},{"name":"client_name","type":"String","description":"Human-readable name of the OAuth client."},{"name":"client_uri","type":"String","description":"URL of the home page of the client."},{"name":"created_at","type":"Time","description":"Timestamp when the OAuth client was created."},{"name":"has_rotated_secret","type":"Bool","description":"Indicates whether the client has a rotated secret that has not yet been deleted."},{"name":"logo_uri","type":"String","description":"URL of the client's logo."},{"name":"policy_uri","type":"String","description":"URL that points to a privacy policy document."},{"name":"promoted_at","type":"Time","description":"Timestamp when the OAuth client was promoted to public visibility."},{"name":"token_endpoint_auth_method","type":"String","description":"The authentication method the client uses at the token endpoint."},{"name":"tos_uri","type":"String","description":"URL that points to a terms of service document."},{"name":"updated_at","type":"Time","description":"Timestamp when the OAuth client was last updated."},{"name":"visibility","type":"String","description":"Visibility of the OAuth client."},{"name":"allowed_cors_origins","type":"List[String]","description":"Array of allowed CORS origins."},{"name":"grant_types","type":"List[String]","description":"Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally."},{"name":"optional_scopes","type":"List[String]","description":"Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional."},{"name":"post_logout_redirect_uris","type":"List[String]","description":"Array of allowed post-logout redirect URIs."},{"name":"redirect_uris","type":"List[String]","description":"Array of allowed redirect URIs for the client."},{"name":"response_types","type":"List[String]","description":"Array of OAuth response types the client is allowed to use."},{"name":"scopes","type":"List[String]","description":"Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`."},{"name":"client_uri_verification","type":"Attributes","description":"Client URI domain control verification state.","children":[{"name":"status","type":"String","description":"Current verification status for the client URI host."},{"name":"text","type":"String","description":"Exact TXT record value that must be added to DNS to prove ownership of the client URI host."}]}]}]},"get /accounts/{}/pages/projects":{"operationId":"pages-project-get-projects","declarations":[{"kind":"list-data-source","name":"cloudflare_pages_projects","stainlessResource":"pages.projects","methodName":"list","snippet":"data \"cloudflare_pages_projects\" \"example_pages_projects\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"ID of the project."},{"name":"canonical_deployment","type":"Attributes","description":"Most recent production deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"created_on","type":"Time","description":"When the project was created."},{"name":"deployment_configs","type":"Attributes","description":"Configs for deployments in a project.","children":[{"name":"preview","type":"Attributes","description":"Configs for preview deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]},{"name":"production","type":"Attributes","description":"Configs for production deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]}]},{"name":"framework","type":"String","description":"Framework the project is using."},{"name":"framework_version","type":"String","description":"Version of the framework the project is using."},{"name":"latest_deployment","type":"Attributes","description":"Most recent deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"preview_script_name","type":"String","description":"Name of the preview script."},{"name":"production_branch","type":"String","description":"Production branch of the project. Used to identify production deployments."},{"name":"production_script_name","type":"String","description":"Name of the production script."},{"name":"uses_functions","type":"Bool","description":"Whether the project uses functions."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"domains","type":"List[String]","description":"A list of associated custom domains for the project."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"subdomain","type":"String","description":"The Cloudflare subdomain associated with the project."}]}]}]},"get /accounts/{}/pages/projects/{}":{"operationId":"pages-project-get-project","declarations":[{"kind":"data-source","name":"cloudflare_pages_project","stainlessResource":"pages.projects","methodName":"get","snippet":"data \"cloudflare_pages_project\" \"example_pages_project\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n}\n","required":[{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"created_on","type":"Time","description":"When the project was created."},{"name":"framework","type":"String","description":"Framework the project is using."},{"name":"framework_version","type":"String","description":"Version of the framework the project is using."},{"name":"name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"preview_script_name","type":"String","description":"Name of the preview script."},{"name":"production_branch","type":"String","description":"Production branch of the project. Used to identify production deployments."},{"name":"production_script_name","type":"String","description":"Name of the production script."},{"name":"subdomain","type":"String","description":"The Cloudflare subdomain associated with the project."},{"name":"uses_functions","type":"Bool","description":"Whether the project uses functions."},{"name":"domains","type":"List[String]","description":"A list of associated custom domains for the project."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"canonical_deployment","type":"Attributes","description":"Most recent production deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"deployment_configs","type":"Attributes","description":"Configs for deployments in a project.","children":[{"name":"preview","type":"Attributes","description":"Configs for preview deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]},{"name":"production","type":"Attributes","description":"Configs for production deploys.","children":[{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"environment","type":"String","description":"The Service environment."},{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."}]},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]}]},{"name":"latest_deployment","type":"Attributes","description":"Most recent deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]}]}]},"get /accounts/{}/pages/projects/{}/domains":{"operationId":"pages-domains-get-domains","declarations":[{"kind":"list-data-source","name":"cloudflare_pages_domains","stainlessResource":"pages.projects.domains","methodName":"list","snippet":"data \"cloudflare_pages_domains\" \"example_pages_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"certificate_authority","type":"String"},{"name":"created_on","type":"String"},{"name":"domain_id","type":"String"},{"name":"name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"status","type":"String"},{"name":"validation_data","type":"Attributes","children":[{"name":"method","type":"String"},{"name":"status","type":"String"},{"name":"error_message","type":"String"},{"name":"txt_name","type":"String"},{"name":"txt_value","type":"String"}]},{"name":"verification_data","type":"Attributes","children":[{"name":"status","type":"String"},{"name":"error_message","type":"String"}]},{"name":"zone_tag","type":"String"}]}]}]},"get /accounts/{}/pages/projects/{}/domains/{}":{"operationId":"pages-domains-get-domain","declarations":[{"kind":"data-source","name":"cloudflare_pages_domain","stainlessResource":"pages.projects.domains","methodName":"get","snippet":"data \"cloudflare_pages_domain\" \"example_pages_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n domain_name = \"example.com\"\n}\n","required":[{"name":"domain_name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"certificate_authority","type":"String"},{"name":"created_on","type":"String"},{"name":"domain_id","type":"String"},{"name":"name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`."},{"name":"status","type":"String"},{"name":"zone_tag","type":"String"},{"name":"validation_data","type":"Attributes","children":[{"name":"method","type":"String"},{"name":"status","type":"String"},{"name":"error_message","type":"String"},{"name":"txt_name","type":"String"},{"name":"txt_value","type":"String"}]},{"name":"verification_data","type":"Attributes","children":[{"name":"status","type":"String"},{"name":"error_message","type":"String"}]}]}]},"get /accounts/{}/pipelines/v1/pipelines/{}":{"operationId":"getV4AccountsByAccount_idPipelinesV1PipelinesByPipeline_id","declarations":[{"kind":"data-source","name":"cloudflare_pipeline","stainlessResource":"pipelines","methodName":"get_v1","snippet":"data \"cloudflare_pipeline\" \"example_pipeline\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n pipeline_id = \"043e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"pipeline_id","type":"String","description":"Specifies the public ID of the pipeline."},{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the public ID of the pipeline."},{"name":"created_at","type":"String"},{"name":"failure_reason","type":"String","description":"Indicates the reason for the failure of the Pipeline."},{"name":"modified_at","type":"String"},{"name":"name","type":"String","description":"Indicates the name of the Pipeline."},{"name":"sql","type":"String","description":"Specifies SQL for the Pipeline processing flow."},{"name":"status","type":"String","description":"Indicates the current status of the Pipeline."},{"name":"tables","type":"List[Attributes]","description":"List of streams and sinks used by this pipeline.","children":[{"name":"id","type":"String","description":"Unique identifier for the connection (stream or sink)."},{"name":"latest","type":"Int64","description":"Latest available version of the connection."},{"name":"name","type":"String","description":"Name of the connection."},{"name":"type","type":"String","description":"Type of the connection."},{"name":"version","type":"Int64","description":"Current version of the connection used by this pipeline."}]}]}]},"get /accounts/{}/pipelines/v1/sinks":{"operationId":"getV4AccountsByAccount_idPipelinesV1Sinks","declarations":[{"kind":"list-data-source","name":"cloudflare_pipeline_sinks","stainlessResource":"pipelines.sinks","methodName":"list","snippet":"data \"cloudflare_pipeline_sinks\" \"example_pipeline_sinks\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"x\"\n pipeline_id = \"pipeline_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"name","type":"String","description":"Filters sinks by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Indicates a unique identifier for this sink."},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Defines the name of the Sink."},{"name":"type","type":"String","description":"Specifies the type of sink."},{"name":"config","type":"Attributes","description":"Defines the configuration of the R2 Sink.","children":[{"name":"account_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"bucket","type":"String","description":"R2 Bucket to write to"},{"name":"file_naming","type":"Attributes","description":"Controls filename prefix/suffix and strategy.","children":[{"name":"prefix","type":"String","description":"The prefix to use in file name. i.e prefix-.parquet"},{"name":"strategy","type":"String","description":"Filename generation strategy."},{"name":"suffix","type":"String","description":"This will overwrite the default file suffix. i.e .parquet, use with caution"}]},{"name":"jurisdiction","type":"String","description":"Jurisdiction this bucket is hosted in"},{"name":"partitioning","type":"Attributes","description":"Data-layout partitioning for sinks.","children":[{"name":"time_pattern","type":"String","description":"The pattern of the date string"}]},{"name":"path","type":"String","description":"Subpath within the bucket to write to"},{"name":"rolling_policy","type":"Attributes","description":"Rolling policy for file sinks (when & why to close a file and open a new one).","children":[{"name":"file_size_bytes","type":"Int64","description":"Files will be rolled after reaching this number of bytes"},{"name":"inactivity_seconds","type":"Int64","description":"Number of seconds of inactivity to wait before rolling over to a new file"},{"name":"interval_seconds","type":"Int64","description":"Number of seconds to wait before rolling over to a new file"}]},{"name":"table_name","type":"String","description":"Table name"},{"name":"namespace","type":"String","description":"Table namespace"}]},{"name":"format","type":"Attributes","description":"Defines the output data format of a sink.","children":[{"name":"type","type":"String"},{"name":"compression","type":"String","description":"Specifies the compression applied to JSON sink output."},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}]}]}]},"get /accounts/{}/pipelines/v1/sinks/{}":{"operationId":"getV4AccountsByAccount_idPipelinesV1SinksBySink_id","declarations":[{"kind":"data-source","name":"cloudflare_pipeline_sink","stainlessResource":"pipelines.sinks","methodName":"get","snippet":"data \"cloudflare_pipeline_sink\" \"example_pipeline_sink\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n sink_id = \"0223105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"sink_id","type":"String","description":"Specifies the publid ID of the sink."},{"name":"filter","type":"Attributes","children":[{"name":"name","type":"String","description":"Filters sinks by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String"}]}],"computed":[{"name":"id","type":"String","description":"Specifies the publid ID of the sink."},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Defines the name of the Sink."},{"name":"type","type":"String","description":"Specifies the type of sink."},{"name":"config","type":"Attributes","description":"Defines the configuration of the R2 Sink.","children":[{"name":"account_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"bucket","type":"String","description":"R2 Bucket to write to"},{"name":"file_naming","type":"Attributes","description":"Controls filename prefix/suffix and strategy.","children":[{"name":"prefix","type":"String","description":"The prefix to use in file name. i.e prefix-.parquet"},{"name":"strategy","type":"String","description":"Filename generation strategy."},{"name":"suffix","type":"String","description":"This will overwrite the default file suffix. i.e .parquet, use with caution"}]},{"name":"jurisdiction","type":"String","description":"Jurisdiction this bucket is hosted in"},{"name":"partitioning","type":"Attributes","description":"Data-layout partitioning for sinks.","children":[{"name":"time_pattern","type":"String","description":"The pattern of the date string"}]},{"name":"path","type":"String","description":"Subpath within the bucket to write to"},{"name":"rolling_policy","type":"Attributes","description":"Rolling policy for file sinks (when & why to close a file and open a new one).","children":[{"name":"file_size_bytes","type":"Int64","description":"Files will be rolled after reaching this number of bytes"},{"name":"inactivity_seconds","type":"Int64","description":"Number of seconds of inactivity to wait before rolling over to a new file"},{"name":"interval_seconds","type":"Int64","description":"Number of seconds to wait before rolling over to a new file"}]},{"name":"table_name","type":"String","description":"Table name"},{"name":"namespace","type":"String","description":"Table namespace"}]},{"name":"format","type":"Attributes","description":"Defines the output data format of a sink.","children":[{"name":"type","type":"String"},{"name":"compression","type":"String","description":"Specifies the compression applied to JSON sink output."},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}]}]},"get /accounts/{}/pipelines/v1/streams":{"operationId":"getV4AccountsByAccount_idPipelinesV1Streams","declarations":[{"kind":"list-data-source","name":"cloudflare_pipeline_streams","stainlessResource":"pipelines.streams","methodName":"list","snippet":"data \"cloudflare_pipeline_streams\" \"example_pipeline_streams\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"x\"\n pipeline_id = \"043e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"name","type":"String","description":"Filters streams by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String","description":"Specifies the public ID of the pipeline."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Indicates a unique identifier for this stream."},{"name":"created_at","type":"Time"},{"name":"http","type":"Attributes","children":[{"name":"authentication","type":"Bool","description":"Indicates that authentication is required for the HTTP endpoint."},{"name":"enabled","type":"Bool","description":"Indicates that the HTTP endpoint is enabled."},{"name":"cors","type":"Attributes","description":"Specifies the CORS options for the HTTP endpoint.","children":[{"name":"origins","type":"List[String]"}]}]},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Indicates the name of the Stream."},{"name":"version","type":"Int64","description":"Indicates the current version of this stream."},{"name":"worker_binding","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicates that the worker binding is enabled."}]},{"name":"endpoint","type":"String","description":"Indicates the endpoint URL of this stream."},{"name":"format","type":"Attributes","description":"Defines the data format of the events.","children":[{"name":"type","type":"String"},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"compression","type":"String"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}]}]}]},"get /accounts/{}/pipelines/v1/streams/{}":{"operationId":"getV4AccountsByAccount_idPipelinesV1StreamsByStream_id","declarations":[{"kind":"data-source","name":"cloudflare_pipeline_stream","stainlessResource":"pipelines.streams","methodName":"get","snippet":"data \"cloudflare_pipeline_stream\" \"example_pipeline_stream\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n stream_id = \"033e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account."}],"optional":[{"name":"stream_id","type":"String","description":"Specifies the public ID of the stream."},{"name":"filter","type":"Attributes","children":[{"name":"name","type":"String","description":"Filters streams by name (case-insensitive substring)."},{"name":"pipeline_id","type":"String","description":"Specifies the public ID of the pipeline."}]}],"computed":[{"name":"id","type":"String","description":"Specifies the public ID of the stream."},{"name":"created_at","type":"Time"},{"name":"endpoint","type":"String","description":"Indicates the endpoint URL of this stream."},{"name":"modified_at","type":"Time"},{"name":"name","type":"String","description":"Indicates the name of the Stream."},{"name":"version","type":"Int64","description":"Indicates the current version of this stream."},{"name":"format","type":"Attributes","description":"Defines the data format of the events.","children":[{"name":"type","type":"String"},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"compression","type":"String"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"http","type":"Attributes","children":[{"name":"authentication","type":"Bool","description":"Indicates that authentication is required for the HTTP endpoint."},{"name":"enabled","type":"Bool","description":"Indicates that the HTTP endpoint is enabled."},{"name":"cors","type":"Attributes","description":"Specifies the CORS options for the HTTP endpoint.","children":[{"name":"origins","type":"List[String]"}]}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]},{"name":"worker_binding","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicates that the worker binding is enabled."}]}]}]},"get /accounts/{}/queues":{"operationId":"queues-list","declarations":[{"kind":"list-data-source","name":"cloudflare_queues","stainlessResource":"queues","methodName":"list","snippet":"data \"cloudflare_queues\" \"example_queues\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"consumers","type":"List[Attributes]","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]},{"name":"consumers_total_count","type":"Float64"},{"name":"created_on","type":"String"},{"name":"jurisdiction","type":"String"},{"name":"modified_on","type":"String"},{"name":"producers","type":"List[Attributes]","children":[{"name":"script","type":"String"},{"name":"type","type":"String"},{"name":"bucket_name","type":"String"}]},{"name":"producers_total_count","type":"Float64"},{"name":"queue_id","type":"String"},{"name":"queue_name","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"delivery_delay","type":"Float64","description":"Number of seconds to delay delivery of all messages to consumers."},{"name":"delivery_paused","type":"Bool","description":"Indicates if message delivery to consumers is currently paused."},{"name":"message_retention_period","type":"Float64","description":"Number of seconds after which an unconsumed message will be delayed."}]}]}]}]},"get /accounts/{}/queues/{}":{"operationId":"queues-get","declarations":[{"kind":"data-source","name":"cloudflare_queue","stainlessResource":"queues","methodName":"get","snippet":"data \"cloudflare_queue\" \"example_queue\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"queue_id","type":"String","description":"A Resource identifier."},{"name":"account_id","type":"String","description":"A Resource identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"A Resource identifier."},{"name":"consumers_total_count","type":"Float64"},{"name":"created_on","type":"String"},{"name":"jurisdiction","type":"String"},{"name":"modified_on","type":"String"},{"name":"producers_total_count","type":"Float64"},{"name":"queue_name","type":"String"},{"name":"consumers","type":"List[Attributes]","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]},{"name":"producers","type":"List[Attributes]","children":[{"name":"script","type":"String"},{"name":"type","type":"String"},{"name":"bucket_name","type":"String"}]},{"name":"settings","type":"Attributes","children":[{"name":"delivery_delay","type":"Float64","description":"Number of seconds to delay delivery of all messages to consumers."},{"name":"delivery_paused","type":"Bool","description":"Indicates if message delivery to consumers is currently paused."},{"name":"message_retention_period","type":"Float64","description":"Number of seconds after which an unconsumed message will be delayed."}]}]}]},"get /accounts/{}/queues/{}/consumers":{"operationId":"queues-list-consumers","declarations":[{"kind":"list-data-source","name":"cloudflare_queue_consumers","stainlessResource":"queues.consumers","methodName":"list","snippet":"data \"cloudflare_queue_consumers\" \"example_queue_consumers\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier."},{"name":"queue_id","type":"String","description":"A Resource identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]}]}]},"get /accounts/{}/queues/{}/consumers/{}":{"operationId":"queues-get-consumer","declarations":[{"kind":"data-source","name":"cloudflare_queue_consumer","stainlessResource":"queues.consumers","methodName":"get","snippet":"data \"cloudflare_queue_consumer\" \"example_queue_consumer\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n consumer_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier."},{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"queue_id","type":"String","description":"A Resource identifier."}],"optional":[],"computed":[{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"type","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]}]}]},"get /accounts/{}/r2-catalog/{}":{"operationId":"get-catalog-details","declarations":[{"kind":"data-source","name":"cloudflare_r2_data_catalog","stainlessResource":"r2_data_catalog","methodName":"get","snippet":"data \"cloudflare_r2_data_catalog\" \"example_r2_data_catalog\" {\n account_id = \"0123456789abcdef0123456789abcdef\"\n bucket_name = \"my-data-bucket\"\n}\n","required":[{"name":"bucket_name","type":"String","description":"Specifies the R2 bucket name."},{"name":"account_id","type":"String","description":"Use this to identify the account."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the R2 bucket name."},{"name":"bucket","type":"String","description":"Specifies the associated R2 bucket name."},{"name":"credential_status","type":"String","description":"Shows the credential configuration status."},{"name":"name","type":"String","description":"Specifies the catalog name (generated from account and bucket name)."},{"name":"status","type":"String","description":"Indicates the status of the catalog."},{"name":"maintenance_config","type":"Attributes","description":"Configures maintenance for the catalog.","children":[{"name":"compaction","type":"Attributes","description":"Configures compaction for catalog maintenance.","children":[{"name":"state","type":"String","description":"Specifies the state of maintenance operations."},{"name":"target_size_mb","type":"String","description":"Sets the target file size for compaction in megabytes. Defaults to \"128\"."}]},{"name":"interval","type":"String","description":"Scheduling interval between normal table maintenance runs."},{"name":"snapshot_expiration","type":"Attributes","description":"Configures snapshot expiration settings.","children":[{"name":"max_snapshot_age","type":"String","description":"Specifies the maximum age for snapshots. The system deletes snapshots older than this age.\nFormat: where unit is d (days), h (hours), m (minutes), or s (seconds).\nExamples: \"7d\" (7 days), \"48h\" (48 hours), \"2880m\" (2,880 minutes).\nDefaults to \"7d\".\n"},{"name":"min_snapshots_to_keep","type":"Int64","description":"Specifies the minimum number of snapshots to retain. Defaults to 100."},{"name":"state","type":"String","description":"Specifies the state of maintenance operations."}]}]}]}]},"get /accounts/{}/r2/buckets/{}":{"operationId":"r2-get-bucket","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket","stainlessResource":"r2.buckets","methodName":"get","snippet":"data \"cloudflare_r2_bucket\" \"example_r2_bucket\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"bucket_name","type":"String","description":"Name of the bucket."},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the bucket."},{"name":"creation_date","type":"String","description":"Creation timestamp."},{"name":"jurisdiction","type":"String","description":"Jurisdiction where objects in this bucket are guaranteed to be stored."},{"name":"location","type":"String","description":"Location of the bucket."},{"name":"name","type":"String","description":"Name of the bucket."},{"name":"storage_class","type":"String","description":"Storage class for newly uploaded objects, unless specified otherwise."}]}]},"get /accounts/{}/r2/buckets/{}/cors":{"operationId":"r2-get-bucket-cors-policy","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_cors","stainlessResource":"r2.buckets.cors","methodName":"get","snippet":"data \"cloudflare_r2_bucket_cors\" \"example_r2_bucket_cors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"allowed","type":"Attributes","description":"Object specifying allowed origins, methods and headers for this CORS rule.","children":[{"name":"methods","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Methods header R2 sets when requesting objects in a bucket from a browser."},{"name":"origins","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Origin header R2 sets when requesting objects in a bucket from a browser."},{"name":"headers","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Headers header R2 sets when requesting objects in this bucket from a browser. Cross-origin requests that include custom headers (e.g. x-user-id) should specify these headers as AllowedHeaders."}]},{"name":"id","type":"String","description":"Identifier for this rule."},{"name":"expose_headers","type":"List[String]","description":"Specifies the headers that can be exposed back, and accessed by, the JavaScript making the cross-origin request. If you need to access headers beyond the safelisted response headers, such as Content-Encoding or cf-cache-status, you must specify it here."},{"name":"max_age_seconds","type":"Float64","description":"Specifies the amount of time (in seconds) browsers are allowed to cache CORS preflight responses. Browsers may limit this to 2 hours or less, even if the maximum value (86400) is specified."}]}]}]},"get /accounts/{}/r2/buckets/{}/domains/custom/{}":{"operationId":"r2-get-custom-domain-settings","declarations":[{"kind":"data-source","name":"cloudflare_r2_custom_domain","stainlessResource":"r2.buckets.domains.custom","methodName":"get","snippet":"data \"cloudflare_r2_custom_domain\" \"example_r2_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n domain = \"example-domain/custom-domain.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."},{"name":"domain","type":"String","description":"Name of the custom domain."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"Whether this bucket is publicly accessible at the specified custom domain."},{"name":"min_tls","type":"String","description":"Minimum TLS Version the custom domain will accept for incoming connections. If not set, defaults to 1.0."},{"name":"zone_id","type":"String","description":"Zone ID of the custom domain resides in."},{"name":"zone_name","type":"String","description":"Zone that the custom domain resides in."},{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."},{"name":"status","type":"Attributes","children":[{"name":"ownership","type":"String","description":"Ownership status of the domain."},{"name":"ssl","type":"String","description":"SSL certificate status."}]}]}]},"get /accounts/{}/r2/buckets/{}/lifecycle":{"operationId":"r2-get-bucket-lifecycle-configuration","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_lifecycle","stainlessResource":"r2.buckets.lifecycle","methodName":"get","snippet":"data \"cloudflare_r2_bucket_lifecycle\" \"example_r2_bucket_lifecycle\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"conditions","type":"Attributes","description":"Conditions that apply to all transitions of this rule.","children":[{"name":"prefix","type":"String","description":"Transitions will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"abort_multipart_uploads_transition","type":"Attributes","description":"Transition to abort ongoing multipart uploads.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"}]}]},{"name":"delete_objects_transition","type":"Attributes","description":"Transition to delete objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]}]},{"name":"storage_class_transitions","type":"List[Attributes]","description":"Transitions to change the storage class of objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"storage_class","type":"String"}]}]}]}]},"get /accounts/{}/r2/buckets/{}/lock":{"operationId":"r2-get-bucket-lock-configuration","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_lock","stainlessResource":"r2.buckets.locks","methodName":"get","snippet":"data \"cloudflare_r2_bucket_lock\" \"example_r2_bucket_lock\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"condition","type":"Attributes","description":"Condition to apply a lock rule to an object for how long in seconds.","children":[{"name":"max_age_seconds","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"prefix","type":"String","description":"Rule will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]}]}]},"get /accounts/{}/r2/buckets/{}/sippy":{"operationId":"r2-get-bucket-sippy-config","declarations":[{"kind":"data-source","name":"cloudflare_r2_bucket_sippy","stainlessResource":"r2.buckets.sippy","methodName":"get","snippet":"data \"cloudflare_r2_bucket_sippy\" \"example_r2_bucket_sippy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource."},{"name":"bucket_name","type":"String","description":"Name of the bucket."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"State of Sippy for this bucket."},{"name":"destination","type":"Attributes","description":"Details about the configured destination bucket.","children":[{"name":"access_key_id","type":"String","description":"ID of the Cloudflare API token used when writing objects to this\nbucket.\n"},{"name":"account","type":"String"},{"name":"bucket","type":"String","description":"Name of the bucket on the provider."},{"name":"r2_bucket_sippy_provider","type":"String"}]},{"name":"source","type":"Attributes","description":"Details about the configured source bucket.","children":[{"name":"bucket","type":"String","description":"Name of the bucket on the provider (AWS, GCS only)."},{"name":"bucket_url","type":"String","description":"S3-compatible URL (Generic S3-compatible providers only)."},{"name":"container","type":"String","description":"Name of the Azure Blob Storage container (Azure only)."},{"name":"r2_bucket_sippy_provider","type":"String"},{"name":"region","type":"String","description":"Region where the bucket resides (AWS only)."}]}]}]},"get /accounts/{}/registrar/domains":{"operationId":"registrar-domains-list-domains","declarations":[{"kind":"list-data-source","name":"cloudflare_registrar_domains","stainlessResource":"registrar.domains","methodName":"list","snippet":"data \"cloudflare_registrar_domains\" \"example_registrar_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"available","type":"Bool","description":"Shows if a domain is available for transferring into Cloudflare Registrar."},{"name":"can_register","type":"Bool","description":"Indicates eligibility to register the domain as a new domain."},{"name":"created_at","type":"Time","description":"Shows time of creation."},{"name":"current_registrar","type":"String","description":"Shows name of current registrar."},{"name":"expires_at","type":"Time","description":"Shows when domain name registration expires."},{"name":"locked","type":"Bool","description":"Shows whether a registrar lock is in place for a domain."},{"name":"registrant_contact","type":"Attributes","description":"Shows contact information for domain registrant.","children":[{"name":"address","type":"String","description":"Address."},{"name":"city","type":"String","description":"City."},{"name":"country","type":"String","description":"The country in which the user lives."},{"name":"first_name","type":"String","description":"User's first name."},{"name":"last_name","type":"String","description":"User's last name."},{"name":"organization","type":"String","description":"Name of organization."},{"name":"phone","type":"String","description":"User's telephone number."},{"name":"state","type":"String","description":"State."},{"name":"zip","type":"String","description":"The zipcode or postal code where the user lives."},{"name":"id","type":"String","description":"Contact Identifier."},{"name":"address2","type":"String","description":"Optional address line for unit, floor, suite, etc."},{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"fax","type":"String","description":"Contact fax number."}]},{"name":"registry_statuses","type":"String","description":"A comma-separated list of registry status codes. Refer to [EPP Status Codes](https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en) for the full list."},{"name":"supported_tld","type":"Bool","description":"Indicates whether Cloudflare Registrar currently supports a particular TLD. Refer to [TLD Policies](https://www.cloudflare.com/tld-policies/) for a list of supported TLDs."},{"name":"transfer_in","type":"Attributes","description":"Statuses for domain transfers into Cloudflare Registrar.","children":[{"name":"accept_foa","type":"String","description":"Status of the registrant authorization step."},{"name":"approve_transfer","type":"String","description":"Status of the registry transfer-approval step."},{"name":"can_cancel_transfer","type":"Bool","description":"Indicates if cancellation is still possible."},{"name":"disable_privacy","type":"String","description":"Status of the privacy-guard disabling step at the foreign registrar."},{"name":"enter_auth_code","type":"String","description":"Status of the auth-code entry and verification step."},{"name":"unlock_domain","type":"String","description":"Status of the domain-unlock step at the foreign registrar."}]},{"name":"updated_at","type":"Time","description":"Last updated."}]}]}]},"get /accounts/{}/registrar/domains/{}":{"operationId":"registrar-domains-get-domain","declarations":[{"kind":"data-source","name":"cloudflare_registrar_domain","stainlessResource":"registrar.domains","methodName":"get","snippet":"data \"cloudflare_registrar_domain\" \"example_registrar_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_name = \"example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"domain_name","type":"String","description":"Provides a fully qualified domain name (FQDN), including the extension\n(e.g., `example.com`, `mybrand.app`). The domain name uniquely identifies\na registration. Cloudflare permits only one registration per domain, making\nthe domain name a natural idempotency key for registration requests.\n"}],"optional":[],"computed":[]}]},"get /accounts/{}/resource-library/applications":{"operationId":"getResourceLibraryApplications","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_resource_library_applications","stainlessResource":"zero_trust.resource_library.applications","methodName":"list","snippet":"data \"cloudflare_zero_trust_resource_library_applications\" \"example_zero_trust_resource_library_applications\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n fields = \"fields\"\n filter = \"filter\"\n order_by = \"order_by\"\n search = \"xx\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"fields","type":"String","description":"Return only the listed properties on each application, as a comma-separated list.\nUse this to keep responses small when you only need part of each application — for\nexample populating a picker with `fields=id,name` instead of downloading every\nhostname and IP subnet.\n\nOmit this parameter to receive the full application object.\n\n`id` is always returned.\n\nSelectable properties: `id`, `name`, `human_id`, `version`, `hostnames`,\n`support_domains`, `ip_subnets`, `port_protocols`, `supported`, `gen_ai_score`,\n`application_confidence_score`, `created_at`, `updated_at`, `review_status`.\n\nUnknown or empty property names return `400`.\n"},{"name":"filter","type":"String","description":"Filter applications using key:value format. Supported filter keys:\n- name: Filter by application name (e.g., name:HR)\n- id: Filter by application ID (e.g., id:498)\n- human_id: Filter by human-readable ID (e.g., human_id:HR)\n- hostname: Filter by hostname or support domain (e.g., hostname:portal.example.com)\n- source: Filter by application source name (e.g., source:cloudflare)\n- ip_subnet: Filter by IP subnet using CIDR containment — returns applications where any stored subnet contains the search value (e.g., ip_subnet:10.0.1.5/32 matches apps with 10.0.0.0/16)\n- category_id: Filter by category ID (e.g., category_id:12).\n- category_name: Filter by category name (e.g., category_name:HR).\n- supported: Filter by supported Cloudflare product (e.g., supported:ACCESS). Values: GATEWAY, ACCESS, CASB.\n- review_status: Filter by the account's Gateway review status. Values: approved, unapproved, in_review, unreviewed.\n.\n"},{"name":"order_by","type":"String","description":"Order results using field:direction format. Supported fields are name, id, human_id,\ncategory_id, application_type, application_confidence_score, and gen_ai_score.\nSupported directions are asc and desc. Ignored when search is provided; results are\nranked by relevance instead.\n"},{"name":"search","type":"String","description":"Fuzzy search across application name and hostnames. Results are ranked by relevance. Must be between 2 and 200 characters. Can be combined with filter parameters."},{"name":"limit","type":"Int64","description":"Limit of number of results to return (max 250)."},{"name":"offset","type":"Int64","description":"Offset of results to return."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Returns the application ID."},{"name":"application_confidence_score","type":"Float64","description":"Confidence score for the application. Returns -1 when no score is available."},{"name":"application_score_composition","type":"unknown","description":"Returns the score composition breakdown for the application."},{"name":"application_source","type":"String","description":"Returns the application source."},{"name":"application_type","type":"String","description":"Returns the application type."},{"name":"application_type_description","type":"String","description":"Returns the application type description."},{"name":"category_id","type":"Int64","description":"Returns the category ID."},{"name":"created_at","type":"String","description":"Returns the application creation time."},{"name":"gen_ai_score","type":"Float64","description":"GenAI score for the application. Returns -1 when no score is available."},{"name":"hostnames","type":"Set[String]","description":"Hostnames matched by the application."},{"name":"human_id","type":"String","description":"Returns the human readable ID."},{"name":"ip_subnets","type":"Set[String]","description":"IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128."},{"name":"name","type":"String","description":"Returns the application name."},{"name":"port_protocols","type":"Set[String]","description":"Port and protocol pairs matched by the application."},{"name":"review_status","type":"String","description":"The account-specific Gateway review status. Applications with no assigned review status are returned as `unreviewed`."},{"name":"support_domains","type":"Set[String]","description":"Support domains matched by the application."},{"name":"supported","type":"Set[String]","description":"Cloudflare products that support this application."},{"name":"updated_at","type":"String","description":"Returns the application update time."},{"name":"version","type":"String","description":"Returns the application version."}]}]}]},"get /accounts/{}/resource-library/applications/{}":{"operationId":"getResourceLibraryApplicationById","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_resource_library_application","stainlessResource":"zero_trust.resource_library.applications","methodName":"get","snippet":"data \"cloudflare_zero_trust_resource_library_application\" \"example_zero_trust_resource_library_application\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = 498\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"id","type":"Int64","description":"Returns the application ID."},{"name":"filter","type":"Attributes","children":[{"name":"fields","type":"String","description":"Return only the listed properties on each application, as a comma-separated list.\nUse this to keep responses small when you only need part of each application — for\nexample populating a picker with `fields=id,name` instead of downloading every\nhostname and IP subnet.\n\nOmit this parameter to receive the full application object.\n\n`id` is always returned.\n\nSelectable properties: `id`, `name`, `human_id`, `version`, `hostnames`,\n`support_domains`, `ip_subnets`, `port_protocols`, `supported`, `gen_ai_score`,\n`application_confidence_score`, `created_at`, `updated_at`, `review_status`.\n\nUnknown or empty property names return `400`.\n"},{"name":"filter","type":"String","description":"Filter applications using key:value format. Supported filter keys:\n- name: Filter by application name (e.g., name:HR)\n- id: Filter by application ID (e.g., id:498)\n- human_id: Filter by human-readable ID (e.g., human_id:HR)\n- hostname: Filter by hostname or support domain (e.g., hostname:portal.example.com)\n- source: Filter by application source name (e.g., source:cloudflare)\n- ip_subnet: Filter by IP subnet using CIDR containment — returns applications where any stored subnet contains the search value (e.g., ip_subnet:10.0.1.5/32 matches apps with 10.0.0.0/16)\n- category_id: Filter by category ID (e.g., category_id:12).\n- category_name: Filter by category name (e.g., category_name:HR).\n- supported: Filter by supported Cloudflare product (e.g., supported:ACCESS). Values: GATEWAY, ACCESS, CASB.\n- review_status: Filter by the account's Gateway review status. Values: approved, unapproved, in_review, unreviewed.\n.\n"},{"name":"limit","type":"Int64","description":"Limit of number of results to return (max 250)."},{"name":"offset","type":"Int64","description":"Offset of results to return."},{"name":"order_by","type":"String","description":"Order results using field:direction format. Supported fields are name, id, human_id,\ncategory_id, application_type, application_confidence_score, and gen_ai_score.\nSupported directions are asc and desc. Ignored when search is provided; results are\nranked by relevance instead.\n"},{"name":"search","type":"String","description":"Fuzzy search across application name and hostnames. Results are ranked by relevance. Must be between 2 and 200 characters. Can be combined with filter parameters."}]}],"computed":[{"name":"application_confidence_score","type":"Float64","description":"Confidence score for the application. Returns -1 when no score is available."},{"name":"application_source","type":"String","description":"Returns the application source."},{"name":"application_type","type":"String","description":"Returns the application type."},{"name":"application_type_description","type":"String","description":"Returns the application type description."},{"name":"category_id","type":"Int64","description":"Returns the category ID."},{"name":"created_at","type":"String","description":"Returns the application creation time."},{"name":"gen_ai_score","type":"Float64","description":"GenAI score for the application. Returns -1 when no score is available."},{"name":"human_id","type":"String","description":"Returns the human readable ID."},{"name":"name","type":"String","description":"Returns the application name."},{"name":"updated_at","type":"String","description":"Returns the application update time."},{"name":"version","type":"String","description":"Returns the application version."},{"name":"hostnames","type":"Set[String]","description":"Hostnames matched by the application."},{"name":"ip_subnets","type":"Set[String]","description":"IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128."},{"name":"port_protocols","type":"Set[String]","description":"Port and protocol pairs matched by the application."},{"name":"support_domains","type":"Set[String]","description":"Support domains matched by the application."},{"name":"supported","type":"Set[String]","description":"Cloudflare products that support this application."},{"name":"application_score_composition","type":"unknown","description":"Returns the score composition breakdown for the application."}]}]},"get /accounts/{}/resource-library/categories":{"operationId":"getResourceLibraryCategories","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_resource_library_categories","stainlessResource":"zero_trust.resource_library.categories","methodName":"list","snippet":"data \"cloudflare_zero_trust_resource_library_categories\" \"example_zero_trust_resource_library_categories\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"limit","type":"Int64","description":"Limit of number of results to return."},{"name":"offset","type":"Int64","description":"Offset of results to return."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"Int64","description":"Returns the category ID."},{"name":"created_at","type":"String","description":"Returns the category creation time."},{"name":"description","type":"String","description":"Returns the category description."},{"name":"name","type":"String","description":"Returns the category name."}]}]}]},"get /accounts/{}/resource-library/categories/{}":{"operationId":"getResourceLibraryCategoryById","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_resource_library_category","stainlessResource":"zero_trust.resource_library.categories","methodName":"get","snippet":"data \"cloudflare_zero_trust_resource_library_category\" \"example_zero_trust_resource_library_category\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = 12\n}\n","required":[{"name":"account_id","type":"String"},{"name":"id","type":"Int64","description":"Returns the category ID."}],"optional":[],"computed":[{"name":"created_at","type":"String","description":"Returns the category creation time."},{"name":"description","type":"String","description":"Returns the category description."},{"name":"name","type":"String","description":"Returns the category name."}]}]},"get /accounts/{}/roles":{"operationId":"account-roles-list-roles","declarations":[{"kind":"list-data-source","name":"cloudflare_account_roles","stainlessResource":"accounts.roles","methodName":"list","snippet":"data \"cloudflare_account_roles\" \"example_account_roles\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Role identifier tag."},{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]}]}]},"get /accounts/{}/roles/{}":{"operationId":"account-roles-role-details","declarations":[{"kind":"data-source","name":"cloudflare_account_role","stainlessResource":"accounts.roles","methodName":"get","snippet":"data \"cloudflare_account_role\" \"example_account_role\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n role_id = \"3536bcfad5faccb999b47003c79917fb\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."},{"name":"role_id","type":"String","description":"Role identifier tag."}],"optional":[],"computed":[{"name":"description","type":"String","description":"Description of role's permissions."},{"name":"id","type":"String","description":"Role identifier tag."},{"name":"name","type":"String","description":"Role name."},{"name":"permissions","type":"Attributes","children":[{"name":"analytics","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"billing","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"cache_purge","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"dns_records","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"lb","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"logs","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"organization","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"ssl","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"waf","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zone_settings","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]},{"name":"zones","type":"Attributes","children":[{"name":"read","type":"Bool"},{"name":"write","type":"Bool"}]}]}]}]},"get /accounts/{}/rules/lists":{"operationId":"lists-get-lists","declarations":[{"kind":"list-data-source","name":"cloudflare_lists","stainlessResource":"rules.lists","methodName":"list","snippet":"data \"cloudflare_lists\" \"example_lists\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique ID of the list."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"kind","type":"String","description":"The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects)."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"name","type":"String","description":"An informative name for the list. Use this name in filter and rule expressions."},{"name":"num_items","type":"Float64","description":"The number of items in the list."},{"name":"num_referencing_filters","type":"Float64","description":"The number of [filters](/api/resources/filters/) referencing the list."},{"name":"description","type":"String","description":"An informative summary of the list."}]}]}]},"get /accounts/{}/rules/lists/{}":{"operationId":"lists-get-a-list","declarations":[{"kind":"data-source","name":"cloudflare_list","stainlessResource":"rules.lists","methodName":"get","snippet":"data \"cloudflare_list\" \"example_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n}\n","required":[{"name":"list_id","type":"String","description":"The unique ID of the list."},{"name":"account_id","type":"String","description":"The Account ID for this resource."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the list."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"description","type":"String","description":"An informative summary of the list."},{"name":"kind","type":"String","description":"The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects)."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"name","type":"String","description":"An informative name for the list. Use this name in filter and rule expressions."},{"name":"num_items","type":"Float64","description":"The number of items in the list."},{"name":"num_referencing_filters","type":"Float64","description":"The number of [filters](/api/resources/filters/) referencing the list."}]}]},"get /accounts/{}/rules/lists/{}/items":{"operationId":"lists-get-list-items","declarations":[{"kind":"list-data-source","name":"cloudflare_list_items","stainlessResource":"rules.lists.items","methodName":"list","snippet":"data \"cloudflare_list_items\" \"example_list_items\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n per_page = 1\n search = \"1.1.1.\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource."},{"name":"list_id","type":"String","description":"The unique ID of the list."}],"optional":[{"name":"per_page","type":"Int64","description":"Amount of results to include in each paginated response. A non-negative 32 bit integer."},{"name":"search","type":"String","description":"A search query to filter returned items. Its meaning depends on the list type: IP addresses must start with the provided string, hostnames and bulk redirects must contain the string, and ASNs must match the string exactly."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]},{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."}]}]}]},"get /accounts/{}/rules/lists/{}/items/{}":{"operationId":"lists-get-a-list-item","declarations":[{"kind":"data-source","name":"cloudflare_list_item","stainlessResource":"rules.lists.items","methodName":"get","snippet":"data \"cloudflare_list_item\" \"example_list_item\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n item_id = \"34b12448945f11eaa1b71c4d701ab86e\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource."},{"name":"item_id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"list_id","type":"String","description":"The unique ID of the list."}],"optional":[],"computed":[{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]}]}]},"get /accounts/{}/rum/site_info/{}":{"operationId":"web-analytics-get-site","declarations":[{"kind":"data-source","name":"cloudflare_web_analytics_site","stainlessResource":"rum.site_info","methodName":"get","snippet":"data \"cloudflare_web_analytics_site\" \"example_web_analytics_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"site_id","type":"String","description":"Identifier."},{"name":"filter","type":"Attributes","children":[{"name":"order_by","type":"String","description":"The property used to sort the list of results."}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"auto_install","type":"Bool","description":"If enabled, the JavaScript snippet is automatically injected for orange-clouded sites."},{"name":"created","type":"Time"},{"name":"site_tag","type":"String","description":"The Web Analytics site identifier."},{"name":"site_token","type":"String","description":"The Web Analytics site token."},{"name":"snippet","type":"String","description":"Encoded JavaScript snippet."},{"name":"rules","type":"List[Attributes]","description":"A list of rules.","children":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"host","type":"String","description":"The hostname the rule will be applied to."},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]","description":"The paths the rule will be applied to."},{"name":"priority","type":"Float64"}]},{"name":"ruleset","type":"Attributes","children":[{"name":"id","type":"String","description":"The Web Analytics ruleset identifier."},{"name":"enabled","type":"Bool","description":"Whether the ruleset is enabled."},{"name":"zone_name","type":"String"},{"name":"zone_tag","type":"String","description":"The zone identifier."}]}]}]},"get /accounts/{}/rum/site_info/list":{"operationId":"web-analytics-list-sites","declarations":[{"kind":"list-data-source","name":"cloudflare_web_analytics_sites","stainlessResource":"rum.site_info","methodName":"list","snippet":"data \"cloudflare_web_analytics_sites\" \"example_web_analytics_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n order_by = \"host\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"order_by","type":"String","description":"The property used to sort the list of results."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The Web Analytics site identifier."},{"name":"auto_install","type":"Bool","description":"If enabled, the JavaScript snippet is automatically injected for orange-clouded sites."},{"name":"created","type":"Time"},{"name":"rules","type":"List[Attributes]","description":"A list of rules.","children":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"host","type":"String","description":"The hostname the rule will be applied to."},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]","description":"The paths the rule will be applied to."},{"name":"priority","type":"Float64"}]},{"name":"ruleset","type":"Attributes","children":[{"name":"id","type":"String","description":"The Web Analytics ruleset identifier."},{"name":"enabled","type":"Bool","description":"Whether the ruleset is enabled."},{"name":"zone_name","type":"String"},{"name":"zone_tag","type":"String","description":"The zone identifier."}]},{"name":"site_tag","type":"String","description":"The Web Analytics site identifier."},{"name":"site_token","type":"String","description":"The Web Analytics site token."},{"name":"snippet","type":"String","description":"Encoded JavaScript snippet."}]}]}]},"get /accounts/{}/secondary_dns/acls":{"operationId":"secondary-dns-(-acl)-list-ac-ls","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_zone_transfers_acls","stainlessResource":"dns.zone_transfers.acls","methodName":"list","snippet":"data \"cloudflare_dns_zone_transfers_acls\" \"example_dns_zone_transfers_acls\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"ip_range","type":"String","description":"Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively."},{"name":"name","type":"String","description":"The name of the acl."}]}]}]},"get /accounts/{}/secondary_dns/acls/{}":{"operationId":"secondary-dns-(-acl)-acl-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_acl","stainlessResource":"dns.zone_transfers.acls","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_acl\" \"example_dns_zone_transfers_acl\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n acl_id = \"23ff594956f20c2a721606e94745a8aa\"\n}\n","required":[{"name":"acl_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ip_range","type":"String","description":"Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively."},{"name":"name","type":"String","description":"The name of the acl."}]}]},"get /accounts/{}/secondary_dns/peers":{"operationId":"secondary-dns-(-peer)-list-peers","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_zone_transfers_peers","stainlessResource":"dns.zone_transfers.peers","methodName":"list","snippet":"data \"cloudflare_dns_zone_transfers_peers\" \"example_dns_zone_transfers_peers\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"name","type":"String","description":"The name of the peer."},{"name":"ip","type":"String","description":"IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to."},{"name":"ixfr_enable","type":"Bool","description":"Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones."},{"name":"port","type":"Float64","description":"DNS port of primary or secondary nameserver, depending on what zone this peer is linked to."},{"name":"tsig_id","type":"String","description":"TSIG authentication will be used for zone transfer if configured."}]}]}]},"get /accounts/{}/secondary_dns/peers/{}":{"operationId":"secondary-dns-(-peer)-peer-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_peer","stainlessResource":"dns.zone_transfers.peers","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_peer\" \"example_dns_zone_transfers_peer\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n peer_id = \"23ff594956f20c2a721606e94745a8aa\"\n}\n","required":[{"name":"peer_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"ip","type":"String","description":"IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to."},{"name":"ixfr_enable","type":"Bool","description":"Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones."},{"name":"name","type":"String","description":"The name of the peer."},{"name":"port","type":"Float64","description":"DNS port of primary or secondary nameserver, depending on what zone this peer is linked to."},{"name":"tsig_id","type":"String","description":"TSIG authentication will be used for zone transfer if configured."}]}]},"get /accounts/{}/secondary_dns/tsigs":{"operationId":"secondary-dns-(-tsig)-list-tsi-gs","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_zone_transfers_tsigs","stainlessResource":"dns.zone_transfers.tsigs","methodName":"list","snippet":"data \"cloudflare_dns_zone_transfers_tsigs\" \"example_dns_zone_transfers_tsigs\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"algo","type":"String","description":"TSIG algorithm."},{"name":"name","type":"String","description":"TSIG key name."},{"name":"secret","type":"String","description":"TSIG secret.","sensitive":true}]}]}]},"get /accounts/{}/secondary_dns/tsigs/{}":{"operationId":"secondary-dns-(-tsig)-tsig-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_tsig","stainlessResource":"dns.zone_transfers.tsigs","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_tsig\" \"example_dns_zone_transfers_tsig\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n tsig_id = \"69cd1e104af3e6ed3cb344f263fd0d5a\"\n}\n","required":[{"name":"tsig_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"algo","type":"String","description":"TSIG algorithm."},{"name":"name","type":"String","description":"TSIG key name."},{"name":"secret","type":"String","description":"TSIG secret.","sensitive":true}]}]},"get /accounts/{}/secrets_store/stores":{"operationId":"secrets-store-list","declarations":[{"kind":"list-data-source","name":"cloudflare_secrets_stores","stainlessResource":"secrets_store.stores","methodName":"list","snippet":"data \"cloudflare_secrets_stores\" \"example_secrets_stores\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order stores by values in the given field."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Store Identifier."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the store."},{"name":"account_id","type":"String","description":"Account Identifier."}]}]}]},"get /accounts/{}/secrets_store/stores/{}":{"operationId":"secrets-store-get-store-by-id","declarations":[{"kind":"data-source","name":"cloudflare_secrets_store","stainlessResource":"secrets_store.stores","methodName":"get","snippet":"data \"cloudflare_secrets_store\" \"example_secrets_store\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"store_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order stores by values in the given field."}]}],"computed":[{"name":"id","type":"String"},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the store."}]}]},"get /accounts/{}/secrets_store/stores/{}/secrets":{"operationId":"secrets-store-secrets-list","declarations":[{"kind":"list-data-source","name":"cloudflare_secrets_store_secrets","stainlessResource":"secrets_store.stores.secrets","methodName":"list","snippet":"data \"cloudflare_secrets_store_secrets\" \"example_secrets_store_secrets\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n scopes = [\"workers\"]\n search = \"search\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"store_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Search secrets using a filter string, filtering across name and comment."},{"name":"scopes","type":"List[String]","description":"Only secrets with the given scopes will be returned."},{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order secrets by values in the given field."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Secret identifier tag."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the secret."},{"name":"status","type":"String"},{"name":"store_id","type":"String","description":"Store Identifier."},{"name":"comment","type":"String","description":"Freeform text describing the secret."},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."}]}]}]},"get /accounts/{}/secrets_store/stores/{}/secrets/{}":{"operationId":"secrets-store-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_secrets_store_secret","stainlessResource":"secrets_store.stores.secrets","methodName":"get","snippet":"data \"cloudflare_secrets_store_secret\" \"example_secrets_store_secret\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n secret_id = \"3fd85f74b32742f1bff64a85009dda07\"\n}\n","required":[{"name":"account_id","type":"String"},{"name":"store_id","type":"String"}],"optional":[{"name":"secret_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order secrets by values in the given field."},{"name":"scopes","type":"List[String]","description":"Only secrets with the given scopes will be returned."},{"name":"search","type":"String","description":"Search secrets using a filter string, filtering across name and comment."}]}],"computed":[{"name":"id","type":"String"},{"name":"comment","type":"String","description":"Freeform text describing the secret."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the secret."},{"name":"status","type":"String"},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."}]}]},"get /accounts/{}/shares":{"operationId":"shares-list","declarations":[{"kind":"list-data-source","name":"cloudflare_shares","stainlessResource":"resource_sharing","methodName":"list","snippet":"data \"cloudflare_shares\" \"example_shares\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n include_recipient_counts = true\n include_resources = true\n kind = \"sent\"\n resource_types = [\"custom-ruleset\"]\n status = \"active\"\n tag = [\"env=production\"]\n target_type = \"account\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."}],"optional":[{"name":"include_recipient_counts","type":"Bool","description":"Include recipient counts in the response."},{"name":"include_resources","type":"Bool","description":"Include resources in the response."},{"name":"kind","type":"String","description":"Filter shares by kind."},{"name":"status","type":"String","description":"Filter shares by status."},{"name":"target_type","type":"String","description":"Filter shares by target_type."},{"name":"resource_types","type":"List[String]","description":"Filter share resources by resource_types."},{"name":"tag","type":"List[String]","description":"Filter shares by tag. Each value is either `key=value` (matches shares whose tags contain that key/value pair) or `key` alone (matches shares that have any value for that key). May be repeated; multiple `tag` parameters are ANDed together. Maximum 20 `tag` parameters per request."},{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"order","type":"String","description":"Order shares by values in the given field."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Share identifier tag."},{"name":"account_id","type":"String","description":"Account identifier."},{"name":"account_name","type":"String","description":"The display name of an account."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"name","type":"String","description":"The name of the share."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"status","type":"String"},{"name":"target_type","type":"String"},{"name":"associated_recipient_count","type":"Int64","description":"The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"associating_recipient_count","type":"Int64","description":"The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociated_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociating_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"kind","type":"String"},{"name":"resources","type":"List[Attributes]","description":"A list of resources that are part of the share. This field is only included when requested via the 'include_resources' parameter.","children":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]}]}]},"get /accounts/{}/shares/{}":{"operationId":"shares-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_share","stainlessResource":"resource_sharing","methodName":"get","snippet":"data \"cloudflare_share\" \"example_share\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_recipient_counts = true\n include_resources = true\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."}],"optional":[{"name":"share_id","type":"String","description":"Share identifier tag."},{"name":"include_recipient_counts","type":"Bool","description":"Include recipient counts in the response."},{"name":"include_resources","type":"Bool","description":"Include resources in the response."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to sort objects."},{"name":"kind","type":"String","description":"Filter shares by kind."},{"name":"order","type":"String","description":"Order shares by values in the given field."},{"name":"resource_types","type":"List[String]","description":"Filter share resources by resource_types."},{"name":"status","type":"String","description":"Filter shares by status."},{"name":"tag","type":"List[String]","description":"Filter shares by tag. Each value is either `key=value` (matches shares whose tags contain that key/value pair) or `key` alone (matches shares that have any value for that key). May be repeated; multiple `tag` parameters are ANDed together. Maximum 20 `tag` parameters per request."},{"name":"target_type","type":"String","description":"Filter shares by target_type."}]}],"computed":[{"name":"id","type":"String","description":"Share identifier tag."},{"name":"account_name","type":"String","description":"The display name of an account."},{"name":"associated_recipient_count","type":"Int64","description":"The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"associating_recipient_count","type":"Int64","description":"The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"disassociated_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociating_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"kind","type":"String"},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"name","type":"String","description":"The name of the share."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"status","type":"String"},{"name":"target_type","type":"String"},{"name":"resources","type":"List[Attributes]","description":"A list of resources that are part of the share. This field is only included when requested via the 'include_resources' parameter.","children":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]}]},"get /accounts/{}/shares/{}/recipients":{"operationId":"share-recipients-list","declarations":[{"kind":"list-data-source","name":"cloudflare_share_recipients","stainlessResource":"resource_sharing.recipients","methodName":"list","snippet":"data \"cloudflare_share_recipients\" \"example_share_recipients\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_resources = true\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"include_resources","type":"Bool","description":"Include resources in the response."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Share Recipient identifier tag."},{"name":"account_id","type":"String","description":"Account identifier."},{"name":"association_status","type":"String","description":"The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\n"},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resources","type":"List[Attributes]","children":[{"name":"error","type":"String","description":"Share Recipient error message."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"terminal","type":"Bool","description":"Whether the error is terminal or will be continually retried."}]}]}]}]},"get /accounts/{}/shares/{}/recipients/{}":{"operationId":"share-recipients-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_share_recipient","stainlessResource":"resource_sharing.recipients","methodName":"get","snippet":"data \"cloudflare_share_recipient\" \"example_share_recipient\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n recipient_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_resources = true\n}\n","required":[{"name":"recipient_id","type":"String","description":"Share Recipient identifier tag."},{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"include_resources","type":"Bool","description":"Include resources in the response."}],"computed":[{"name":"id","type":"String","description":"Share Recipient identifier tag."},{"name":"association_status","type":"String","description":"The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\n"},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resources","type":"List[Attributes]","children":[{"name":"error","type":"String","description":"Share Recipient error message."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"terminal","type":"Bool","description":"Whether the error is terminal or will be continually retried."}]}]}]},"get /accounts/{}/shares/{}/resources":{"operationId":"share-resources-list","declarations":[{"kind":"list-data-source","name":"cloudflare_share_resources","stainlessResource":"resource_sharing.resources","methodName":"list","snippet":"data \"cloudflare_share_resources\" \"example_share_resources\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n resource_type = \"custom-ruleset\"\n status = \"active\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"resource_type","type":"String","description":"Filter share resources by resource_type."},{"name":"status","type":"String","description":"Filter share resources by status."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]}]},"get /accounts/{}/shares/{}/resources/{}":{"operationId":"share-resources-get-by-id","declarations":[{"kind":"data-source","name":"cloudflare_share_resource","stainlessResource":"resource_sharing.resources","methodName":"get","snippet":"data \"cloudflare_share_resource\" \"example_share_resource\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n share_resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier."},{"name":"share_id","type":"String","description":"Share identifier tag."}],"optional":[{"name":"share_resource_id","type":"String","description":"Share Resource identifier."},{"name":"filter","type":"Attributes","children":[{"name":"resource_type","type":"String","description":"Filter share resources by resource_type."},{"name":"status","type":"String","description":"Filter share resources by status."}]}],"computed":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."},{"name":"meta","type":"unknown","description":"Resource Metadata."}]}]},"get /accounts/{}/sso_connectors":{"operationId":"get-all-sso-connectors","declarations":[{"kind":"list-data-source","name":"cloudflare_sso_connectors","stainlessResource":"iam.sso","methodName":"list","snippet":"data \"cloudflare_sso_connectors\" \"example_sso_connectors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"SSO Connector identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the SSO connector"},{"name":"email_domain","type":"String"},{"name":"enabled","type":"Bool"},{"name":"updated_on","type":"Time","description":"Timestamp for the last update of the SSO connector"},{"name":"use_fedramp_language","type":"Bool","description":"Controls the display of FedRAMP language to the user during SSO login"},{"name":"verification","type":"Attributes","children":[{"name":"code","type":"String","description":"DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership."},{"name":"status","type":"String","description":"The status of the verification code from the verification process."}]}]}]}]},"get /accounts/{}/sso_connectors/{}":{"operationId":"get-sso-connector","declarations":[{"kind":"data-source","name":"cloudflare_sso_connector","stainlessResource":"iam.sso","methodName":"get","snippet":"data \"cloudflare_sso_connector\" \"example_sso_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n sso_connector_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"sso_connector_id","type":"String","description":"SSO Connector identifier tag."},{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[],"computed":[{"name":"id","type":"String","description":"SSO Connector identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the SSO connector"},{"name":"email_domain","type":"String"},{"name":"enabled","type":"Bool"},{"name":"updated_on","type":"Time","description":"Timestamp for the last update of the SSO connector"},{"name":"use_fedramp_language","type":"Bool","description":"Controls the display of FedRAMP language to the user during SSO login"},{"name":"verification","type":"Attributes","children":[{"name":"code","type":"String","description":"DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership."},{"name":"status","type":"String","description":"The status of the verification code from the verification process."}]}]}]},"get /accounts/{}/storage/kv/namespaces":{"operationId":"workers-kv-namespace-list-namespaces","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_kv_namespaces","stainlessResource":"kv.namespaces","methodName":"list","snippet":"data \"cloudflare_workers_kv_namespaces\" \"example_workers_kv_namespaces\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"id\"\n}\n","required":[{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces."}],"optional":[{"name":"direction","type":"String","description":"Sort namespaces in ascending (`asc`) or descending (`desc`) order."},{"name":"order","type":"String","description":"Namespace field to sort by (`id` or `title`)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"ID of the Workers KV namespace."},{"name":"title","type":"String","description":"Human-readable string name for a Workers KV namespace."},{"name":"jurisdiction","type":"String","description":"Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time."},{"name":"supports_url_encoding","type":"Bool","description":"True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"."}]}]}]},"get /accounts/{}/storage/kv/namespaces/{}":{"operationId":"workers-kv-namespace-get-a-namespace","declarations":[{"kind":"data-source","name":"cloudflare_workers_kv_namespace","stainlessResource":"kv.namespaces","methodName":"get","snippet":"data \"cloudflare_workers_kv_namespace\" \"example_workers_kv_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n}\n","required":[{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces."}],"optional":[{"name":"namespace_id","type":"String","description":"ID of the Workers KV namespace."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sort namespaces in ascending (`asc`) or descending (`desc`) order."},{"name":"order","type":"String","description":"Namespace field to sort by (`id` or `title`)."}]}],"computed":[{"name":"id","type":"String","description":"ID of the Workers KV namespace."},{"name":"jurisdiction","type":"String","description":"Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time."},{"name":"supports_url_encoding","type":"Bool","description":"True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"."},{"name":"title","type":"String","description":"Human-readable string name for a Workers KV namespace."}]}]},"get /accounts/{}/storage/kv/namespaces/{}/values/{}":{"operationId":"workers-kv-namespace-read-key-value-pair","declarations":[{"kind":"data-source","name":"cloudflare_workers_kv","stainlessResource":"kv.namespaces.values","methodName":"get","snippet":"data \"cloudflare_workers_kv\" \"example_workers_kv\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n key_name = \"My-Key\"\n}\n","required":[{"name":"key_name","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL."},{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces."},{"name":"namespace_id","type":"String","description":"ID of the Workers KV namespace."}],"optional":[],"computed":[{"name":"id","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL."},{"name":"value","type":"unknown"}]}]},"get /accounts/{}/stream":{"operationId":"stream-videos-list-videos","declarations":[{"kind":"list-data-source","name":"cloudflare_streams","stainlessResource":"stream","methodName":"list","snippet":"data \"cloudflare_streams\" \"example_streams\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"ea95132c15732412d22c1476fa83f27a\"\n after = \"2019-12-27T18:11:19.117Z\"\n before = \"2019-12-27T18:11:19.117Z\"\n creator = \"creator-id_abcde12345\"\n end = \"2014-01-02T02:20:00Z\"\n limit = 1\n live_input_id = \"live_input_id\"\n name = \"name\"\n search = \"puppy.mp4\"\n start = \"2014-01-02T02:20:00Z\"\n status = \"inprogress\"\n type = \"live\"\n video_name = \"puppy.mp4\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"after","type":"Time","description":"Alias for 'start'. Returns videos created after this date/time (RFC 3339 format)."},{"name":"before","type":"Time","description":"Alias for 'end'. Returns videos created before this date/time (RFC 3339 format)."},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"end","type":"Time","description":"Lists videos created before the specified date."},{"name":"id","type":"String","description":"Filter by video ID(s). Can be a single ID or a comma-separated list of IDs."},{"name":"limit","type":"Int64","description":"Maximum number of videos to return (default 1000, max 1000)."},{"name":"live_input_id","type":"String","description":"Filter by live input ID to find videos associated with a specific live stream."},{"name":"name","type":"String","description":"Filter by video name/UID(s). Can be a single name or a comma-separated list."},{"name":"search","type":"String","description":"Provides a partial word match of the `name` key in the `meta` field. Slow for medium to large video libraries. May be unavailable for very large libraries."},{"name":"start","type":"Time","description":"Lists videos created after the specified date."},{"name":"status","type":"String","description":"Specifies the processing status for all quality levels for a video."},{"name":"type","type":"String","description":"Specifies whether the video is `vod` or `live`."},{"name":"video_name","type":"String","description":"Provides a fast, exact string match on the `name` key in the `meta` field."},{"name":"asc","type":"Bool","description":"Lists videos in ascending order of creation."},{"name":"include_counts","type":"Bool","description":"Includes the total number of videos associated with the submitted query parameters."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin."},{"name":"clipped_from","type":"String","description":"The unique identifier of the source video this video was clipped from."},{"name":"created","type":"Time","description":"The date and time the media item was created."},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"duration","type":"Float64","description":"The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready."},{"name":"input","type":"Attributes","children":[{"name":"height","type":"Int64","description":"The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready."},{"name":"width","type":"Int64","description":"The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready."}]},{"name":"live_input","type":"String","description":"The live input ID used to upload a video with Stream Live."},{"name":"max_duration_seconds","type":"Int64","description":"The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown."},{"name":"max_size_bytes","type":"Int64","description":"The maximum size in bytes for the video upload."},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing videos."},{"name":"modified","type":"Time","description":"The date and time the media item was last modified."},{"name":"playback","type":"Attributes","children":[{"name":"dash","type":"String","description":"DASH Media Presentation Description for the video."},{"name":"hls","type":"String","description":"The HLS manifest for the video."}]},{"name":"preview","type":"String","description":"The video's preview page URI. This field is omitted until encoding is complete."},{"name":"public_details","type":"Attributes","description":"Public details for the video including title, share link, channel link, and logo.","children":[{"name":"channel_link","type":"String"},{"name":"logo","type":"String"},{"name":"media_id","type":"Int64"},{"name":"share_link","type":"String"},{"name":"title","type":"String"}]},{"name":"ready_to_stream","type":"Bool","description":"Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"ready_to_stream_at","type":"Time","description":"Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video."},{"name":"scheduled_deletion","type":"Time","description":"Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time."},{"name":"size","type":"Float64","description":"The size of the media item in bytes."},{"name":"status","type":"Attributes","description":"Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.","children":[{"name":"error_reason_code","type":"String","description":"Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use."},{"name":"error_reason_text","type":"String","description":"Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state."},{"name":"pct_complete","type":"String","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"state","type":"String","description":"Specifies the processing status for all quality levels for a video."}]},{"name":"thumbnail","type":"String","description":"The media item's thumbnail URI. This field is omitted until encoding is complete."},{"name":"thumbnail_timestamp_pct","type":"Float64","description":"The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"uploaded","type":"Time","description":"The date and time the media item was uploaded."},{"name":"upload_expiry","type":"Time","description":"The date and time when the video upload URL is no longer valid for direct user uploads."},{"name":"watermark","type":"Attributes","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]}]}]},"get /accounts/{}/stream/{}":{"operationId":"stream-videos-retrieve-video-details","declarations":[{"kind":"data-source","name":"cloudflare_stream","stainlessResource":"stream","methodName":"get","snippet":"data \"cloudflare_stream\" \"example_stream\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}],"optional":[],"computed":[{"name":"clipped_from","type":"String","description":"The unique identifier of the source video this video was clipped from."},{"name":"created","type":"Time","description":"The date and time the media item was created."},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"duration","type":"Float64","description":"The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready."},{"name":"live_input","type":"String","description":"The live input ID used to upload a video with Stream Live."},{"name":"max_duration_seconds","type":"Int64","description":"The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown."},{"name":"max_size_bytes","type":"Int64","description":"The maximum size in bytes for the video upload."},{"name":"modified","type":"Time","description":"The date and time the media item was last modified."},{"name":"preview","type":"String","description":"The video's preview page URI. This field is omitted until encoding is complete."},{"name":"ready_to_stream","type":"Bool","description":"Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"ready_to_stream_at","type":"Time","description":"Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video."},{"name":"scheduled_deletion","type":"Time","description":"Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time."},{"name":"size","type":"Float64","description":"The size of the media item in bytes."},{"name":"thumbnail","type":"String","description":"The media item's thumbnail URI. This field is omitted until encoding is complete."},{"name":"thumbnail_timestamp_pct","type":"Float64","description":"The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"upload_expiry","type":"Time","description":"The date and time when the video upload URL is no longer valid for direct user uploads."},{"name":"uploaded","type":"Time","description":"The date and time the media item was uploaded."},{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin."},{"name":"input","type":"Attributes","children":[{"name":"height","type":"Int64","description":"The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready."},{"name":"width","type":"Int64","description":"The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready."}]},{"name":"playback","type":"Attributes","children":[{"name":"dash","type":"String","description":"DASH Media Presentation Description for the video."},{"name":"hls","type":"String","description":"The HLS manifest for the video."}]},{"name":"public_details","type":"Attributes","description":"Public details for the video including title, share link, channel link, and logo.","children":[{"name":"channel_link","type":"String"},{"name":"logo","type":"String"},{"name":"media_id","type":"Int64"},{"name":"share_link","type":"String"},{"name":"title","type":"String"}]},{"name":"status","type":"Attributes","description":"Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.","children":[{"name":"error_reason_code","type":"String","description":"Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use."},{"name":"error_reason_text","type":"String","description":"Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state."},{"name":"pct_complete","type":"String","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"state","type":"String","description":"Specifies the processing status for all quality levels for a video."}]},{"name":"watermark","type":"Attributes","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing videos."}]}]},"get /accounts/{}/stream/{}/audio":{"operationId":"list-audio-tracks","declarations":[{"kind":"data-source","name":"cloudflare_stream_audio_track","stainlessResource":"stream.audio_tracks","methodName":"get","snippet":"data \"cloudflare_stream_audio_track\" \"example_stream_audio_track\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}],"optional":[],"computed":[{"name":"audio","type":"List[Attributes]","description":"Array of audio tracks for the video.","children":[{"name":"default","type":"Bool","description":"Denotes whether the audio track will be played by default in a player."},{"name":"label","type":"String","description":"A string to uniquely identify the track amongst other audio track labels for the specified video."},{"name":"status","type":"String","description":"Specifies the processing status of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}]}]}]},"get /accounts/{}/stream/{}/captions/{}":{"operationId":"stream-subtitles/-captions-get-caption-or-subtitle-for-language","declarations":[{"kind":"data-source","name":"cloudflare_stream_caption_language","stainlessResource":"stream.captions.language","methodName":"get","snippet":"data \"cloudflare_stream_caption_language\" \"example_stream_caption_language\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n language = \"tr\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"language","type":"String","description":"The language tag in BCP 47 format."}],"optional":[],"computed":[{"name":"generated","type":"Bool","description":"Whether the caption was generated via AI."},{"name":"label","type":"String","description":"The language label displayed in the native language to users."},{"name":"status","type":"String","description":"The status of a generated caption."}]}]},"get /accounts/{}/stream/{}/downloads":{"operationId":"stream-mp4-downloads-list-downloads","declarations":[{"kind":"data-source","name":"cloudflare_stream_download","stainlessResource":"stream.downloads","methodName":"get","snippet":"data \"cloudflare_stream_download\" \"example_stream_download\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}],"optional":[],"computed":[{"name":"audio","type":"Attributes","description":"The audio-only download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]},{"name":"default","type":"Attributes","description":"The default video download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]}]}]},"get /accounts/{}/stream/keys":{"operationId":"stream-signing-keys-list-signing-keys","declarations":[{"kind":"data-source","name":"cloudflare_stream_key","stainlessResource":"stream.keys","methodName":"get","snippet":"data \"cloudflare_stream_key\" \"example_stream_key\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created","type":"Time","description":"The date and time a signing key was created."},{"name":"key_id","type":"String","description":"The unique identifier for the signing key."}]}]},"get /accounts/{}/stream/live_inputs/{}":{"operationId":"stream-live-inputs-retrieve-a-live-input","declarations":[{"kind":"data-source","name":"cloudflare_stream_live_input","stainlessResource":"stream.live_inputs","methodName":"get","snippet":"data \"cloudflare_stream_live_input\" \"example_stream_live_input\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n live_input_identifier = \"66be4bf738797e01e1fca35a7bdecdcd\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"live_input_identifier","type":"String","description":"A unique identifier for a live input."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and time the live input was created."},{"name":"delete_recording_after_days","type":"Float64","description":"Indicates the number of days after which the live inputs recordings will be deleted. When a stream completes and the recording is ready, the value is used to calculate a scheduled deletion date for that recording. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion."},{"name":"enabled","type":"Bool","description":"Indicates whether the live input is enabled and can accept streams."},{"name":"keys_rotated_at","type":"Time","description":"The date and time the live input keys were last rotated. Omitted for live inputs that have never had their keys rotated."},{"name":"modified","type":"Time","description":"The date and time the live input was last modified."},{"name":"prefer_low_latency","type":"Bool","description":"When enabled, the live stream is delivered using Low-Latency HLS (LL-HLS), reducing glass-to-glass latency for viewers at the cost of reduced player compatibility."},{"name":"status","type":"String","description":"The connection status of a live input."},{"name":"uid","type":"String","description":"A unique identifier for a live input."},{"name":"playback","type":"Attributes","description":"Details for playing a live input's broadcast using the HLS or DASH manifests. URLs reference the live input ID.","children":[{"name":"dash","type":"String","description":"The DASH manifest URL used to play live video, referencing the live input ID."},{"name":"hls","type":"String","description":"The HLS manifest URL used to play live video, referencing the live input ID."}]},{"name":"recording","type":"Attributes","description":"Records the input to a Cloudflare Stream video. Behavior depends on the mode. In most cases, the video will initially be viewable as a live video and transition to on-demand after a condition is satisfied.","children":[{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display videos created with this input. Enter allowed origin domains in an array and use `*` for wildcard subdomains. An empty array allows videos to be viewed on any origin."},{"name":"hide_live_viewer_count","type":"Bool","description":"Disables reporting the number of live viewers when this property is set to `true`."},{"name":"mode","type":"String","description":"Specifies the recording behavior for the live input. Set this value to `off` to prevent a recording. Set the value to `automatic` to begin a recording and transition to on-demand after Stream Live stops receiving input."},{"name":"require_signed_urls","type":"Bool","description":"Indicates if a video using the live input has the `requireSignedURLs` property set. Also enforces access controls on any video recording of the livestream with the live input."},{"name":"timeout_seconds","type":"Int64","description":"Determines the amount of time a live input configured in `automatic` mode should wait before a recording transitions from live to on-demand. `0` is recommended for most use cases and indicates the platform default should be used."}]},{"name":"rtmps","type":"Attributes","description":"Details for streaming to an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use when streaming via RTMPS to a live input.","sensitive":true},{"name":"url","type":"String","description":"The RTMPS URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"rtmps_playback","type":"Attributes","description":"Details for playback from an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use for playback via RTMPS.","sensitive":true},{"name":"url","type":"String","description":"The URL used to play live video over RTMPS.","sensitive":true}]},{"name":"srt","type":"Attributes","description":"Details for streaming to a live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use when streaming via SRT to a live input.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use when streaming via SRT."},{"name":"url","type":"String","description":"The SRT URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"srt_playback","type":"Attributes","description":"Details for playback from an live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use for playback via SRT.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use for playback via SRT."},{"name":"url","type":"String","description":"The URL used to play live video over SRT.","sensitive":true}]},{"name":"web_rtc","type":"Attributes","description":"Details for streaming to a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The WebRTC URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"web_rtc_playback","type":"Attributes","description":"Details for playback from a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The URL used to play live video over WebRTC.","sensitive":true}]},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing live inputs."}]}]},"get /accounts/{}/stream/watermarks":{"operationId":"stream-watermark-profile-list-watermark-profiles","declarations":[{"kind":"list-data-source","name":"cloudflare_stream_watermarks","stainlessResource":"stream.watermarks","methodName":"list","snippet":"data \"cloudflare_stream_watermarks\" \"example_stream_watermarks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]}]},"get /accounts/{}/stream/watermarks/{}":{"operationId":"stream-watermark-profile-watermark-profile-details","declarations":[{"kind":"data-source","name":"cloudflare_stream_watermark","stainlessResource":"stream.watermarks","methodName":"get","snippet":"data \"cloudflare_stream_watermark\" \"example_stream_watermark\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."},{"name":"identifier","type":"String","description":"The unique identifier for a watermark profile."}],"optional":[],"computed":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]},"get /accounts/{}/stream/webhook":{"operationId":"stream-webhook-view-webhooks","declarations":[{"kind":"data-source","name":"cloudflare_stream_webhook","stainlessResource":"stream.webhooks","methodName":"get","snippet":"data \"cloudflare_stream_webhook\" \"example_stream_webhook\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag."}],"optional":[],"computed":[{"name":"modified","type":"Time","description":"The date and time the webhook was last modified."},{"name":"notification_url","type":"String","description":"The URL where webhooks will be sent."},{"name":"secret","type":"String","description":"The secret used to verify webhook signatures.","sensitive":true}]}]},"get /accounts/{}/teamnet/routes":{"operationId":"tunnel-route-list-tunnel-routes","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_routes","stainlessResource":"zero_trust.networks.routes","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_routes\" \"example_zero_trust_tunnel_cloudflared_routes\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n is_deleted = true\n network_subset = \"172.16.0.0/16\"\n network_superset = \"172.16.0.0/16\"\n route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n tun_types = [\"cfd_tunnel\"]\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted routes. If `false`, exclude deleted routes. If empty, all routes will be included."},{"name":"network_subset","type":"String","description":"If set, only list routes that are contained within this IP range."},{"name":"network_superset","type":"String","description":"If set, only list routes that contain this IP range."},{"name":"route_id","type":"String","description":"UUID of the route."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."},{"name":"tun_types","type":"List[String]","description":"The types of tunnels to filter by, separated by commas."},{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the route."},{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range connected by the route, in CIDR notation."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."},{"name":"virtual_network_name","type":"String","description":"A user-friendly name for the virtual network."}]}]}]},"get /accounts/{}/teamnet/routes/{}":{"operationId":"tunnel-route-get-tunnel-route","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_route","stainlessResource":"zero_trust.networks.routes","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_route\" \"example_zero_trust_tunnel_cloudflared_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"route_id","type":"String","description":"UUID of the route."},{"name":"filter","type":"Attributes","children":[{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted routes. If `false`, exclude deleted routes. If empty, all routes will be included."},{"name":"network_subset","type":"String","description":"If set, only list routes that are contained within this IP range."},{"name":"network_superset","type":"String","description":"If set, only list routes that contain this IP range."},{"name":"tun_types","type":"List[String]","description":"The types of tunnels to filter by, separated by commas."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."}]}],"computed":[{"name":"id","type":"String","description":"UUID of the route."},{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range connected by the route, in CIDR notation."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."}]}]},"get /accounts/{}/teamnet/virtual_networks":{"operationId":"tunnel-virtual-network-list-virtual-networks","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_virtual_networks","stainlessResource":"zero_trust.networks.virtual_networks","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_virtual_networks\" \"example_zero_trust_tunnel_cloudflared_virtual_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n is_default = true\n is_default_network = true\n is_deleted = true\n name = \"us-east-1-vpc\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"is_default","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_default_network","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted virtual networks. If `false`, exclude deleted virtual networks. If empty, all virtual networks will be included."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"comment","type":"String","description":"Optional remark describing the virtual network."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"is_default_network","type":"Bool","description":"If `true`, this virtual network is the default for the account."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."}]}]}]},"get /accounts/{}/teamnet/virtual_networks/{}":{"operationId":"tunnel-virtual-network-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_cloudflared_virtual_network","stainlessResource":"zero_trust.networks.virtual_networks","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_cloudflared_virtual_network\" \"example_zero_trust_tunnel_cloudflared_virtual_network\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"is_default","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_default_network","type":"Bool","description":"If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included."},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted virtual networks. If `false`, exclude deleted virtual networks. If empty, all virtual networks will be included."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."}]}],"computed":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"comment","type":"String","description":"Optional remark describing the virtual network."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"is_default_network","type":"Bool","description":"If `true`, this virtual network is the default for the account."},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."}]}]},"get /accounts/{}/tokens":{"operationId":"account-api-tokens-list-tokens","declarations":[{"kind":"list-data-source","name":"cloudflare_account_tokens","stainlessResource":"accounts.tokens","methodName":"list","snippet":"data \"cloudflare_account_tokens\" \"example_account_tokens\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."}]}]}]},"get /accounts/{}/tokens/{}":{"operationId":"account-api-tokens-token-details","declarations":[{"kind":"data-source","name":"cloudflare_account_token","stainlessResource":"accounts.tokens","methodName":"get","snippet":"data \"cloudflare_account_token\" \"example_account_token\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n token_id = \"ed17574386854bf78a67040be0a770b0\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"token_id","type":"String","description":"Token identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."}]}],"computed":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]}]}]},"get /accounts/{}/tokens/permission_groups":{"operationId":"account-api-tokens-list-permission-groups","declarations":[{"kind":"data-source","name":"cloudflare_account_api_token_permission_groups","stainlessResource":"accounts.tokens.permission_groups","methodName":"get","snippet":"data \"cloudflare_account_api_token_permission_groups\" \"example_account_api_token_permission_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"name","type":"String","description":"Filter by the name of the permission group.\nThe value must be URL-encoded."},{"name":"scope","type":"String","description":"Filter by the scope of the permission group.\nThe value must be URL-encoded."}],"computed":[{"name":"permission_groups","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Public ID."},{"name":"category","type":"String","description":"Product category that this permission group belongs to."},{"name":"is_selectable","type":"Bool","description":"Whether the caller can select this permission group when creating a token."},{"name":"name","type":"String","description":"Permission Group Name"},{"name":"scopes","type":"List[String]","description":"Resources to which the Permission Group is scoped"}]}]},{"kind":"list-data-source","name":"cloudflare_account_api_token_permission_groups_list","stainlessResource":"accounts.tokens.permission_groups","methodName":"list","snippet":"data \"cloudflare_account_api_token_permission_groups_list\" \"example_account_api_token_permission_groups_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag."}],"optional":[{"name":"name","type":"String","description":"Filter by the name of the permission group.\nThe value must be URL-encoded."},{"name":"scope","type":"String","description":"Filter by the scope of the permission group.\nThe value must be URL-encoded."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Public ID."},{"name":"category","type":"String","description":"Product category that this permission group belongs to."},{"name":"is_selectable","type":"Bool","description":"Whether the caller can select this permission group when creating a token."},{"name":"name","type":"String","description":"Permission Group Name"},{"name":"scopes","type":"List[String]","description":"Resources to which the Permission Group is scoped"}]}]}]},"get /accounts/{}/vuln_scanner/credential_sets":{"operationId":"list-credential-sets","declarations":[{"kind":"list-data-source","name":"cloudflare_vulnerability_scanner_credential_sets","stainlessResource":"vulnerability_scanner.credential_sets","methodName":"list","snippet":"data \"cloudflare_vulnerability_scanner_credential_sets\" \"example_vulnerability_scanner_credential_sets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Credential set identifier."},{"name":"name","type":"String","description":"Human-readable name."}]}]}]},"get /accounts/{}/vuln_scanner/credential_sets/{}":{"operationId":"get-credential-set","declarations":[{"kind":"data-source","name":"cloudflare_vulnerability_scanner_credential_set","stainlessResource":"vulnerability_scanner.credential_sets","methodName":"get","snippet":"data \"cloudflare_vulnerability_scanner_credential_set\" \"example_vulnerability_scanner_credential_set\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"credential_set_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"name","type":"String","description":"Human-readable name."}]}]},"get /accounts/{}/vuln_scanner/credential_sets/{}/credentials":{"operationId":"list-credentials","declarations":[{"kind":"list-data-source","name":"cloudflare_vulnerability_scanner_credentials","stainlessResource":"vulnerability_scanner.credential_sets.credentials","methodName":"list","snippet":"data \"cloudflare_vulnerability_scanner_credentials\" \"example_vulnerability_scanner_credentials\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"credential_set_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Credential identifier."},{"name":"credential_set_id","type":"String","description":"Parent credential set identifier."},{"name":"location","type":"String","description":"Where the credential is attached in outgoing requests."},{"name":"location_name","type":"String","description":"Name of the header or cookie where the credential is attached.\n"},{"name":"name","type":"String","description":"Human-readable name."}]}]}]},"get /accounts/{}/vuln_scanner/credential_sets/{}/credentials/{}":{"operationId":"get-credential","declarations":[{"kind":"data-source","name":"cloudflare_vulnerability_scanner_credential","stainlessResource":"vulnerability_scanner.credential_sets.credentials","methodName":"get","snippet":"data \"cloudflare_vulnerability_scanner_credential\" \"example_vulnerability_scanner_credential\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n credential_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"credential_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."},{"name":"credential_set_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"location","type":"String","description":"Where the credential is attached in outgoing requests."},{"name":"location_name","type":"String","description":"Name of the header or cookie where the credential is attached.\n"},{"name":"name","type":"String","description":"Human-readable name."}]}]},"get /accounts/{}/vuln_scanner/target_environments":{"operationId":"list-target-environments","declarations":[{"kind":"list-data-source","name":"cloudflare_vulnerability_scanner_target_environments","stainlessResource":"vulnerability_scanner.target_environments","methodName":"list","snippet":"data \"cloudflare_vulnerability_scanner_target_environments\" \"example_vulnerability_scanner_target_environments\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Target environment identifier."},{"name":"name","type":"String","description":"Human-readable name."},{"name":"target","type":"Attributes","description":"Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.\n","children":[{"name":"type","type":"String"},{"name":"zone_tag","type":"String","description":"Cloudflare zone tag. The zone must belong to the account.\n"}]},{"name":"description","type":"String","description":"Optional description providing additional context."}]}]}]},"get /accounts/{}/vuln_scanner/target_environments/{}":{"operationId":"get-target-environment","declarations":[{"kind":"data-source","name":"cloudflare_vulnerability_scanner_target_environment","stainlessResource":"vulnerability_scanner.target_environments","methodName":"get","snippet":"data \"cloudflare_vulnerability_scanner_target_environment\" \"example_vulnerability_scanner_target_environment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n target_environment_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"target_environment_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"description","type":"String","description":"Optional description providing additional context."},{"name":"name","type":"String","description":"Human-readable name."},{"name":"target","type":"Attributes","description":"Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.\n","children":[{"name":"type","type":"String"},{"name":"zone_tag","type":"String","description":"Cloudflare zone tag. The zone must belong to the account.\n"}]}]}]},"get /accounts/{}/warp_connector":{"operationId":"cloudflare-tunnel-list-warp-connector-tunnels","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_tunnel_warp_connectors","stainlessResource":"zero_trust.tunnels.warp_connector","methodName":"list","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connectors\" \"example_zero_trust_tunnel_warp_connectors\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n exclude_prefix = \"vpc1-\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n include_prefix = \"vpc1-\"\n is_deleted = true\n name = \"blog\"\n status = \"healthy\"\n uuid = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n was_active_at = \"2009-11-10T23:00:00Z\"\n was_inactive_at = \"2009-11-10T23:00:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for the tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."}]}]}]},"get /accounts/{}/warp_connector/{}":{"operationId":"cloudflare-tunnel-get-a-warp-connector-tunnel","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_warp_connector","stainlessResource":"zero_trust.tunnels.warp_connector","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connector\" \"example_zero_trust_tunnel_warp_connector\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"filter","type":"Attributes","children":[{"name":"exclude_prefix","type":"String"},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"include_prefix","type":"String"},{"name":"is_deleted","type":"Bool","description":"If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included."},{"name":"name","type":"String","description":"A user-friendly name for the tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"uuid","type":"String","description":"UUID of the tunnel."},{"name":"was_active_at","type":"Time"},{"name":"was_inactive_at","type":"Time"}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"get /accounts/{}/warp_connector/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-get-warp-connector-configuration","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_warp_connector_config","stainlessResource":"zero_trust.tunnels.warp_connector.configurations","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connector_config\" \"example_zero_trust_tunnel_warp_connector_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"configuration_version","type":"Int64","description":"Monotonically increasing configuration version, incremented on each PUT."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"ha_mode","type":"String","description":"High-availability mode for the Mesh node. `none` means HA is enabled but no provider is configured yet (newly created nodes default to this). `disabled` means HA is explicitly turned off. `aws` uses AWS ENI move for failover. `local` uses virtual IPs (VIPs) on the local interface."},{"name":"updated_at","type":"Time","description":"Timestamp of the last update. Null if never updated."},{"name":"config","type":"Attributes","description":"Provider-specific configuration. Present for `aws` and `local` modes.","children":[{"name":"fnr_id","type":"String","description":"Floating Network Resource ID — the secondary ENI that is moved between nodes on failover."},{"name":"vips","type":"List[Attributes]","description":"VIPs to assign on the CloudflareWARP interface.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]},{"name":"vips_previous","type":"List[Attributes]","description":"VIPs to clean up on demotion or version drift.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]}]}]}]},"get /accounts/{}/warp_connector/{}/token":{"operationId":"cloudflare-tunnel-get-a-warp-connector-tunnel-token","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_tunnel_warp_connector_token","stainlessResource":"zero_trust.tunnels.warp_connector.token","methodName":"get","snippet":"data \"cloudflare_zero_trust_tunnel_warp_connector_token\" \"example_zero_trust_tunnel_warp_connector_token\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[],"computed":[{"name":"token","type":"String","description":"The Tunnel Token is used as a mechanism to authenticate the operation of a tunnel.","sensitive":true}]}]},"get /accounts/{}/workers/dispatch/namespaces":{"operationId":"namespace-worker-list","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_for_platforms_dispatch_namespaces","stainlessResource":"workers_for_platforms.dispatch.namespaces","methodName":"list","snippet":"data \"cloudflare_workers_for_platforms_dispatch_namespaces\" \"example_workers_for_platforms_dispatch_namespaces\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"created_by","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"modified_by","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"namespace_id","type":"String","description":"API Resource UUID tag."},{"name":"namespace_name","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"script_count","type":"Int64","description":"The current number of scripts in this Dispatch Namespace."},{"name":"trusted_workers","type":"Bool","description":"Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"."}]}]}]},"get /accounts/{}/workers/dispatch/namespaces/{}":{"operationId":"namespace-worker-get-namespace","declarations":[{"kind":"data-source","name":"cloudflare_workers_for_platforms_dispatch_namespace","stainlessResource":"workers_for_platforms.dispatch.namespaces","methodName":"get","snippet":"data \"cloudflare_workers_for_platforms_dispatch_namespace\" \"example_workers_for_platforms_dispatch_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dispatch_namespace = \"my-dispatch-namespace\"\n}\n","required":[{"name":"dispatch_namespace","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"created_by","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"modified_by","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"namespace_id","type":"String","description":"API Resource UUID tag."},{"name":"namespace_name","type":"String","description":"Name of the Workers for Platforms dispatch namespace."},{"name":"script_count","type":"Int64","description":"The current number of scripts in this Dispatch Namespace."},{"name":"trusted_workers","type":"Bool","description":"Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"."}]}]},"get /accounts/{}/workers/domains":{"operationId":"workers.domains.list","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_custom_domains","stainlessResource":"workers.domains","methodName":"list","snippet":"data \"cloudflare_workers_custom_domains\" \"example_workers_custom_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n environment = \"production\"\n hostname = \"app.example.com\"\n service = \"my-worker\"\n zone_id = \"593c9c94de529bbbfaac7c53ced0447d\"\n zone_name = \"example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"environment","type":"String","description":"Worker environment associated with the domain."},{"name":"hostname","type":"String","description":"Hostname of the domain."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Immutable ID of the domain."},{"name":"cert_id","type":"String","description":"ID of the TLS certificate issued for the domain."},{"name":"environment","type":"String","description":"Worker environment associated with the domain.","deprecated":"Deprecated."},{"name":"hostname","type":"String","description":"Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."}]}]}]},"get /accounts/{}/workers/domains/{}":{"operationId":"workers.domains.get","declarations":[{"kind":"data-source","name":"cloudflare_workers_custom_domain","stainlessResource":"workers.domains","methodName":"get","snippet":"data \"cloudflare_workers_custom_domain\" \"example_workers_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_id = \"dbe10b4bc17c295377eabd600e1787fd\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"domain_id","type":"String","description":"ID of the domain."},{"name":"filter","type":"Attributes","children":[{"name":"environment","type":"String","description":"Worker environment associated with the domain."},{"name":"hostname","type":"String","description":"Hostname of the domain."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."}]}],"computed":[{"name":"id","type":"String","description":"ID of the domain."},{"name":"cert_id","type":"String","description":"ID of the TLS certificate issued for the domain."},{"name":"environment","type":"String","description":"Worker environment associated with the domain.","deprecated":"Deprecated."},{"name":"hostname","type":"String","description":"Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker."},{"name":"service","type":"String","description":"Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker."},{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname."},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname."}]}]},"get /accounts/{}/workers/scripts":{"operationId":"worker-script-list-workers","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_scripts","stainlessResource":"workers.scripts","methodName":"list","snippet":"data \"cloudflare_workers_scripts\" \"example_workers_scripts\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tags = \"production:yes,staging:no\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"tags","type":"String","description":"Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The name used to identify the script."},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"etag","type":"String","description":"Hashed script content, can be used in a If-None-Match header when updating."},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the Worker's most recent version,\nincluding Durable Object classes (with their `storage`\nbackend) and named Worker entrypoints. Tombstoned lifecycle\nentries are omitted, so only live exports (`created` and\n`expecting-transfer`) are returned.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the default export."},{"name":"has_assets","type":"Bool","description":"Whether a Worker contains assets."},{"name":"has_modules","type":"Bool","description":"Whether a Worker contains modules."},{"name":"last_deployed_from","type":"String","description":"The client most recently used to deploy this Worker."},{"name":"logpush","type":"Bool","description":"Whether Logpush is turned on for the Worker."},{"name":"migration_tag","type":"String","description":"The tag of the Durable Object migration that was most recently applied for this Worker."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"named_handlers","type":"List[Attributes]","description":"Named exports, such as Durable Object class implementations and named entrypoints.","children":[{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the named export."},{"name":"name","type":"String","description":"The name of the export."}]},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for incoming requests. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"last_analyzed_at","type":"Time","description":"The last time the script was analyzed for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"status","type":"String","description":"Status of [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"placement_mode","type":"String","deprecated":"Deprecated."},{"name":"placement_status","type":"String","deprecated":"Deprecated."},{"name":"routes","type":"List[Attributes]","description":"Routes associated with the Worker.","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."},{"name":"script","type":"String","description":"Name of the script to run if the route matches."}]},{"name":"tag","type":"String","description":"The immutable ID of the script."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"tail_consumers","type":"Set[Attributes]","description":"List of Workers that will consume logs from the attached Worker.","children":[{"name":"service","type":"String","description":"Name of Worker that is to be the consumer."},{"name":"environment","type":"String","description":"Optional environment if the Worker utilizes one."},{"name":"namespace","type":"String","description":"Optional dispatch namespace the script belongs to."}]},{"name":"usage_model","type":"String","description":"Usage model for the Worker invocations."}]}]}]},"get /accounts/{}/workers/scripts/{}":{"operationId":"worker-script-download-worker","declarations":[{"kind":"data-source","name":"cloudflare_workers_script","stainlessResource":"workers.scripts","methodName":"get","snippet":"data \"cloudflare_workers_script\" \"example_workers_script\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"script_name","type":"String","description":"Name of the script."},{"name":"filter","type":"Attributes","children":[{"name":"tags","type":"String","description":"Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'."}]}],"computed":[{"name":"id","type":"String","description":"Name of the script."},{"name":"script","type":"String"}]}]},"get /accounts/{}/workers/scripts/{}/deployments":{"operationId":"worker-deployments-list-deployments","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_deployments","stainlessResource":"workers.scripts.deployments","methodName":"list","snippet":"data \"cloudflare_workers_deployments\" \"example_workers_deployments\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n since = \"2019-12-27T18:11:19.117Z\"\n until = \"2019-12-27T18:11:19.117Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"script_name","type":"String","description":"Name of the script."}],"optional":[{"name":"since","type":"Time","description":"Start of the deployment creation time range, inclusive."},{"name":"until","type":"Time","description":"End of the deployment creation time range, inclusive."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"deployments","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"source","type":"String"},{"name":"strategy","type":"String"},{"name":"versions","type":"List[Attributes]","description":"Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.","children":[{"name":"percentage","type":"Float64","description":"Percentage of traffic served by this version."},{"name":"version_id","type":"String","description":"Identifier of the Worker Version."}]},{"name":"annotations","type":"Attributes","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the deployment. Truncated to 1000 bytes if longer."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the deployment."}]},{"name":"author_email","type":"String"}]}]}]}]},"get /accounts/{}/workers/scripts/{}/deployments/{}":{"operationId":"worker-deployments-get-deployment","declarations":[{"kind":"data-source","name":"cloudflare_workers_deployment","stainlessResource":"workers.scripts.deployments","methodName":"get","snippet":"data \"cloudflare_workers_deployment\" \"example_workers_deployment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n deployment_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"deployment_id","type":"String"},{"name":"account_id","type":"String","description":"Identifier."},{"name":"script_name","type":"String","description":"Name of the script."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"author_email","type":"String"},{"name":"created_on","type":"Time"},{"name":"source","type":"String"},{"name":"strategy","type":"String"},{"name":"annotations","type":"Attributes","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the deployment. Truncated to 1000 bytes if longer."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the deployment."}]},{"name":"versions","type":"List[Attributes]","description":"Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.","children":[{"name":"percentage","type":"Float64","description":"Percentage of traffic served by this version."},{"name":"version_id","type":"String","description":"Identifier of the Worker Version."}]}]}]},"get /accounts/{}/workers/scripts/{}/schedules":{"operationId":"worker-cron-trigger-get-cron-triggers","declarations":[{"kind":"data-source","name":"cloudflare_workers_cron_trigger","stainlessResource":"workers.scripts.schedules","methodName":"get","snippet":"data \"cloudflare_workers_cron_trigger\" \"example_workers_cron_trigger\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}\n","required":[{"name":"script_name","type":"String","description":"Name of the script."},{"name":"account_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the script."},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}]}]},"get /accounts/{}/workers/scripts/{}/subdomain":{"operationId":"worker-script-get-subdomain","declarations":[{"kind":"data-source","name":"cloudflare_workers_script_subdomain","stainlessResource":"workers.scripts.subdomain","methodName":"get","snippet":"data \"cloudflare_workers_script_subdomain\" \"example_workers_script_subdomain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"script_name","type":"String","description":"Name of the script."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"Whether the Worker is available on the workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether the Worker's Preview URLs are available on the workers.dev subdomain."}]}]},"get /accounts/{}/workers/workers":{"operationId":"listWorkers","declarations":[{"kind":"list-data-source","name":"cloudflare_workers","stainlessResource":"workers.beta.workers","methodName":"list","snippet":"data \"cloudflare_workers\" \"example_workers\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"order","type":"String","description":"Sort direction."},{"name":"order_by","type":"String","description":"Property to sort results by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Immutable ID of the Worker."},{"name":"created_on","type":"Time","description":"When the Worker was created."},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled for the Worker."},{"name":"name","type":"String","description":"Name of the Worker."},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"references","type":"Attributes","description":"Other resources that reference the Worker and depend on it existing.","children":[{"name":"dispatch_namespace_outbounds","type":"List[Attributes]","description":"Other Workers that reference the Worker as an outbound for a dispatch namespace.","children":[{"name":"namespace_id","type":"String","description":"ID of the dispatch namespace."},{"name":"namespace_name","type":"String","description":"Name of the dispatch namespace."},{"name":"worker_id","type":"String","description":"ID of the Worker using the dispatch namespace."},{"name":"worker_name","type":"String","description":"Name of the Worker using the dispatch namespace."}]},{"name":"domains","type":"List[Attributes]","description":"Custom domains connected to the Worker.","children":[{"name":"id","type":"String","description":"ID of the custom domain."},{"name":"certificate_id","type":"String","description":"ID of the TLS certificate issued for the custom domain."},{"name":"hostname","type":"String","description":"Full hostname of the custom domain, including the zone name."},{"name":"zone_id","type":"String","description":"ID of the zone."},{"name":"zone_name","type":"String","description":"Name of the zone."}]},{"name":"durable_objects","type":"List[Attributes]","description":"Other Workers that reference Durable Object classes implemented by the Worker.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace being used."},{"name":"namespace_name","type":"String","description":"Name of the Durable Object namespace being used."},{"name":"worker_id","type":"String","description":"ID of the Worker using the Durable Object implementation."},{"name":"worker_name","type":"String","description":"Name of the Worker using the Durable Object implementation."}]},{"name":"queues","type":"List[Attributes]","description":"Queues that send messages to the Worker.","children":[{"name":"queue_consumer_id","type":"String","description":"ID of the queue consumer configuration."},{"name":"queue_id","type":"String","description":"ID of the queue."},{"name":"queue_name","type":"String","description":"Name of the queue."}]},{"name":"workers","type":"List[Attributes]","description":"Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).","children":[{"name":"id","type":"String","description":"ID of the referencing Worker."},{"name":"name","type":"String","description":"Name of the referencing Worker."}]}]},{"name":"subdomain","type":"Attributes","description":"Subdomain settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether the *.workers.dev subdomain is enabled for the Worker."},{"name":"preview_url_suffix","type":"String","description":"Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker."},{"name":"url","type":"String","description":"The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain."}]},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from the Worker.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]},{"name":"updated_on","type":"Time","description":"When the Worker was most recently updated."},{"name":"deployed_on","type":"Time","description":"When the Worker's most recent deployment was created. `null` if the Worker has never been deployed."},{"name":"previews_base_config","type":"Attributes","description":"Template configuration used when creating new Previews for this Worker.","children":[{"name":"cache_options","type":"Attributes","description":"Cache options used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"env","type":"Map[Attributes]","description":"Bindings used when creating new Previews, keyed by binding name.","children":[{"name":"type","type":"String","description":"The kind of resource that the binding provides."}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime for newly created Previews.","children":[{"name":"cpu_ms","type":"Int64","description":"The amount of CPU time this Worker can use in milliseconds."},{"name":"subrequests","type":"Int64","description":"The number of subrequests this Worker can make per request."}]},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled when creating new Previews."},{"name":"observability","type":"Attributes","description":"Observability settings used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Placement configuration used when creating new Previews.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from newly created Previews.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]}]}]}]},"get /accounts/{}/workers/workers/{}":{"operationId":"getWorker","declarations":[{"kind":"data-source","name":"cloudflare_worker","stainlessResource":"workers.beta.workers","methodName":"get","snippet":"data \"cloudflare_worker\" \"example_worker\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."}],"optional":[{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name."},{"name":"filter","type":"Attributes","children":[{"name":"order","type":"String","description":"Sort direction."},{"name":"order_by","type":"String","description":"Property to sort results by."}]}],"computed":[{"name":"id","type":"String","description":"Identifier for the Worker, which can be ID or name."},{"name":"created_on","type":"Time","description":"When the Worker was created."},{"name":"deployed_on","type":"Time","description":"When the Worker's most recent deployment was created. `null` if the Worker has never been deployed."},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled for the Worker."},{"name":"name","type":"String","description":"Name of the Worker."},{"name":"updated_on","type":"Time","description":"When the Worker was most recently updated."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"previews_base_config","type":"Attributes","description":"Template configuration used when creating new Previews for this Worker.","children":[{"name":"cache_options","type":"Attributes","description":"Cache options used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"env","type":"Map[Attributes]","description":"Bindings used when creating new Previews, keyed by binding name.","children":[{"name":"type","type":"String","description":"The kind of resource that the binding provides."}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime for newly created Previews.","children":[{"name":"cpu_ms","type":"Int64","description":"The amount of CPU time this Worker can use in milliseconds."},{"name":"subrequests","type":"Int64","description":"The number of subrequests this Worker can make per request."}]},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled when creating new Previews."},{"name":"observability","type":"Attributes","description":"Observability settings used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Placement configuration used when creating new Previews.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from newly created Previews.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]},{"name":"references","type":"Attributes","description":"Other resources that reference the Worker and depend on it existing.","children":[{"name":"dispatch_namespace_outbounds","type":"List[Attributes]","description":"Other Workers that reference the Worker as an outbound for a dispatch namespace.","children":[{"name":"namespace_id","type":"String","description":"ID of the dispatch namespace."},{"name":"namespace_name","type":"String","description":"Name of the dispatch namespace."},{"name":"worker_id","type":"String","description":"ID of the Worker using the dispatch namespace."},{"name":"worker_name","type":"String","description":"Name of the Worker using the dispatch namespace."}]},{"name":"domains","type":"List[Attributes]","description":"Custom domains connected to the Worker.","children":[{"name":"id","type":"String","description":"ID of the custom domain."},{"name":"certificate_id","type":"String","description":"ID of the TLS certificate issued for the custom domain."},{"name":"hostname","type":"String","description":"Full hostname of the custom domain, including the zone name."},{"name":"zone_id","type":"String","description":"ID of the zone."},{"name":"zone_name","type":"String","description":"Name of the zone."}]},{"name":"durable_objects","type":"List[Attributes]","description":"Other Workers that reference Durable Object classes implemented by the Worker.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace being used."},{"name":"namespace_name","type":"String","description":"Name of the Durable Object namespace being used."},{"name":"worker_id","type":"String","description":"ID of the Worker using the Durable Object implementation."},{"name":"worker_name","type":"String","description":"Name of the Worker using the Durable Object implementation."}]},{"name":"queues","type":"List[Attributes]","description":"Queues that send messages to the Worker.","children":[{"name":"queue_consumer_id","type":"String","description":"ID of the queue consumer configuration."},{"name":"queue_id","type":"String","description":"ID of the queue."},{"name":"queue_name","type":"String","description":"Name of the queue."}]},{"name":"workers","type":"List[Attributes]","description":"Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).","children":[{"name":"id","type":"String","description":"ID of the referencing Worker."},{"name":"name","type":"String","description":"Name of the referencing Worker."}]}]},{"name":"subdomain","type":"Attributes","description":"Subdomain settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether the *.workers.dev subdomain is enabled for the Worker."},{"name":"preview_url_suffix","type":"String","description":"Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker."},{"name":"url","type":"String","description":"The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain."}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from the Worker.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]}]},"get /accounts/{}/workers/workers/{}/versions":{"operationId":"listWorkerVersions","declarations":[{"kind":"list-data-source","name":"cloudflare_worker_versions","stainlessResource":"workers.beta.workers.versions","methodName":"list","snippet":"data \"cloudflare_worker_versions\" \"example_worker_versions\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Version identifier."},{"name":"created_on","type":"Time","description":"When the version was created."},{"name":"number","type":"Int64","description":"The integer version number, starting from one."},{"name":"urls","type":"List[String]","description":"All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version."},{"name":"annotations","type":"Attributes","description":"Metadata about the version.","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the version. Truncated to 1000 bytes if longer."},{"name":"workers_tag","type":"String","description":"User-provided identifier for the version. Maximum 100 bytes."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the version."}]},{"name":"assets","type":"Attributes","description":"Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"config","type":"Attributes","description":"Configuration for assets within a Worker.","children":[{"name":"base_path","type":"String","description":"The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%."},{"name":"html_handling","type":"String","description":"Determines the redirects and rewrites of requests for HTML content."},{"name":"not_found_handling","type":"String","description":"Determines the response when a request does not match a static asset, and there is no Worker script."},{"name":"run_worker_first","type":"List[String]","description":"Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules."}]},{"name":"jwt","type":"String","description":"Token provided upon successful upload of all files from a registered manifest.","sensitive":true}]},{"name":"author_email","type":"String","description":"Email of the user who created the version."},{"name":"author_id","type":"String","description":"Identifier of the user who created the version."},{"name":"bindings","type":"List[Attributes]","description":"List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.","children":[{"name":"name","type":"String","description":"A JavaScript variable name for the binding."},{"name":"type","type":"String","description":"The kind of resource that the binding provides."},{"name":"instance_name","type":"String","description":"The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance."},{"name":"namespace","type":"String","description":"The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field."},{"name":"dataset","type":"String","description":"The name of the dataset to bind to."},{"name":"database_id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"part","type":"String","description":"The name of the file containing the data content. Only accepted for `service worker syntax` Workers."},{"name":"outbound","type":"Attributes","description":"Outbound worker.","children":[{"name":"params","type":"List[Attributes]","description":"Pass information from the Dispatch Worker to the Outbound Worker through the parameters.","children":[{"name":"name","type":"String","description":"Name of the parameter."}]},{"name":"worker","type":"Attributes","description":"Outbound worker.","children":[{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the outbound worker."},{"name":"environment","type":"String","description":"Environment of the outbound worker."},{"name":"service","type":"String","description":"Name of the outbound worker."}]}]},{"name":"class_name","type":"String","description":"The exported class name of the Durable Object."},{"name":"dispatch_namespace","type":"String","description":"The dispatch namespace the Durable Object script belongs to."},{"name":"environment","type":"String","description":"The environment of the script_name to bind to."},{"name":"namespace_id","type":"String","description":"Namespace identifier tag."},{"name":"script_name","type":"String","description":"The script where the Durable Object is defined, if it is external to this Worker."},{"name":"old_name","type":"String","description":"The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions."},{"name":"version_id","type":"String","description":"Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version."},{"name":"json","type":"unknown","description":"JSON data to use."},{"name":"certificate_id","type":"String","description":"Identifier of the certificate to bind to."},{"name":"text","type":"String","description":"The text value to use.","sensitive":true},{"name":"pipeline","type":"String","description":"Name of the Pipeline to bind to."},{"name":"stream","type":"String","description":"ID of a K2 stream owned by the account deploying the Worker."},{"name":"queue_name","type":"String","description":"Name of the Queue to bind to."},{"name":"simple","type":"Attributes","description":"The rate limit configuration.","children":[{"name":"limit","type":"Float64","description":"The limit (requests per period)."},{"name":"period","type":"Int64","description":"The period in seconds."},{"name":"mitigation_timeout","type":"Int64","description":"Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero.\n"}]},{"name":"bucket_name","type":"String","description":"R2 bucket to bind to."},{"name":"jurisdiction","type":"String","description":"The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket."},{"name":"allowed_destination_addresses","type":"List[String]","description":"List of allowed destination addresses."},{"name":"allowed_sender_addresses","type":"List[String]","description":"List of allowed sender addresses."},{"name":"destination_address","type":"String","description":"Destination address for the email."},{"name":"service","type":"String","description":"Name of Worker to bind to."},{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the target Worker."},{"name":"index_name","type":"String","description":"Name of the Vectorize index to bind to."},{"name":"secret_name","type":"String","description":"Name of the secret in the store."},{"name":"store_id","type":"String","description":"ID of the store containing the secret."},{"name":"app_id","type":"String","description":"ID of the Flagship app to bind to for feature flag evaluation."},{"name":"algorithm","type":"unknown","description":"Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)."},{"name":"format","type":"String","description":"Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format)."},{"name":"usages","type":"Set[String]","description":"Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)."},{"name":"key_base64","type":"String","description":"Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".","sensitive":true},{"name":"key_jwk","type":"unknown","description":"Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".","sensitive":true},{"name":"workflow_name","type":"String","description":"Name of the Workflow to bind to."},{"name":"service_id","type":"String","description":"Identifier of the VPC service to bind to."},{"name":"identity","type":"String","description":"Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\n"},{"name":"network_id","type":"String","description":"Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id.\n"},{"name":"tunnel_id","type":"String","description":"UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id.\n"}]},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"containers","type":"Set[Attributes]","description":"List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.","children":[{"name":"class_name","type":"String","description":"Select which Durable Object class should get this container attached."}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"exports_reconciliation","type":"Attributes","description":"Summary of the declarative exports reconciliation that ran on\nthis upload. Populated only when the uploaded metadata included\nan `exports` block. Durable Object entries drive reconciliation;\n`type: worker` entries do not contribute to this summary.\n","children":[{"name":"created","type":"List[String]","description":"Class names for which a new namespace was provisioned."},{"name":"deleted","type":"List[String]","description":"Class names whose namespace was deleted by a `deleted` tombstone."},{"name":"info","type":"List[Attributes]","description":"Non-blocking info entries (stale tombstones, tombstone applied\nwith class still in code). See `exports_reconciliation_info`.\n","children":[{"name":"class","type":"String","description":"The class name the info entry is about."},{"name":"message","type":"String","description":"Human-readable explanation."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the entry relates to, when applicable."},{"name":"referencing_scripts","type":"List[String]","description":"Other Workers in the account that still bind to the affected\nclass. Advisory: while non-empty the tombstone is not yet safe\nto remove — redeploy these Workers with bindings re-pointed\nfirst.\n"}]},{"name":"removable_entries","type":"List[String]","description":"Source class names whose tombstone entry is now stale and safe\nto delete from `exports` (no remaining referencing scripts).\n"},{"name":"renamed","type":"List[Attributes]","description":"Applied `renamed` tombstones.","children":[{"name":"from","type":"String","description":"The original (source) class name."},{"name":"to","type":"String","description":"The new class name (`renamed_to`)."}]},{"name":"transfer_pending","type":"List[Attributes]","description":"Phase-1 transfer hints recorded on the target side.","children":[{"name":"class","type":"String","description":"The target-side class name awaiting transfer."},{"name":"from","type":"String","description":"The source script the namespace will be transferred from."}]},{"name":"transferred","type":"List[Attributes]","description":"Committed `transferred` tombstones (phase-2).","children":[{"name":"class","type":"String","description":"The source class name that was transferred."},{"name":"phase","type":"String","description":"The transfer phase. Currently always `committed`."},{"name":"to","type":"String","description":"The destination script that now owns the namespace."}]},{"name":"updated","type":"List[String]","description":"Class names whose provisioned namespace was mutated in place."},{"name":"warnings","type":"List[Attributes]","description":"Non-blocking warnings. See `exports_reconciliation_warning`.","children":[{"name":"class","type":"String","description":"The class name the warning is about."},{"name":"message","type":"String","description":"Human-readable explanation of the warning."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the warning relates to, when applicable."}]}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."},{"name":"subrequests","type":"Int64","description":"Subrequest limit per request."}]},{"name":"main_module","type":"String","description":"The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler)."},{"name":"migration_tag","type":"String","description":"Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects."},{"name":"migrations","type":"Attributes","description":"Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"new_tag","type":"String","description":"Tag to set as the latest migration tag."},{"name":"old_tag","type":"String","description":"Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]},{"name":"steps","type":"List[Attributes]","description":"Migrations to apply in order.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]}]}]},{"name":"modules","type":"Set[Attributes]","description":"Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"content_base64","type":"String","description":"The base64-encoded module content."},{"name":"content_type","type":"String","description":"The content type of the module."},{"name":"name","type":"String","description":"The name of the module."}]},{"name":"package_dependencies","type":"List[Attributes]","description":"The list of npm packages that were installed and used when this Worker\nversion was built.\n","children":[{"name":"installed_version","type":"String","description":"The exact version that was resolved and installed by the package manager."},{"name":"name","type":"String","description":"The npm package name."},{"name":"package_json_version","type":"String","description":"The version constraint as written in package.json."}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"source","type":"String","description":"The client used to create the version."},{"name":"startup_time_ms","type":"Int64","description":"Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)."},{"name":"usage_model","type":"String","description":"Usage model for the version.","deprecated":"Deprecated."}]}]}]},"get /accounts/{}/workers/workers/{}/versions/{}":{"operationId":"getWorkerVersion","declarations":[{"kind":"data-source","name":"cloudflare_worker_version","stainlessResource":"workers.beta.workers.versions","methodName":"get","snippet":"data \"cloudflare_worker_version\" \"example_worker_version\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n version_id = \"version_id\"\n include = \"modules\"\n}\n","required":[{"name":"version_id","type":"String","description":"Identifier for the version, which can be a UUID, a UUID prefix (minimum length 8), or the literal \"latest\" to operate on the most recently created version."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name."}],"optional":[{"name":"include","type":"String","description":"Whether to include the `modules` property of the version in the response, which contains code and sourcemap content and may add several megabytes to the response size."}],"computed":[{"name":"id","type":"String","description":"Identifier for the version, which can be a UUID, a UUID prefix (minimum length 8), or the literal \"latest\" to operate on the most recently created version."},{"name":"author_email","type":"String","description":"Email of the user who created the version."},{"name":"author_id","type":"String","description":"Identifier of the user who created the version."},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"created_on","type":"Time","description":"When the version was created."},{"name":"main_module","type":"String","description":"The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler)."},{"name":"migration_tag","type":"String","description":"Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects."},{"name":"number","type":"Int64","description":"The integer version number, starting from one."},{"name":"source","type":"String","description":"The client used to create the version."},{"name":"startup_time_ms","type":"Int64","description":"Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)."},{"name":"usage_model","type":"String","description":"Usage model for the version.","deprecated":"Deprecated."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"urls","type":"List[String]","description":"All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version."},{"name":"annotations","type":"Attributes","description":"Metadata about the version.","children":[{"name":"workers_message","type":"String","description":"Human-readable message about the version. Truncated to 1000 bytes if longer."},{"name":"workers_tag","type":"String","description":"User-provided identifier for the version. Maximum 100 bytes."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the version."}]},{"name":"assets","type":"Attributes","description":"Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"config","type":"Attributes","description":"Configuration for assets within a Worker.","children":[{"name":"base_path","type":"String","description":"The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%."},{"name":"html_handling","type":"String","description":"Determines the redirects and rewrites of requests for HTML content."},{"name":"not_found_handling","type":"String","description":"Determines the response when a request does not match a static asset, and there is no Worker script."},{"name":"run_worker_first","type":"List[String]","description":"Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules."}]},{"name":"jwt","type":"String","description":"Token provided upon successful upload of all files from a registered manifest.","sensitive":true}]},{"name":"bindings","type":"List[Attributes]","description":"List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.","children":[{"name":"name","type":"String","description":"A JavaScript variable name for the binding."},{"name":"type","type":"String","description":"The kind of resource that the binding provides."},{"name":"instance_name","type":"String","description":"The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance."},{"name":"namespace","type":"String","description":"The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field."},{"name":"dataset","type":"String","description":"The name of the dataset to bind to."},{"name":"database_id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"part","type":"String","description":"The name of the file containing the data content. Only accepted for `service worker syntax` Workers."},{"name":"outbound","type":"Attributes","description":"Outbound worker.","children":[{"name":"params","type":"List[Attributes]","description":"Pass information from the Dispatch Worker to the Outbound Worker through the parameters.","children":[{"name":"name","type":"String","description":"Name of the parameter."}]},{"name":"worker","type":"Attributes","description":"Outbound worker.","children":[{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the outbound worker."},{"name":"environment","type":"String","description":"Environment of the outbound worker."},{"name":"service","type":"String","description":"Name of the outbound worker."}]}]},{"name":"class_name","type":"String","description":"The exported class name of the Durable Object."},{"name":"dispatch_namespace","type":"String","description":"The dispatch namespace the Durable Object script belongs to."},{"name":"environment","type":"String","description":"The environment of the script_name to bind to."},{"name":"namespace_id","type":"String","description":"Namespace identifier tag."},{"name":"script_name","type":"String","description":"The script where the Durable Object is defined, if it is external to this Worker."},{"name":"old_name","type":"String","description":"The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions."},{"name":"version_id","type":"String","description":"Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version."},{"name":"json","type":"unknown","description":"JSON data to use."},{"name":"certificate_id","type":"String","description":"Identifier of the certificate to bind to."},{"name":"text","type":"String","description":"The text value to use.","sensitive":true},{"name":"pipeline","type":"String","description":"Name of the Pipeline to bind to."},{"name":"stream","type":"String","description":"ID of a K2 stream owned by the account deploying the Worker."},{"name":"queue_name","type":"String","description":"Name of the Queue to bind to."},{"name":"simple","type":"Attributes","description":"The rate limit configuration.","children":[{"name":"limit","type":"Float64","description":"The limit (requests per period)."},{"name":"period","type":"Int64","description":"The period in seconds."},{"name":"mitigation_timeout","type":"Int64","description":"Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero.\n"}]},{"name":"bucket_name","type":"String","description":"R2 bucket to bind to."},{"name":"jurisdiction","type":"String","description":"The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket."},{"name":"allowed_destination_addresses","type":"List[String]","description":"List of allowed destination addresses."},{"name":"allowed_sender_addresses","type":"List[String]","description":"List of allowed sender addresses."},{"name":"destination_address","type":"String","description":"Destination address for the email."},{"name":"service","type":"String","description":"Name of Worker to bind to."},{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the target Worker."},{"name":"index_name","type":"String","description":"Name of the Vectorize index to bind to."},{"name":"secret_name","type":"String","description":"Name of the secret in the store."},{"name":"store_id","type":"String","description":"ID of the store containing the secret."},{"name":"app_id","type":"String","description":"ID of the Flagship app to bind to for feature flag evaluation."},{"name":"algorithm","type":"unknown","description":"Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)."},{"name":"format","type":"String","description":"Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format)."},{"name":"usages","type":"Set[String]","description":"Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)."},{"name":"key_base64","type":"String","description":"Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".","sensitive":true},{"name":"key_jwk","type":"unknown","description":"Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".","sensitive":true},{"name":"workflow_name","type":"String","description":"Name of the Workflow to bind to."},{"name":"service_id","type":"String","description":"Identifier of the VPC service to bind to."},{"name":"identity","type":"String","description":"Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\n"},{"name":"network_id","type":"String","description":"Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id.\n"},{"name":"tunnel_id","type":"String","description":"UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id.\n"}]},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"containers","type":"Set[Attributes]","description":"List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.","children":[{"name":"class_name","type":"String","description":"Select which Durable Object class should get this container attached."}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"exports_reconciliation","type":"Attributes","description":"Summary of the declarative exports reconciliation that ran on\nthis upload. Populated only when the uploaded metadata included\nan `exports` block. Durable Object entries drive reconciliation;\n`type: worker` entries do not contribute to this summary.\n","children":[{"name":"created","type":"List[String]","description":"Class names for which a new namespace was provisioned."},{"name":"deleted","type":"List[String]","description":"Class names whose namespace was deleted by a `deleted` tombstone."},{"name":"info","type":"List[Attributes]","description":"Non-blocking info entries (stale tombstones, tombstone applied\nwith class still in code). See `exports_reconciliation_info`.\n","children":[{"name":"class","type":"String","description":"The class name the info entry is about."},{"name":"message","type":"String","description":"Human-readable explanation."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the entry relates to, when applicable."},{"name":"referencing_scripts","type":"List[String]","description":"Other Workers in the account that still bind to the affected\nclass. Advisory: while non-empty the tombstone is not yet safe\nto remove — redeploy these Workers with bindings re-pointed\nfirst.\n"}]},{"name":"removable_entries","type":"List[String]","description":"Source class names whose tombstone entry is now stale and safe\nto delete from `exports` (no remaining referencing scripts).\n"},{"name":"renamed","type":"List[Attributes]","description":"Applied `renamed` tombstones.","children":[{"name":"from","type":"String","description":"The original (source) class name."},{"name":"to","type":"String","description":"The new class name (`renamed_to`)."}]},{"name":"transfer_pending","type":"List[Attributes]","description":"Phase-1 transfer hints recorded on the target side.","children":[{"name":"class","type":"String","description":"The target-side class name awaiting transfer."},{"name":"from","type":"String","description":"The source script the namespace will be transferred from."}]},{"name":"transferred","type":"List[Attributes]","description":"Committed `transferred` tombstones (phase-2).","children":[{"name":"class","type":"String","description":"The source class name that was transferred."},{"name":"phase","type":"String","description":"The transfer phase. Currently always `committed`."},{"name":"to","type":"String","description":"The destination script that now owns the namespace."}]},{"name":"updated","type":"List[String]","description":"Class names whose provisioned namespace was mutated in place."},{"name":"warnings","type":"List[Attributes]","description":"Non-blocking warnings. See `exports_reconciliation_warning`.","children":[{"name":"class","type":"String","description":"The class name the warning is about."},{"name":"message","type":"String","description":"Human-readable explanation of the warning."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the warning relates to, when applicable."}]}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."},{"name":"subrequests","type":"Int64","description":"Subrequest limit per request."}]},{"name":"migrations","type":"Attributes","description":"Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"new_tag","type":"String","description":"Tag to set as the latest migration tag."},{"name":"old_tag","type":"String","description":"Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]},{"name":"steps","type":"List[Attributes]","description":"Migrations to apply in order.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]}]}]},{"name":"modules","type":"Set[Attributes]","description":"Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","children":[{"name":"content_base64","type":"String","description":"The base64-encoded module content."},{"name":"content_type","type":"String","description":"The content type of the module."},{"name":"name","type":"String","description":"The name of the module."}]},{"name":"package_dependencies","type":"List[Attributes]","description":"The list of npm packages that were installed and used when this Worker\nversion was built.\n","children":[{"name":"installed_version","type":"String","description":"The exact version that was resolved and installed by the package manager."},{"name":"name","type":"String","description":"The npm package name."},{"name":"package_json_version","type":"String","description":"The version constraint as written in package.json."}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]}]}]},"get /accounts/{}/workflows":{"operationId":"wor-list-workflows","declarations":[{"kind":"list-data-source","name":"cloudflare_workflows","stainlessResource":"workflows","methodName":"list","snippet":"data \"cloudflare_workflows\" \"example_workflows\" {\n account_id = \"account_id\"\n search = \"x\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"search","type":"String","description":"Allows filtering workflows` name."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"class_name","type":"String"},{"name":"created_on","type":"Time"},{"name":"instances","type":"Map[Float64]"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String"},{"name":"script_name","type":"String"},{"name":"triggered_on","type":"Time"},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"next_instance","type":"String"}]},{"name":"script_deleted","type":"Bool","description":"Whether the bound Worker was deleted, leaving this Workflow inactive."}]}]}]},"get /accounts/{}/workflows/{}":{"operationId":"wor-get-workflow-details","declarations":[{"kind":"data-source","name":"cloudflare_workflow","stainlessResource":"workflows","methodName":"get","snippet":"data \"cloudflare_workflow\" \"example_workflow\" {\n account_id = \"account_id\"\n workflow_name = \"x\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"workflow_name","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"search","type":"String","description":"Allows filtering workflows` name."}]}],"computed":[{"name":"id","type":"String"},{"name":"class_name","type":"String"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String"},{"name":"script_deleted","type":"Bool","description":"Whether the bound Worker was deleted, leaving this Workflow inactive."},{"name":"script_name","type":"String"},{"name":"triggered_on","type":"Time"},{"name":"instances","type":"Map[Float64]"},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"next_instance","type":"String"}]}]}]},"get /accounts/{}/zerotrust/connectivity_settings":{"operationId":"zero-trust-accounts-get-connectivity-settings","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_connectivity_settings","stainlessResource":"zero_trust.connectivity_settings","methodName":"get","snippet":"data \"cloudflare_zero_trust_connectivity_settings\" \"example_zero_trust_connectivity_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Cloudflare account ID"},{"name":"icmp_proxy_enabled","type":"Bool","description":"A flag to enable the ICMP proxy for the account network."},{"name":"offramp_warp_enabled","type":"Bool","description":"A flag to enable WARP to WARP traffic."}]}]},"get /accounts/{}/zerotrust/routes/hostname":{"operationId":"zero-trust-networks-route-hostname-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_network_hostname_routes","stainlessResource":"zero_trust.networks.hostname_routes","methodName":"list","snippet":"data \"cloudflare_zero_trust_network_hostname_routes\" \"example_zero_trust_network_hostname_routes\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n comment = \"example%20comment\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n hostname = \"office-1.local\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"comment","type":"String","description":"If set, only list hostname routes with the given comment."},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"hostname","type":"String","description":"If set, only list hostname routes that contain a substring of the given value, the filter is case-insensitive."},{"name":"id","type":"String","description":"The hostname route ID."},{"name":"tunnel_id","type":"String","description":"If set, only list hostname routes that point to a specific tunnel."},{"name":"is_deleted","type":"Bool","description":"If `true`, only return deleted hostname routes. If `false`, exclude deleted hostname routes."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"comment","type":"String","description":"An optional description of the hostname route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"hostname","type":"String","description":"The hostname of the route."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."}]}]}]},"get /accounts/{}/zerotrust/routes/hostname/{}":{"operationId":"zero-trust-networks-route-hostname-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_network_hostname_route","stainlessResource":"zero_trust.networks.hostname_routes","methodName":"get","snippet":"data \"cloudflare_zero_trust_network_hostname_route\" \"example_zero_trust_network_hostname_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n hostname_route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[{"name":"hostname_route_id","type":"String","description":"The hostname route ID."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"comment","type":"String","description":"If set, only list hostname routes with the given comment."},{"name":"existed_at","type":"String","description":"If provided, include only resources that were created (and not deleted) before this time. URL encoded."},{"name":"hostname","type":"String","description":"If set, only list hostname routes that contain a substring of the given value, the filter is case-insensitive."},{"name":"is_deleted","type":"Bool","description":"If `true`, only return deleted hostname routes. If `false`, exclude deleted hostname routes."},{"name":"tunnel_id","type":"String","description":"If set, only list hostname routes that point to a specific tunnel."}]}],"computed":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"comment","type":"String","description":"An optional description of the hostname route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"hostname","type":"String","description":"The hostname of the route."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."}]}]},"get /accounts/{}/zerotrust/subnets/warp/{}":{"operationId":"zero-trust-networks-subnet-get-warp","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_subnet","stainlessResource":"zero_trust.networks.subnets.warp","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_subnet\" \"example_zero_trust_device_subnet\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n subnet_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"subnet_id","type":"String","description":"The UUID of the subnet."},{"name":"account_id","type":"String","description":"Cloudflare account ID"}],"optional":[],"computed":[{"name":"id","type":"String","description":"The UUID of the subnet."},{"name":"comment","type":"String","description":"An optional description of the subnet."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"is_default_network","type":"Bool","description":"If `true`, this is the default subnet for the account. There can only be one default subnet per account."},{"name":"name","type":"String","description":"A user-friendly name for the subnet."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range defining the subnet, in CIDR notation."},{"name":"subnet_type","type":"String","description":"The type of subnet."},{"name":"capacity","type":"Attributes","description":"IP capacity information for the subnet.","children":[{"name":"total","type":"Int64","description":"Total number of assignable IPs in the subnet."},{"name":"used","type":"Int64","description":"Number of assigned IPs in the subnet."}]}]}]},"get /accounts/{}/zt_risk_scoring/behaviors":{"operationId":"dlp-risk-score-behaviors-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_risk_behavior","stainlessResource":"zero_trust.risk_scoring.behaviours","methodName":"get","snippet":"data \"cloudflare_zero_trust_risk_behavior\" \"example_zero_trust_risk_behavior\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"behaviors","type":"Map[Attributes]","children":[{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"risk_level","type":"String"}]}]}]},"get /accounts/{}/zt_risk_scoring/integrations":{"operationId":"dlp-zt-risk-score-integration-list","declarations":[{"kind":"list-data-source","name":"cloudflare_zero_trust_risk_scoring_integrations","stainlessResource":"zero_trust.risk_scoring.integrations","methodName":"list","snippet":"data \"cloudflare_zero_trust_risk_scoring_integrations\" \"example_zero_trust_risk_scoring_integrations\" {\n account_id = \"account_id\"\n}\n","required":[{"name":"account_id","type":"String"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The id of the integration, a UUIDv4."},{"name":"account_tag","type":"String","description":"The Cloudflare account tag."},{"name":"active","type":"Bool","description":"Whether this integration is enabled and should export changes in risk score."},{"name":"created_at","type":"Time","description":"When the integration was created in RFC3339 format."},{"name":"integration_type","type":"String"},{"name":"reference_id","type":"String","description":"A reference ID defined by the client.\nShould be set to the Access-Okta IDP integration ID.\nUseful when the risk-score integration needs to be associated with a secondary asset and recalled using that ID."},{"name":"tenant_url","type":"String","description":"The base URL for the tenant. E.g. \"https://tenant.okta.com\"."},{"name":"well_known_url","type":"String","description":"The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1."}]}]}]},"get /accounts/{}/zt_risk_scoring/integrations/{}":{"operationId":"dlp-zt-risk-score-integration-get","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_risk_scoring_integration","stainlessResource":"zero_trust.risk_scoring.integrations","methodName":"get","snippet":"data \"cloudflare_zero_trust_risk_scoring_integration\" \"example_zero_trust_risk_scoring_integration\" {\n account_id = \"account_id\"\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"integration_id","type":"String"},{"name":"account_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"account_tag","type":"String","description":"The Cloudflare account tag."},{"name":"active","type":"Bool","description":"Whether this integration is enabled and should export changes in risk score."},{"name":"created_at","type":"Time","description":"When the integration was created in RFC3339 format."},{"name":"integration_type","type":"String"},{"name":"reference_id","type":"String","description":"A reference ID defined by the client.\nShould be set to the Access-Okta IDP integration ID.\nUseful when the risk-score integration needs to be associated with a secondary asset and recalled using that ID."},{"name":"tenant_url","type":"String","description":"The base URL for the tenant. E.g. \"https://tenant.okta.com\"."},{"name":"well_known_url","type":"String","description":"The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1."}]}]},"get /certificates":{"operationId":"origin-ca-list-certificates","declarations":[{"kind":"list-data-source","name":"cloudflare_origin_ca_certificates","stainlessResource":"origin_ca_certificates","methodName":"list","snippet":"data \"cloudflare_origin_ca_certificates\" \"example_origin_ca_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"hostnames","type":"List[String]","description":"Array of hostnames or wildcard names bound to the certificate.\nHostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode."},{"name":"request_type","type":"String","description":"Signature type desired on certificate (\"origin-rsa\" (rsa), \"origin-ecc\" (ecdsa), or \"keyless-certificate\" (for Keyless SSL servers)."},{"name":"requested_validity","type":"Float64","description":"The number of days for which the certificate should be valid."},{"name":"id","type":"String","description":"The x509 serial number of the Origin CA certificate."},{"name":"certificate","type":"String","description":"The Origin CA certificate. Will be newline-encoded."},{"name":"expires_on","type":"String","description":"When the certificate will expire."}]}]}]},"get /certificates/{}":{"operationId":"origin-ca-get-certificate","declarations":[{"kind":"data-source","name":"cloudflare_origin_ca_certificate","stainlessResource":"origin_ca_certificates","methodName":"get","snippet":"data \"cloudflare_origin_ca_certificate\" \"example_origin_ca_certificate\" {\n certificate_id = \"328578533902268680212849205732770752308931942346\"\n}\n","required":[],"optional":[{"name":"certificate_id","type":"String","description":"The x509 serial number of the Origin CA certificate."},{"name":"filter","type":"Attributes","children":[{"name":"zone_id","type":"String","description":"Identifier."},{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."}]}],"computed":[{"name":"id","type":"String","description":"The x509 serial number of the Origin CA certificate."},{"name":"certificate","type":"String","description":"The Origin CA certificate. Will be newline-encoded."},{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"expires_on","type":"String","description":"When the certificate will expire."},{"name":"request_type","type":"String","description":"Signature type desired on certificate (\"origin-rsa\" (rsa), \"origin-ecc\" (ecdsa), or \"keyless-certificate\" (for Keyless SSL servers)."},{"name":"requested_validity","type":"Float64","description":"The number of days for which the certificate should be valid."},{"name":"hostnames","type":"List[String]","description":"Array of hostnames or wildcard names bound to the certificate.\nHostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode."}]}]},"get /ips":{"operationId":"cloudflare-ips-cloudflare-ip-details","declarations":[{"kind":"data-source","name":"cloudflare_ip_ranges","stainlessResource":"ips","methodName":"list","snippet":"data \"cloudflare_ip_ranges\" \"example_ip_ranges\" {\n networks = \"networks\"\n}\n","required":[],"optional":[{"name":"networks","type":"String","description":"Specified as `jdcloud` to list IPs used by JD Cloud data centers."}],"computed":[{"name":"etag","type":"String","description":"A digest of the IP data. Useful for determining if the data has changed."},{"name":"ipv4_cidrs","type":"List[String]","description":"List of Cloudflare IPv4 CIDR addresses."},{"name":"ipv6_cidrs","type":"List[String]","description":"List of Cloudflare IPv6 CIDR addresses."},{"name":"jdcloud_cidrs","type":"List[String]","description":"List IPv4 and IPv6 CIDRs, only populated if `?networks=jdcloud` is used."}]}]},"get /oauth/scopes":{"operationId":"oauth-scopes-list","declarations":[{"kind":"list-data-source","name":"cloudflare_oauth_scopes","stainlessResource":"iam.oauth_scopes","methodName":"list","snippet":"data \"cloudflare_oauth_scopes\" \"example_oauth_scopes\" {\n\n}\n","required":[],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The scope label to use in the scopes array when creating or updating an OAuth client."},{"name":"name","type":"String","description":"Human-readable name of the OAuth scope."},{"name":"category","type":"String","description":"Category for grouping scopes in the UI."},{"name":"scopes","type":"List[String]","description":"The underlying resource scopes (Bach scopes) that define which resources this OAuth scope can act upon."}]}]}]},"get /organizations":{"operationId":"Organization_listOrganizations","declarations":[{"kind":"list-data-source","name":"cloudflare_organizations","stainlessResource":"organizations","methodName":"list","snippet":"data \"cloudflare_organizations\" \"example_organizations\" {\n id = [\"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"]\n containing = {\n account = \"account\"\n organization = \"organization\"\n user = \"user\"\n }\n name = {\n contains = \"contains\"\n ends_with = \"endsWith\"\n starts_with = \"startsWith\"\n }\n page_size = 0\n page_token = \"page_token\"\n parent = {\n id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n }\n}\n","required":[],"optional":[{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"id","type":"List[String]","description":"Only return organizations with the specified IDs (ex. id=foo&id=bar). Send multiple elements\nby repeating the query value."},{"name":"containing","type":"Attributes","children":[{"name":"account","type":"String","description":"Filter the list of organizations to the ones that contain this particular\naccount."},{"name":"organization","type":"String","description":"Filter the list of organizations to the ones that contain this particular\norganization."},{"name":"user","type":"String","description":"Filter the list of organizations to the ones that contain this particular\nuser.\n\nIMPORTANT: Just because an organization \"contains\" a user is not a\nrepresentation of any authorization or privilege to manage any resources\ntherein. An organization \"containing\" a user simply means the user is managed by\nthat organization."}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name contains a particular\nstring."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name ends with a particular\nstring."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name starts with a\nparticular string."}]},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter the list of organizations to the ones that are a sub-organization\nof the specified organization.\n\n\"null\" is a valid value to provide for this parameter. It means \"where\nan organization has no parent (i.e. it is a 'root' organization).\""}]},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"create_time","type":"Time"},{"name":"meta","type":"Attributes","children":[{"name":"hierarchy_tags","type":"List[String]","description":"Ordered chain of organization tags from the root organization down to\n(and including) this organization itself. Root organizations return a\nsingle-element array containing their own tag; sub-organizations return\n`[rootTag, ...intermediateTags, parentTag, selfTag]`. Useful for\nconstructing authorization scopes that need to cover every ancestor\nin the hierarchy."},{"name":"managed_by","type":"String"},{"name":"tenant_flags","type":"Attributes","description":"Enable features for Organizations.","children":[{"name":"account_creation","type":"String"},{"name":"account_creation_applies_tenant_defaults","type":"String"},{"name":"account_deletion","type":"String"},{"name":"account_migration","type":"String"},{"name":"account_mobility","type":"String"},{"name":"enterprise_capability","type":"String"},{"name":"member_management","type":"String"},{"name":"sub_org_creation","type":"String"}]}]},{"name":"name","type":"String"},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"profile","type":"Attributes","children":[{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}]}]}]}]},"get /organizations/{}":{"operationId":"Organizations_retrieve","declarations":[{"kind":"data-source","name":"cloudflare_organization","stainlessResource":"organizations","methodName":"get","snippet":"data \"cloudflare_organization\" \"example_organization\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n}\n","required":[],"optional":[{"name":"organization_id","type":"String"},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"List[String]","description":"Only return organizations with the specified IDs (ex. id=foo&id=bar). Send multiple elements\nby repeating the query value."},{"name":"containing","type":"Attributes","children":[{"name":"account","type":"String","description":"Filter the list of organizations to the ones that contain this particular\naccount."},{"name":"organization","type":"String","description":"Filter the list of organizations to the ones that contain this particular\norganization."},{"name":"user","type":"String","description":"Filter the list of organizations to the ones that contain this particular\nuser.\n\nIMPORTANT: Just because an organization \"contains\" a user is not a\nrepresentation of any authorization or privilege to manage any resources\ntherein. An organization \"containing\" a user simply means the user is managed by\nthat organization."}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name contains a particular\nstring."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name ends with a particular\nstring."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of organizations to where the name starts with a\nparticular string."}]},{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter the list of organizations to the ones that are a sub-organization\nof the specified organization.\n\n\"null\" is a valid value to provide for this parameter. It means \"where\nan organization has no parent (i.e. it is a 'root' organization).\""}]}]}],"computed":[{"name":"id","type":"String"},{"name":"create_time","type":"Time"},{"name":"name","type":"String"},{"name":"meta","type":"Attributes","children":[{"name":"hierarchy_tags","type":"List[String]","description":"Ordered chain of organization tags from the root organization down to\n(and including) this organization itself. Root organizations return a\nsingle-element array containing their own tag; sub-organizations return\n`[rootTag, ...intermediateTags, parentTag, selfTag]`. Useful for\nconstructing authorization scopes that need to cover every ancestor\nin the hierarchy."},{"name":"managed_by","type":"String"},{"name":"tenant_flags","type":"Attributes","description":"Enable features for Organizations.","children":[{"name":"account_creation","type":"String"},{"name":"account_creation_applies_tenant_defaults","type":"String"},{"name":"account_deletion","type":"String"},{"name":"account_migration","type":"String"},{"name":"account_mobility","type":"String"},{"name":"enterprise_capability","type":"String"},{"name":"member_management","type":"String"},{"name":"sub_org_creation","type":"String"}]}]},{"name":"parent","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"profile","type":"Attributes","children":[{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}]}]}]},"get /organizations/{}/accounts":{"operationId":"Organizations_getAccounts","declarations":[{"kind":"data-source","name":"cloudflare_organization_accounts","stainlessResource":"organizations.organization_accounts","methodName":"get","required":[{"name":"organization_id","type":"String"}],"optional":[{"name":"direction","type":"String","description":"Sort direction for the order_by field. Valid values: `asc`, `desc`.\nDefaults to `asc` when order_by is specified."},{"name":"include_tags","type":"Bool","description":"Include Account tags from the resource tag mirror. Omit this parameter to preserve the existing Account response shape."},{"name":"order_by","type":"String","description":"Field to order results by. Currently supported values: `account_name`.\nWhen not specified, results are ordered by internal account ID."},{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"account_pubname","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of accounts to where the account_pubname contains\na particular string."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the account_pubname ends with\na particular string."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the account_pubname starts with\na particular string."}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"(case-insensitive) Filter the list of accounts to where the name contains a particular\nstring."},{"name":"ends_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the name ends with a particular\nstring."},{"name":"starts_with","type":"String","description":"(case-insensitive) Filter the list of accounts to where the name starts with a\nparticular string."}]},{"name":"include_total","type":"Bool","description":"Whether to calculate and return the exact result_info.total_size for cursor\npagination. Defaults to true. When false, total_size is omitted. page_size and\ninclude_total may change between pages; next_page_token remains the authoritative\ncontinuation signal.\nLegacy page/per_page requests always calculate total_count."}],"computed":[{"name":"organization_accounts","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"name","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"abuse_contact_email","type":"String"},{"name":"access_approval_expiry","type":"Time"},{"name":"api_access_enabled","type":"Bool"},{"name":"default_nameservers","type":"String","description":"Use [DNS Settings](https://developers.cloudflare.com/api/operations/dns-settings-for-an-account-list-dns-settings) instead. Deprecated.","deprecated":"Deprecated."},{"name":"enforce_twofactor","type":"Bool"},{"name":"use_account_custom_ns_by_default","type":"Bool","description":"Use [DNS Settings](https://developers.cloudflare.com/api/operations/dns-settings-for-an-account-list-dns-settings) instead. Deprecated.","deprecated":"Deprecated."}]},{"name":"type","type":"String"},{"name":"tags","type":"Map[String]","description":"Account tags, present only when `include_tags=true` is requested."}]}]}]},"get /organizations/{}/members":{"operationId":"Members_list","declarations":[{"kind":"list-data-source","name":"cloudflare_organization_members","stainlessResource":"organizations.members","methodName":"list","required":[{"name":"organization_id","type":"String"}],"optional":[{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"status","type":"List[String]","description":"Filter the list of memberships by membership status."},{"name":"user","type":"Attributes","children":[{"name":"email","type":"String","description":"Filter the list of memberships for a specific email that ends with a substring."}]},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Organization Member ID"},{"name":"create_time","type":"Time"},{"name":"meta","type":"Map[unknown]"},{"name":"status","type":"String"},{"name":"update_time","type":"Time"},{"name":"user","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"email","type":"String"},{"name":"name","type":"String"},{"name":"two_factor_authentication_enabled","type":"Bool"}]}]}]}]},"get /organizations/{}/members/{}":{"operationId":"Members_retrieve","declarations":[{"kind":"data-source","name":"cloudflare_organization_member","stainlessResource":"organizations.members","methodName":"get","required":[{"name":"organization_id","type":"String"}],"optional":[{"name":"member_id","type":"String","description":"Organization Member ID"},{"name":"filter","type":"Attributes","children":[{"name":"page_size","type":"Int64","description":"The amount of items to return. Defaults to 10."},{"name":"page_token","type":"String","description":"An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token."},{"name":"status","type":"List[String]","description":"Filter the list of memberships by membership status."},{"name":"user","type":"Attributes","children":[{"name":"email","type":"String","description":"Filter the list of memberships for a specific email that ends with a substring."}]}]}],"computed":[{"name":"id","type":"String","description":"Organization Member ID"},{"name":"create_time","type":"Time"},{"name":"status","type":"String"},{"name":"update_time","type":"Time"},{"name":"meta","type":"Map[unknown]"},{"name":"user","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"email","type":"String"},{"name":"name","type":"String"},{"name":"two_factor_authentication_enabled","type":"Bool"}]}]}]},"get /organizations/{}/profile":{"operationId":"Organizations_getProfile","declarations":[{"kind":"data-source","name":"cloudflare_organization_profile","stainlessResource":"organizations.organization_profile","methodName":"get","snippet":"data \"cloudflare_organization_profile\" \"example_organization_profile\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n}\n","required":[{"name":"organization_id","type":"String"}],"optional":[],"computed":[{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}]}]},"get /user":{"operationId":"user-user-details","declarations":[{"kind":"data-source","name":"cloudflare_user","stainlessResource":"user","methodName":"get","snippet":"data \"cloudflare_user\" \"example_user\" {\n\n}\n","required":[],"optional":[],"computed":[{"name":"country","type":"String","description":"The country in which the user lives."},{"name":"email","type":"String","description":"Current email address of the user."},{"name":"first_name","type":"String","description":"User's first name"},{"name":"has_business_zones","type":"Bool","description":"Indicates whether user has any business zones"},{"name":"has_enterprise_zones","type":"Bool","description":"Indicates whether user has any enterprise zones"},{"name":"has_pro_zones","type":"Bool","description":"Indicates whether user has any pro zones"},{"name":"id","type":"String","description":"Identifier of the user."},{"name":"last_name","type":"String","description":"User's last name"},{"name":"suspended","type":"Bool","description":"Indicates whether user has been suspended"},{"name":"telephone","type":"String","description":"User's telephone number"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."},{"name":"two_factor_authentication_locked","type":"Bool","description":"Indicates whether two-factor authentication is required by one of the accounts that the user is a member of."},{"name":"zipcode","type":"String","description":"The zipcode or postal code where the user lives."},{"name":"betas","type":"List[String]","description":"Lists the betas that the user is participating in."},{"name":"organizations","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Organization name."},{"name":"permissions","type":"List[String]","description":"Access permissions for this User."},{"name":"roles","type":"List[String]","description":"List of roles that a user has within an organization."},{"name":"status","type":"String","description":"Whether the user is a member of the organization or has an invitation pending."}]}]}]},"get /user/tokens":{"operationId":"user-api-tokens-list-tokens","declarations":[{"kind":"list-data-source","name":"cloudflare_api_tokens","stainlessResource":"user.tokens","methodName":"list","snippet":"data \"cloudflare_api_tokens\" \"example_api_tokens\" {\n direction = \"desc\"\n}\n","required":[],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."}]}]}]},"get /user/tokens/{}":{"operationId":"user-api-tokens-token-details","declarations":[{"kind":"data-source","name":"cloudflare_api_token","stainlessResource":"user.tokens","methodName":"get","snippet":"data \"cloudflare_api_token\" \"example_api_token\" {\n token_id = \"ed17574386854bf78a67040be0a770b0\"\n}\n","required":[],"optional":[{"name":"token_id","type":"String","description":"Token identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"include_expired","type":"Bool","description":"When true, includes recently-expired tokens in the response."}]}],"computed":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"name","type":"String","description":"Token name."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"status","type":"String","description":"Status of the token."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]}]}]},"get /user/tokens/permission_groups":{"operationId":"permission-groups-list-permission-groups","declarations":[{"kind":"list-data-source","name":"cloudflare_api_token_permission_groups_list","stainlessResource":"user.tokens.permission_groups","methodName":"list","snippet":"data \"cloudflare_api_token_permission_groups_list\" \"example_api_token_permission_groups_list\" {\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}\n","required":[],"optional":[{"name":"name","type":"String","description":"Filter by the name of the permission group.\nThe value must be URL-encoded."},{"name":"scope","type":"String","description":"Filter by the scope of the permission group.\nThe value must be URL-encoded."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Public ID."},{"name":"category","type":"String","description":"Product category that this permission group belongs to."},{"name":"is_selectable","type":"Bool","description":"Whether the caller can select this permission group when creating a token."},{"name":"name","type":"String","description":"Permission Group Name"},{"name":"scopes","type":"List[String]","description":"Resources to which the Permission Group is scoped"}]}]}]},"get /zones":{"operationId":"zones-get","declarations":[{"kind":"list-data-source","name":"cloudflare_zones","stainlessResource":"zones","methodName":"list","snippet":"data \"cloudflare_zones\" \"example_zones\" {\n account = {\n id = \"id\"\n name = \"name\"\n }\n direction = \"desc\"\n name = \"name\"\n order = \"status\"\n status = \"initializing\"\n type = [\"full\"]\n}\n","required":[],"optional":[{"name":"direction","type":"String","description":"Direction to order zones."},{"name":"name","type":"String","description":"A domain name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"},{"name":"order","type":"String","description":"Field to order zones by."},{"name":"status","type":"String","description":"Specify a zone status to filter by."},{"name":"type","type":"List[String]","description":"Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type \"internal\" are excluded from the results."},{"name":"account","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter by an account ID."},{"name":"name","type":"String","description":"An account Name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"}]},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"account","type":"Attributes","description":"The account the zone belongs to.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the account."}]},{"name":"activated_on","type":"Time","description":"The last time proof of ownership was detected and the zone was made\nactive."},{"name":"created_on","type":"Time","description":"When the zone was created."},{"name":"development_mode","type":"Float64","description":"The interval (in seconds) from when development mode expires\n(positive integer) or last expired (negative integer) for the\ndomain. If development mode has never been enabled, this value is 0."},{"name":"meta","type":"Attributes","description":"Metadata about the zone.","children":[{"name":"cdn_only","type":"Bool","description":"The zone is only configured for CDN."},{"name":"custom_certificate_quota","type":"Int64","description":"Number of Custom Certificates the zone can have."},{"name":"dns_only","type":"Bool","description":"The zone is only configured for DNS."},{"name":"foundation_dns","type":"Bool","description":"The zone is setup with Foundation DNS."},{"name":"page_rule_quota","type":"Int64","description":"Number of Page Rules a zone can have."},{"name":"phishing_detected","type":"Bool","description":"The zone has been flagged for phishing."},{"name":"step","type":"Int64"}]},{"name":"modified_on","type":"Time","description":"When the zone was last modified."},{"name":"name","type":"String","description":"The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment (\"label\") not exceeding 63 characters."},{"name":"name_servers","type":"List[String]","description":"The name servers Cloudflare assigns to a zone."},{"name":"original_dnshost","type":"String","description":"DNS host at the time of switching to Cloudflare."},{"name":"original_name_servers","type":"List[String]","description":"Original name servers before moving to Cloudflare."},{"name":"original_registrar","type":"String","description":"Registrar for the domain at the time of switching to Cloudflare."},{"name":"owner","type":"Attributes","description":"The owner of the zone.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Name of the owner."},{"name":"type","type":"String","description":"The type of owner."}]},{"name":"plan","type":"Attributes","description":"A Zones subscription information.","deprecated":"Please use the `/zones/{zone_id}/subscription` API\nto update a zone's plan. Changing this value will create/cancel\nassociated subscriptions. To view available plans for this zone,\nsee [Zone Plans](https://developers.cloudflare.com/api/resources/zones/subresources/plans/).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"can_subscribe","type":"Bool","description":"States if the subscription can be activated."},{"name":"currency","type":"String","description":"The denomination of the customer."},{"name":"externally_managed","type":"Bool","description":"If this Zone is managed by another company."},{"name":"frequency","type":"String","description":"How often the customer is billed."},{"name":"is_subscribed","type":"Bool","description":"States if the subscription active."},{"name":"legacy_discount","type":"Bool","description":"If the legacy discount applies to this Zone."},{"name":"legacy_id","type":"String","description":"The legacy name of the plan."},{"name":"name","type":"String","description":"Name of the owner."},{"name":"price","type":"Float64","description":"How much the customer is paying."}]},{"name":"cname_suffix","type":"String","description":"Allows the customer to use a custom apex.\n*Tenants Only Configuration*."},{"name":"paused","type":"Bool","description":"Indicates whether the zone is only using Cloudflare DNS services. A\ntrue value means the zone will not receive security or performance\nbenefits.\n"},{"name":"permissions","type":"List[String]","description":"Legacy permissions based on legacy user membership information.","deprecated":"This has been replaced by Account memberships."},{"name":"status","type":"String","description":"The zone status on Cloudflare."},{"name":"tenant","type":"Attributes","description":"The root organizational unit that this zone belongs to (such as a tenant or organization).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the Tenant account."}]},{"name":"tenant_unit","type":"Attributes","description":"The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization).","children":[{"name":"id","type":"String","description":"Identifier"}]},{"name":"type","type":"String","description":"A full zone implies that DNS is hosted with Cloudflare. A partial zone is\ntypically a partner-hosted zone or a CNAME setup.\n"},{"name":"vanity_name_servers","type":"List[String]","description":"An array of domains used for custom name servers. This is only available for Business and Enterprise plans."},{"name":"verification_key","type":"String","description":"Verification key for partial zone setup."}]}]}]},"get /zones/{}":{"operationId":"zones-0-get","declarations":[{"kind":"data-source","name":"cloudflare_zone","stainlessResource":"zones","methodName":"get","snippet":"data \"cloudflare_zone\" \"example_zone\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[],"optional":[{"name":"zone_id","type":"String","description":"Identifier"},{"name":"filter","type":"Attributes","children":[{"name":"account","type":"Attributes","children":[{"name":"id","type":"String","description":"Filter by an account ID."},{"name":"name","type":"String","description":"An account Name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"}]},{"name":"direction","type":"String","description":"Direction to order zones."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"name","type":"String","description":"A domain name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`\n"},{"name":"order","type":"String","description":"Field to order zones by."},{"name":"status","type":"String","description":"Specify a zone status to filter by."},{"name":"type","type":"List[String]","description":"Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type \"internal\" are excluded from the results."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"activated_on","type":"Time","description":"The last time proof of ownership was detected and the zone was made\nactive."},{"name":"cname_suffix","type":"String","description":"Allows the customer to use a custom apex.\n*Tenants Only Configuration*."},{"name":"created_on","type":"Time","description":"When the zone was created."},{"name":"development_mode","type":"Float64","description":"The interval (in seconds) from when development mode expires\n(positive integer) or last expired (negative integer) for the\ndomain. If development mode has never been enabled, this value is 0."},{"name":"modified_on","type":"Time","description":"When the zone was last modified."},{"name":"name","type":"String","description":"The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment (\"label\") not exceeding 63 characters."},{"name":"original_dnshost","type":"String","description":"DNS host at the time of switching to Cloudflare."},{"name":"original_registrar","type":"String","description":"Registrar for the domain at the time of switching to Cloudflare."},{"name":"paused","type":"Bool","description":"Indicates whether the zone is only using Cloudflare DNS services. A\ntrue value means the zone will not receive security or performance\nbenefits.\n"},{"name":"status","type":"String","description":"The zone status on Cloudflare."},{"name":"type","type":"String","description":"A full zone implies that DNS is hosted with Cloudflare. A partial zone is\ntypically a partner-hosted zone or a CNAME setup.\n"},{"name":"verification_key","type":"String","description":"Verification key for partial zone setup."},{"name":"name_servers","type":"List[String]","description":"The name servers Cloudflare assigns to a zone."},{"name":"original_name_servers","type":"List[String]","description":"Original name servers before moving to Cloudflare."},{"name":"permissions","type":"List[String]","description":"Legacy permissions based on legacy user membership information.","deprecated":"This has been replaced by Account memberships."},{"name":"vanity_name_servers","type":"List[String]","description":"An array of domains used for custom name servers. This is only available for Business and Enterprise plans."},{"name":"account","type":"Attributes","description":"The account the zone belongs to.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the account."}]},{"name":"meta","type":"Attributes","description":"Metadata about the zone.","children":[{"name":"cdn_only","type":"Bool","description":"The zone is only configured for CDN."},{"name":"custom_certificate_quota","type":"Int64","description":"Number of Custom Certificates the zone can have."},{"name":"dns_only","type":"Bool","description":"The zone is only configured for DNS."},{"name":"foundation_dns","type":"Bool","description":"The zone is setup with Foundation DNS."},{"name":"page_rule_quota","type":"Int64","description":"Number of Page Rules a zone can have."},{"name":"phishing_detected","type":"Bool","description":"The zone has been flagged for phishing."},{"name":"step","type":"Int64"}]},{"name":"owner","type":"Attributes","description":"The owner of the zone.","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Name of the owner."},{"name":"type","type":"String","description":"The type of owner."}]},{"name":"plan","type":"Attributes","description":"A Zones subscription information.","deprecated":"Please use the `/zones/{zone_id}/subscription` API\nto update a zone's plan. Changing this value will create/cancel\nassociated subscriptions. To view available plans for this zone,\nsee [Zone Plans](https://developers.cloudflare.com/api/resources/zones/subresources/plans/).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"can_subscribe","type":"Bool","description":"States if the subscription can be activated."},{"name":"currency","type":"String","description":"The denomination of the customer."},{"name":"externally_managed","type":"Bool","description":"If this Zone is managed by another company."},{"name":"frequency","type":"String","description":"How often the customer is billed."},{"name":"is_subscribed","type":"Bool","description":"States if the subscription active."},{"name":"legacy_discount","type":"Bool","description":"If the legacy discount applies to this Zone."},{"name":"legacy_id","type":"String","description":"The legacy name of the plan."},{"name":"name","type":"String","description":"Name of the owner."},{"name":"price","type":"Float64","description":"How much the customer is paying."}]},{"name":"tenant","type":"Attributes","description":"The root organizational unit that this zone belongs to (such as a tenant or organization).","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"The name of the Tenant account."}]},{"name":"tenant_unit","type":"Attributes","description":"The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization).","children":[{"name":"id","type":"String","description":"Identifier"}]}]}]},"get /zones/{}/acm/custom_trust_store":{"operationId":"custom-origin-trust-store-list-details","declarations":[{"kind":"list-data-source","name":"cloudflare_custom_origin_trust_stores","stainlessResource":"acm.custom_trust_store","methodName":"list","snippet":"data \"cloudflare_custom_origin_trust_stores\" \"example_custom_origin_trust_stores\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Certificate identifier tag."},{"name":"certificate","type":"String","description":"The root CA certificate in PEM format. Only root CA certificates are accepted; intermediate and leaf certificates are not supported."},{"name":"expires_on","type":"Time","description":"When the certificate expires."},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"updated_at","type":"Time","description":"When the certificate was last modified."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."}]}]}]},"get /zones/{}/acm/custom_trust_store/{}":{"operationId":"custom-origin-trust-store-details","declarations":[{"kind":"data-source","name":"cloudflare_custom_origin_trust_store","stainlessResource":"acm.custom_trust_store","methodName":"get","snippet":"data \"cloudflare_custom_origin_trust_store\" \"example_custom_origin_trust_store\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_origin_trust_store_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"custom_origin_trust_store_id","type":"String","description":"Certificate identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."}]}],"computed":[{"name":"id","type":"String","description":"Certificate identifier tag."},{"name":"certificate","type":"String","description":"The root CA certificate in PEM format. Only root CA certificates are accepted; intermediate and leaf certificates are not supported."},{"name":"expires_on","type":"Time","description":"When the certificate expires."},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"updated_at","type":"Time","description":"When the certificate was last modified."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."}]}]},"get /zones/{}/acm/total_tls":{"operationId":"total-tls-total-tls-settings-details","declarations":[{"kind":"data-source","name":"cloudflare_total_tls","stainlessResource":"acm.total_tls","methodName":"get","snippet":"data \"cloudflare_total_tls\" \"example_total_tls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"certificate_authority","type":"String","description":"The Certificate Authority that Total TLS certificates will be issued through."},{"name":"enabled","type":"Bool","description":"If enabled, Total TLS will order a hostname specific TLS certificate for any proxied A, AAAA, or CNAME record in your zone."},{"name":"validity_period","type":"Int64","description":"The validity period in days for the certificates ordered via Total TLS."}]}]},"get /zones/{}/addressing/regional_hostnames":{"operationId":"dls-zone-regional-hostnames-list","declarations":[{"kind":"list-data-source","name":"cloudflare_regional_hostnames","stainlessResource":"addressing.regional_hostnames","methodName":"list","snippet":"data \"cloudflare_regional_hostnames\" \"example_regional_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"created_on","type":"Time","description":"When the regional hostname was created"},{"name":"hostname","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"region_key","type":"String","description":"Identifying key for the region"},{"name":"routing","type":"String","description":"Configure which routing method to use for the regional hostname"}]}]}]},"get /zones/{}/addressing/regional_hostnames/{}":{"operationId":"dls-zone-regional-hostnames-fetch","declarations":[{"kind":"data-source","name":"cloudflare_regional_hostname","stainlessResource":"addressing.regional_hostnames","methodName":"get","snippet":"data \"cloudflare_regional_hostname\" \"example_regional_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"foo.example.com\"\n}\n","required":[{"name":"hostname","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`"},{"name":"created_on","type":"Time","description":"When the regional hostname was created"},{"name":"region_key","type":"String","description":"Identifying key for the region"},{"name":"routing","type":"String","description":"Configure which routing method to use for the regional hostname"}]}]},"get /zones/{}/api_gateway/configuration":{"operationId":"api-shield-settings-retrieve-information-about-specific-configuration-properties","declarations":[{"kind":"data-source","name":"cloudflare_api_shield","stainlessResource":"api_gateway.configurations","methodName":"get","snippet":"data \"cloudflare_api_shield\" \"example_api_shield\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n normalize = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"normalize","type":"Bool","description":"Ensures that the configuration is written or retrieved in normalized fashion"}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"auth_id_characteristics","type":"List[Attributes]","children":[{"name":"name","type":"String","description":"The name of the characteristic field, i.e., the header or cookie name."},{"name":"type","type":"String","description":"The type of characteristic."}]}]}]},"get /zones/{}/api_gateway/discovery/operations":{"operationId":"api-shield-api-discovery-retrieve-discovered-operations-on-a-zone","declarations":[{"kind":"list-data-source","name":"cloudflare_api_shield_discovery_operations","stainlessResource":"api_gateway.discovery.operations","methodName":"list","snippet":"data \"cloudflare_api_shield_discovery_operations\" \"example_api_shield_discovery_operations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n diff = true\n direction = \"desc\"\n endpoint = \"/api/v1\"\n host = [\"api.cloudflare.com\"]\n method = [\"GET\"]\n order = \"method\"\n origin = \"ML\"\n state = \"review\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"diff","type":"Bool","description":"When `true`, only return API Discovery results that are not saved into API Shield Endpoint Management"},{"name":"direction","type":"String","description":"Direction to order results."},{"name":"endpoint","type":"String","description":"Filter results to only include endpoints containing this pattern."},{"name":"order","type":"String","description":"Field to order by"},{"name":"origin","type":"String","description":"Filter results to only include discovery results sourced from a particular discovery engine\n * `ML` - Discovered operations that were sourced using ML API Discovery\n * `SessionIdentifier` - Discovered operations that were sourced using Session Identifier API Discovery\n"},{"name":"state","type":"String","description":"Filter results to only include discovery results in a particular state. States are as follows\n * `review` - Discovered operations that are not saved into API Shield Endpoint Management\n * `saved` - Discovered operations that are already saved into API Shield Endpoint Management\n * `ignored` - Discovered operations that have been marked as ignored\n"},{"name":"host","type":"List[String]","description":"Filter results to only include the specified hosts."},{"name":"method","type":"List[String]","description":"Filter results to only include the specified HTTP methods."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"endpoint","type":"String","description":"The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/."},{"name":"host","type":"String","description":"RFC3986-compliant host."},{"name":"last_updated","type":"Time"},{"name":"method","type":"String","description":"The HTTP method used to access the endpoint."},{"name":"origin","type":"List[String]","description":"API discovery engine(s) that discovered this operation"},{"name":"state","type":"String","description":"State of operation in API Discovery\n * `review` - Operation is not saved into API Shield Endpoint Management\n * `saved` - Operation is saved into API Shield Endpoint Management\n * `ignored` - Operation is marked as ignored\n"},{"name":"features","type":"Attributes","children":[{"name":"traffic_stats","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"period_seconds","type":"Int64","description":"The period in seconds these statistics were computed over"},{"name":"requests","type":"Float64","description":"The average number of requests seen during this period"}]}]}]}]}]},"get /zones/{}/api_gateway/operations":{"operationId":"api-shield-endpoint-management-retrieve-information-about-all-operations-on-a-zone","declarations":[{"kind":"list-data-source","name":"cloudflare_api_shield_operations","stainlessResource":"api_gateway.operations","methodName":"list","snippet":"data \"cloudflare_api_shield_operations\" \"example_api_shield_operations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n endpoint = \"/api/v1\"\n feature = [\"thresholds\"]\n host = [\"api.cloudflare.com\"]\n method = [\"GET\"]\n order = \"method\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"endpoint","type":"String","description":"Filter results to only include endpoints containing this pattern."},{"name":"order","type":"String","description":"Field to order by. When requesting a feature, the feature keys are available for ordering as well, e.g., `thresholds.suggested_threshold`."},{"name":"feature","type":"List[String]","description":"Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning."},{"name":"host","type":"List[String]","description":"Filter results to only include the specified hosts."},{"name":"method","type":"List[String]","description":"Filter results to only include the specified HTTP methods."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"endpoint","type":"String","description":"The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/."},{"name":"host","type":"String","description":"RFC3986-compliant host."},{"name":"last_updated","type":"Time"},{"name":"method","type":"String","description":"The HTTP method used to access the endpoint."},{"name":"operation_id","type":"String","description":"UUID."},{"name":"features","type":"Attributes","children":[{"name":"thresholds","type":"Attributes","children":[{"name":"auth_id_tokens","type":"Int64","description":"The total number of auth-ids seen across this calculation."},{"name":"data_points","type":"Int64","description":"The number of data points used for the threshold suggestion calculation."},{"name":"last_updated","type":"Time"},{"name":"p50","type":"Int64","description":"The p50 quantile of requests (in period_seconds)."},{"name":"p90","type":"Int64","description":"The p90 quantile of requests (in period_seconds)."},{"name":"p99","type":"Int64","description":"The p99 quantile of requests (in period_seconds)."},{"name":"period_seconds","type":"Int64","description":"The period over which this threshold is suggested."},{"name":"requests","type":"Int64","description":"The estimated number of requests covered by these calculations."},{"name":"suggested_threshold","type":"Int64","description":"The suggested threshold in requests done by the same auth_id or period_seconds."}]},{"name":"parameter_schemas","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"parameter_schemas","type":"Attributes","description":"An operation schema object containing a response.","children":[{"name":"parameters","type":"List[unknown]","description":"An array containing the learned parameter schemas."},{"name":"responses","type":"unknown","description":"An empty response object. This field is required to yield a valid operation schema."}]}]},{"name":"api_routing","type":"Attributes","description":"API Routing settings on endpoint.","children":[{"name":"last_updated","type":"Time"},{"name":"route","type":"String","description":"Target route."}]},{"name":"confidence_intervals","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"suggested_threshold","type":"Attributes","children":[{"name":"confidence_intervals","type":"Attributes","children":[{"name":"p90","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p95","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p99","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]}]},{"name":"mean","type":"Float64","description":"Suggested threshold."}]}]},{"name":"schema_info","type":"Attributes","children":[{"name":"active_schema","type":"Attributes","description":"Schema active on endpoint.","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"Schema file name."}]},{"name":"mitigation_action","type":"String","description":"Action taken on requests failing validation."}]}]}]}]}]},"get /zones/{}/api_gateway/operations/{}":{"operationId":"api-shield-endpoint-management-retrieve-information-about-an-operation","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_operation","stainlessResource":"api_gateway.operations","methodName":"get","snippet":"data \"cloudflare_api_shield_operation\" \"example_api_shield_operation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n feature = [\"thresholds\"]\n with_schemas = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"operation_id","type":"String","description":"UUID."},{"name":"feature","type":"List[String]","description":"Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning."},{"name":"with_schemas","type":"Bool","description":"When true, includes OpenAPI schemas (both uploaded and learned) for the operation in the response. Due to the conversion overhead, this parameter is only supported on single-operation retrieval."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Direction to order results."},{"name":"endpoint","type":"String","description":"Filter results to only include endpoints containing this pattern."},{"name":"feature","type":"List[String]","description":"Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning."},{"name":"host","type":"List[String]","description":"Filter results to only include the specified hosts."},{"name":"method","type":"List[String]","description":"Filter results to only include the specified HTTP methods."},{"name":"order","type":"String","description":"Field to order by. When requesting a feature, the feature keys are available for ordering as well, e.g., `thresholds.suggested_threshold`."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"endpoint","type":"String","description":"The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/."},{"name":"host","type":"String","description":"RFC3986-compliant host."},{"name":"last_updated","type":"Time"},{"name":"method","type":"String","description":"The HTTP method used to access the endpoint."},{"name":"features","type":"Attributes","children":[{"name":"thresholds","type":"Attributes","children":[{"name":"auth_id_tokens","type":"Int64","description":"The total number of auth-ids seen across this calculation."},{"name":"data_points","type":"Int64","description":"The number of data points used for the threshold suggestion calculation."},{"name":"last_updated","type":"Time"},{"name":"p50","type":"Int64","description":"The p50 quantile of requests (in period_seconds)."},{"name":"p90","type":"Int64","description":"The p90 quantile of requests (in period_seconds)."},{"name":"p99","type":"Int64","description":"The p99 quantile of requests (in period_seconds)."},{"name":"period_seconds","type":"Int64","description":"The period over which this threshold is suggested."},{"name":"requests","type":"Int64","description":"The estimated number of requests covered by these calculations."},{"name":"suggested_threshold","type":"Int64","description":"The suggested threshold in requests done by the same auth_id or period_seconds."}]},{"name":"parameter_schemas","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"parameter_schemas","type":"Attributes","description":"An operation schema object containing a response.","children":[{"name":"parameters","type":"List[unknown]","description":"An array containing the learned parameter schemas."},{"name":"responses","type":"unknown","description":"An empty response object. This field is required to yield a valid operation schema."}]}]},{"name":"api_routing","type":"Attributes","description":"API Routing settings on endpoint.","children":[{"name":"last_updated","type":"Time"},{"name":"route","type":"String","description":"Target route."}]},{"name":"confidence_intervals","type":"Attributes","children":[{"name":"last_updated","type":"Time"},{"name":"suggested_threshold","type":"Attributes","children":[{"name":"confidence_intervals","type":"Attributes","children":[{"name":"p90","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p95","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]},{"name":"p99","type":"Attributes","description":"Upper and lower bound for percentile estimate","children":[{"name":"lower","type":"Float64","description":"Lower bound for percentile estimate"},{"name":"upper","type":"Float64","description":"Upper bound for percentile estimate"}]}]},{"name":"mean","type":"Float64","description":"Suggested threshold."}]}]},{"name":"schema_info","type":"Attributes","children":[{"name":"active_schema","type":"Attributes","description":"Schema active on endpoint.","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"name","type":"String","description":"Schema file name."}]},{"name":"mitigation_action","type":"String","description":"Action taken on requests failing validation."}]}]},{"name":"schemas","type":"Attributes","description":"OpenAPI JSON schemas for an operation, including both user-uploaded and Cloudflare-learned schemas.","children":[{"name":"learned","type":"Attributes","description":"An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.","children":[{"name":"parameters","type":"List[Map[unknown]]","description":"OpenAPI parameter objects describing path, query, header, or cookie parameters."},{"name":"request_body","type":"Map[unknown]","description":"OpenAPI request body object describing the expected request payload."}]},{"name":"uploaded","type":"Attributes","description":"An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.","children":[{"name":"parameters","type":"List[Map[unknown]]","description":"OpenAPI parameter objects describing path, query, header, or cookie parameters."},{"name":"request_body","type":"Map[unknown]","description":"OpenAPI request body object describing the expected request payload."}]}]}]}]},"get /zones/{}/api_gateway/operations/{}/schema_validation":{"operationId":"api-shield-schema-validation-retrieve-operation-level-settings","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_operation_schema_validation_settings","stainlessResource":"api_gateway.operations.schema_validation","methodName":"get","snippet":"data \"cloudflare_api_shield_operation_schema_validation_settings\" \"example_api_shield_operation_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation\n\n - `log` log request when request does not conform to schema for this operation\n - `block` deny access to the site when request does not conform to schema for this operation\n - `none` will skip mitigation for this operation\n - `null` indicates that no operation level mitigation is in place, see Zone Level Schema Validation Settings for mitigation action that will be applied\n"}]}]},"get /zones/{}/api_gateway/settings/schema_validation":{"operationId":"api-shield-schema-validation-retrieve-zone-level-settings","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_schema_validation_settings","stainlessResource":"api_gateway.settings.schema_validation","methodName":"get","snippet":"data \"cloudflare_api_shield_schema_validation_settings\" \"example_api_shield_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used when there is no mitigation action defined on the operation\n\nMitigation actions are as follows:\n\n * `log` - log request when request does not conform to schema\n * `block` - deny access to the site when request does not conform to schema\n\nA special value of of `none` will skip running schema validation entirely for the request when there is no mitigation action defined on the operation\n"},{"name":"validation_override_mitigation_action","type":"String","description":"When set, this overrides both zone level and operation level mitigation actions.\n\n - `none` will skip running schema validation entirely for the request\n - `null` indicates that no override is in place\n"}]}]},"get /zones/{}/api_gateway/user_schemas":{"operationId":"api-shield-schema-validation-retrieve-information-about-all-schemas","declarations":[{"kind":"list-data-source","name":"cloudflare_api_shield_schemas","stainlessResource":"api_gateway.user_schemas","methodName":"list","snippet":"data \"cloudflare_api_shield_schemas\" \"example_api_shield_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"validation_enabled","type":"Bool","description":"Flag whether schema is enabled for validation."},{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"Kind of schema"},{"name":"name","type":"String","description":"Name of the schema"},{"name":"schema_id","type":"String","description":"UUID."},{"name":"source","type":"String","description":"Source of the schema"},{"name":"validation_enabled","type":"Bool","description":"Flag whether schema is enabled for validation."}]}]}]},"get /zones/{}/api_gateway/user_schemas/{}":{"operationId":"api-shield-schema-validation-retrieve-information-about-specific-schema","declarations":[{"kind":"data-source","name":"cloudflare_api_shield_schema","stainlessResource":"api_gateway.user_schemas","methodName":"get","snippet":"data \"cloudflare_api_shield_schema\" \"example_api_shield_schema\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n schema_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n omit_source = true\n}\n","required":[{"name":"schema_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."}],"computed":[{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"Kind of schema"},{"name":"name","type":"String","description":"Name of the schema"},{"name":"source","type":"String","description":"Source of the schema"},{"name":"validation_enabled","type":"Bool","description":"Flag whether schema is enabled for validation."}]}]},"get /zones/{}/argo/smart_routing":{"operationId":"argo-smart-routing-get-argo-smart-routing-setting","declarations":[{"kind":"data-source","name":"cloudflare_argo_smart_routing","stainlessResource":"argo.smart_routing","methodName":"get","snippet":"data \"cloudflare_argo_smart_routing\" \"example_argo_smart_routing\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specifies the zone associated with the API call."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the zone associated with the API call."},{"name":"editable","type":"Bool","description":"Specifies if the setting is editable."},{"name":"modified_on","type":"Time","description":"Specifies the time when the setting was last modified."},{"name":"value","type":"String","description":"Specifies the enablement value of Argo Smart Routing."}]}]},"get /zones/{}/argo/tiered_caching":{"operationId":"tiered-caching-get-tiered-caching-setting","declarations":[{"kind":"data-source","name":"cloudflare_argo_tiered_caching","stainlessResource":"argo.tiered_caching","methodName":"get","snippet":"data \"cloudflare_argo_tiered_caching\" \"example_argo_tiered_caching\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Tiered Cache zone setting."}]}]},"get /zones/{}/bot_management":{"operationId":"bot-management-for-a-zone-get-config","declarations":[{"kind":"data-source","name":"cloudflare_bot_management","stainlessResource":"bot_management","methodName":"get","snippet":"data \"cloudflare_bot_management\" \"example_bot_management\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"ai_bots_migration_opt_out","type":"Bool","description":"Temporary migration flag tracking zones opted out of AI bots managed-rule updates."},{"name":"ai_bots_protection","type":"String","description":"Enable rule to block AI Scrapers and Crawlers."},{"name":"ai_training","type":"String","description":"Configure robots.txt policy for AI model training bots."},{"name":"ai_user","type":"String","description":"Configure robots.txt policy for AI assistant and agent bots."},{"name":"aisearch","type":"String","description":"Configure robots.txt policy for AI search bots."},{"name":"auto_update_model","type":"Bool","description":"Automatically update to the newest bot detection models created by Cloudflare as they are released. [Learn more.](https://developers.cloudflare.com/bots/reference/machine-learning-models#model-versions-and-release-notes)"},{"name":"bm_cookie_enabled","type":"Bool","description":"Indicates that the bot management cookie can be placed on end user devices accessing the site. Defaults to true"},{"name":"bot_preference_sync_enabled","type":"Bool","description":"Enable Bot Preference Sync for this zone. When enabled, Cloudflare can serve robots.txt content derived from the zone's AI Search, AI User, and AI Training preferences."},{"name":"cf_robots_variant","type":"String","description":"Specifies the Robots Access Control License variant to use."},{"name":"content_bots_protection","type":"String","description":"Enable rule to block content bots. When enabled, blocks automated traffic with low bot scores, excluding safe verified bot categories. Exceptions should be managed via skip rules."},{"name":"crawler_protection","type":"String","description":"Enable rule to punish AI Scrapers and Crawlers via a link maze."},{"name":"enable_js","type":"Bool","description":"Use lightweight, invisible JavaScript detections to improve Bot Management. [Learn more about JavaScript Detections](https://developers.cloudflare.com/bots/reference/javascript-detections/)."},{"name":"fight_mode","type":"Bool","description":"Whether to enable Bot Fight Mode."},{"name":"is_robots_txt_managed","type":"Bool","description":"Enable cloudflare managed robots.txt. If an existing robots.txt is detected, then managed robots.txt will be prepended to the existing robots.txt."},{"name":"jsd_api_results_enabled","type":"Bool","description":"Whether to use JavaScript Detection results submitted through the API for this zone."},{"name":"optimize_wordpress","type":"Bool","description":"Whether to optimize Super Bot Fight Mode protections for Wordpress."},{"name":"sbfm_definitely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on definitely automated requests."},{"name":"sbfm_likely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on likely automated requests."},{"name":"sbfm_static_resource_protection","type":"Bool","description":"Super Bot Fight Mode (SBFM) to enable static resource protection.\nEnable if static resources on your application need bot protection.\nNote: Static resource protection can also result in legitimate traffic being blocked.\n"},{"name":"sbfm_verified_bots","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on verified bots requests."},{"name":"suppress_session_score","type":"Bool","description":"Whether to disable tracking the highest bot score for a session in the Bot Management cookie."},{"name":"using_latest_model","type":"Bool","description":"A read-only field that indicates whether the zone currently is running the latest ML model.\n"},{"name":"stale_zone_configuration","type":"Attributes","description":"A read-only field that shows which unauthorized settings are currently active on the zone. These settings typically result from upgrades or downgrades.","children":[{"name":"optimize_wordpress","type":"Bool","description":"Indicates that the zone's wordpress optimization for SBFM is turned on."},{"name":"sbfm_definitely_automated","type":"String","description":"Indicates that the zone's definitely automated requests are being blocked or challenged."},{"name":"sbfm_likely_automated","type":"String","description":"Indicates that the zone's likely automated requests are being blocked or challenged."},{"name":"sbfm_static_resource_protection","type":"String","description":"Indicates that the zone's static resource protection is turned on."},{"name":"sbfm_verified_bots","type":"String","description":"Indicates that the zone's verified bot requests are being blocked."},{"name":"suppress_session_score","type":"Bool","description":"Indicates that the zone's session score tracking is disabled."},{"name":"fight_mode","type":"Bool","description":"Indicates that the zone's Bot Fight Mode is turned on."}]}]}]},"get /zones/{}/cache/cache_reserve":{"operationId":"zone-cache-settings-get-cache-reserve-setting","declarations":[{"kind":"data-source","name":"cloudflare_zone_cache_reserve","stainlessResource":"cache.cache_reserve","methodName":"get","snippet":"data \"cloudflare_zone_cache_reserve\" \"example_zone_cache_reserve\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Cache Reserve zone setting."}]}]},"get /zones/{}/cache/regional_tiered_cache":{"operationId":"zone-cache-settings-get-regional-tiered-cache-setting","declarations":[{"kind":"data-source","name":"cloudflare_regional_tiered_cache","stainlessResource":"cache.regional_tiered_cache","methodName":"get","snippet":"data \"cloudflare_regional_tiered_cache\" \"example_regional_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Regional Tiered Cache zone setting."}]}]},"get /zones/{}/cache/tiered_cache_smart_topology_enable":{"operationId":"smart-tiered-cache-get-smart-tiered-cache-setting","declarations":[{"kind":"data-source","name":"cloudflare_tiered_cache","stainlessResource":"cache.smart_tiered_cache","methodName":"get","snippet":"data \"cloudflare_tiered_cache\" \"example_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"String","description":"Value of the Smart Tiered Cache zone setting."}]}]},"get /zones/{}/cache/variants":{"operationId":"zone-cache-settings-get-variants-setting","declarations":[{"kind":"data-source","name":"cloudflare_zone_cache_variants","stainlessResource":"cache.variants","methodName":"get","snippet":"data \"cloudflare_zone_cache_variants\" \"example_zone_cache_variants\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"Attributes","description":"Value of the zone setting.","children":[{"name":"avif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for avif."},{"name":"bmp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for bmp."},{"name":"gif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for gif."},{"name":"jp2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jp2."},{"name":"jpeg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpeg."},{"name":"jpg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg."},{"name":"jpg2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg2."},{"name":"png","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for png."},{"name":"tif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tif."},{"name":"tiff","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tiff."},{"name":"webp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for webp."}]}]}]},"get /zones/{}/certificate_authorities/hostname_associations":{"operationId":"client-certificate-for-a-zone-list-hostname-associations","declarations":[{"kind":"data-source","name":"cloudflare_certificate_authorities_hostname_associations","stainlessResource":"certificate_authorities.hostname_associations","methodName":"get","snippet":"data \"cloudflare_certificate_authorities_hostname_associations\" \"example_certificate_authorities_hostname_associations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n mtls_certificate_id = \"b2134436-2555-4acf-be5b-26c48136575e\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"mtls_certificate_id","type":"String","description":"The UUID to match against for a certificate that was uploaded to the mTLS Certificate Management endpoint. If no mtls_certificate_id is given, the results will be the hostnames associated to your active Cloudflare Managed CA."}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"hostnames","type":"List[String]"}]}]},"get /zones/{}/client_certificates":{"operationId":"client-certificate-for-a-zone-list-client-certificates","declarations":[{"kind":"list-data-source","name":"cloudflare_client_certificates","stainlessResource":"client_certificates","methodName":"list","snippet":"data \"cloudflare_client_certificates\" \"example_client_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n status = \"all\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"status","type":"String","description":"Client Certitifcate Status to filter results by."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Client Certificate Tag"},{"name":"certificate","type":"String","description":"The Client Certificate PEM."},{"name":"certificate_authority","type":"Attributes","description":"Certificate Authority used to issue the Client Certificate.","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"common_name","type":"String","description":"Common Name of the Client Certificate."},{"name":"country","type":"String","description":"Country, provided by the CSR."},{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"expires_on","type":"String","description":"Date that the Client Certificate expires."},{"name":"fingerprint_sha256","type":"String","description":"Unique identifier of the Client Certificate."},{"name":"issued_on","type":"String","description":"Date that the Client Certificate was issued by the Certificate Authority."},{"name":"location","type":"String","description":"Location, provided by the CSR."},{"name":"organization","type":"String","description":"Organization, provided by the CSR."},{"name":"organizational_unit","type":"String","description":"Organizational Unit, provided by the CSR."},{"name":"serial_number","type":"String","description":"The serial number on the created Client Certificate."},{"name":"signature","type":"String","description":"The type of hash used for the Client Certificate.."},{"name":"ski","type":"String","description":"Subject Key Identifier."},{"name":"state","type":"String","description":"State, provided by the CSR."},{"name":"status","type":"String","description":"Client Certificates may be active or revoked, and the pending_reactivation or pending_revocation represent in-progress asynchronous transitions."},{"name":"validity_days","type":"Int64","description":"The number of days the Client Certificate will be valid after the issued_on date."}]}]}]},"get /zones/{}/client_certificates/{}":{"operationId":"client-certificate-for-a-zone-client-certificate-details","declarations":[{"kind":"data-source","name":"cloudflare_client_certificate","stainlessResource":"client_certificates","methodName":"get","snippet":"data \"cloudflare_client_certificate\" \"example_client_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n client_certificate_id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"client_certificate_id","type":"String","description":"Client Certificate Tag"},{"name":"filter","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Limit to the number of records returned."},{"name":"offset","type":"Int64","description":"Offset the results."},{"name":"status","type":"String","description":"Client Certitifcate Status to filter results by."}]}],"computed":[{"name":"id","type":"String","description":"Client Certificate Tag"},{"name":"certificate","type":"String","description":"The Client Certificate PEM."},{"name":"common_name","type":"String","description":"Common Name of the Client Certificate."},{"name":"country","type":"String","description":"Country, provided by the CSR."},{"name":"csr","type":"String","description":"The Certificate Signing Request (CSR). Must be newline-encoded."},{"name":"expires_on","type":"String","description":"Date that the Client Certificate expires."},{"name":"fingerprint_sha256","type":"String","description":"Unique identifier of the Client Certificate."},{"name":"issued_on","type":"String","description":"Date that the Client Certificate was issued by the Certificate Authority."},{"name":"location","type":"String","description":"Location, provided by the CSR."},{"name":"organization","type":"String","description":"Organization, provided by the CSR."},{"name":"organizational_unit","type":"String","description":"Organizational Unit, provided by the CSR."},{"name":"serial_number","type":"String","description":"The serial number on the created Client Certificate."},{"name":"signature","type":"String","description":"The type of hash used for the Client Certificate.."},{"name":"ski","type":"String","description":"Subject Key Identifier."},{"name":"state","type":"String","description":"State, provided by the CSR."},{"name":"status","type":"String","description":"Client Certificates may be active or revoked, and the pending_reactivation or pending_revocation represent in-progress asynchronous transitions."},{"name":"validity_days","type":"Int64","description":"The number of days the Client Certificate will be valid after the issued_on date."},{"name":"certificate_authority","type":"Attributes","description":"Certificate Authority used to issue the Client Certificate.","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]}]}]},"get /zones/{}/cloud_connector/rules":{"operationId":"zone-cloud-connector-rules","declarations":[{"kind":"data-source","name":"cloudflare_cloud_connector_rules","stainlessResource":"cloud_connector.rules","methodName":"list","snippet":"data \"cloudflare_cloud_connector_rules\" \"example_cloud_connector_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"cloud_connector_rules_provider","type":"String","description":"Cloud Provider type"},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String"},{"name":"parameters","type":"Attributes","description":"Parameters of Cloud Connector Rule","children":[{"name":"host","type":"String","description":"Host to perform Cloud Connection to"}]}]}]},"get /zones/{}/content-upload-scan/payloads":{"operationId":"waf-content-scanning-list-custom-scan-expressions","declarations":[{"kind":"list-data-source","name":"cloudflare_content_scanning_expressions","stainlessResource":"content_scanning.payloads","methodName":"list","snippet":"data \"cloudflare_content_scanning_expressions\" \"example_content_scanning_expressions\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Defines the unique ID for this Content Scanning custom expression."},{"name":"payload","type":"String","description":"Defines the custom content extraction expression used to reach content objects in the request."}]}]}]},"get /zones/{}/content-upload-scan/settings":{"operationId":"waf-content-scanning-get-status","declarations":[{"kind":"data-source","name":"cloudflare_content_scanning","stainlessResource":"content_scanning","methodName":"get","snippet":"data \"cloudflare_content_scanning\" \"example_content_scanning\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[{"name":"modified","type":"String","description":"Defines the last modification date (ISO 8601) of the Content Scanning status."},{"name":"value","type":"String","description":"Defines the status of Content Scanning."}]}]},"get /zones/{}/ct/alerting":{"operationId":"ct-alerting-get-subscription","declarations":[{"kind":"data-source","name":"cloudflare_ct_alerting","stainlessResource":"zones.ct.alerting","methodName":"get","snippet":"data \"cloudflare_ct_alerting\" \"example_ct_alerting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Whether CT alerting is enabled for the zone."},{"name":"emails","type":"List[String]","description":"Email addresses that receive CT alert notifications for the zone. A maximum of 100 addresses may be configured. Each address must be a valid RFC 5322 email address and must not contain a comma.\n"}]}]},"get /zones/{}/custom_certificates":{"operationId":"custom-ssl-for-a-zone-list-ssl-configurations","declarations":[{"kind":"list-data-source","name":"cloudflare_custom_ssls","stainlessResource":"custom_certificates","methodName":"list","snippet":"data \"cloudflare_custom_ssls\" \"example_custom_ssls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n status = \"active\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Custom certificate identifier tag."},{"name":"zone_id","type":"String","description":"Identifier."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.","children":[{"name":"label","type":"String"}]},{"name":"hosts","type":"List[String]"},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"keyless_server","type":"Attributes","children":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"policy_restrictions","type":"String","description":"The policy restrictions returned by the API. This field is returned in responses\nwhen a policy has been set. The API accepts the \"policy\" field in requests but\nreturns this field as \"policy_restrictions\" in responses.\n\nSpecifies the region(s) where your private key can be held locally for optimal\nTLS performance. Format is a boolean expression, for example:\n\"(country: US) or (region: EU)\"\n"},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacy_custom' certificates, but 'legacy_custom' certificates will always supercede 'sni_custom' certificates."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."}]}]}]},"get /zones/{}/custom_certificates/{}":{"operationId":"custom-ssl-for-a-zone-ssl-configuration-details","declarations":[{"kind":"data-source","name":"cloudflare_custom_ssl","stainlessResource":"custom_certificates","methodName":"get","snippet":"data \"cloudflare_custom_ssl\" \"example_custom_ssl\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_certificate_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"custom_certificate_id","type":"String","description":"Custom certificate identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any)."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."}]}],"computed":[{"name":"id","type":"String","description":"Custom certificate identifier tag."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"policy_restrictions","type":"String","description":"The policy restrictions returned by the API. This field is returned in responses\nwhen a policy has been set. The API accepts the \"policy\" field in requests but\nreturns this field as \"policy_restrictions\" in responses.\n\nSpecifies the region(s) where your private key can be held locally for optimal\nTLS performance. Format is a boolean expression, for example:\n\"(country: US) or (region: EU)\"\n"},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacy_custom' certificates, but 'legacy_custom' certificates will always supercede 'sni_custom' certificates."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"status","type":"String","description":"Status of the zone's custom SSL."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"hosts","type":"List[String]"},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.","children":[{"name":"label","type":"String"}]},{"name":"keyless_server","type":"Attributes","children":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]}]}]},"get /zones/{}/custom_hostnames":{"operationId":"custom-hostname-for-a-zone-list-custom-hostnames","declarations":[{"kind":"list-data-source","name":"cloudflare_custom_hostnames","stainlessResource":"custom_hostnames","methodName":"list","snippet":"data \"cloudflare_custom_hostnames\" \"example_custom_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n certificate_authority = \"google\"\n custom_origin_server = \"origin2.example.com\"\n direction = \"desc\"\n hostname = {\n contain = \"example.com\"\n exact = \"app.example.com\"\n starts_with = \"app\"\n }\n hostname_status = \"provisioned\"\n ssl_status = \"active\"\n wildcard = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"certificate_authority","type":"String","description":"Filter by the certificate authority that issued the SSL certificate."},{"name":"custom_origin_server","type":"String","description":"Filter by custom origin server name."},{"name":"direction","type":"String","description":"Direction to order hostnames."},{"name":"hostname_status","type":"String","description":"Filter by the hostname's activation status."},{"name":"id","type":"String","description":"Hostname ID to match against. This ID was generated and returned during the initial custom_hostname creation. This parameter cannot be used with the 'hostname', 'hostname.exact', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"ssl_status","type":"String","description":"Filter by SSL certificate status."},{"name":"wildcard","type":"Bool","description":"Filter by whether the custom hostname is a wildcard hostname."},{"name":"hostname","type":"Attributes","children":[{"name":"contain","type":"String","description":"Filters hostnames by a substring match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.startsWith' parameters."},{"name":"exact","type":"String","description":"Fully qualified domain name to match against. This parameter cannot be used with the 'id', 'hostname', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"starts_with","type":"String","description":"Filters hostnames by a prefix match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.contain' parameters."}]},{"name":"order","type":"String","description":"Field to order hostnames by."},{"name":"ssl","type":"Int64","description":"Whether to filter hostnames based on if they have SSL enabled."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Custom hostname identifier tag."},{"name":"hostname","type":"String","description":"The custom hostname that will point to your hostname via CNAME."},{"name":"created_at","type":"Time","description":"This is the time the hostname was created."},{"name":"custom_metadata","type":"Map[String]","description":"Unique key/value metadata for this hostname. These are per-hostname (customer) settings."},{"name":"custom_origin_server","type":"String","description":"a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record."},{"name":"custom_origin_sni","type":"String","description":"A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or the string ':request_host_header:' which will cause the host header in the request to be used as SNI. Not configurable with default/fallback origin server."},{"name":"ownership_verification","type":"Attributes","description":"This is a record which can be placed to activate a hostname.","children":[{"name":"name","type":"String","description":"DNS Name for record."},{"name":"type","type":"String","description":"DNS Record type."},{"name":"value","type":"String","description":"Content for the record."}]},{"name":"ownership_verification_http","type":"Attributes","description":"This presents the token to be served by the given http url to activate a hostname.","children":[{"name":"http_body","type":"String","description":"Token to be served."},{"name":"http_url","type":"String","description":"The HTTP URL that will be checked during custom hostname verification and where the customer should host the token."}]},{"name":"ssl","type":"Attributes","children":[{"name":"id","type":"String","description":"Custom hostname SSL identifier tag."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"certificate_authority","type":"String","description":"The Certificate Authority that will issue the certificate."},{"name":"custom_certificate","type":"String","description":"If a custom uploaded certificate is used."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"custom_key","type":"String","description":"The key for a custom uploaded certificate.","sensitive":true},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"expires_on","type":"Time","description":"The time the custom certificate expires on."},{"name":"hosts","type":"List[String]","description":"A list of Hostnames on a custom uploaded certificate."},{"name":"issuer","type":"String","description":"The issuer on a custom uploaded certificate."},{"name":"method","type":"String","description":"Domain control validation (DCV) method used for this hostname."},{"name":"serial_number","type":"String","description":"The serial number on a custom uploaded certificate."},{"name":"settings","type":"Attributes","children":[{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."},{"name":"early_hints","type":"String","description":"Whether or not Early Hints is enabled."},{"name":"http2","type":"String","description":"Whether or not HTTP2 is enabled."},{"name":"min_tls_version","type":"String","description":"The minimum TLS version supported."},{"name":"tls_1_3","type":"String","description":"Whether or not TLS 1.3 is enabled."}]},{"name":"signature","type":"String","description":"The signature on a custom uploaded certificate."},{"name":"status","type":"String","description":"Status of the hostname's SSL certificates."},{"name":"type","type":"String","description":"Level of validation to be used for this hostname. Domain validation (dv) must be used."},{"name":"uploaded_on","type":"Time","description":"The time the custom certificate was uploaded."},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"wildcard","type":"Bool","description":"Indicates whether the certificate covers a wildcard."}]},{"name":"status","type":"String","description":"Status of the hostname's activation."},{"name":"verification_errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a hostname."}]}]}]},"get /zones/{}/custom_hostnames/{}":{"operationId":"custom-hostname-for-a-zone-custom-hostname-details","declarations":[{"kind":"data-source","name":"cloudflare_custom_hostname","stainlessResource":"custom_hostnames","methodName":"get","snippet":"data \"cloudflare_custom_hostname\" \"example_custom_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_hostname_id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"custom_hostname_id","type":"String","description":"Custom hostname identifier tag."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"Hostname ID to match against. This ID was generated and returned during the initial custom_hostname creation. This parameter cannot be used with the 'hostname', 'hostname.exact', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"certificate_authority","type":"String","description":"Filter by the certificate authority that issued the SSL certificate."},{"name":"custom_origin_server","type":"String","description":"Filter by custom origin server name."},{"name":"direction","type":"String","description":"Direction to order hostnames."},{"name":"hostname","type":"Attributes","children":[{"name":"contain","type":"String","description":"Filters hostnames by a substring match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.startsWith' parameters."},{"name":"exact","type":"String","description":"Fully qualified domain name to match against. This parameter cannot be used with the 'id', 'hostname', 'hostname.contain', or 'hostname.startsWith' parameters."},{"name":"starts_with","type":"String","description":"Filters hostnames by a prefix match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.contain' parameters."}]},{"name":"hostname_status","type":"String","description":"Filter by the hostname's activation status."},{"name":"order","type":"String","description":"Field to order hostnames by."},{"name":"ssl","type":"Int64","description":"Whether to filter hostnames based on if they have SSL enabled."},{"name":"ssl_status","type":"String","description":"Filter by SSL certificate status."},{"name":"wildcard","type":"Bool","description":"Filter by whether the custom hostname is a wildcard hostname."}]}],"computed":[{"name":"id","type":"String","description":"Custom hostname identifier tag."},{"name":"created_at","type":"Time","description":"This is the time the hostname was created."},{"name":"custom_origin_server","type":"String","description":"a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record."},{"name":"custom_origin_sni","type":"String","description":"A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or the string ':request_host_header:' which will cause the host header in the request to be used as SNI. Not configurable with default/fallback origin server."},{"name":"hostname","type":"String","description":"The custom hostname that will point to your hostname via CNAME."},{"name":"status","type":"String","description":"Status of the hostname's activation."},{"name":"custom_metadata","type":"Map[String]","description":"Unique key/value metadata for this hostname. These are per-hostname (customer) settings."},{"name":"verification_errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a hostname."},{"name":"ownership_verification","type":"Attributes","description":"This is a record which can be placed to activate a hostname.","children":[{"name":"name","type":"String","description":"DNS Name for record."},{"name":"type","type":"String","description":"DNS Record type."},{"name":"value","type":"String","description":"Content for the record."}]},{"name":"ownership_verification_http","type":"Attributes","description":"This presents the token to be served by the given http url to activate a hostname.","children":[{"name":"http_body","type":"String","description":"Token to be served."},{"name":"http_url","type":"String","description":"The HTTP URL that will be checked during custom hostname verification and where the customer should host the token."}]},{"name":"ssl","type":"Attributes","children":[{"name":"id","type":"String","description":"Custom hostname SSL identifier tag."},{"name":"bundle_method","type":"String","description":"A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it."},{"name":"certificate_authority","type":"String","description":"The Certificate Authority that will issue the certificate."},{"name":"custom_certificate","type":"String","description":"If a custom uploaded certificate is used."},{"name":"custom_csr_id","type":"String","description":"The identifier for the Custom CSR that was used."},{"name":"custom_key","type":"String","description":"The key for a custom uploaded certificate.","sensitive":true},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"expires_on","type":"Time","description":"The time the custom certificate expires on."},{"name":"hosts","type":"List[String]","description":"A list of Hostnames on a custom uploaded certificate."},{"name":"issuer","type":"String","description":"The issuer on a custom uploaded certificate."},{"name":"method","type":"String","description":"Domain control validation (DCV) method used for this hostname."},{"name":"serial_number","type":"String","description":"The serial number on a custom uploaded certificate."},{"name":"settings","type":"Attributes","children":[{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."},{"name":"early_hints","type":"String","description":"Whether or not Early Hints is enabled."},{"name":"http2","type":"String","description":"Whether or not HTTP2 is enabled."},{"name":"min_tls_version","type":"String","description":"The minimum TLS version supported."},{"name":"tls_1_3","type":"String","description":"Whether or not TLS 1.3 is enabled."}]},{"name":"signature","type":"String","description":"The signature on a custom uploaded certificate."},{"name":"status","type":"String","description":"Status of the hostname's SSL certificates."},{"name":"type","type":"String","description":"Level of validation to be used for this hostname. Domain validation (dv) must be used."},{"name":"uploaded_on","type":"Time","description":"The time the custom certificate was uploaded."},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"wildcard","type":"Bool","description":"Indicates whether the certificate covers a wildcard."}]}]}]},"get /zones/{}/custom_hostnames/fallback_origin":{"operationId":"custom-hostname-fallback-origin-for-a-zone-get-fallback-origin-for-custom-hostnames","declarations":[{"kind":"data-source","name":"cloudflare_custom_hostname_fallback_origin","stainlessResource":"custom_hostnames.fallback_origin","methodName":"get","snippet":"data \"cloudflare_custom_hostname_fallback_origin\" \"example_custom_hostname_fallback_origin\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_at","type":"Time","description":"This is the time the fallback origin was created."},{"name":"origin","type":"String","description":"Your origin hostname that requests to your custom hostnames will be sent to."},{"name":"status","type":"String","description":"Status of the fallback origin's activation."},{"name":"updated_at","type":"Time","description":"This is the time the fallback origin was updated."},{"name":"errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a fallback origin."}]}]},"get /zones/{}/dcv_delegation/uuid":{"operationId":"dcv-delegation-uuid-get","declarations":[{"kind":"data-source","name":"cloudflare_dcv_delegation","stainlessResource":"dcv_delegation","methodName":"get","snippet":"data \"cloudflare_dcv_delegation\" \"example_dcv_delegation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"uuid","type":"String","description":"The DCV Delegation unique identifier."}]}]},"get /zones/{}/devices/policy/certificates":{"operationId":"devices-get-policy-certificates","declarations":[{"kind":"data-source","name":"cloudflare_zero_trust_device_default_profile_certificates","stainlessResource":"zero_trust.devices.policies.default.certificates","methodName":"get","snippet":"data \"cloudflare_zero_trust_device_default_profile_certificates\" \"example_zero_trust_device_default_profile_certificates\" {\n zone_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"The current status of the device policy certificate provisioning feature for WARP clients."}]}]},"get /zones/{}/dns_records":{"operationId":"dns-records-for-a-zone-list-dns-records","declarations":[{"kind":"list-data-source","name":"cloudflare_dns_records","stainlessResource":"dns.records","methodName":"list","snippet":"data \"cloudflare_dns_records\" \"example_dns_records\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n comment = {\n absent = \"absent\"\n contains = \"ello, worl\"\n endswith = \"o, world\"\n exact = \"Hello, world\"\n present = \"present\"\n startswith = \"Hello, w\"\n }\n content = {\n contains = \"7.0.0.\"\n endswith = \".0.1\"\n exact = \"127.0.0.1\"\n startswith = \"127.0.\"\n }\n name = {\n contains = \"w.example.\"\n endswith = \".example.com\"\n exact = \"www.example.com\"\n startswith = \"www.example\"\n }\n search = \"www.cloudflare.com\"\n shadowed_by_name = \"sub.example.com\"\n shadowing_name = \"www.sub.example.com\"\n tag = {\n absent = \"important\"\n contains = \"greeting:ello, worl\"\n endswith = \"greeting:o, world\"\n exact = \"greeting:Hello, world\"\n present = \"important\"\n startswith = \"greeting:Hello, w\"\n }\n type = \"A\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"search","type":"String","description":"Allows searching in multiple properties of a DNS record simultaneously. This parameter is intended for human users, not automation. Its exact behavior is intentionally left unspecified and is subject to change in the future. This parameter works independently of the `match` setting. For automated searches, please use the other available parameters.\n"},{"name":"shadowed_by_name","type":"String","description":"Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires `include_shadow_metadata=true`. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowing_name","type":"String","description":"Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"type","type":"String","description":"Record type."},{"name":"comment","type":"Attributes","children":[{"name":"absent","type":"String","description":"If this parameter is present, only records *without* a comment are returned.\n"},{"name":"contains","type":"String","description":"Substring of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"present","type":"String","description":"If this parameter is present, only records *with* a comment are returned.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record comment. Comment filters are case-insensitive.\n"}]},{"name":"content","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record content. Content filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record content. Content filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record content. Content filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record content. Content filters are case-insensitive.\n"}]},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record name. Name filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record name. Name filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record name. Name filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record name. Name filters are case-insensitive.\n"}]},{"name":"tag","type":"Attributes","children":[{"name":"absent","type":"String","description":"Name of a tag which must *not* be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"contains","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value contains ``. Tag filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value ends with ``. Tag filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value is ``. Tag filters are case-insensitive.\n"},{"name":"present","type":"String","description":"Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value starts with ``. Tag filters are case-insensitive.\n"}]},{"name":"direction","type":"String","description":"Direction to order DNS records in."},{"name":"include_shadow_metadata","type":"Bool","description":"Whether to include shadow metadata in the `meta` field of each record in the response. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead. Note that the interaction between tag filters is controlled by the `tag-match` parameter instead.\n"},{"name":"order","type":"String","description":"Field to order DNS records by."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"tag_match","type":"String","description":"Whether to match all tag search requirements or at least one (any). If set to `all`, acts like a logical AND between tag filters. If set to `any`, acts like a logical OR instead. Note that the regular `match` parameter is still used to combine the resulting condition with other filters that aren't related to tags.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"name","type":"String","description":"Complete DNS record name, including the zone name, in Punycode."},{"name":"ttl","type":"Float64","description":"Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterprise zones."},{"name":"type","type":"String","description":"Record type."},{"name":"comment","type":"String","description":"Comments or notes about the DNS record. This field has no effect on DNS responses."},{"name":"content","type":"String","description":"A valid IPv4 address."},{"name":"private_routing","type":"Bool","description":"Enables private network routing to the origin."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"settings","type":"Attributes","description":"Settings for the DNS record.","children":[{"name":"ipv4_only","type":"Bool","description":"When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"ipv6_only","type":"Bool","description":"When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"flatten_cname","type":"Bool","description":"If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened."}]},{"name":"tags","type":"Set[String]","description":"Custom tags for the DNS record. This field has no effect on DNS responses."},{"name":"id","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the record was created."},{"name":"meta","type":"Attributes","description":"Extra Cloudflare-specific metadata about the record.","children":[{"name":"dead_glue","type":"Bool","description":"Whether this glue record is not served because a shallower NS delegation takes precedence over the deeper delegation that needs it. Present only when true; reachable glue carries only `is_glue`. See [Unreachable glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#unreachable-glue-records).\n"},{"name":"is_glue","type":"Bool","description":"Whether this A or AAAA record is glue for a subdomain NS delegation. See [Glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#glue-records).\n"},{"name":"shadowed_by","type":"List[String]","description":"IDs of the NS records that shadow this record. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowed_records_count","type":"Int64","description":"Number of records shadowed by this NS delegation. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"}]},{"name":"modified_on","type":"Time","description":"When the record was last modified."},{"name":"proxiable","type":"Bool","description":"Whether the record can be proxied by Cloudflare or not."},{"name":"comment_modified_on","type":"Time","description":"When the record comment was last modified. Omitted if there is no comment."},{"name":"tags_modified_on","type":"Time","description":"When the record tags were last modified. Omitted if there are no tags."},{"name":"priority","type":"Float64","description":"Required for MX and URI records; ignored for other record types (but may still be returned by the API). Records with lower priorities are preferred. This field is to be deprecated in favor of the priority field within the data map."},{"name":"data","type":"Attributes","description":"Components of a CAA record.","children":[{"name":"flags","type":"Dynamic Float64 | String","description":"Flags for the CAA record."},{"name":"tag","type":"String","description":"Name of the property controlled by this record (e.g.: issue, issuewild, iodef)."},{"name":"value","type":"String","description":"Value of the record. This field's semantics depend on the chosen tag."},{"name":"algorithm","type":"Float64","description":"Algorithm."},{"name":"certificate","type":"String","description":"Certificate."},{"name":"key_tag","type":"Float64","description":"Key Tag."},{"name":"type","type":"Float64","description":"Type."},{"name":"protocol","type":"Float64","description":"Protocol."},{"name":"public_key","type":"String","description":"Public Key."},{"name":"digest","type":"String","description":"Digest."},{"name":"digest_type","type":"Float64","description":"Digest Type."},{"name":"priority","type":"Float64","description":"Priority."},{"name":"target","type":"String","description":"Target."},{"name":"altitude","type":"Float64","description":"Altitude of location in meters."},{"name":"lat_degrees","type":"Float64","description":"Degrees of latitude."},{"name":"lat_direction","type":"String","description":"Latitude direction."},{"name":"lat_minutes","type":"Float64","description":"Minutes of latitude."},{"name":"lat_seconds","type":"Float64","description":"Seconds of latitude."},{"name":"long_degrees","type":"Float64","description":"Degrees of longitude."},{"name":"long_direction","type":"String","description":"Longitude direction."},{"name":"long_minutes","type":"Float64","description":"Minutes of longitude."},{"name":"long_seconds","type":"Float64","description":"Seconds of longitude."},{"name":"precision_horz","type":"Float64","description":"Horizontal precision of location."},{"name":"precision_vert","type":"Float64","description":"Vertical precision of location."},{"name":"size","type":"Float64","description":"Size of location in meters."},{"name":"order","type":"Float64","description":"Order."},{"name":"preference","type":"Float64","description":"Preference."},{"name":"regex","type":"String","description":"Regex."},{"name":"replacement","type":"String","description":"Replacement."},{"name":"service","type":"String","description":"Service."},{"name":"matching_type","type":"Float64","description":"Matching Type."},{"name":"selector","type":"Float64","description":"Selector."},{"name":"usage","type":"Float64","description":"Usage."},{"name":"port","type":"Float64","description":"The port of the service."},{"name":"weight","type":"Float64","description":"The record weight."},{"name":"fingerprint","type":"String","description":"Fingerprint."}]}]}]}]},"get /zones/{}/dns_records/{}":{"operationId":"dns-records-for-a-zone-dns-record-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_record","stainlessResource":"dns.records","methodName":"get","snippet":"data \"cloudflare_dns_record\" \"example_dns_record\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns_record_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n include_shadow_metadata = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"dns_record_id","type":"String","description":"Identifier."},{"name":"include_shadow_metadata","type":"Bool","description":"Whether to include shadow metadata in the `meta` field of each record in the response. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"filter","type":"Attributes","children":[{"name":"comment","type":"Attributes","children":[{"name":"absent","type":"String","description":"If this parameter is present, only records *without* a comment are returned.\n"},{"name":"contains","type":"String","description":"Substring of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record comment. Comment filters are case-insensitive.\n"},{"name":"present","type":"String","description":"If this parameter is present, only records *with* a comment are returned.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record comment. Comment filters are case-insensitive.\n"}]},{"name":"content","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record content. Content filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record content. Content filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record content. Content filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record content. Content filters are case-insensitive.\n"}]},{"name":"direction","type":"String","description":"Direction to order DNS records in."},{"name":"match","type":"String","description":"Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead. Note that the interaction between tag filters is controlled by the `tag-match` parameter instead.\n"},{"name":"name","type":"Attributes","children":[{"name":"contains","type":"String","description":"Substring of the DNS record name. Name filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"Suffix of the DNS record name. Name filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"Exact value of the DNS record name. Name filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"Prefix of the DNS record name. Name filters are case-insensitive.\n"}]},{"name":"order","type":"String","description":"Field to order DNS records by."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"search","type":"String","description":"Allows searching in multiple properties of a DNS record simultaneously. This parameter is intended for human users, not automation. Its exact behavior is intentionally left unspecified and is subject to change in the future. This parameter works independently of the `match` setting. For automated searches, please use the other available parameters.\n"},{"name":"shadowed_by_name","type":"String","description":"Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires `include_shadow_metadata=true`. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowing_name","type":"String","description":"Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"tag","type":"Attributes","children":[{"name":"absent","type":"String","description":"Name of a tag which must *not* be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"contains","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value contains ``. Tag filters are case-insensitive.\n"},{"name":"endswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value ends with ``. Tag filters are case-insensitive.\n"},{"name":"exact","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value is ``. Tag filters are case-insensitive.\n"},{"name":"present","type":"String","description":"Name of a tag which must be present on the DNS record. Tag filters are case-insensitive.\n"},{"name":"startswith","type":"String","description":"A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value starts with ``. Tag filters are case-insensitive.\n"}]},{"name":"tag_match","type":"String","description":"Whether to match all tag search requirements or at least one (any). If set to `all`, acts like a logical AND between tag filters. If set to `any`, acts like a logical OR instead. Note that the regular `match` parameter is still used to combine the resulting condition with other filters that aren't related to tags.\n"},{"name":"type","type":"String","description":"Record type."}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"comment","type":"String","description":"Comments or notes about the DNS record. This field has no effect on DNS responses."},{"name":"comment_modified_on","type":"Time","description":"When the record comment was last modified. Omitted if there is no comment."},{"name":"content","type":"String","description":"A valid IPv4 address."},{"name":"created_on","type":"Time","description":"When the record was created."},{"name":"modified_on","type":"Time","description":"When the record was last modified."},{"name":"name","type":"String","description":"Complete DNS record name, including the zone name, in Punycode."},{"name":"priority","type":"Float64","description":"Required for MX and URI records; ignored for other record types (but may still be returned by the API). Records with lower priorities are preferred. This field is to be deprecated in favor of the priority field within the data map."},{"name":"private_routing","type":"Bool","description":"Enables private network routing to the origin."},{"name":"proxiable","type":"Bool","description":"Whether the record can be proxied by Cloudflare or not."},{"name":"proxied","type":"Bool","description":"Whether the record is receiving the performance and security benefits of Cloudflare."},{"name":"tags_modified_on","type":"Time","description":"When the record tags were last modified. Omitted if there are no tags."},{"name":"ttl","type":"Float64","description":"Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterprise zones."},{"name":"type","type":"String","description":"Record type."},{"name":"tags","type":"Set[String]","description":"Custom tags for the DNS record. This field has no effect on DNS responses."},{"name":"data","type":"Attributes","description":"Components of a CAA record.","children":[{"name":"flags","type":"Dynamic Float64 | String","description":"Flags for the CAA record."},{"name":"tag","type":"String","description":"Name of the property controlled by this record (e.g.: issue, issuewild, iodef)."},{"name":"value","type":"String","description":"Value of the record. This field's semantics depend on the chosen tag."},{"name":"algorithm","type":"Float64","description":"Algorithm."},{"name":"certificate","type":"String","description":"Certificate."},{"name":"key_tag","type":"Float64","description":"Key Tag."},{"name":"type","type":"Float64","description":"Type."},{"name":"protocol","type":"Float64","description":"Protocol."},{"name":"public_key","type":"String","description":"Public Key."},{"name":"digest","type":"String","description":"Digest."},{"name":"digest_type","type":"Float64","description":"Digest Type."},{"name":"priority","type":"Float64","description":"Priority."},{"name":"target","type":"String","description":"Target."},{"name":"altitude","type":"Float64","description":"Altitude of location in meters."},{"name":"lat_degrees","type":"Float64","description":"Degrees of latitude."},{"name":"lat_direction","type":"String","description":"Latitude direction."},{"name":"lat_minutes","type":"Float64","description":"Minutes of latitude."},{"name":"lat_seconds","type":"Float64","description":"Seconds of latitude."},{"name":"long_degrees","type":"Float64","description":"Degrees of longitude."},{"name":"long_direction","type":"String","description":"Longitude direction."},{"name":"long_minutes","type":"Float64","description":"Minutes of longitude."},{"name":"long_seconds","type":"Float64","description":"Seconds of longitude."},{"name":"precision_horz","type":"Float64","description":"Horizontal precision of location."},{"name":"precision_vert","type":"Float64","description":"Vertical precision of location."},{"name":"size","type":"Float64","description":"Size of location in meters."},{"name":"order","type":"Float64","description":"Order."},{"name":"preference","type":"Float64","description":"Preference."},{"name":"regex","type":"String","description":"Regex."},{"name":"replacement","type":"String","description":"Replacement."},{"name":"service","type":"String","description":"Service."},{"name":"matching_type","type":"Float64","description":"Matching Type."},{"name":"selector","type":"Float64","description":"Selector."},{"name":"usage","type":"Float64","description":"Usage."},{"name":"port","type":"Float64","description":"The port of the service."},{"name":"weight","type":"Float64","description":"The record weight."},{"name":"fingerprint","type":"String","description":"Fingerprint."}]},{"name":"meta","type":"Attributes","description":"Extra Cloudflare-specific metadata about the record.","children":[{"name":"dead_glue","type":"Bool","description":"Whether this glue record is not served because a shallower NS delegation takes precedence over the deeper delegation that needs it. Present only when true; reachable glue carries only `is_glue`. See [Unreachable glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#unreachable-glue-records).\n"},{"name":"is_glue","type":"Bool","description":"Whether this A or AAAA record is glue for a subdomain NS delegation. See [Glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#glue-records).\n"},{"name":"shadowed_by","type":"List[String]","description":"IDs of the NS records that shadow this record. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"},{"name":"shadowed_records_count","type":"Int64","description":"Number of records shadowed by this NS delegation. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records).\n"}]},{"name":"settings","type":"Attributes","description":"Settings for the DNS record.","children":[{"name":"ipv4_only","type":"Bool","description":"When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"ipv6_only","type":"Bool","description":"When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6."},{"name":"flatten_cname","type":"Bool","description":"If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened."}]}]}]},"get /zones/{}/dnssec":{"operationId":"dnssec-dnssec-details","declarations":[{"kind":"data-source","name":"cloudflare_zone_dnssec","stainlessResource":"dns.dnssec","methodName":"get","snippet":"data \"cloudflare_zone_dnssec\" \"example_zone_dnssec\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"algorithm","type":"String","description":"Algorithm key code."},{"name":"digest","type":"String","description":"Digest hash."},{"name":"digest_algorithm","type":"String","description":"Type of digest algorithm."},{"name":"digest_type","type":"String","description":"Coded type for digest algorithm."},{"name":"dnssec_multi_signer","type":"Bool","description":"If true, multi-signer DNSSEC is enabled on the zone, allowing multiple\nproviders to serve a DNSSEC-signed zone at the same time.\nThis is required for DNSKEY records (except those automatically\ngenerated by Cloudflare) to be added to the zone.\n\nSee [Multi-signer DNSSEC](https://developers.cloudflare.com/dns/dnssec/multi-signer-dnssec/) for details."},{"name":"dnssec_presigned","type":"Bool","description":"If true, allows Cloudflare to transfer in a DNSSEC-signed zone\nincluding signatures from an external provider, without requiring\nCloudflare to sign any records on the fly.\n\nNote that this feature has some limitations.\nSee [Cloudflare as Secondary](https://developers.cloudflare.com/dns/zone-setups/zone-transfers/cloudflare-as-secondary/setup/#dnssec) for details."},{"name":"dnssec_use_nsec3","type":"Bool","description":"If true, enables the use of NSEC3 together with DNSSEC on the zone.\nCombined with setting dnssec_presigned to true, this enables the use of\nNSEC3 records when transferring in from an external provider.\nIf dnssec_presigned is instead set to false (default), NSEC3 records will be\ngenerated and signed at request time.\n\nSee [DNSSEC with NSEC3](https://developers.cloudflare.com/dns/dnssec/enable-nsec3/) for details."},{"name":"ds","type":"String","description":"Full DS record."},{"name":"flags","type":"Float64","description":"Flag for DNSSEC record."},{"name":"key_tag","type":"Float64","description":"Code for key tag."},{"name":"key_type","type":"String","description":"Algorithm key type."},{"name":"modified_on","type":"Time","description":"When DNSSEC was last modified."},{"name":"public_key","type":"String","description":"Public key for DS record."},{"name":"status","type":"String","description":"Status of DNSSEC, based on user-desired state and presence of necessary records."}]}]},"get /zones/{}/email/routing":{"operationId":"email-routing-settings-get-email-routing-settings","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_settings","stainlessResource":"email_routing","methodName":"get","snippet":"data \"cloudflare_email_routing_settings\" \"example_email_routing_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created","type":"Time","description":"The date and time the settings have been created."},{"name":"enabled","type":"Bool","description":"State of the zone settings for Email Routing."},{"name":"modified","type":"Time","description":"The date and time the settings have been modified."},{"name":"name","type":"String","description":"Domain of your zone."},{"name":"skip_wizard","type":"Bool","description":"Flag to check if the user skipped the configuration wizard."},{"name":"status","type":"String","description":"Show the state of your account, and the type or configuration error."},{"name":"support_subaddress","type":"Bool","description":"Whether subaddressing (plus-addressing) is honored when matching incoming mail against routing rules."},{"name":"tag","type":"String","description":"Email Routing settings tag. (Deprecated, replaced by Email Routing settings identifier)","deprecated":"Deprecated."}]}]},"get /zones/{}/email/routing/dns":{"operationId":"email-routing-settings-email-routing-dns-settings","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_dns","stainlessResource":"email_routing.dns","methodName":"get","snippet":"data \"cloudflare_email_routing_dns\" \"example_email_routing_dns\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n subdomain = \"example.net\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"subdomain","type":"String","description":"Deprecated. When supplied, the response shape differs from the documented default and is not modeled in generated SDKs. Do not rely on this parameter."}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"dns","type":"List[Attributes]","children":[{"name":"content","type":"String","description":"DNS record content."},{"name":"name","type":"String","description":"DNS record name (or @ for the zone apex)."},{"name":"priority","type":"Float64","description":"Required for MX, SRV and URI records. Unused by other record types. Records with lower priorities are preferred."},{"name":"ttl","type":"Float64","description":"Time to live, in seconds, of the DNS record. Must be between 60 and 86400, or 1 for 'automatic'."},{"name":"type","type":"String","description":"DNS record type."}]}]}]},"get /zones/{}/email/routing/rules/{}":{"operationId":"email-routing-routing-rules-get-routing-rule","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_rule","stainlessResource":"email_routing.rules","methodName":"get","snippet":"data \"cloudflare_email_routing_rule\" \"example_email_routing_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_identifier = \"a7e6fb77503c41d8a7f3113c6918f10c\"\n}\n","required":[{"name":"rule_identifier","type":"String","description":"Routing rule identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Routing rule identifier."},{"name":"enabled","type":"Bool","description":"Routing rule status."},{"name":"name","type":"String","description":"Routing rule name."},{"name":"priority","type":"Float64","description":"Priority of the routing rule."},{"name":"source","type":"String","description":"Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\n"},{"name":"tag","type":"String","description":"Routing rule tag. (Deprecated, replaced by routing rule identifier)","deprecated":"Deprecated."},{"name":"actions","type":"List[Attributes]","description":"List actions patterns.","children":[{"name":"type","type":"String","description":"Type of supported action."},{"name":"value","type":"List[String]","description":"List of values for the action. Currently limited to a single value."}]},{"name":"matchers","type":"List[Attributes]","description":"Matching patterns to forward to your actions.","children":[{"name":"type","type":"String","description":"Type of matcher."},{"name":"field","type":"String","description":"Field for type matcher."},{"name":"value","type":"String","description":"Value for matcher."}]}]}]},"get /zones/{}/email/routing/rules/catch_all":{"operationId":"email-routing-routing-rules-get-catch-all-rule","declarations":[{"kind":"data-source","name":"cloudflare_email_routing_catch_all","stainlessResource":"email_routing.rules.catch_alls","methodName":"get","snippet":"data \"cloudflare_email_routing_catch_all\" \"example_email_routing_catch_all\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Routing rule status."},{"name":"name","type":"String","description":"Routing rule name."},{"name":"source","type":"String","description":"Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\n"},{"name":"tag","type":"String","description":"Routing rule tag. (Deprecated, replaced by routing rule identifier)","deprecated":"Deprecated."},{"name":"actions","type":"List[Attributes]","description":"List actions for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of action for catch-all rule."},{"name":"value","type":"List[String]","description":"List of values for the action. Currently limited to a single value."}]},{"name":"matchers","type":"List[Attributes]","description":"List of matchers for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of matcher. Default is 'all'."}]}]}]},"get /zones/{}/email/sending/subdomains":{"operationId":"email-sending-subdomains-list-sending-subdomains","declarations":[{"kind":"list-data-source","name":"cloudflare_email_sending_subdomains","stainlessResource":"email_sending.subdomains","methodName":"list","snippet":"data \"cloudflare_email_sending_subdomains\" \"example_email_sending_subdomains\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Sending subdomain identifier."},{"name":"enabled","type":"Bool","description":"Whether Email Sending is enabled on this subdomain."},{"name":"name","type":"String","description":"The exact domain name or a leftmost wildcard such as `*.example.com`."},{"name":"tag","type":"String","description":"Sending subdomain identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"dkim_selector","type":"String","description":"The DKIM selector used for email signing. Wildcard rows publish the selector and sign with `d=`."},{"name":"drop_suppressed_recipients","type":"Bool","description":"Whether a send request that includes a recipient suppressed on\nthis subdomain drops that recipient and still delivers to the\nrest, instead of failing the entire request.\n"},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"preview_enabled","type":"Bool","description":"Whether sent messages from this subdomain can be previewed in the activity log."},{"name":"return_path_domain","type":"String","description":"The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`."}]}]}]},"get /zones/{}/email/sending/subdomains/{}":{"operationId":"email-sending-subdomains-get-sending-subdomain","declarations":[{"kind":"data-source","name":"cloudflare_email_sending_subdomain","stainlessResource":"email_sending.subdomains","methodName":"get","snippet":"data \"cloudflare_email_sending_subdomain\" \"example_email_sending_subdomain\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n subdomain_id = \"aabbccdd11223344aabbccdd11223344\"\n}\n","required":[{"name":"subdomain_id","type":"String","description":"Sending subdomain identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Sending subdomain identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"dkim_selector","type":"String","description":"The DKIM selector used for email signing. Wildcard rows publish the selector and sign with `d=`."},{"name":"drop_suppressed_recipients","type":"Bool","description":"Whether a send request that includes a recipient suppressed on\nthis subdomain drops that recipient and still delivers to the\nrest, instead of failing the entire request.\n"},{"name":"enabled","type":"Bool","description":"Whether Email Sending is enabled on this subdomain."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"name","type":"String","description":"The exact domain name or a leftmost wildcard such as `*.example.com`."},{"name":"preview_enabled","type":"Bool","description":"Whether sent messages from this subdomain can be previewed in the activity log."},{"name":"return_path_domain","type":"String","description":"The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`."},{"name":"tag","type":"String","description":"Sending subdomain identifier."}]}]},"get /zones/{}/filters":{"operationId":"filters-list-filters","declarations":[{"kind":"list-data-source","name":"cloudflare_filters","stainlessResource":"filters","methodName":"list","snippet":"data \"cloudflare_filters\" \"example_filters\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"372e67954025e0ba6aaa6d586b9e0b61\"\n description = \"browsers\"\n expression = \"php\"\n paused = false\n ref = \"FIL-100\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"description","type":"String","description":"A case-insensitive string to find in the description."},{"name":"expression","type":"String","description":"A case-insensitive string to find in the expression."},{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"The filter ref (a short reference tag) to search for. Must be an exact match."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}]}]},"get /zones/{}/filters/{}":{"operationId":"filters-get-a-filter","declarations":[{"kind":"data-source","name":"cloudflare_filter","stainlessResource":"filters","methodName":"get","snippet":"data \"cloudflare_filter\" \"example_filter\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n filter_id = \"372e67954025e0ba6aaa6d586b9e0b61\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"filter_id","type":"String","description":"The unique identifier of the filter."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"A case-insensitive string to find in the description."},{"name":"expression","type":"String","description":"A case-insensitive string to find in the expression."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"The filter ref (a short reference tag) to search for. Must be an exact match."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}]},"get /zones/{}/firewall/lockdowns":{"operationId":"zone-lockdown-list-zone-lockdown-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_zone_lockdowns","stainlessResource":"firewall.lockdowns","methodName":"list","snippet":"data \"cloudflare_zone_lockdowns\" \"example_zone_lockdowns\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_on = \"2014-01-01T05:20:00.12345Z\"\n description = \"endpoints\"\n description_search = \"endpoints\"\n ip = \"1.2.3.4\"\n ip_range_search = \"1.2.3.0/16\"\n ip_search = \"1.2.3.4\"\n modified_on = \"2014-01-01T05:20:00.12345Z\"\n priority = 5\n uri_search = \"/some/path\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"description_search","type":"String","description":"A string to search for in the description of existing rules."},{"name":"ip","type":"String","description":"A single IP address to search for in existing rules."},{"name":"ip_range_search","type":"String","description":"A single IP address range to search for in existing rules."},{"name":"ip_search","type":"String","description":"A single IP address to search for in existing rules."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"priority","type":"Float64","description":"The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority."},{"name":"uri_search","type":"String","description":"A single URI to search for in the list of URLs of existing rules."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"configurations","type":"List[Attributes]","description":"A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule."},{"name":"value","type":"String","description":"The IP address to match. This address will be compared to the IP address of incoming requests."}]},{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"urls","type":"Set[String]","description":"The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns."}]}]}]},"get /zones/{}/firewall/lockdowns/{}":{"operationId":"zone-lockdown-get-a-zone-lockdown-rule","declarations":[{"kind":"data-source","name":"cloudflare_zone_lockdown","stainlessResource":"firewall.lockdowns","methodName":"get","snippet":"data \"cloudflare_zone_lockdown\" \"example_zone_lockdown\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lock_downs_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"lock_downs_id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"filter","type":"Attributes","children":[{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"description_search","type":"String","description":"A string to search for in the description of existing rules."},{"name":"ip","type":"String","description":"A single IP address to search for in existing rules."},{"name":"ip_range_search","type":"String","description":"A single IP address range to search for in existing rules."},{"name":"ip_search","type":"String","description":"A single IP address to search for in existing rules."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"priority","type":"Float64","description":"The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority."},{"name":"uri_search","type":"String","description":"A single URI to search for in the list of URLs of existing rules."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"urls","type":"Set[String]","description":"The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns."},{"name":"configurations","type":"List[Attributes]","description":"A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule."},{"name":"value","type":"String","description":"The IP address to match. This address will be compared to the IP address of incoming requests."}]}]}]},"get /zones/{}/firewall/rules":{"operationId":"firewall-rules-list-firewall-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_firewall_rules","stainlessResource":"firewall.rules","methodName":"list","snippet":"data \"cloudflare_firewall_rules\" \"example_firewall_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"372e67954025e0ba6aaa6d586b9e0b60\"\n action = \"block\"\n description = \"mir\"\n paused = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"action","type":"String","description":"The action to search for. Must be an exact match."},{"name":"description","type":"String","description":"A case-insensitive string to find in the description."},{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"action","type":"String","description":"The action to apply to a matched request. The `log` action is only available on an Enterprise plan."},{"name":"description","type":"String","description":"An informative summary of the firewall rule."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."},{"name":"deleted","type":"Bool","description":"When true, indicates that the firewall rule was deleted."}]},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"priority","type":"Float64","description":"The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority."},{"name":"products","type":"List[String]"},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related firewall rules."}]}]}]},"get /zones/{}/firewall/rules/{}":{"operationId":"firewall-rules-get-a-firewall-rule","declarations":[{"kind":"data-source","name":"cloudflare_firewall_rule","stainlessResource":"firewall.rules","methodName":"get","snippet":"data \"cloudflare_firewall_rule\" \"example_firewall_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_id = \"372e67954025e0ba6aaa6d586b9e0b60\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"rule_id","type":"String","description":"The unique identifier of the firewall rule."}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"action","type":"String","description":"The action to apply to a matched request. The `log` action is only available on an Enterprise plan."},{"name":"description","type":"String","description":"An informative summary of the firewall rule."},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"priority","type":"Float64","description":"The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related firewall rules."},{"name":"products","type":"List[String]"}]}]},"get /zones/{}/firewall/ua_rules":{"operationId":"user-agent-blocking-rules-list-user-agent-blocking-rules","declarations":[{"kind":"list-data-source","name":"cloudflare_user_agent_blocking_rules","stainlessResource":"firewall.ua_rules","methodName":"list","snippet":"data \"cloudflare_user_agent_blocking_rules\" \"example_user_agent_blocking_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n description = \"abusive\"\n paused = false\n user_agent = \"Safari\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"user_agent","type":"String","description":"A string to search for in the user agent values of existing rules."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier of the User Agent Blocking rule."},{"name":"configuration","type":"Attributes","description":"The configuration object for the current rule.","children":[{"name":"target","type":"String","description":"The configuration target for this rule. You must set the target to `ua` for User Agent Blocking rules."},{"name":"value","type":"String","description":"The exact user agent string to match. This value will be compared to the received `User-Agent` HTTP header value."}]},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"mode","type":"String","description":"The action to apply to a matched request."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."}]}]}]},"get /zones/{}/firewall/ua_rules/{}":{"operationId":"user-agent-blocking-rules-get-a-user-agent-blocking-rule","declarations":[{"kind":"data-source","name":"cloudflare_user_agent_blocking_rule","stainlessResource":"firewall.ua_rules","methodName":"get","snippet":"data \"cloudflare_user_agent_blocking_rule\" \"example_user_agent_blocking_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ua_rule_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"ua_rule_id","type":"String","description":"The unique identifier of the User Agent Blocking rule."},{"name":"filter","type":"Attributes","children":[{"name":"description","type":"String","description":"A string to search for in the description of existing rules."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"user_agent","type":"String","description":"A string to search for in the user agent values of existing rules."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the User Agent Blocking rule."},{"name":"description","type":"String","description":"An informative summary of the rule."},{"name":"mode","type":"String","description":"The action to apply to a matched request."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."},{"name":"configuration","type":"Attributes","description":"The configuration object for the current rule.","children":[{"name":"target","type":"String","description":"The configuration target for this rule. You must set the target to `ua` for User Agent Blocking rules."},{"name":"value","type":"String","description":"The exact user agent string to match. This value will be compared to the received `User-Agent` HTTP header value."}]}]}]},"get /zones/{}/healthchecks":{"operationId":"health-checks-list-health-checks","declarations":[{"kind":"list-data-source","name":"cloudflare_healthchecks","stainlessResource":"healthchecks","methodName":"list","snippet":"data \"cloudflare_healthchecks\" \"example_healthchecks\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"address","type":"String","description":"The hostname or IP address of the origin server to run health checks on."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means Cloudflare will pick a default region."},{"name":"consecutive_fails","type":"Int64","description":"The number of consecutive fails required from a health check before changing the health to unhealthy."},{"name":"consecutive_successes","type":"Int64","description":"The number of consecutive successes required from a health check before changing the health to healthy."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-readable description of the health check."},{"name":"failure_reason","type":"String","description":"The current failure reason if status is unhealthy."},{"name":"http_config","type":"Attributes","description":"Parameters specific to an HTTP or HTTPS health check.","children":[{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when the health check uses HTTPS."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy."},{"name":"expected_codes","type":"List[String]","description":"The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if the origin returns a 3xx status code."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden."},{"name":"method","type":"String","description":"The HTTP method to use for the health check."},{"name":"path","type":"String","description":"The endpoint path to health check against."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS."}]},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"status","type":"String","description":"The current status of the origin server according to the health check."},{"name":"suspended","type":"Bool","description":"If suspended, no health checks are sent to the origin."},{"name":"tcp_config","type":"Attributes","description":"Parameters specific to TCP health check.","children":[{"name":"method","type":"String","description":"The TCP connection method to use for the health check."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80."}]},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'."}]}]}]},"get /zones/{}/healthchecks/{}":{"operationId":"health-checks-health-check-details","declarations":[{"kind":"data-source","name":"cloudflare_healthcheck","stainlessResource":"healthchecks","methodName":"get","snippet":"data \"cloudflare_healthcheck\" \"example_healthcheck\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n healthcheck_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"healthcheck_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"address","type":"String","description":"The hostname or IP address of the origin server to run health checks on."},{"name":"consecutive_fails","type":"Int64","description":"The number of consecutive fails required from a health check before changing the health to unhealthy."},{"name":"consecutive_successes","type":"Int64","description":"The number of consecutive successes required from a health check before changing the health to healthy."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-readable description of the health check."},{"name":"failure_reason","type":"String","description":"The current failure reason if status is unhealthy."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"status","type":"String","description":"The current status of the origin server according to the health check."},{"name":"suspended","type":"Bool","description":"If suspended, no health checks are sent to the origin."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means Cloudflare will pick a default region."},{"name":"http_config","type":"Attributes","description":"Parameters specific to an HTTP or HTTPS health check.","children":[{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when the health check uses HTTPS."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy."},{"name":"expected_codes","type":"List[String]","description":"The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if the origin returns a 3xx status code."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden."},{"name":"method","type":"String","description":"The HTTP method to use for the health check."},{"name":"path","type":"String","description":"The endpoint path to health check against."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS."}]},{"name":"tcp_config","type":"Attributes","description":"Parameters specific to TCP health check.","children":[{"name":"method","type":"String","description":"The TCP connection method to use for the health check."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80."}]}]}]},"get /zones/{}/hold":{"operationId":"zones-0-hold-get","declarations":[{"kind":"data-source","name":"cloudflare_zone_hold","stainlessResource":"zones.holds","methodName":"get","snippet":"data \"cloudflare_zone_hold\" \"example_zone_hold\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"hold","type":"Bool"},{"name":"hold_after","type":"String"},{"name":"include_subdomains","type":"String"}]}]},"get /zones/{}/hostnames/settings/{}":{"operationId":"per-hostname-tls-settings-list","declarations":[{"kind":"list-data-source","name":"cloudflare_hostname_tls_settings","stainlessResource":"hostnames.settings.tls","methodName":"list","snippet":"data \"cloudflare_hostname_tls_settings\" \"example_hostname_tls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n}\n","required":[{"name":"setting_id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"created_at","type":"Time","description":"This is the time the tls setting was originally created for this hostname."},{"name":"hostname","type":"String","description":"The hostname for which the tls settings are set."},{"name":"status","type":"String","description":"Deployment status for the given tls setting."},{"name":"updated_at","type":"Time","description":"This is the time the tls setting was updated."},{"name":"value","type":"String","description":"The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`)."}]}]}]},"get /zones/{}/hostnames/settings/{}/{}":{"operationId":"per-hostname-tls-settings-get","declarations":[{"kind":"data-source","name":"cloudflare_hostname_tls_setting","stainlessResource":"hostnames.settings.tls","methodName":"get","snippet":"data \"cloudflare_hostname_tls_setting\" \"example_hostname_tls_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n hostname = \"app.example.com\"\n}\n","required":[{"name":"hostname","type":"String","description":"The hostname for which the tls settings are set."},{"name":"setting_id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"created_at","type":"Time","description":"This is the time the tls setting was originally created for this hostname."},{"name":"status","type":"String","description":"Deployment status for the given tls setting."},{"name":"updated_at","type":"Time","description":"This is the time the tls setting was updated."},{"name":"value","type":"String","description":"The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`)."}]}]},"get /zones/{}/keyless_certificates":{"operationId":"keyless-ssl-for-a-zone-list-keyless-ssl-configurations","declarations":[{"kind":"list-data-source","name":"cloudflare_keyless_certificates","stainlessResource":"keyless_certificates","methodName":"list","snippet":"data \"cloudflare_keyless_certificates\" \"example_keyless_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]}]}]},"get /zones/{}/keyless_certificates/{}":{"operationId":"keyless-ssl-for-a-zone-get-keyless-ssl-configuration","declarations":[{"kind":"data-source","name":"cloudflare_keyless_certificate","stainlessResource":"keyless_certificates","methodName":"get","snippet":"data \"cloudflare_keyless_certificate\" \"example_keyless_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n keyless_certificate_id = \"4d2844d2ce78891c34d0b6c0535a291e\"\n}\n","required":[{"name":"keyless_certificate_id","type":"String","description":"Keyless certificate identifier tag."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Keyless certificate identifier tag."},{"name":"created_on","type":"Time","description":"When the Keyless SSL was created."},{"name":"enabled","type":"Bool","description":"Whether or not the Keyless SSL is on or off."},{"name":"host","type":"String","description":"The keyless SSL name."},{"name":"modified_on","type":"Time","description":"When the Keyless SSL was last modified."},{"name":"name","type":"String","description":"The keyless SSL name."},{"name":"port","type":"Float64","description":"The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server."},{"name":"status","type":"String","description":"Status of the Keyless SSL."},{"name":"permissions","type":"List[String]","description":"Available permissions for the Keyless SSL for the current user requesting the item."},{"name":"tunnel","type":"Attributes","description":"Configuration for using Keyless SSL through a Cloudflare Tunnel.","children":[{"name":"private_ip","type":"String","description":"Private IP of the Key Server Host."},{"name":"vnet_id","type":"String","description":"Cloudflare Tunnel Virtual Network ID."}]}]}]},"get /zones/{}/leaked-credential-checks":{"operationId":"waf-product-api-leaked-credentials-get-status","declarations":[{"kind":"data-source","name":"cloudflare_leaked_credential_check","stainlessResource":"leaked_credential_checks","methodName":"get","snippet":"data \"cloudflare_leaked_credential_check\" \"example_leaked_credential_check\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[{"name":"enabled","type":"Bool","description":"Determines whether or not Leaked Credential Checks are enabled."}]}]},"get /zones/{}/leaked-credential-checks/detections":{"operationId":"waf-product-api-leaked-credentials-list-detections","declarations":[{"kind":"list-data-source","name":"cloudflare_leaked_credential_check_rules","stainlessResource":"leaked_credential_checks.detections","methodName":"list","snippet":"data \"cloudflare_leaked_credential_check_rules\" \"example_leaked_credential_check_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Defines the unique ID for this custom detection."},{"name":"password","type":"String","description":"Defines ehe ruleset expression to use in matching the password in a request."},{"name":"username","type":"String","description":"Defines the ruleset expression to use in matching the username in a request."}]}]}]},"get /zones/{}/leaked-credential-checks/detections/{}":{"operationId":"waf-product-api-leaked-credentials-get-detection","declarations":[{"kind":"data-source","name":"cloudflare_leaked_credential_check_rule","stainlessResource":"leaked_credential_checks.detections","methodName":"get","snippet":"data \"cloudflare_leaked_credential_check_rule\" \"example_leaked_credential_check_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n detection_id = \"18a14bafaa8eb1df04ce683ec18c765e\"\n}\n","required":[{"name":"detection_id","type":"String","description":"Defines the unique ID for this custom detection."},{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Defines the unique ID for this custom detection."},{"name":"password","type":"String","description":"Defines ehe ruleset expression to use in matching the password in a request."},{"name":"username","type":"String","description":"Defines the ruleset expression to use in matching the username in a request."}]}]},"get /zones/{}/logs/control/retention/flag":{"operationId":"get-zones-zone_id-logs-control-retention-flag","declarations":[{"kind":"data-source","name":"cloudflare_logpull_retention","stainlessResource":"logs.control.retention","methodName":"get","snippet":"data \"cloudflare_logpull_retention\" \"example_logpull_retention\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"flag","type":"Bool","description":"The log retention flag for Logpull API."}]}]},"get /zones/{}/managed_headers":{"operationId":"listManagedTransforms","declarations":[{"kind":"data-source","name":"cloudflare_managed_transforms","stainlessResource":"managed_transforms","methodName":"list","snippet":"data \"cloudflare_managed_transforms\" \"example_managed_transforms\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone."},{"name":"managed_request_headers","type":"List[Attributes]","description":"The list of Managed Request Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]},{"name":"managed_response_headers","type":"List[Attributes]","description":"The list of Managed Response Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]}]}]},"get /zones/{}/observability/tracing/rules":{"operationId":"zone.observability.tracing.rules.get","declarations":[{"kind":"data-source","name":"cloudflare_zone_tracing_rules","stainlessResource":"zones.observability.tracing.rules","methodName":"get","snippet":"data \"cloudflare_zone_tracing_rules\" \"example_zone_tracing_rules\" {\n zone_id = \"zone_id\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the zone ID."},{"name":"rules","type":"List[Attributes]","description":"Trace rules in evaluation order.","children":[{"name":"action","type":"String"},{"name":"action_parameters","type":"Attributes","children":[{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."}]},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String","description":"A Rules language expression that selects requests."}]}]}]},"get /zones/{}/observability/tracing/settings":{"operationId":"zone.observability.tracing.settings.get","declarations":[{"kind":"data-source","name":"cloudflare_zone_tracing","stainlessResource":"zones.observability.tracing.settings","methodName":"get","snippet":"data \"cloudflare_zone_tracing\" \"example_zone_tracing\" {\n zone_id = \"zone_id\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the zone ID."},{"name":"enabled","type":"Bool","description":"Whether Cloudflare Traces is enabled for the zone."},{"name":"forward_context","type":"Bool","description":"Whether trace context is sent externally or across a zone boundary."},{"name":"persist","type":"Bool","description":"Whether traces are persisted in Cloudflare."},{"name":"propagation_policy","type":"String","description":"When inbound trace context may be continued. Authenticated propagation is not supported yet."},{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."},{"name":"destinations","type":"List[String]","description":"Up to 100 OpenTelemetry destination identifiers that receive traces."}]}]},"get /zones/{}/origin_tls_client_auth/settings":{"operationId":"zone-level-authenticated-origin-pulls-get-enablement-setting-for-zone","declarations":[{"kind":"data-source","name":"cloudflare_authenticated_origin_pulls_settings","stainlessResource":"origin_tls_client_auth.settings","methodName":"get","snippet":"data \"cloudflare_authenticated_origin_pulls_settings\" \"example_authenticated_origin_pulls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Indicates whether zone-level authenticated origin pulls is enabled."}]}]},"get /zones/{}/origin/cloud_regions":{"operationId":"origin-cloud-regions-v2-list","declarations":[{"kind":"list-data-source","name":"cloudflare_origin_cloud_regions","stainlessResource":"cache.origin_cloud_regions","methodName":"list","snippet":"data \"cloudflare_origin_cloud_regions\" \"example_origin_cloud_regions\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The origin IP address (IPv4 or IPv6). Normalized to canonical form (RFC 5952 for IPv6)."},{"name":"origin_ip","type":"String","description":"The origin IP address (IPv4 or IPv6). Normalized to canonical form (RFC 5952 for IPv6)."},{"name":"region","type":"String","description":"Cloud vendor region identifier."},{"name":"vendor","type":"String","description":"Cloud vendor hosting the origin."},{"name":"modified_on","type":"Time","description":"Time this mapping was last modified."}]}]}]},"get /zones/{}/origin/cloud_regions/{}":{"operationId":"origin-cloud-regions-v2-get","declarations":[{"kind":"data-source","name":"cloudflare_origin_cloud_region","stainlessResource":"cache.origin_cloud_regions","methodName":"get","snippet":"data \"cloudflare_origin_cloud_region\" \"example_origin_cloud_region\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin_ip = \"192.0.2.1\"\n}\n","required":[{"name":"origin_ip","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"modified_on","type":"Time","description":"Time this mapping was last modified."},{"name":"region","type":"String","description":"Cloud vendor region identifier."},{"name":"vendor","type":"String","description":"Cloud vendor hosting the origin."}]}]},"get /zones/{}/page_shield/connections":{"operationId":"page-shield-list-connections","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_connections_list","stainlessResource":"page_shield.connections","methodName":"list","snippet":"data \"cloudflare_page_shield_connections_list\" \"example_page_shield_connections_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n exclude_cdn_cgi = true\n exclude_urls = \"blog.cloudflare.com,www.example\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n per_page = 100\n prioritize_malicious = true\n status = \"active,inactive\"\n urls = \"blog.cloudflare.com,www.example\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"The direction used to sort returned connections."},{"name":"exclude_cdn_cgi","type":"Bool","description":"When true, excludes connections seen in a `/cdn-cgi` path from the returned connections. The default value is true."},{"name":"exclude_urls","type":"String","description":"Excludes connections whose URL contains one of the URL-encoded URLs separated by commas.\n"},{"name":"export","type":"String","description":"Export the list of connections as a file, limited to 50000 entries."},{"name":"hosts","type":"String","description":"Includes connections that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"order_by","type":"String","description":"The field used to sort returned connections."},{"name":"page","type":"String","description":"The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the connections\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of connections\n"},{"name":"page_url","type":"String","description":"Includes connections that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"per_page","type":"Float64","description":"The number of results per page."},{"name":"prioritize_malicious","type":"Bool","description":"When true, malicious connections appear first in the returned connections."},{"name":"status","type":"String","description":"Filters the returned connections using a comma-separated list of connection statuses. Accepted values: `active`, `infrequent`, and `inactive`. The default value is `active`."},{"name":"urls","type":"String","description":"Includes connections whose URL contain one or more URL-encoded URLs separated by commas.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"added_at","type":"Time"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"last_seen_at","type":"Time"},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"domain_reported_malicious","type":"Bool"},{"name":"first_page_url","type":"String"},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"page_urls","type":"List[String]"},{"name":"url_reported_malicious","type":"Bool"}]}]}]},"get /zones/{}/page_shield/connections/{}":{"operationId":"page-shield-get-connection","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_connections","stainlessResource":"page_shield.connections","methodName":"get","snippet":"data \"cloudflare_page_shield_connections\" \"example_page_shield_connections\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connection_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"connection_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"added_at","type":"Time"},{"name":"domain_reported_malicious","type":"Bool"},{"name":"first_page_url","type":"String"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"id","type":"String","description":"Identifier"},{"name":"last_seen_at","type":"Time"},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"url_reported_malicious","type":"Bool"},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"page_urls","type":"List[String]"}]}]},"get /zones/{}/page_shield/cookies":{"operationId":"page-shield-list-cookies","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_cookies_list","stainlessResource":"page_shield.cookies","methodName":"list","snippet":"data \"cloudflare_page_shield_cookies_list\" \"example_page_shield_cookies_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n domain = \"example.com\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n http_only = true\n name = \"session_id\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n path = \"/\"\n per_page = 100\n same_site = \"strict\"\n secure = true\n type = \"first_party\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"The direction used to sort returned cookies.'"},{"name":"domain","type":"String","description":"Filters the returned cookies that match the specified domain attribute"},{"name":"export","type":"String","description":"Export the list of cookies as a file, limited to 50000 entries."},{"name":"hosts","type":"String","description":"Includes cookies that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"http_only","type":"Bool","description":"Filters the returned cookies that are set with HttpOnly"},{"name":"name","type":"String","description":"Filters the returned cookies that match the specified name.\nWildcards are supported at the start and end to support starts with, ends with\nand contains. e.g. session*\n"},{"name":"order_by","type":"String","description":"The field used to sort returned cookies."},{"name":"page","type":"String","description":"The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the cookies\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of cookies\n"},{"name":"page_url","type":"String","description":"Includes connections that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"path","type":"String","description":"Filters the returned cookies that match the specified path attribute"},{"name":"per_page","type":"Float64","description":"The number of results per page."},{"name":"same_site","type":"String","description":"Filters the returned cookies that match the specified same_site attribute"},{"name":"secure","type":"Bool","description":"Filters the returned cookies that are set with Secure"},{"name":"type","type":"String","description":"Filters the returned cookies that match the specified type attribute"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"last_seen_at","type":"Time"},{"name":"name","type":"String"},{"name":"type","type":"String"},{"name":"domain_attribute","type":"String"},{"name":"expires_attribute","type":"Time"},{"name":"http_only_attribute","type":"Bool"},{"name":"max_age_attribute","type":"Int64"},{"name":"page_urls","type":"List[String]"},{"name":"path_attribute","type":"String"},{"name":"same_site_attribute","type":"String"},{"name":"secure_attribute","type":"Bool"}]}]}]},"get /zones/{}/page_shield/cookies/{}":{"operationId":"page-shield-get-cookie","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_cookies","stainlessResource":"page_shield.cookies","methodName":"get","snippet":"data \"cloudflare_page_shield_cookies\" \"example_page_shield_cookies\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cookie_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"cookie_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"domain_attribute","type":"String"},{"name":"expires_attribute","type":"Time"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"http_only_attribute","type":"Bool"},{"name":"id","type":"String","description":"Identifier"},{"name":"last_seen_at","type":"Time"},{"name":"max_age_attribute","type":"Int64"},{"name":"name","type":"String"},{"name":"path_attribute","type":"String"},{"name":"same_site_attribute","type":"String"},{"name":"secure_attribute","type":"Bool"},{"name":"type","type":"String"},{"name":"page_urls","type":"List[String]"}]}]},"get /zones/{}/page_shield/policies":{"operationId":"page-shield-list-policies","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_policies","stainlessResource":"page_shield.policies","methodName":"list","snippet":"data \"cloudflare_page_shield_policies\" \"example_page_shield_policies\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"action","type":"String","description":"The action to take if the expression matches"},{"name":"description","type":"String","description":"A description for the policy"},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled"},{"name":"expression","type":"String","description":"The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax"},{"name":"value","type":"String","description":"The policy which will be applied"}]}]}]},"get /zones/{}/page_shield/policies/{}":{"operationId":"page-shield-get-policy","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_policy","stainlessResource":"page_shield.policies","methodName":"get","snippet":"data \"cloudflare_page_shield_policy\" \"example_page_shield_policy\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"policy_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"action","type":"String","description":"The action to take if the expression matches"},{"name":"description","type":"String","description":"A description for the policy"},{"name":"enabled","type":"Bool","description":"Whether the policy is enabled"},{"name":"expression","type":"String","description":"The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax"},{"name":"value","type":"String","description":"The policy which will be applied"}]}]},"get /zones/{}/page_shield/scripts":{"operationId":"page-shield-list-scripts","declarations":[{"kind":"list-data-source","name":"cloudflare_page_shield_scripts_list","stainlessResource":"page_shield.scripts","methodName":"list","snippet":"data \"cloudflare_page_shield_scripts_list\" \"example_page_shield_scripts_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n exclude_urls = \"blog.cloudflare.com,www.example\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n per_page = 100\n prioritize_malicious = true\n status = \"active,inactive\"\n urls = \"blog.cloudflare.com,www.example\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"direction","type":"String","description":"The direction used to sort returned scripts."},{"name":"exclude_urls","type":"String","description":"Excludes scripts whose URL contains one of the URL-encoded URLs separated by commas.\n"},{"name":"export","type":"String","description":"Export the list of scripts as a file, limited to 50000 entries."},{"name":"hosts","type":"String","description":"Includes scripts that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"order_by","type":"String","description":"The field used to sort returned scripts."},{"name":"page","type":"String","description":"The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the scripts\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of scripts\n"},{"name":"page_url","type":"String","description":"Includes scripts that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match\n"},{"name":"per_page","type":"Float64","description":"The number of results per page."},{"name":"prioritize_malicious","type":"Bool","description":"When true, malicious scripts appear first in the returned scripts."},{"name":"status","type":"String","description":"Filters the returned scripts using a comma-separated list of scripts statuses. Accepted values: `active`, `infrequent`, and `inactive`. The default value is `active`."},{"name":"urls","type":"String","description":"Includes scripts whose URL contain one or more URL-encoded URLs separated by commas.\n"},{"name":"exclude_cdn_cgi","type":"Bool","description":"When true, excludes scripts seen in a `/cdn-cgi` path from the returned scripts. The default value is true."},{"name":"exclude_duplicates","type":"Bool","description":"When true, excludes duplicate scripts. We consider a script duplicate of another if their javascript\ncontent matches and they share the same url host and zone hostname. In such case, we return the most\nrecent script for the URL host and zone hostname combination.\n"},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"added_at","type":"Time"},{"name":"first_seen_at","type":"Time"},{"name":"host","type":"String"},{"name":"last_seen_at","type":"Time"},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"cryptomining_score","type":"Int64","description":"The cryptomining score of the JavaScript content."},{"name":"dataflow_score","type":"Int64","description":"The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"domain_reported_malicious","type":"Bool"},{"name":"fetched_at","type":"String","description":"The timestamp of when the script was last fetched."},{"name":"first_page_url","type":"String"},{"name":"hash","type":"String","description":"The computed hash of the analyzed script."},{"name":"js_integrity_score","type":"Int64","description":"The integrity score of the JavaScript content."},{"name":"magecart_score","type":"Int64","description":"The magecart score of the JavaScript content."},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"malware_score","type":"Int64","description":"The malware score of the JavaScript content."},{"name":"obfuscation_score","type":"Int64","description":"The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"page_urls","type":"List[String]"},{"name":"url_reported_malicious","type":"Bool"}]}]}]},"get /zones/{}/page_shield/scripts/{}":{"operationId":"page-shield-get-script","declarations":[{"kind":"data-source","name":"cloudflare_page_shield_scripts","stainlessResource":"page_shield.scripts","methodName":"get","snippet":"data \"cloudflare_page_shield_scripts\" \"example_page_shield_scripts\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"script_id","type":"String","description":"Identifier"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"added_at","type":"Time"},{"name":"cryptomining_score","type":"Int64","description":"The cryptomining score of the JavaScript content."},{"name":"dataflow_score","type":"Int64","description":"The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"domain_reported_malicious","type":"Bool"},{"name":"fetched_at","type":"String","description":"The timestamp of when the script was last fetched."},{"name":"first_page_url","type":"String"},{"name":"first_seen_at","type":"Time"},{"name":"hash","type":"String","description":"The computed hash of the analyzed script."},{"name":"host","type":"String"},{"name":"id","type":"String","description":"Identifier"},{"name":"js_integrity_score","type":"Int64","description":"The integrity score of the JavaScript content."},{"name":"last_seen_at","type":"Time"},{"name":"magecart_score","type":"Int64","description":"The magecart score of the JavaScript content."},{"name":"malware_score","type":"Int64","description":"The malware score of the JavaScript content."},{"name":"obfuscation_score","type":"Int64","description":"The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"url","type":"String"},{"name":"url_contains_cdn_cgi_path","type":"Bool"},{"name":"url_reported_malicious","type":"Bool"},{"name":"malicious_domain_categories","type":"List[String]"},{"name":"malicious_url_categories","type":"List[String]"},{"name":"page_urls","type":"List[String]"},{"name":"versions","type":"List[Attributes]","children":[{"name":"cryptomining_score","type":"Int64","description":"The cryptomining score of the JavaScript content."},{"name":"dataflow_score","type":"Int64","description":"The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."},{"name":"fetched_at","type":"String","description":"The timestamp of when the script was last fetched."},{"name":"hash","type":"String","description":"The computed hash of the analyzed script."},{"name":"js_integrity_score","type":"Int64","description":"The integrity score of the JavaScript content."},{"name":"magecart_score","type":"Int64","description":"The magecart score of the JavaScript content."},{"name":"malware_score","type":"Int64","description":"The malware score of the JavaScript content."},{"name":"obfuscation_score","type":"Int64","description":"The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.","deprecated":"Deprecated."}]}]}]},"get /zones/{}/pagerules/{}":{"operationId":"page-rules-get-a-page-rule","declarations":[{"kind":"data-source","name":"cloudflare_page_rule","stainlessResource":"page_rules","methodName":"get","snippet":"data \"cloudflare_page_rule\" \"example_page_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pagerule_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"pagerule_id","type":"String","description":"Identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"The timestamp of when the Page Rule was created."},{"name":"modified_on","type":"Time","description":"The timestamp of when the Page Rule was last modified."},{"name":"priority","type":"Int64","description":"The priority of the rule, used to define which Page Rule is processed\nover another. A higher number indicates a higher priority. For example,\nif you have a catch-all Page Rule (rule A: `/images/*`) but want a more\nspecific Page Rule to take precedence (rule B: `/images/special/*`),\nspecify a higher priority for rule B so it overrides rule A.\n"},{"name":"status","type":"String","description":"The status of the Page Rule."},{"name":"actions","type":"List[Attributes]","description":"The set of actions to perform if the targets of this rule match the\nrequest. Actions can redirect to another URL or override settings, but\nnot both.\n","children":[{"name":"id","type":"String","description":"If enabled, any `http://`` URL is converted to `https://` through a\n301 redirect.\n"},{"name":"value","type":"String","description":"The status of Automatic HTTPS Rewrites.\n"}]},{"name":"targets","type":"List[Attributes]","description":"The rule targets to evaluate on each request.","children":[{"name":"constraint","type":"Attributes","description":"String constraint.","children":[{"name":"operator","type":"String","description":"The matches operator can use asterisks and pipes as wildcard and 'or' operators."},{"name":"value","type":"String","description":"The URL pattern to match against the current request. The pattern may contain up to four asterisks ('*') as placeholders."}]},{"name":"target","type":"String","description":"A target based on the URL of the request."}]}]}]},"get /zones/{}/precursor":{"operationId":"precursor-for-a-zone-get-config","declarations":[{"kind":"data-source","name":"cloudflare_precursor","stainlessResource":"precursor","methodName":"get","snippet":"data \"cloudflare_precursor\" \"example_precursor\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"default_mode","type":"String","description":"The zone-level Precursor enforcement mode applied to requests that do\nnot match a more specific enforcement rule.\n","deprecated":"Deprecated."},{"name":"enforcement_rules","type":"List[Attributes]","description":"The ordered list of enforcement rules for the zone.","deprecated":"Deprecated.","children":[{"name":"expression","type":"String","description":"The filter expression that determines which requests the rule matches."},{"name":"mode","type":"String","description":"The override mode Precursor applies to requests matching an enforcement\nrule. Unlike `default_mode`, this cannot be `off`.\n"},{"name":"id","type":"String","description":"The read-only identifier that Cloudflare assigns to the rule."},{"name":"description","type":"String","description":"An informative description of the rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is active."}]}]}]},"get /zones/{}/rate_limits/{}":{"operationId":"rate-limits-for-a-zone-get-a-rate-limit","declarations":[{"kind":"data-source","name":"cloudflare_rate_limit","stainlessResource":"rate_limits","methodName":"get","snippet":"data \"cloudflare_rate_limit\" \"example_rate_limit\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rate_limit_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}\n","required":[{"name":"rate_limit_id","type":"String","description":"Defines the unique identifier of the rate limit."},{"name":"zone_id","type":"String","description":"Defines an identifier."}],"optional":[],"computed":[]}]},"get /zones/{}/schema_validation/schemas":{"operationId":"schema-validation-list-schemas-paginated","declarations":[{"kind":"list-data-source","name":"cloudflare_schema_validation_schemas_list","stainlessResource":"schema_validation.schemas","methodName":"list","snippet":"data \"cloudflare_schema_validation_schemas_list\" \"example_schema_validation_schemas_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"validation_enabled","type":"Bool","description":"Filter for enabled schemas"},{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"A unique identifier of this schema"},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The kind of the schema"},{"name":"name","type":"String","description":"A human-readable name for the schema"},{"name":"schema_id","type":"String","description":"A unique identifier of this schema"},{"name":"source","type":"String","description":"The raw schema, e.g., the OpenAPI schema, either as JSON or YAML"},{"name":"validation_enabled","type":"Bool","description":"An indicator if this schema is enabled"}]}]}]},"get /zones/{}/schema_validation/schemas/{}":{"operationId":"schema-validation-get-schema","declarations":[{"kind":"data-source","name":"cloudflare_schema_validation_schemas","stainlessResource":"schema_validation.schemas","methodName":"get","snippet":"data \"cloudflare_schema_validation_schemas\" \"example_schema_validation_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n schema_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n omit_source = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"schema_id","type":"String","description":"UUID."},{"name":"omit_source","type":"Bool","description":"Omit the source-files of schemas and only retrieve their meta-data."},{"name":"filter","type":"Attributes","children":[{"name":"validation_enabled","type":"Bool","description":"Filter for enabled schemas"}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"kind","type":"String","description":"The kind of the schema"},{"name":"name","type":"String","description":"A human-readable name for the schema"},{"name":"source","type":"String","description":"The raw schema, e.g., the OpenAPI schema, either as JSON or YAML"},{"name":"validation_enabled","type":"Bool","description":"An indicator if this schema is enabled"}]}]},"get /zones/{}/schema_validation/settings":{"operationId":"schema-validation-get-settings","declarations":[{"kind":"data-source","name":"cloudflare_schema_validation_settings","stainlessResource":"schema_validation.settings","methodName":"get","snippet":"data \"cloudflare_schema_validation_settings\" \"example_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used\n\nMitigation actions are as follows:\n\n - `log` - log request when request does not conform to schema\n - `block` - deny access to the site when request does not conform to schema\n - `none` - skip running schema validation\n"},{"name":"validation_override_mitigation_action","type":"String","description":"When not null, this overrides global both zone level and operation level mitigation actions. This can serve as a quick way to disable schema validation for the whole zone.\n\n - `\"none\"` will skip running schema validation entirely for the request\n"}]}]},"get /zones/{}/schema_validation/settings/operations":{"operationId":"schema-validation-list-per-operation-settings","declarations":[{"kind":"list-data-source","name":"cloudflare_schema_validation_operation_settings_list","stainlessResource":"schema_validation.settings.operations","methodName":"list","snippet":"data \"cloudflare_schema_validation_operation_settings_list\" \"example_schema_validation_operation_settings_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation which supersedes a global schema validation setting just for this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\n"},{"name":"operation_id","type":"String","description":"UUID."}]}]}]},"get /zones/{}/schema_validation/settings/operations/{}":{"operationId":"schema-validation-get-per-operation-setting","declarations":[{"kind":"data-source","name":"cloudflare_schema_validation_operation_settings","stainlessResource":"schema_validation.settings.operations","methodName":"get","snippet":"data \"cloudflare_schema_validation_operation_settings\" \"example_schema_validation_operation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation which supersedes a global schema validation setting just for this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\n"}]}]},"get /zones/{}/secondary_dns/incoming":{"operationId":"secondary-dns-(-secondary-zone)-secondary-zone-configuration-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_incoming","stainlessResource":"dns.zone_transfers.incoming","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_incoming\" \"example_dns_zone_transfers_incoming\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"auto_refresh_seconds","type":"Float64","description":"How often should a secondary zone auto refresh regardless of DNS NOTIFY.\nNot applicable for primary zones."},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"modified_time","type":"String","description":"The time for a specific event."},{"name":"name","type":"String","description":"Zone name."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}]}]},"get /zones/{}/secondary_dns/outgoing":{"operationId":"secondary-dns-(-primary-zone)-primary-zone-configuration-details","declarations":[{"kind":"data-source","name":"cloudflare_dns_zone_transfers_outgoing","stainlessResource":"dns.zone_transfers.outgoing","methodName":"get","snippet":"data \"cloudflare_dns_zone_transfers_outgoing\" \"example_dns_zone_transfers_outgoing\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"last_transferred_time","type":"String","description":"The time for a specific event."},{"name":"name","type":"String","description":"Zone name."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}]}]},"get /zones/{}/settings":{"operationId":"zone-settings-get-all-zone-settings","declarations":[{"kind":"list-data-source","name":"cloudflare_zone_settings","stainlessResource":"zones.settings","methodName":"list","snippet":"data \"cloudflare_zone_settings\" \"example_zone_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"ID of the zone setting."},{"name":"value","type":"String","description":"Current value of the zone setting."},{"name":"editable","type":"Bool","description":"Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)."},{"name":"modified_on","type":"Time","description":"last time this setting was modified."},{"name":"time_remaining","type":"Float64","description":"Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false."},{"name":"enabled","type":"Bool","description":"ssl-recommender enrollment setting."}]}]}]},"get /zones/{}/settings/{}":{"operationId":"zone-settings-get-single-setting","declarations":[{"kind":"data-source","name":"cloudflare_zone_setting","stainlessResource":"zones.settings","methodName":"get","snippet":"data \"cloudflare_zone_setting\" \"example_zone_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"always_online\"\n}\n","required":[{"name":"setting_id","type":"String","description":"Setting name"},{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Setting name"},{"name":"editable","type":"Bool","description":"Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)."},{"name":"enabled","type":"Bool","description":"ssl-recommender enrollment setting."},{"name":"modified_on","type":"Time","description":"last time this setting was modified."},{"name":"time_remaining","type":"Float64","description":"Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false."},{"name":"value","type":"String","description":"Current value of the zone setting."}]}]},"get /zones/{}/settings/auto_origin_tls_kex":{"operationId":"ssl-detector-auto-origin-tls-kex-get-enrollment","declarations":[{"kind":"data-source","name":"cloudflare_zone_auto_origin_tls_kex","stainlessResource":"ssl.auto_origin_tls_kex","methodName":"get","snippet":"data \"cloudflare_zone_auto_origin_tls_kex\" \"example_zone_auto_origin_tls_kex\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"enabled","type":"Bool","description":"Whether Auto-Origin TLS KEX selection is enabled for the zone."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"get /zones/{}/settings/google-tag-gateway/config":{"operationId":"zone-settings-get-google-tag-gateway-config","declarations":[{"kind":"data-source","name":"cloudflare_google_tag_gateway","stainlessResource":"google_tag_gateway.config","methodName":"get","snippet":"data \"cloudflare_google_tag_gateway\" \"example_google_tag_gateway\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Enables or disables Google Tag Gateway for this zone."},{"name":"endpoint","type":"String","description":"Specifies the endpoint path for proxying Google Tag Manager requests. Use an absolute path starting with '/', with no nested paths and alphanumeric characters only (e.g. /metrics)."},{"name":"hide_original_ip","type":"Bool","description":"Hides the original client IP address from Google when enabled."},{"name":"measurement_id","type":"String","description":"Specify the Google Tag Manager container or measurement ID (e.g. GTM-XXXXXXX or G-XXXXXXXXXX)."},{"name":"set_up_tag","type":"Bool","description":"Set up the associated Google Tag on the zone automatically when enabled."}]}]},"get /zones/{}/settings/nel":{"operationId":"nel-settings-get","declarations":[{"kind":"data-source","name":"cloudflare_nel_setting","stainlessResource":"zones.nel","methodName":"get","snippet":"data \"cloudflare_nel_setting\" \"example_nel_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier of the zone."},{"name":"editable","type":"Bool","description":"Whether the setting is editable. This is false when the zone's plan does not include NEL or the NEL product feature is not enabled.\n"},{"name":"modified_on","type":"Time","description":"When the setting was last modified. A zero value (0001-01-01T00:00:00Z) indicates the setting has never been explicitly set and is using the default value.\n"},{"name":"value","type":"Attributes","description":"The NEL configuration value.","children":[{"name":"enabled","type":"Bool","description":"Whether Network Error Logging is enabled for the zone. When enabled, browsers report network errors to Cloudflare's NEL endpoint.\n"}]}]}]},"get /zones/{}/settings/origin_tls_compliance_modes":{"operationId":"zone-cache-settings-get-origin-tls-compliance-modes-setting","declarations":[{"kind":"data-source","name":"cloudflare_origin_tls_compliance_modes","stainlessResource":"origin_tls_compliance_modes","methodName":"get","snippet":"data \"cloudflare_origin_tls_compliance_modes\" \"example_origin_tls_compliance_modes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."},{"name":"value","type":"List[String]","description":"List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone's origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint."}]}]},"get /zones/{}/snippets":{"operationId":"listZoneSnippets","declarations":[{"kind":"list-data-source","name":"cloudflare_snippets","stainlessResource":"snippets","methodName":"list","snippet":"data \"cloudflare_snippets\" \"example_snippets\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identify the snippet."},{"name":"created_on","type":"Time","description":"Indicates when the snippet was created."},{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"modified_on","type":"Time","description":"Indicates when the snippet was last modified."}]}]}]},"get /zones/{}/snippets/{}":{"operationId":"getZoneSnippet","declarations":[{"kind":"data-source","name":"cloudflare_snippet","stainlessResource":"snippets","methodName":"get","snippet":"data \"cloudflare_snippet\" \"example_snippet\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n snippet_name = \"my_snippet\"\n}\n","required":[{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identify the snippet."},{"name":"created_on","type":"Time","description":"Indicates when the snippet was created."},{"name":"modified_on","type":"Time","description":"Indicates when the snippet was last modified."}]}]},"get /zones/{}/snippets/snippet_rules":{"operationId":"listZoneSnippetRules","declarations":[{"kind":"data-source","name":"cloudflare_snippet_rules","stainlessResource":"snippets.rules","methodName":"get","snippet":"data \"cloudflare_snippet_rules\" \"example_snippet_rules\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Use this field to specify the unique ID of the zone."},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."}]},{"kind":"list-data-source","name":"cloudflare_snippet_rules_list","stainlessResource":"snippets.rules","methodName":"list","snippet":"data \"cloudflare_snippet_rules_list\" \"example_snippet_rules_list\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Specify the unique ID of the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."}]}]}]},"get /zones/{}/spectrum/apps":{"operationId":"spectrum-applications-list-spectrum-applications","declarations":[{"kind":"list-data-source","name":"cloudflare_spectrum_applications","stainlessResource":"spectrum.apps","methodName":"list","snippet":"data \"cloudflare_spectrum_applications\" \"example_spectrum_applications\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier."}],"optional":[{"name":"direction","type":"String","description":"Sets the direction by which results are ordered."},{"name":"order","type":"String","description":"Application field by which results are ordered."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"App identifier."},{"name":"created_on","type":"Time","description":"When the Application was created."},{"name":"dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the application."},{"name":"type","type":"String","description":"The type of DNS record associated with the application."}]},{"name":"modified_on","type":"Time","description":"When the Application was last modified."},{"name":"protocol","type":"String","description":"The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`."},{"name":"traffic_type","type":"String","description":"Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`."},{"name":"argo_smart_routing","type":"Bool","description":"Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"."},{"name":"edge_ips","type":"Attributes","description":"The anycast edge IP configuration for the hostname of this application.","children":[{"name":"connectivity","type":"String","description":"The IP versions supported for inbound connections on Spectrum anycast IPs."},{"name":"type","type":"String","description":"The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names."},{"name":"ips","type":"List[String]","description":"The array of customer owned IPs we broadcast via anycast for this hostname and application."}]},{"name":"ip_firewall","type":"Bool","description":"Enables IP Access Rules for this application.\nNotes: Only available for TCP applications."},{"name":"origin_direct","type":"List[String]","description":"List of origin IP addresses. Array may contain multiple IP addresses for load balancing."},{"name":"origin_dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the origin."},{"name":"ttl","type":"Int64","description":"The TTL of our resolution of your DNS record in seconds."},{"name":"type","type":"String","description":"The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records."}]},{"name":"origin_port","type":"Dynamic Int64 | String","description":"The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field."},{"name":"origin_worker_id","type":"String","description":"Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"."},{"name":"proxy_protocol","type":"String","description":"Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol."},{"name":"tls","type":"String","description":"The type of TLS termination associated with the application."},{"name":"virtual_network_id","type":"String","description":"Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks."}]}]}]},"get /zones/{}/spectrum/apps/{}":{"operationId":"spectrum-applications-get-spectrum-application-configuration","declarations":[{"kind":"data-source","name":"cloudflare_spectrum_application","stainlessResource":"spectrum.apps","methodName":"get","snippet":"data \"cloudflare_spectrum_application\" \"example_spectrum_application\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n app_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier."}],"optional":[{"name":"app_id","type":"String","description":"App identifier."},{"name":"filter","type":"Attributes","children":[{"name":"direction","type":"String","description":"Sets the direction by which results are ordered."},{"name":"order","type":"String","description":"Application field by which results are ordered."}]}],"computed":[{"name":"id","type":"String","description":"App identifier."},{"name":"argo_smart_routing","type":"Bool","description":"Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"."},{"name":"created_on","type":"Time","description":"When the Application was created."},{"name":"ip_firewall","type":"Bool","description":"Enables IP Access Rules for this application.\nNotes: Only available for TCP applications."},{"name":"modified_on","type":"Time","description":"When the Application was last modified."},{"name":"origin_worker_id","type":"String","description":"Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"."},{"name":"protocol","type":"String","description":"The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`."},{"name":"proxy_protocol","type":"String","description":"Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol."},{"name":"tls","type":"String","description":"The type of TLS termination associated with the application."},{"name":"traffic_type","type":"String","description":"Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`."},{"name":"virtual_network_id","type":"String","description":"Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks."},{"name":"origin_direct","type":"List[String]","description":"List of origin IP addresses. Array may contain multiple IP addresses for load balancing."},{"name":"dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the application."},{"name":"type","type":"String","description":"The type of DNS record associated with the application."}]},{"name":"edge_ips","type":"Attributes","description":"The anycast edge IP configuration for the hostname of this application.","children":[{"name":"connectivity","type":"String","description":"The IP versions supported for inbound connections on Spectrum anycast IPs."},{"name":"type","type":"String","description":"The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names."},{"name":"ips","type":"List[String]","description":"The array of customer owned IPs we broadcast via anycast for this hostname and application."}]},{"name":"origin_dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the origin."},{"name":"ttl","type":"Int64","description":"The TTL of our resolution of your DNS record in seconds."},{"name":"type","type":"String","description":"The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records."}]},{"name":"origin_port","type":"Dynamic Int64 | String","description":"The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field."}]}]},"get /zones/{}/spectrum/protocols":{"operationId":"spectrum-applications-list-spectrum-application-protocols","declarations":[{"kind":"list-data-source","name":"cloudflare_spectrum_protocols","stainlessResource":"spectrum.protocols","methodName":"list","snippet":"data \"cloudflare_spectrum_protocols\" \"example_spectrum_protocols\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"description","type":"String","description":"The full name of the application protocol."},{"name":"name","type":"String","description":"The short name of the application protocol."},{"name":"ports","type":"List[Int64]","description":"The available listening ports for the given protocol."},{"name":"transport","type":"String","description":"The transport layer protocol used by the application protocol"}]}]}]},"get /zones/{}/speed_api/schedule/{}":{"operationId":"speed-get-scheduled-test","declarations":[{"kind":"data-source","name":"cloudflare_observatory_scheduled_test","stainlessResource":"speed.schedule","methodName":"get","snippet":"data \"cloudflare_observatory_scheduled_test\" \"example_observatory_scheduled_test\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n url = \"example.com\"\n region = \"us-central1\"\n}\n","required":[{"name":"url","type":"String","description":"A URL."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"region","type":"String","description":"A test region."}],"computed":[{"name":"frequency","type":"String","description":"The frequency of the test."}]}]},"get /zones/{}/ssl/certificate_packs":{"operationId":"certificate-packs-list-certificate-packs","declarations":[{"kind":"list-data-source","name":"cloudflare_certificate_packs","stainlessResource":"ssl.certificate_packs","methodName":"list","snippet":"data \"cloudflare_certificate_packs\" \"example_certificate_packs\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n deploy = \"staging\"\n status = \"all\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"deploy","type":"String","description":"Specify the deployment environment for the certificate packs."},{"name":"status","type":"String","description":"Include Certificate Packs of all statuses, not just active ones."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"The unique identifier for a certificate_pack."},{"name":"certificates","type":"List[Attributes]","description":"Array of certificates in this pack.","children":[{"name":"id","type":"String","description":"Certificate identifier."},{"name":"hosts","type":"List[String]","description":"Hostnames covered by this certificate."},{"name":"status","type":"String","description":"Certificate status."},{"name":"bundle_method","type":"String","description":"Certificate bundle method."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally.","children":[{"name":"label","type":"String"}]},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"zone_id","type":"String","description":"Identifier."}]},{"name":"hosts","type":"Set[String]","description":"Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty."},{"name":"status","type":"String","description":"Status of certificate pack."},{"name":"type","type":"String","description":"Type of certificate pack."},{"name":"certificate_authority","type":"String","description":"Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities)."},{"name":"cloudflare_branding","type":"Bool","description":"Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true."},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"primary_certificate","type":"String","description":"Identifier of the primary certificate in a pack."},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_method","type":"String","description":"Validation Method selected for the order."},{"name":"validation_records","type":"List[Attributes]","description":"Certificates' validation records.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"validity_days","type":"Int64","description":"Validity Days selected for the order."}]}]}]},"get /zones/{}/ssl/certificate_packs/{}":{"operationId":"certificate-packs-get-certificate-pack","declarations":[{"kind":"data-source","name":"cloudflare_certificate_pack","stainlessResource":"ssl.certificate_packs","methodName":"get","snippet":"data \"cloudflare_certificate_pack\" \"example_certificate_pack\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_pack_id = \"3822ff90-ea29-44df-9e55-21300bb9419b\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"certificate_pack_id","type":"String","description":"The unique identifier for a certificate_pack."},{"name":"filter","type":"Attributes","children":[{"name":"deploy","type":"String","description":"Specify the deployment environment for the certificate packs."},{"name":"status","type":"String","description":"Include Certificate Packs of all statuses, not just active ones."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier for a certificate_pack."},{"name":"certificate_authority","type":"String","description":"Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities)."},{"name":"cloudflare_branding","type":"Bool","description":"Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true."},{"name":"primary_certificate","type":"String","description":"Identifier of the primary certificate in a pack."},{"name":"status","type":"String","description":"Status of certificate pack."},{"name":"type","type":"String","description":"Type of certificate pack."},{"name":"validation_method","type":"String","description":"Validation Method selected for the order."},{"name":"validity_days","type":"Int64","description":"Validity Days selected for the order."},{"name":"hosts","type":"Set[String]","description":"Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty."},{"name":"certificates","type":"List[Attributes]","description":"Array of certificates in this pack.","children":[{"name":"id","type":"String","description":"Certificate identifier."},{"name":"hosts","type":"List[String]","description":"Hostnames covered by this certificate."},{"name":"status","type":"String","description":"Certificate status."},{"name":"bundle_method","type":"String","description":"Certificate bundle method."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally.","children":[{"name":"label","type":"String"}]},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"zone_id","type":"String","description":"Identifier."}]},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","description":"Certificates' validation records.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]}]}]},"get /zones/{}/ssl/universal/settings":{"operationId":"universal-ssl-settings-for-a-zone-universal-ssl-settings-details","declarations":[{"kind":"data-source","name":"cloudflare_universal_ssl_setting","stainlessResource":"ssl.universal.settings","methodName":"get","snippet":"data \"cloudflare_universal_ssl_setting\" \"example_universal_ssl_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"enabled","type":"Bool","description":"Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.\n\nBy disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.\n\n* HSTS\n* Always Use HTTPS\n* Opportunistic Encryption\n* Onion Routing\n* Any Page Rules redirecting traffic to HTTPS\n\nSimilarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare's edge.\n\nIf you do not have a valid custom or advanced certificate at Cloudflare's edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain."}]}]},"get /zones/{}/subscription":{"operationId":"zone-subscription-zone-subscription-details","declarations":[{"kind":"data-source","name":"cloudflare_zone_subscription","stainlessResource":"zones.subscriptions","methodName":"get","snippet":"data \"cloudflare_zone_subscription\" \"example_zone_subscription\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier"}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"currency","type":"String","description":"The monetary unit in which pricing information is displayed."},{"name":"current_period_end","type":"Time","description":"The end of the current period and also when the next billing is due."},{"name":"current_period_start","type":"Time","description":"When the current billing period started. May match initial_period_start if this is the first period."},{"name":"frequency","type":"String","description":"How often the subscription is renewed automatically."},{"name":"price","type":"Float64","description":"The price of the subscription that will be billed, in US dollars."},{"name":"state","type":"String","description":"The state that the subscription is in."},{"name":"rate_plan","type":"Attributes","description":"The rate plan applied to the subscription.","children":[{"name":"id","type":"String","description":"The ID of the rate plan."},{"name":"currency","type":"String","description":"The currency applied to the rate plan subscription."},{"name":"externally_managed","type":"Bool","description":"Whether this rate plan is managed externally from Cloudflare."},{"name":"is_contract","type":"Bool","description":"Whether a rate plan is enterprise-based (or newly adopted term contract)."},{"name":"public_name","type":"String","description":"The full name of the rate plan."},{"name":"scope","type":"String","description":"The scope that this rate plan applies to."},{"name":"sets","type":"List[String]","description":"The list of sets this rate plan applies to. Returns array of strings."}]}]}]},"get /zones/{}/token_validation/config":{"operationId":"token-validation-config-list","declarations":[{"kind":"list-data-source","name":"cloudflare_token_validation_configs","stainlessResource":"token_validation.configuration","methodName":"list","snippet":"data \"cloudflare_token_validation_configs\" \"example_token_validation_configs\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"credentials","type":"Attributes","children":[{"name":"keys","type":"List[Attributes]","children":[{"name":"alg","type":"String","description":"Algorithm"},{"name":"e","type":"String","description":"RSA exponent"},{"name":"kid","type":"String","description":"Key ID"},{"name":"kty","type":"String","description":"Key Type"},{"name":"n","type":"String","description":"RSA modulus"},{"name":"crv","type":"String","description":"Curve"},{"name":"x","type":"String","description":"X EC coordinate"},{"name":"y","type":"String","description":"Y EC coordinate"}]}]},{"name":"description","type":"String"},{"name":"last_updated","type":"Time"},{"name":"title","type":"String"},{"name":"token_sources","type":"List[String]"},{"name":"token_type","type":"String"}]}]}]},"get /zones/{}/token_validation/config/{}":{"operationId":"token-validation-config-get","declarations":[{"kind":"data-source","name":"cloudflare_token_validation_config","stainlessResource":"token_validation.configuration","methodName":"get","snippet":"data \"cloudflare_token_validation_config\" \"example_token_validation_config\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n config_id = \"4a7ee8d3-dd63-4ceb-9d5f-c27831854ce7\"\n}\n","required":[{"name":"config_id","type":"String","description":"UUID."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"description","type":"String"},{"name":"last_updated","type":"Time"},{"name":"title","type":"String"},{"name":"token_type","type":"String"},{"name":"token_sources","type":"List[String]"},{"name":"credentials","type":"Attributes","children":[{"name":"keys","type":"List[Attributes]","children":[{"name":"alg","type":"String","description":"Algorithm"},{"name":"e","type":"String","description":"RSA exponent"},{"name":"kid","type":"String","description":"Key ID"},{"name":"kty","type":"String","description":"Key Type"},{"name":"n","type":"String","description":"RSA modulus"},{"name":"crv","type":"String","description":"Curve"},{"name":"x","type":"String","description":"X EC coordinate"},{"name":"y","type":"String","description":"Y EC coordinate"}]}]}]}]},"get /zones/{}/token_validation/rules":{"operationId":"token-validation-rules-list","declarations":[{"kind":"list-data-source","name":"cloudflare_token_validation_rules_list","stainlessResource":"token_validation.rules","methodName":"list","snippet":"data \"cloudflare_token_validation_rules_list\" \"example_token_validation_rules_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n action = \"log\"\n enabled = true\n host = \"www.example.com\"\n hostname = \"www.example.com\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n token_configuration = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"host","type":"String","description":"Select rules with this host in `include`."},{"name":"hostname","type":"String","description":"Select rules with this host in `include`."},{"name":"id","type":"String","description":"Select rules with these IDs."},{"name":"rule_id","type":"String","description":"Select rules with these IDs."},{"name":"token_configuration","type":"List[String]","description":"Select rules using any of these token configurations."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"description","type":"String","description":"A human-readable description that gives more details than `title`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"expression","type":"String","description":"Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n"},{"name":"selector","type":"Attributes","description":"Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n","children":[{"name":"exclude","type":"List[Attributes]","description":"Ignore operations that were otherwise included by `include`.","children":[{"name":"operation_ids","type":"List[String]","description":"Excluded operation IDs."}]},{"name":"include","type":"List[Attributes]","description":"Select all matching operations.","children":[{"name":"host","type":"List[String]","description":"Included hostnames."}]}]},{"name":"title","type":"String","description":"A human-readable name for the rule."},{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"last_updated","type":"Time"}]}]}]},"get /zones/{}/token_validation/rules/{}":{"operationId":"token-validation-rules-get","declarations":[{"kind":"data-source","name":"cloudflare_token_validation_rules","stainlessResource":"token_validation.rules","methodName":"get","snippet":"data \"cloudflare_token_validation_rules\" \"example_token_validation_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_id = \"4a7ee8d3-dd63-4ceb-9d5f-c27831854ce7\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"rule_id","type":"String","description":"UUID."},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"Select rules with these IDs."},{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"host","type":"String","description":"Select rules with this host in `include`."},{"name":"hostname","type":"String","description":"Select rules with this host in `include`."},{"name":"token_configuration","type":"List[String]","description":"Select rules using any of these token configurations."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"created_at","type":"Time"},{"name":"description","type":"String","description":"A human-readable description that gives more details than `title`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"expression","type":"String","description":"Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n"},{"name":"last_updated","type":"Time"},{"name":"title","type":"String","description":"A human-readable name for the rule."},{"name":"selector","type":"Attributes","description":"Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n","children":[{"name":"exclude","type":"List[Attributes]","description":"Ignore operations that were otherwise included by `include`.","children":[{"name":"operation_ids","type":"List[String]","description":"Excluded operation IDs."}]},{"name":"include","type":"List[Attributes]","description":"Select all matching operations.","children":[{"name":"host","type":"List[String]","description":"Included hostnames."}]}]}]}]},"get /zones/{}/url_normalization":{"operationId":"getUrlNormalization","declarations":[{"kind":"data-source","name":"cloudflare_url_normalization_settings","stainlessResource":"url_normalization","methodName":"get","snippet":"data \"cloudflare_url_normalization_settings\" \"example_url_normalization_settings\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone."},{"name":"scope","type":"String","description":"The scope of the URL normalization."},{"name":"type","type":"String","description":"The type of URL normalization performed by Cloudflare."}]}]},"get /zones/{}/waiting_rooms/{}":{"operationId":"waiting-room-waiting-room-details","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room","stainlessResource":"waiting_rooms","methodName":"get","snippet":"data \"cloudflare_waiting_room\" \"example_waiting_room\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"cookie_suffix","type":"String","description":"Appends a '_' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(__cf_waitingroom). If `cookie_suffix` is \"abcd\", the cookie name will be `__cf_waitingroom_abcd`. This field is required if using `additional_routes`."},{"name":"created_on","type":"Time"},{"name":"custom_page_html","type":"String","description":"Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custom_page_html is provided, the default waiting room will be used. The template is based on mustache ( https://mustache.github.io/ ). There are several variables that are evaluated by the Cloudflare edge:\n1. {{`waitTimeKnown`}} Acts like a boolean value that indicates the behavior to take when wait time is not available, for instance when queue_all is **true**.\n2. {{`waitTimeFormatted`}} Estimated wait time for the user. For example, five minutes. Alternatively, you can use:\n3. {{`waitTime`}} Number of minutes of estimated wait for a user.\n4. {{`waitTimeHours`}} Number of hours of estimated wait for a user (`Math.floor(waitTime/60)`).\n5. {{`waitTimeHourMinutes`}} Number of minutes above the `waitTimeHours` value (`waitTime%60`).\n6. {{`queueIsFull`}} Changes to **true** when no more people can be added to the queue.\n\nTo view the full list of variables, look at the `cfWaitingRoom` object described under the `json_response_enabled` property in other Waiting Room API calls."},{"name":"default_template_language","type":"String","description":"The language of the default page template. If no default_template_language is provided, then `en-US` (English) will be used."},{"name":"description","type":"String","description":"A note that you can use to add more details about the waiting room."},{"name":"disable_session_renewal","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If `true`, an accepted user will have session_duration minutes to browse the site. After that, they will have to go through the waiting room again. If `false`, a user's session cookie will be automatically renewed on every request."},{"name":"host","type":"String","description":"The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination must be unique."},{"name":"json_response_enabled","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. If `true`, requests to the waiting room with the header `Accept: application/json` will receive a JSON response object with information on the user's status in the waiting room as opposed to the configured static HTML page. This JSON response object has one property `cfWaitingRoom` which is an object containing the following fields:\n1. `inWaitingRoom`: Boolean indicating if the user is in the waiting room (always **true**).\n2. `waitTimeKnown`: Boolean indicating if the current estimated wait times are accurate. If **false**, they are not available.\n3. `waitTime`: Valid only when `waitTimeKnown` is **true**. Integer indicating the current estimated time in minutes the user will wait in the waiting room. When `queueingMethod` is **random**, this is set to `waitTime50Percentile`.\n4. `waitTime25Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 25% of users that gain entry the fastest (25th percentile).\n5. `waitTime50Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 50% of users that gain entry the fastest (50th percentile). In other words, half of the queued users are expected to let into the origin website before `waitTime50Percentile` and half are expected to be let in after it.\n6. `waitTime75Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 75% of users that gain entry the fastest (75th percentile).\n7. `waitTimeFormatted`: String displaying the `waitTime` formatted in English for users. If `waitTimeKnown` is **false**, `waitTimeFormatted` will display **unavailable**.\n8. `queueIsFull`: Boolean indicating if the waiting room's queue is currently full and not accepting new users at the moment.\n9. `queueAll`: Boolean indicating if all users will be queued in the waiting room and no one will be let into the origin website.\n10. `lastUpdated`: String displaying the timestamp as an ISO 8601 string of the user's last attempt to leave the waiting room and be let into the origin website. The user is able to make another attempt after `refreshIntervalSeconds` past this time. If the user makes a request too soon, it will be ignored and `lastUpdated` will not change.\n11. `refreshIntervalSeconds`: Integer indicating the number of seconds after `lastUpdated` until the user is able to make another attempt to leave the waiting room and be let into the origin website. When the `queueingMethod` is `reject`, there is no specified refresh time —\\_it will always be **zero**.\n12. `queueingMethod`: The queueing method currently used by the waiting room. It is either **fifo**, **random**, **passthrough**, or **reject**.\n13. `isFIFOQueue`: Boolean indicating if the waiting room uses a FIFO (First-In-First-Out) queue.\n14. `isRandomQueue`: Boolean indicating if the waiting room uses a Random queue where users gain access randomly.\n15. `isPassthroughQueue`: Boolean indicating if the waiting room uses a passthrough queue. Keep in mind that when passthrough is enabled, this JSON response will only exist when `queueAll` is **true** or `isEventPrequeueing` is **true** because in all other cases requests will go directly to the origin.\n16. `isRejectQueue`: Boolean indicating if the waiting room uses a reject queue.\n17. `isEventActive`: Boolean indicating if an event is currently occurring. Events are able to change a waiting room's behavior during a specified period of time. For additional information, look at the event properties `prequeue_start_time`, `event_start_time`, and `event_end_time` in the documentation for creating waiting room events. Events are considered active between these start and end times, as well as during the prequeueing period if it exists.\n18. `isEventPrequeueing`: Valid only when `isEventActive` is **true**. Boolean indicating if an event is currently prequeueing users before it starts.\n19. `timeUntilEventStart`: Valid only when `isEventPrequeueing` is **true**. Integer indicating the number of minutes until the event starts.\n20. `timeUntilEventStartFormatted`: String displaying the `timeUntilEventStart` formatted in English for users. If `isEventPrequeueing` is **false**, `timeUntilEventStartFormatted` will display **unavailable**.\n21. `timeUntilEventEnd`: Valid only when `isEventActive` is **true**. Integer indicating the number of minutes until the event ends.\n22. `timeUntilEventEndFormatted`: String displaying the `timeUntilEventEnd` formatted in English for users. If `isEventActive` is **false**, `timeUntilEventEndFormatted` will display **unavailable**.\n23. `shuffleAtEventStart`: Valid only when `isEventActive` is **true**. Boolean indicating if the users in the prequeue are shuffled randomly when the event starts.\n24. `turnstile`: Empty when turnstile isn't enabled. String displaying an html tag to display the Turnstile widget. Please add the `{{{turnstile}}}` tag to the `custom_html` template to ensure the Turnstile widget appears.\n25. `infiniteQueue`: Boolean indicating whether the response is for a user in the infinite queue.\n\nAn example cURL to a waiting room could be:\n\n\tcurl -X GET \"https://example.com/waitingroom\" \\\n\t\t-H \"Accept: application/json\"\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **fifo** and no event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 0,\n\t\t\t\"waitTime50Percentile\": 0,\n\t\t\t\"waitTime75Percentile\": 0,\n\t\t\t\"waitTimeFormatted\": \"10 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"fifo\",\n\t\t\t\"isFIFOQueue\": true,\n\t\t\t\"isRandomQueue\": false,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": false,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 0,\n\t\t\t\"timeUntilEventEndFormatted\": \"unavailable\",\n\t\t\t\"shuffleAtEventStart\": false\n\t\t}\n\t}\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **random** and an event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 5,\n\t\t\t\"waitTime50Percentile\": 10,\n\t\t\t\"waitTime75Percentile\": 15,\n\t\t\t\"waitTimeFormatted\": \"5 minutes to 15 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"random\",\n\t\t\t\"isFIFOQueue\": false,\n\t\t\t\"isRandomQueue\": true,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": true,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 15,\n\t\t\t\"timeUntilEventEndFormatted\": \"15 minutes\",\n\t\t\t\"shuffleAtEventStart\": true\n\t\t}\n\t}"},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. So it is possible that there is a little more or little less traffic coming to the route based on the traffic patterns at that time around the world."},{"name":"next_event_prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will begin queueing."},{"name":"next_event_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will start."},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."},{"name":"queue_all","type":"Bool","description":"If queue_all is `true`, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and estimated time will become unavailable."},{"name":"queueing_method","type":"String","description":"Sets the queueing method used by the waiting room. Changing this parameter from the **default** queueing method is only available for the Waiting Room Advanced subscription. Regardless of the queueing method, if `queue_all` is enabled or an event is prequeueing, users in the waiting room will not be accepted to the origin. These users will always see a waiting room page that refreshes automatically. The valid queueing methods are:\n1. `fifo` **(default)**: First-In-First-Out queue where customers gain access in the order they arrived.\n2. `random`: Random queue where customers gain access randomly, regardless of arrival time.\n3. `passthrough`: Users will pass directly through the waiting room and into the origin website. As a result, any configured limits will not be respected while this is enabled. This method can be used as an alternative to disabling a waiting room (with `suspended`) so that analytics are still reported. This can be used if you wish to allow all traffic normally, but want to restrict traffic during a waiting room event, or vice versa.\n4. `reject`: Users will be immediately rejected from the waiting room. As a result, no users will reach the origin website while this is enabled. This can be used if you wish to reject all traffic while performing maintenance, block traffic during a specified period of time (an event), or block traffic while events are not occurring. Consider a waiting room used for vaccine distribution that only allows traffic during sign-up events, and otherwise blocks all traffic. For this case, the waiting room uses `reject`, and its events override this with `fifo`, `random`, or `passthrough`. When this queueing method is enabled and neither `queueAll` is enabled nor an event is prequeueing, the waiting room page **will not refresh automatically**."},{"name":"queueing_status_code","type":"Int64","description":"HTTP status code returned to a user while in the queue."},{"name":"session_duration","type":"Int64","description":"Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they will be treated as a new user that visits the route."},{"name":"suspended","type":"Bool","description":"Suspends or allows traffic going to the waiting room. If set to `true`, the traffic will not go to the waiting room."},{"name":"total_active_users","type":"Int64","description":"Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available. This value is used as a baseline for the total number of active user sessions on the route. It is possible to have a situation where there are more or less active users sessions on the route based on the traffic patterns at that time around the world."},{"name":"turnstile_action","type":"String","description":"Which action to take when a bot is detected using Turnstile. `log` will\nhave no impact on queueing behavior, simply keeping track of how many\nbots are detected in Waiting Room Analytics. `infinite_queue` will send\nbots to a false queueing state, where they will never reach your\norigin. `infinite_queue` requires Advanced Waiting Room.\n"},{"name":"turnstile_mode","type":"String","description":"Which Turnstile widget type to use for detecting bot traffic. See\n[the Turnstile documentation](https://developers.cloudflare.com/turnstile/concepts/widget/#widget-types)\nfor the definitions of these widget types. Set to `off` to disable the\nTurnstile integration entirely. Setting this to anything other than\n`off` or `invisible` requires Advanced Waiting Room.\n"},{"name":"enabled_origin_commands","type":"List[String]","description":"A list of enabled origin commands."},{"name":"additional_routes","type":"List[Attributes]","description":"Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an implied wildcard at the end of the path. The hostname and path combination must be unique to this and all other waiting rooms.","children":[{"name":"host","type":"String","description":"The hostname to which this waiting room will be applied (no wildcards). The hostname must be the primary domain, subdomain, or custom hostname (if using SSL for SaaS) of this zone. Please do not include the scheme (http:// or https://)."},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."}]},{"name":"cookie_attributes","type":"Attributes","description":"Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.","children":[{"name":"samesite","type":"String","description":"Configures the SameSite attribute on the waiting room cookie. Value `auto` will be translated to `lax` or `none` depending if **Always Use HTTPS** is enabled. Note that when using value `none`, the secure attribute cannot be set to `never`."},{"name":"secure","type":"String","description":"Configures the Secure attribute on the waiting room cookie. Value `always` indicates that the Secure attribute will be set in the Set-Cookie header, `never` indicates that the Secure attribute will not be set, and `auto` will set the Secure attribute depending if **Always Use HTTPS** is enabled."}]}]}]},"get /zones/{}/waiting_rooms/{}/events":{"operationId":"waiting-room-list-events","declarations":[{"kind":"list-data-source","name":"cloudflare_waiting_room_events","stainlessResource":"waiting_rooms.events","methodName":"list","snippet":"data \"cloudflare_waiting_room_events\" \"example_waiting_room_events\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"custom_page_html","type":"String","description":"If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it."},{"name":"description","type":"String","description":"A note that you can use to add more details about the event."},{"name":"disable_session_renewal","type":"Bool","description":"If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it."},{"name":"event_end_time","type":"String","description":"An ISO 8601 timestamp that marks the end of the event."},{"name":"event_start_time","type":"String","description":"An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set."},{"name":"prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`."},{"name":"queueing_method","type":"String","description":"If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it."},{"name":"session_duration","type":"Int64","description":"If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it."},{"name":"shuffle_at_event_start","type":"Bool","description":"If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary."},{"name":"suspended","type":"Bool","description":"Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration."},{"name":"total_active_users","type":"Int64","description":"If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set."},{"name":"turnstile_action","type":"String","description":"If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it."},{"name":"turnstile_mode","type":"String","description":"If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it."}]}]}]},"get /zones/{}/waiting_rooms/{}/events/{}":{"operationId":"waiting-room-event-details","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room_event","stainlessResource":"waiting_rooms.events","methodName":"get","snippet":"data \"cloudflare_waiting_room_event\" \"example_waiting_room_event\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n event_id = \"25756b2dfe6e378a06b033b670413757\"\n}\n","required":[{"name":"event_id","type":"String"},{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"custom_page_html","type":"String","description":"If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it."},{"name":"description","type":"String","description":"A note that you can use to add more details about the event."},{"name":"disable_session_renewal","type":"Bool","description":"If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it."},{"name":"event_end_time","type":"String","description":"An ISO 8601 timestamp that marks the end of the event."},{"name":"event_start_time","type":"String","description":"An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set."},{"name":"prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`."},{"name":"queueing_method","type":"String","description":"If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it."},{"name":"session_duration","type":"Int64","description":"If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it."},{"name":"shuffle_at_event_start","type":"Bool","description":"If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary."},{"name":"suspended","type":"Bool","description":"Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration."},{"name":"total_active_users","type":"Int64","description":"If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set."},{"name":"turnstile_action","type":"String","description":"If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it."},{"name":"turnstile_mode","type":"String","description":"If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it."}]}]},"get /zones/{}/waiting_rooms/{}/rules":{"operationId":"waiting-room-list-waiting-room-rules","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room_rules","stainlessResource":"waiting_rooms.rules","methodName":"get","snippet":"data \"cloudflare_waiting_room_rules\" \"example_waiting_room_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}\n","required":[{"name":"waiting_room_id","type":"String"},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"action","type":"String","description":"The action to take when the expression matches."},{"name":"description","type":"String","description":"The description of the rule."},{"name":"enabled","type":"Bool","description":"When set to true, the rule is enabled."},{"name":"expression","type":"String","description":"Criteria defining when there is a match for the current rule."},{"name":"last_updated","type":"Time"},{"name":"version","type":"String","description":"The version of the rule."}]}]},"get /zones/{}/waiting_rooms/settings":{"operationId":"waiting-room-get-zone-settings","declarations":[{"kind":"data-source","name":"cloudflare_waiting_room_settings","stainlessResource":"waiting_rooms.settings","methodName":"get","snippet":"data \"cloudflare_waiting_room_settings\" \"example_waiting_room_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"search_engine_crawler_bypass","type":"Bool","description":"Whether to allow verified search engine crawlers to bypass all waiting rooms on this zone.\nVerified search engine crawlers will not be tracked or counted by the waiting room system,\nand will not appear in waiting room analytics.\n"}]}]},"get /zones/{}/web3/hostnames":{"operationId":"web3-hostname-list-web3-hostnames","declarations":[{"kind":"list-data-source","name":"cloudflare_web3_hostnames","stainlessResource":"web3.hostnames","methodName":"list","snippet":"data \"cloudflare_web3_hostnames\" \"example_web3_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the identifier of the hostname."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Specify the identifier of the hostname."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"Specify an optional description of the hostname."},{"name":"dnslink","type":"String","description":"Specify the DNSLink value used if the target is ipfs."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"Specify the hostname that points to the target gateway via CNAME."},{"name":"status","type":"String","description":"Specifies the status of the hostname's activation."},{"name":"target","type":"String","description":"Specify the target gateway of the hostname."}]}]}]},"get /zones/{}/web3/hostnames/{}":{"operationId":"web3-hostname-web3-hostname-details","declarations":[{"kind":"data-source","name":"cloudflare_web3_hostname","stainlessResource":"web3.hostnames","methodName":"get","snippet":"data \"cloudflare_web3_hostname\" \"example_web3_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"identifier","type":"String","description":"Specify the identifier of the hostname."},{"name":"zone_id","type":"String","description":"Specify the identifier of the hostname."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the identifier of the hostname."},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"Specify an optional description of the hostname."},{"name":"dnslink","type":"String","description":"Specify the DNSLink value used if the target is ipfs."},{"name":"modified_on","type":"Time"},{"name":"name","type":"String","description":"Specify the hostname that points to the target gateway via CNAME."},{"name":"status","type":"String","description":"Specifies the status of the hostname's activation."},{"name":"target","type":"String","description":"Specify the target gateway of the hostname."}]}]},"get /zones/{}/workers/routes":{"operationId":"worker-routes-list-routes","declarations":[{"kind":"list-data-source","name":"cloudflare_workers_routes","stainlessResource":"workers.routes","methodName":"list","snippet":"data \"cloudflare_workers_routes\" \"example_workers_routes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"Identifier."},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."},{"name":"script","type":"String","description":"Name of the script to run if the route matches."}]}]}]},"get /zones/{}/workers/routes/{}":{"operationId":"worker-routes-get-route","declarations":[{"kind":"data-source","name":"cloudflare_workers_route","stainlessResource":"workers.routes","methodName":"get","snippet":"data \"cloudflare_workers_route\" \"example_workers_route\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n route_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"route_id","type":"String","description":"Identifier."},{"name":"zone_id","type":"String","description":"Identifier."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."},{"name":"script","type":"String","description":"Name of the script to run if the route matches."}]}]},"patch /accounts/{}/devices/policy":{"operationId":"devices-update-default-device-settings-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_default_profile","stainlessResource":"zero_trust.devices.policies.default","methodName":"edit","snippet":"resource \"cloudflare_zero_trust_device_default_profile\" \"example_zero_trust_device_default_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n allow_mode_switch = true\n allow_updates = true\n allowed_to_leave = true\n auto_connect = 0\n captive_portal = 180\n disable_auto_fallback = true\n dns_search_suffixes = [{\n suffix = \"internal.corp\"\n description = \"Example internal domains\"\n }]\n exclude = [{\n address = \"192.0.2.0/24\"\n description = \"Exclude testing domains from the tunnel\"\n }]\n exclude_office_ips = true\n global_acceleration = {\n api_endpoints = [\"198.51.100.1:443\"]\n enabled = true\n masque_endpoints = [\"198.51.100.1:443\"]\n wireguard_endpoints = [\"198.51.100.1:2408\"]\n autoswitch = true\n }\n include = [{\n address = \"192.0.2.0/24\"\n description = \"Include testing domains in the tunnel\"\n }]\n lan_allow_minutes = 30\n lan_allow_subnet_size = 24\n register_interface_ip_with_dns = true\n sccm_vpn_boundary_support = false\n service_mode_v2 = {\n mode = \"proxy\"\n port = 3000\n }\n support_url = \"https://1.1.1.1/help\"\n switch_locked = true\n tunnel_protocol = \"wireguard\"\n uninstall_protection = false\n virtual_networks = {\n allowed = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n default = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]}],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"default","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"gateway_unique_id","type":"String"},{"name":"policy_id","type":"String"},{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed."},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}]}]},"patch /accounts/{}/stream/{}/audio/{}":{"operationId":"edit-audio-tracks","declarations":[{"kind":"resource","name":"cloudflare_stream_audio_track","stainlessResource":"stream.audio_tracks","methodName":"edit","snippet":"resource \"cloudflare_stream_audio_track\" \"example_stream_audio_track\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n audio_identifier = \"ea95132c15732412d22c1476fa83f27a\"\n default = true\n label = \"director commentary\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true}],"optional":[{"name":"audio_identifier","type":"String","description":"The unique identifier for an additional audio track.","requiresReplace":true},{"name":"label","type":"String","description":"A string to uniquely identify the track amongst other audio track labels for the specified video."},{"name":"default","type":"Bool","description":"Denotes whether the audio track will be played by default in a player."}],"computed":[{"name":"status","type":"String","description":"Specifies the processing status of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."},{"name":"audio","type":"List[Attributes]","description":"Array of audio tracks for the video.","children":[{"name":"default","type":"Bool","description":"Denotes whether the audio track will be played by default in a player."},{"name":"label","type":"String","description":"A string to uniquely identify the track amongst other audio track labels for the specified video."},{"name":"status","type":"String","description":"Specifies the processing status of the video."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a media item."}]}]}]},"patch /accounts/{}/zerotrust/connectivity_settings":{"operationId":"zero-trust-accounts-patch-connectivity-settings","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_connectivity_settings","stainlessResource":"zero_trust.connectivity_settings","methodName":"edit","snippet":"resource \"cloudflare_zero_trust_connectivity_settings\" \"example_zero_trust_connectivity_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n icmp_proxy_enabled = true\n offramp_warp_enabled = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true}],"optional":[{"name":"icmp_proxy_enabled","type":"Bool","description":"A flag to enable the ICMP proxy for the account network."},{"name":"offramp_warp_enabled","type":"Bool","description":"A flag to enable WARP to WARP traffic."}],"computed":[{"name":"id","type":"String","description":"Cloudflare account ID","requiresReplace":true}]}]},"patch /user":{"operationId":"user-edit-user","declarations":[{"kind":"resource","name":"cloudflare_user","stainlessResource":"user","methodName":"edit","snippet":"resource \"cloudflare_user\" \"example_user\" {\n country = \"US\"\n first_name = \"John\"\n last_name = \"Appleseed\"\n telephone = \"+1 123-123-1234\"\n zipcode = \"12345\"\n}\n","required":[],"optional":[{"name":"country","type":"String","description":"The country in which the user lives."},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"telephone","type":"String","description":"User's telephone number"},{"name":"zipcode","type":"String","description":"The zipcode or postal code where the user lives."}],"computed":[{"name":"id","type":"String","description":"Identifier of the user."},{"name":"email","type":"String","description":"Current email address of the user."},{"name":"has_business_zones","type":"Bool","description":"Indicates whether user has any business zones"},{"name":"has_enterprise_zones","type":"Bool","description":"Indicates whether user has any enterprise zones"},{"name":"has_pro_zones","type":"Bool","description":"Indicates whether user has any pro zones"},{"name":"suspended","type":"Bool","description":"Indicates whether user has been suspended"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."},{"name":"two_factor_authentication_locked","type":"Bool","description":"Indicates whether two-factor authentication is required by one of the accounts that the user is a member of."},{"name":"betas","type":"List[String]","description":"Lists the betas that the user is participating in."},{"name":"organizations","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"name","type":"String","description":"Organization name."},{"name":"permissions","type":"List[String]","description":"Access permissions for this User."},{"name":"roles","type":"List[String]","description":"List of roles that a user has within an organization."},{"name":"status","type":"String","description":"Whether the user is a member of the organization or has an invitation pending."}]}]}]},"patch /zones/{}/argo/smart_routing":{"operationId":"argo-smart-routing-patch-argo-smart-routing-setting","declarations":[{"kind":"resource","name":"cloudflare_argo_smart_routing","stainlessResource":"argo.smart_routing","methodName":"edit","snippet":"resource \"cloudflare_argo_smart_routing\" \"example_argo_smart_routing\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specifies the zone associated with the API call.","requiresReplace":true},{"name":"value","type":"String","description":"Specifies the enablement value of Argo Smart Routing."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specifies the zone associated with the API call.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Specifies if the setting is editable."},{"name":"modified_on","type":"Time","description":"Specifies the time when the setting was last modified."}]}]},"patch /zones/{}/argo/tiered_caching":{"operationId":"tiered-caching-patch-tiered-caching-setting","declarations":[{"kind":"resource","name":"cloudflare_argo_tiered_caching","stainlessResource":"argo.tiered_caching","methodName":"edit","snippet":"resource \"cloudflare_argo_tiered_caching\" \"example_argo_tiered_caching\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"String","description":"Enables Tiered Caching."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/cache/cache_reserve":{"operationId":"zone-cache-settings-change-cache-reserve-setting","declarations":[{"kind":"resource","name":"cloudflare_zone_cache_reserve","stainlessResource":"cache.cache_reserve","methodName":"edit","snippet":"resource \"cloudflare_zone_cache_reserve\" \"example_zone_cache_reserve\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"value","type":"String","description":"Value of the Cache Reserve zone setting."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/cache/regional_tiered_cache":{"operationId":"zone-cache-settings-change-regional-tiered-cache-setting","declarations":[{"kind":"resource","name":"cloudflare_regional_tiered_cache","stainlessResource":"cache.regional_tiered_cache","methodName":"edit","snippet":"resource \"cloudflare_regional_tiered_cache\" \"example_regional_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"value","type":"String","description":"Value of the Regional Tiered Cache zone setting."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/cache/variants":{"operationId":"zone-cache-settings-change-variants-setting","declarations":[{"kind":"resource","name":"cloudflare_zone_cache_variants","stainlessResource":"cache.variants","methodName":"edit","snippet":"resource \"cloudflare_zone_cache_variants\" \"example_zone_cache_variants\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = {\n avif = [\"image/webp\", \"image/jpeg\"]\n bmp = [\"image/webp\", \"image/jpeg\"]\n gif = [\"image/webp\", \"image/jpeg\"]\n jp2 = [\"image/webp\", \"image/avif\"]\n jpeg = [\"image/webp\", \"image/avif\"]\n jpg = [\"image/webp\", \"image/avif\"]\n jpg2 = [\"image/webp\", \"image/avif\"]\n png = [\"image/webp\", \"image/avif\"]\n tif = [\"image/webp\", \"image/avif\"]\n tiff = [\"image/webp\", \"image/avif\"]\n webp = [\"image/jpeg\", \"image/avif\"]\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"Attributes","description":"Value of the zone setting.","children":[{"name":"avif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for avif."},{"name":"bmp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for bmp."},{"name":"gif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for gif."},{"name":"jp2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jp2."},{"name":"jpeg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpeg."},{"name":"jpg","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg."},{"name":"jpg2","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for jpg2."},{"name":"png","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for png."},{"name":"tif","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tif."},{"name":"tiff","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for tiff."},{"name":"webp","type":"List[String]","description":"List of strings with the MIME types of all the variants that should be served for webp."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/ct/alerting":{"operationId":"ct-alerting-update-subscription","declarations":[{"kind":"resource","name":"cloudflare_ct_alerting","stainlessResource":"zones.ct.alerting","methodName":"edit","snippet":"resource \"cloudflare_ct_alerting\" \"example_ct_alerting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n emails = [\"security@example.com\", \"admin@example.com\"]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether CT alerting is enabled for the zone."}],"optional":[{"name":"emails","type":"List[String]","description":"Email addresses that receive CT alert notifications for the zone. A maximum of 100 addresses may be configured. Each address must be a valid RFC 5322 email address and must not contain a comma.\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"patch /zones/{}/devices/policy/certificates":{"operationId":"devices-update-policy-certificates","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_default_profile_certificates","stainlessResource":"zero_trust.devices.policies.default.certificates","methodName":"edit","snippet":"resource \"cloudflare_zero_trust_device_default_profile_certificates\" \"example_zero_trust_device_default_profile_certificates\" {\n zone_id = \"699d98642c564d2e855e9661899b7252\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool","description":"The current status of the device policy certificate provisioning feature for WARP clients."}],"optional":[],"computed":[]}]},"patch /zones/{}/dnssec":{"operationId":"dnssec-edit-dnssec-status","declarations":[{"kind":"resource","name":"cloudflare_zone_dnssec","stainlessResource":"dns.dnssec","methodName":"edit","snippet":"resource \"cloudflare_zone_dnssec\" \"example_zone_dnssec\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dnssec_multi_signer = false\n dnssec_presigned = true\n dnssec_use_nsec3 = false\n status = \"active\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"dnssec_multi_signer","type":"Bool","description":"If true, multi-signer DNSSEC is enabled on the zone, allowing multiple\nproviders to serve a DNSSEC-signed zone at the same time.\nThis is required for DNSKEY records (except those automatically\ngenerated by Cloudflare) to be added to the zone.\n\nSee [Multi-signer DNSSEC](https://developers.cloudflare.com/dns/dnssec/multi-signer-dnssec/) for details."},{"name":"dnssec_presigned","type":"Bool","description":"If true, allows Cloudflare to transfer in a DNSSEC-signed zone\nincluding signatures from an external provider, without requiring\nCloudflare to sign any records on the fly.\n\nNote that this feature has some limitations.\nSee [Cloudflare as Secondary](https://developers.cloudflare.com/dns/zone-setups/zone-transfers/cloudflare-as-secondary/setup/#dnssec) for details."},{"name":"dnssec_use_nsec3","type":"Bool","description":"If true, enables the use of NSEC3 together with DNSSEC on the zone.\nCombined with setting dnssec_presigned to true, this enables the use of\nNSEC3 records when transferring in from an external provider.\nIf dnssec_presigned is instead set to false (default), NSEC3 records will be\ngenerated and signed at request time.\n\nSee [DNSSEC with NSEC3](https://developers.cloudflare.com/dns/dnssec/enable-nsec3/) for details."},{"name":"status","type":"String","description":"Status of DNSSEC, based on user-desired state and presence of necessary records."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"algorithm","type":"String","description":"Algorithm key code."},{"name":"digest","type":"String","description":"Digest hash."},{"name":"digest_algorithm","type":"String","description":"Type of digest algorithm."},{"name":"digest_type","type":"String","description":"Coded type for digest algorithm."},{"name":"ds","type":"String","description":"Full DS record."},{"name":"flags","type":"Float64","description":"Flag for DNSSEC record."},{"name":"key_tag","type":"Float64","description":"Code for key tag."},{"name":"key_type","type":"String","description":"Algorithm key type."},{"name":"modified_on","type":"Time","description":"When DNSSEC was last modified."},{"name":"public_key","type":"String","description":"Public key for DS record."}]}]},"patch /zones/{}/managed_headers":{"operationId":"updateManagedTransforms","declarations":[{"kind":"resource","name":"cloudflare_managed_transforms","stainlessResource":"managed_transforms","methodName":"edit","snippet":"resource \"cloudflare_managed_transforms\" \"example_managed_transforms\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n managed_request_headers = [{\n id = \"add_bot_protection_headers\"\n enabled = true\n }]\n managed_response_headers = [{\n id = \"add_security_headers\"\n enabled = true\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone.","requiresReplace":true}],"optional":[{"name":"managed_request_headers","type":"List[Attributes]","description":"The list of Managed Request Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]},{"name":"managed_response_headers","type":"List[Attributes]","description":"The list of Managed Response Transforms.","children":[{"name":"id","type":"String","description":"The human-readable identifier of the Managed Transform."},{"name":"enabled","type":"Bool","description":"Whether the Managed Transform is enabled."},{"name":"has_conflict","type":"Bool","description":"Whether the Managed Transform conflicts with the currently-enabled Managed Transforms."},{"name":"conflicts_with","type":"List[String]","description":"The Managed Transforms that this Managed Transform conflicts with."}]}],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone.","requiresReplace":true}]}]},"patch /zones/{}/observability/tracing/settings":{"operationId":"zone.observability.tracing.settings.update","declarations":[{"kind":"resource","name":"cloudflare_zone_tracing","stainlessResource":"zones.observability.tracing.settings","methodName":"update","snippet":"resource \"cloudflare_zone_tracing\" \"example_zone_tracing\" {\n zone_id = \"zone_id\"\n destinations = [\"x\"]\n enabled = true\n forward_context = true\n persist = true\n propagation_policy = \"accept\"\n sampling_ratio = 0\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID.","requiresReplace":true}],"optional":[{"name":"enabled","type":"Bool","description":"Whether Cloudflare Traces is enabled for the zone."},{"name":"forward_context","type":"Bool","description":"Whether trace context is sent externally or across a zone boundary."},{"name":"persist","type":"Bool","description":"Whether traces are persisted in Cloudflare."},{"name":"propagation_policy","type":"String","description":"When inbound trace context may be continued. Authenticated propagation is not supported yet."},{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."},{"name":"destinations","type":"List[String]","description":"Up to 100 OpenTelemetry destination identifiers that receive traces."}],"computed":[{"name":"id","type":"String","description":"Specify the zone ID.","requiresReplace":true}]}]},"patch /zones/{}/settings/{}":{"operationId":"zone-settings-edit-single-setting","declarations":[{"kind":"resource","name":"cloudflare_zone_setting","stainlessResource":"zones.settings","methodName":"edit","snippet":"resource \"cloudflare_zone_setting\" \"example_zone_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"always_online\"\n enabled = true\n}\n","required":[{"name":"setting_id","type":"String","description":"Setting name","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier","requiresReplace":true}],"optional":[{"name":"value","type":"unknown","description":"Value of the zone setting."},{"name":"enabled","type":"Bool","description":"ssl-recommender enrollment setting."}],"computed":[{"name":"id","type":"String","description":"Setting name","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)."},{"name":"modified_on","type":"Time","description":"last time this setting was modified."},{"name":"time_remaining","type":"Float64","description":"Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false."}]}]},"patch /zones/{}/settings/auto_origin_tls_kex":{"operationId":"ssl-detector-auto-origin-tls-kex-patch-enrollment","declarations":[{"kind":"resource","name":"cloudflare_zone_auto_origin_tls_kex","stainlessResource":"ssl.auto_origin_tls_kex","methodName":"edit","snippet":"resource \"cloudflare_zone_auto_origin_tls_kex\" \"example_zone_auto_origin_tls_kex\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Controls enablement of Auto-Origin TLS KEX selection for the zone."}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"patch /zones/{}/settings/nel":{"operationId":"nel-settings-edit","declarations":[{"kind":"resource","name":"cloudflare_nel_setting","stainlessResource":"zones.nel","methodName":"edit","snippet":"resource \"cloudflare_nel_setting\" \"example_nel_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = {\n enabled = false\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier of the zone.","requiresReplace":true},{"name":"value","type":"Attributes","description":"The NEL configuration value.","children":[{"name":"enabled","type":"Bool","description":"Whether Network Error Logging is enabled for the zone. When enabled, browsers report network errors to Cloudflare's NEL endpoint.\n"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Zone setting identifier."},{"name":"editable","type":"Bool","description":"Whether the setting is editable. This is false when the zone's plan does not include NEL or the NEL product feature is not enabled.\n"},{"name":"modified_on","type":"Time","description":"When the setting was last modified. A zero value (0001-01-01T00:00:00Z) indicates the setting has never been explicitly set and is using the default value.\n"}]}]},"patch /zones/{}/ssl/universal/settings":{"operationId":"universal-ssl-settings-for-a-zone-edit-universal-ssl-settings","declarations":[{"kind":"resource","name":"cloudflare_universal_ssl_setting","stainlessResource":"ssl.universal.settings","methodName":"edit","snippet":"resource \"cloudflare_universal_ssl_setting\" \"example_universal_ssl_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"enabled","type":"Bool","description":"Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.\n\nBy disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.\n\n* HSTS\n* Always Use HTTPS\n* Opportunistic Encryption\n* Onion Routing\n* Any Page Rules redirecting traffic to HTTPS\n\nSimilarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare's edge.\n\nIf you do not have a valid custom or advanced certificate at Cloudflare's edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"post /accounts":{"operationId":"account-creation","declarations":[{"kind":"resource","name":"cloudflare_account","stainlessResource":"accounts","methodName":"create","snippet":"resource \"cloudflare_account\" \"example_account\" {\n name = \"name\"\n standalone = true\n type = \"standard\"\n unit = {\n id = \"f267e341f3dd4697bd3b9f71dd96247f\"\n }\n}\n","required":[{"name":"name","type":"String","description":"Account name"}],"optional":[{"name":"standalone","type":"Bool","description":"Set to `true` and omit `unit` to create a standalone Free Account. If provided, this field must be `true`.","requiresReplace":true},{"name":"unit","type":"Attributes","description":"Information related to the tenant unit. Provide its ID and omit `standalone` to create the Account within an Organization. See https://developers.cloudflare.com/tenant/how-to/manage-accounts/.","requiresReplace":true,"children":[{"name":"id","type":"String","description":"Tenant unit ID"}]},{"name":"type","type":"String"},{"name":"managed_by","type":"Attributes","description":"Parent container details","children":[{"name":"parent_org_id","type":"String","description":"ID of the parent Organization, if one exists"},{"name":"parent_org_name","type":"String","description":"Name of the parent Organization, if one exists"}]},{"name":"settings","type":"Attributes","description":"Account settings","children":[{"name":"abuse_contact_email","type":"String","description":"Sets an abuse contact email to notify for abuse reports."},{"name":"enforce_twofactor","type":"Bool","description":"Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled"}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the account"}]}]},"post /accounts/{}/access/ai-controls/mcp/portals":{"operationId":"mcp-portals-api-create-portals","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_ai_controls_mcp_portal","stainlessResource":"zero_trust.access.ai_controls.mcp.portals","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_ai_controls_mcp_portal\" \"example_zero_trust_access_ai_controls_mcp_portal\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-portal\"\n hostname = \"example.com\"\n name = \"My MCP Portal\"\n allow_code_mode = true\n code_mode = \"opt_in\"\n description = \"This is my custom MCP Portal\"\n secure_web_gateway = false\n servers = [{\n server_id = \"my-mcp-server\"\n default_disabled = true\n on_behalf = true\n updated_prompts = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n updated_tools = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n }]\n}\n","required":[{"name":"id","type":"String","description":"Unique identifier for the MCP portal.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"hostname","type":"String","description":"Hostname where the MCP portal is available."},{"name":"name","type":"String","description":"Display name for the MCP portal."}],"optional":[{"name":"allow_code_mode","type":"Bool","description":"Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.","deprecated":"Deprecated."},{"name":"code_mode","type":"String","description":"Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400."},{"name":"description","type":"String","description":"Optional description of the MCP portal."},{"name":"servers","type":"Set[Attributes]","description":"MCP servers attached to the portal and their portal-specific settings.","children":[{"name":"server_id","type":"String","description":"Unique identifier for the MCP server."},{"name":"default_disabled","type":"Bool","description":"Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in this server entry's updated_tools or updated_prompts fields when creating or updating the portal."},{"name":"on_behalf","type":"Bool","description":"Use end-user OAuth credentials when connecting this server to the portal."},{"name":"updated_prompts","type":"List[Attributes]","description":"Portal-specific prompt overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Portal-specific tool overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]}]},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound MCP traffic through Zero Trust Secure Web Gateway."}],"computed":[{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"}]}]},"post /accounts/{}/access/ai-controls/mcp/servers":{"operationId":"mcp-portals-api-create-servers","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_ai_controls_mcp_server","stainlessResource":"zero_trust.access.ai_controls.mcp.servers","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_ai_controls_mcp_server\" \"example_zero_trust_access_ai_controls_mcp_server\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-server\"\n auth_type = \"unauthenticated\"\n hostname = \"https://example.com/mcp\"\n name = \"My MCP Server\"\n auth_credentials = \"sk-my-bearer-token\"\n client_secret = \"client_secret\"\n description = \"This is one remote MCP server\"\n is_shared_oauth_callback_enabled = true\n secure_web_gateway = false\n updated_prompts = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n updated_tools = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n}\n","required":[{"name":"id","type":"String","description":"Unique identifier for the MCP server.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"auth_type","type":"String","description":"Authentication method used to connect to the upstream MCP server.","requiresReplace":true},{"name":"hostname","type":"String","description":"URL of the upstream MCP endpoint.","requiresReplace":true},{"name":"name","type":"String","description":"Display name for the MCP server."}],"optional":[{"name":"auth_credentials","type":"String","description":"Static credential for the upstream MCP server. For auth_type \"bearer\", either a raw token string (e.g. \"sk-abc123\"), which is wrapped server-side as `Authorization: Bearer `, or a JSON-encoded object of the form `{\"headers\":{\"Header-Name\":\"value\",...}}` for custom or multiple static headers (e.g. Cloudflare Access service tokens: `{\"headers\":{\"cf-access-client-id\":\"...\",\"cf-access-client-secret\":\"...\"}}`).","sensitive":true},{"name":"client_secret","type":"String","description":"Pre-registered OAuth client_secret. Write-only - accepted on create/update when auth_credentials.auth_mode is 'manual'. Stored AES-GCM-encrypted in server_oauth_secrets; never returned by read endpoints.","sensitive":true},{"name":"description","type":"String","description":"Optional description of the MCP server."},{"name":"updated_prompts","type":"List[Attributes]","description":"Server-wide prompt capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"updated_tools","type":"List[Attributes]","description":"Server-wide tool capability overrides.","children":[{"name":"name","type":"String","description":"Name of the tool or prompt capability to override."},{"name":"alias","type":"String","description":"Custom name exposed for the capability."},{"name":"description","type":"String","description":"Custom description exposed for the capability."},{"name":"enabled","type":"Bool","description":"Whether the capability is available through the MCP server."}]},{"name":"is_shared_oauth_callback_enabled","type":"Bool","description":"When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true."},{"name":"secure_web_gateway","type":"Bool","description":"Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway."}],"computed":[{"name":"authentication_status","type":"String","description":"Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow."},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"error","type":"String"},{"name":"last_successful_sync","type":"Time"},{"name":"last_synced","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"status","type":"String","description":"Current sync state of the server"},{"name":"prompts","type":"List[Map[unknown]]"},{"name":"tools","type":"List[Map[unknown]]"},{"name":"auth_config_summary","type":"Attributes","description":"Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.","children":[{"name":"auth_mode","type":"String"},{"name":"client_secret_version","type":"Float64"},{"name":"config","type":"Attributes","children":[{"name":"authorization_endpoint","type":"String"},{"name":"issuer","type":"String"},{"name":"resource","type":"String"},{"name":"revocation_endpoint","type":"String"},{"name":"token_endpoint","type":"String"}]},{"name":"has_client_secret","type":"Bool"},{"name":"registration_info","type":"Attributes","children":[{"name":"client_id","type":"String"},{"name":"redirect_uris","type":"List[String]"},{"name":"scope","type":"String"},{"name":"token_endpoint_auth_method","type":"String"}]}]},{"name":"error_details","type":"Attributes","children":[{"name":"cause","type":"String","description":"Underlying error message"},{"name":"is_upstream","type":"Bool","description":"True = MCP server returned an error. False = couldn't reach the server"},{"name":"mcp_code","type":"Float64","description":"MCP protocol error code"},{"name":"retryable","type":"Bool","description":"Whether the error is transient and worth retrying"},{"name":"status_code","type":"Float64","description":"HTTP status code from the server"}]}]}]},"post /accounts/{}/access/custom_pages":{"operationId":"access-custom-pages-create-a-custom-page","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_custom_page","stainlessResource":"zero_trust.access.custom_pages","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_custom_page\" \"example_zero_trust_access_custom_page\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_html = \"

Access Denied

\"\n name = \"name\"\n type = \"identity_denied\"\n contract_version = 0\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"custom_html","type":"String","description":"Custom page HTML."},{"name":"name","type":"String","description":"Custom page name."},{"name":"type","type":"String","description":"Custom page type."}],"optional":[{"name":"app_count","type":"Int64","description":"Number of apps the custom page is assigned to."},{"name":"contract_version","type":"Int64","description":"Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim."}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"uid","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"},{"name":"warnings","type":"List[Attributes]","description":"Advisory validation findings returned when creating or updating a template. Omitted when empty.","children":[{"name":"message","type":"String","description":"Human-readable description of the finding."},{"name":"tier","type":"String","description":"The validation tier that produced the finding (e.g. html, liquid)."},{"name":"ref","type":"String","description":"Optional pointer to the part of the template the finding refers to."}]}]}]},"post /accounts/{}/access/policies":{"operationId":"access-policies-create-an-access-reusable-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_policy","stainlessResource":"zero_trust.access.policies","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_policy\" \"example_zero_trust_access_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n decision = \"allow\"\n include = [{\n certificate = {\n\n }\n }]\n name = \"Allow devs\"\n approval_groups = [{\n approvals_needed = 1\n email_addresses = [\"test1@cloudflare.com\", \"test2@cloudflare.com\"]\n email_list_uuid = \"email_list_uuid\"\n }, {\n approvals_needed = 3\n email_addresses = [\"test@cloudflare.com\", \"test2@cloudflare.com\"]\n email_list_uuid = \"597147a1-976b-4ef2-9af0-81d5d007fc34\"\n }]\n approval_required = true\n connection_rules = {\n rdp = {\n allowed_clipboard_local_to_remote_formats = [\"text\", \"file\"]\n allowed_clipboard_remote_to_local_formats = [\"text\", \"file\"]\n }\n }\n exclude = [{\n certificate = {\n\n }\n }]\n isolation_required = false\n mfa_config = {\n allowed_authenticators = [\"totp\", \"biometrics\", \"security_key\"]\n mfa_disabled = false\n session_duration = \"24h\"\n }\n purpose_justification_prompt = \"Please enter a justification for entering this protected domain.\"\n purpose_justification_required = true\n require = [{\n certificate = {\n\n }\n }]\n session_duration = \"24h\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"decision","type":"String","description":"The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action."},{"name":"name","type":"String","description":"The name of the Access policy."}],"optional":[{"name":"approval_required","type":"Bool","description":"Requires the user to request access from an administrator at the start of each session."},{"name":"isolation_required","type":"Bool","description":"Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature."},{"name":"purpose_justification_prompt","type":"String","description":"A custom message that will appear on the purpose justification screen."},{"name":"purpose_justification_required","type":"Bool","description":"Require users to enter a justification when they log in to the application."},{"name":"session_duration","type":"String","description":"The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h."},{"name":"approval_groups","type":"Set[Attributes]","description":"Administrators who can approve a temporary authentication request.","children":[{"name":"approvals_needed","type":"Float64","description":"The number of approvals needed to obtain access."},{"name":"email_addresses","type":"List[String]","description":"A list of emails that can approve the access request."},{"name":"email_list_uuid","type":"String","description":"The UUID of an re-usable email list."}]},{"name":"connection_rules","type":"Attributes","description":"The rules that define how users may connect to targets secured by your application.","children":[{"name":"rdp","type":"Attributes","description":"The RDP-specific rules that define clipboard behavior for RDP connections.","children":[{"name":"allowed_clipboard_local_to_remote_formats","type":"List[String]","description":"Clipboard formats allowed when copying from local machine to remote RDP session."},{"name":"allowed_clipboard_remote_to_local_formats","type":"List[String]","description":"Clipboard formats allowed when copying from remote RDP session to local machine."}]}]},{"name":"mfa_config","type":"Attributes","description":"Configures multi-factor authentication (MFA) settings.","children":[{"name":"allowed_authenticators","type":"List[String]","description":"Lists the MFA methods that users can authenticate with."},{"name":"mfa_disabled","type":"Bool","description":"Indicates whether to disable MFA for this resource. This option is available at the application and policy level."},{"name":"session_duration","type":"String","description":"Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`."}]},{"name":"exclude","type":"Set[Attributes]","description":"Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"include","type":"Set[Attributes]","description":"Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]},{"name":"require","type":"Set[Attributes]","description":"Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.","children":[{"name":"group","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created Access group."}]},{"name":"any_valid_service_token","type":"Attributes","description":"An empty object which matches on all service tokens."},{"name":"auth_context","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Authentication context."},{"name":"ac_id","type":"String","description":"The ACID of an Authentication context."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"auth_method","type":"Attributes","children":[{"name":"auth_method","type":"String","description":"The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2."}]},{"name":"azure_ad","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an Azure group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Azure identity provider."}]},{"name":"certificate","type":"Attributes"},{"name":"common_name","type":"Attributes","children":[{"name":"common_name","type":"String","description":"The common name to match."}]},{"name":"geo","type":"Attributes","children":[{"name":"country_code","type":"String","description":"The country code that should be matched."}]},{"name":"device_posture","type":"Attributes","children":[{"name":"integration_uid","type":"String","description":"The ID of a device posture integration."},{"name":"account_id","type":"String","description":"The ID of the account that owns the device posture integration."}]},{"name":"email_domain","type":"Attributes","children":[{"name":"domain","type":"String","description":"The email domain to match."}]},{"name":"email_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created email list."}]},{"name":"email","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the user."}]},{"name":"everyone","type":"Attributes","description":"An empty object which matches on all users."},{"name":"external_evaluation","type":"Attributes","children":[{"name":"evaluate_url","type":"String","description":"The API endpoint containing your business logic."},{"name":"keys_url","type":"String","description":"The API endpoint containing the key that Access uses to verify that the response came from your API."}]},{"name":"github_organization","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Github identity provider."},{"name":"name","type":"String","description":"The name of the organization."},{"name":"team","type":"String","description":"The name of the team"}]},{"name":"gsuite","type":"Attributes","children":[{"name":"email","type":"String","description":"The email of the Google Workspace group."},{"name":"identity_provider_id","type":"String","description":"The ID of your Google Workspace identity provider."}]},{"name":"login_method","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of an identity provider."}]},{"name":"ip_list","type":"Attributes","children":[{"name":"id","type":"String","description":"The ID of a previously created IP list."}]},{"name":"ip","type":"Attributes","children":[{"name":"ip","type":"String","description":"An IPv4 or IPv6 CIDR block."}]},{"name":"okta","type":"Attributes","children":[{"name":"identity_provider_id","type":"String","description":"The ID of your Okta identity provider."},{"name":"name","type":"String","description":"The name of the Okta group."}]},{"name":"saml","type":"Attributes","children":[{"name":"attribute_name","type":"String","description":"The name of the SAML attribute."},{"name":"attribute_value","type":"String","description":"The SAML attribute value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your SAML identity provider."}]},{"name":"oidc","type":"Attributes","children":[{"name":"claim_name","type":"String","description":"The name of the OIDC claim."},{"name":"claim_value","type":"String","description":"The OIDC claim value to look for."},{"name":"identity_provider_id","type":"String","description":"The ID of your OIDC identity provider."}]},{"name":"service_token","type":"Attributes","children":[{"name":"token_id","type":"String","description":"The ID of a Service Token."}]},{"name":"linked_app_token","type":"Attributes","children":[{"name":"app_uid","type":"String","description":"The ID of an Access OIDC SaaS application"}]},{"name":"user_risk_score","type":"Attributes","children":[{"name":"user_risk_score","type":"List[String]","description":"A list of risk score levels to match. Values can be low, medium, high, or unscored."}]},{"name":"cloudflare_account_member","type":"Attributes","children":[{"name":"account_id","type":"String","description":"Identifier."}]}]}],"computed":[{"name":"id","type":"String","description":"The UUID of the policy"},{"name":"app_count","type":"Int64","description":"Number of access applications currently using this policy."},{"name":"created_at","type":"Time"},{"name":"reusable","type":"Bool"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/access/tags":{"operationId":"access-tags-create-tag","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_tag","stainlessResource":"zero_trust.access.tags","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_tag\" \"example_zero_trust_access_tag\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"engineers\"\n}\n","required":[{"name":"name","type":"String","description":"The name of the tag","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"The name of the tag","requiresReplace":true},{"name":"app_count","type":"Int64","description":"The number of applications that have this tag"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/addressing/address_maps":{"operationId":"ip-address-management-address-maps-create-address-map","declarations":[{"kind":"resource","name":"cloudflare_address_map","stainlessResource":"addressing.address_maps","methodName":"create","snippet":"resource \"cloudflare_address_map\" \"example_address_map\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n description = \"My Ecommerce zones\"\n enabled = true\n ips = [\"192.0.2.1\"]\n memberships = [{\n identifier = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"zone\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account.","requiresReplace":true}],"optional":[{"name":"ips","type":"List[String]","requiresReplace":true},{"name":"memberships","type":"List[Attributes]","description":"Zones and Accounts which will be assigned IPs on this Address Map. A zone membership will take priority over an account membership.","requiresReplace":true,"children":[{"name":"identifier","type":"String","description":"The identifier for the membership (eg. a zone or account tag)."},{"name":"kind","type":"String","description":"The type of the membership."}]},{"name":"default_sni","type":"String","description":"If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account."},{"name":"description","type":"String","description":"An optional description field which may be used to describe the types of IPs or zones on the map."},{"name":"enabled","type":"Bool","description":"Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled."}],"computed":[{"name":"id","type":"String","description":"Identifier of an Address Map."},{"name":"can_delete","type":"Bool","description":"If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps."},{"name":"can_modify_ips","type":"Bool","description":"If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps."},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/addressing/prefixes":{"operationId":"ip-address-management-prefixes-add-prefix","declarations":[{"kind":"resource","name":"cloudflare_byo_ip_prefix","stainlessResource":"addressing.prefixes","methodName":"create","snippet":"resource \"cloudflare_byo_ip_prefix\" \"example_byo_ip_prefix\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n asn = 13335\n cidr = \"192.0.2.0/24\"\n delegate_loa_creation = true\n description = \"Internal test prefix\"\n loa_document_id = \"d933b1530bc56c9953cf8ce166da8004\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account.","requiresReplace":true},{"name":"asn","type":"Int64","description":"Autonomous System Number (ASN) the prefix will be advertised under.","requiresReplace":true},{"name":"cidr","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format.","requiresReplace":true}],"optional":[{"name":"loa_document_id","type":"String","description":"Identifier for the uploaded LOA document.","requiresReplace":true},{"name":"delegate_loa_creation","type":"Bool","description":"Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner.","requiresReplace":true},{"name":"description","type":"String","description":"Description of the prefix."}],"computed":[{"name":"id","type":"String","description":"Identifier of an IP Prefix."},{"name":"advertised","type":"Bool","description":"Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"advertised_modified_at","type":"Time","description":"Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"approved","type":"String","description":"Approval state of the prefix (P = pending, V = active)."},{"name":"created_at","type":"Time"},{"name":"irr_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"modified_at","type":"Time"},{"name":"on_demand_enabled","type":"Bool","description":"Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"on_demand_locked","type":"Bool","description":"Whether advertisement status of the prefix is locked, meaning it cannot be changed.","deprecated":"Prefer the [BGP Prefixes API](https://developers.cloudflare.com/api/resources/addressing/subresources/prefixes/subresources/bgp_prefixes/) instead, which allows for advertising multiple BGP routes within a single IP Prefix."},{"name":"ownership_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."},{"name":"ownership_validation_token","type":"String","description":"Token provided to demonstrate ownership of the prefix."},{"name":"rpki_validation_state","type":"String","description":"State of one kind of validation for an IP prefix."}]}]},"post /accounts/{}/ai-gateway/gateways":{"operationId":"aig-config-create-gateway","declarations":[{"kind":"resource","name":"cloudflare_ai_gateway","stainlessResource":"ai_gateway","methodName":"create","snippet":"resource \"cloudflare_ai_gateway\" \"example_ai_gateway\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n id = \"my-gateway\"\n cache_invalidate_on_update = true\n cache_ttl = 0\n collect_logs = true\n rate_limiting_interval = 0\n rate_limiting_limit = 0\n authentication = true\n byok_only = true\n dlp = {\n action = \"BLOCK\"\n enabled = true\n profiles = [\"string\"]\n }\n guardrails = {\n prompt = {\n p1 = \"FLAG\"\n s1 = \"FLAG\"\n s10 = \"FLAG\"\n s11 = \"FLAG\"\n s12 = \"FLAG\"\n s13 = \"FLAG\"\n s2 = \"FLAG\"\n s3 = \"FLAG\"\n s4 = \"FLAG\"\n s5 = \"FLAG\"\n s6 = \"FLAG\"\n s7 = \"FLAG\"\n s8 = \"FLAG\"\n s9 = \"FLAG\"\n }\n response = {\n p1 = \"FLAG\"\n s1 = \"FLAG\"\n s10 = \"FLAG\"\n s11 = \"FLAG\"\n s12 = \"FLAG\"\n s13 = \"FLAG\"\n s2 = \"FLAG\"\n s3 = \"FLAG\"\n s4 = \"FLAG\"\n s5 = \"FLAG\"\n s6 = \"FLAG\"\n s7 = \"FLAG\"\n s8 = \"FLAG\"\n s9 = \"FLAG\"\n }\n }\n log_classification = true\n log_management = 10000\n log_management_strategy = \"STOP_INSERTING\"\n logpush = true\n logpush_public_key = \"xxxxxxxxxxxxxxxx\"\n otel = [{\n headers = {\n foo = \"string\"\n }\n url = \"https://example.com\"\n authorization = \"authorization\"\n content_type = \"json\"\n }]\n rate_limiting_technique = \"fixed\"\n retry_backoff = \"constant\"\n retry_delay = 0\n retry_max_attempts = 1\n spend_limits = {\n enabled = true\n rules = [{\n limit = 1\n limit_type = \"cost\"\n window = 1\n id = \"x\"\n enabled = true\n metadata = {\n foo = {\n mode = \"partition\"\n }\n }\n model = {\n mode = \"filter\"\n values = [\"string\"]\n }\n ai_gateway_provider = {\n mode = \"filter\"\n values = [\"string\"]\n }\n technique = \"fixed\"\n }]\n }\n store_id = \"store_id\"\n stripe = {\n authorization = \"authorization\"\n usage_events = [{\n payload = \"payload\"\n }]\n }\n workers_ai_billing_mode = \"postpaid\"\n zdr = true\n}\n","required":[{"name":"id","type":"String","description":"Unique identifier of the AI Gateway within the account.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"cache_invalidate_on_update","type":"Bool"},{"name":"cache_ttl","type":"Int64"},{"name":"collect_logs","type":"Bool"},{"name":"rate_limiting_interval","type":"Int64"},{"name":"rate_limiting_limit","type":"Int64"}],"optional":[{"name":"logpush_public_key","type":"String"},{"name":"rate_limiting_technique","type":"String"},{"name":"retry_backoff","type":"String","description":"Backoff strategy for retry delays"},{"name":"retry_delay","type":"Int64","description":"Delay between retry attempts in milliseconds (0-60000)"},{"name":"retry_max_attempts","type":"Int64","description":"Maximum number of retry attempts for failed requests (1-5)"},{"name":"dlp","type":"Attributes","children":[{"name":"action","type":"String"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"},{"name":"policies","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"action","type":"String"},{"name":"check","type":"List[String]"},{"name":"enabled","type":"Bool"},{"name":"profiles","type":"List[String]"}]}]},{"name":"guardrails","type":"Attributes","children":[{"name":"prompt","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]},{"name":"response","type":"Attributes","children":[{"name":"p1","type":"String"},{"name":"s1","type":"String"},{"name":"s10","type":"String"},{"name":"s11","type":"String"},{"name":"s12","type":"String"},{"name":"s13","type":"String"},{"name":"s2","type":"String"},{"name":"s3","type":"String"},{"name":"s4","type":"String"},{"name":"s5","type":"String"},{"name":"s6","type":"String"},{"name":"s7","type":"String"},{"name":"s8","type":"String"},{"name":"s9","type":"String"}]}]},{"name":"stripe","type":"Attributes","children":[{"name":"authorization","type":"String"},{"name":"usage_events","type":"List[Attributes]","children":[{"name":"payload","type":"String"}]}]},{"name":"authentication","type":"Bool"},{"name":"byok_only","type":"Bool","description":"Requires customer-provided provider credentials and prevents fallback to Unified Billing."},{"name":"log_classification","type":"Bool"},{"name":"log_management","type":"Int64"},{"name":"log_management_strategy","type":"String"},{"name":"logpush","type":"Bool"},{"name":"store_id","type":"String"},{"name":"workers_ai_billing_mode","type":"String","description":"Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway."},{"name":"zdr","type":"Bool"},{"name":"otel","type":"List[Attributes]","children":[{"name":"headers","type":"Map[String]"},{"name":"url","type":"String"},{"name":"authorization","type":"String"},{"name":"content_type","type":"String"}]},{"name":"spend_limits","type":"Attributes","children":[{"name":"enabled","type":"Bool"},{"name":"rules","type":"List[Attributes]","children":[{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Int64"},{"name":"id","type":"String"},{"name":"enabled","type":"Bool"},{"name":"metadata","type":"Map[Attributes]","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"model","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"ai_gateway_provider","type":"Attributes","children":[{"name":"mode","type":"String"},{"name":"values","type":"List[String]"}]},{"name":"technique","type":"String"}]}]}],"computed":[{"name":"created_at","type":"Time"},{"name":"is_default","type":"Bool"},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/ai-gateway/gateways/{}/routes":{"operationId":"aig-config-post-gateway-dynamic-route","declarations":[{"kind":"resource","name":"cloudflare_ai_gateway_dynamic_routing","stainlessResource":"ai_gateway.dynamic_routing","methodName":"create","snippet":"resource \"cloudflare_ai_gateway_dynamic_routing\" \"example_ai_gateway_dynamic_routing\" {\n account_id = \"0d37909e38d3e99c29fa2cd343ac421a\"\n gateway_id = \"54442216\"\n elements = [{\n id = \"id\"\n outputs = {\n next = {\n element_id = \"elementId\"\n }\n }\n type = \"start\"\n }]\n name = \"x\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"gateway_id","type":"String","requiresReplace":true},{"name":"elements","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"id","type":"String"},{"name":"outputs","type":"Attributes","children":[{"name":"next","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"false","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"true","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"element_id","type":"String"},{"name":"fallback","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"success","type":"Attributes","children":[{"name":"element_id","type":"String"}]}]},{"name":"type","type":"String"},{"name":"properties","type":"Attributes","children":[{"name":"conditions","type":"unknown"},{"name":"key","type":"String"},{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Float64"},{"name":"model","type":"String"},{"name":"ai_gateway_dynamic_routing_provider","type":"String"},{"name":"retries","type":"Float64"},{"name":"timeout","type":"Float64"}]}]},{"name":"name","type":"String"}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"success","type":"Bool"},{"name":"deployment","type":"Attributes","children":[{"name":"created_at","type":"String"},{"name":"deployment_id","type":"String"},{"name":"version_id","type":"String"}]},{"name":"route","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"account_tag","type":"String"},{"name":"created_at","type":"Time"},{"name":"deployment","type":"Attributes","children":[{"name":"created_at","type":"String"},{"name":"deployment_id","type":"String"},{"name":"version_id","type":"String"}]},{"name":"elements","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"outputs","type":"Attributes","children":[{"name":"next","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"false","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"true","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"element_id","type":"String"},{"name":"fallback","type":"Attributes","children":[{"name":"element_id","type":"String"}]},{"name":"success","type":"Attributes","children":[{"name":"element_id","type":"String"}]}]},{"name":"type","type":"String"},{"name":"properties","type":"Attributes","children":[{"name":"conditions","type":"unknown"},{"name":"key","type":"String"},{"name":"limit","type":"Float64"},{"name":"limit_type","type":"String"},{"name":"window","type":"Float64"},{"name":"model","type":"String"},{"name":"ai_gateway_dynamic_routing_provider","type":"String"},{"name":"retries","type":"Float64"},{"name":"timeout","type":"Float64"}]}]},{"name":"gateway_id","type":"String"},{"name":"modified_at","type":"Time"},{"name":"name","type":"String"},{"name":"version","type":"Attributes","children":[{"name":"active","type":"String"},{"name":"created_at","type":"String"},{"name":"data","type":"String"},{"name":"version_id","type":"String"},{"name":"is_valid","type":"Bool"}]}]},{"name":"version","type":"Attributes","children":[{"name":"active","type":"String"},{"name":"created_at","type":"String"},{"name":"data","type":"String"},{"name":"version_id","type":"String"},{"name":"is_valid","type":"Bool"}]}]}]},"post /accounts/{}/ai-search/instances":{"operationId":"ai-search-create-instance","declarations":[{"kind":"resource","name":"cloudflare_ai_search_instance","stainlessResource":"ai_search.instances","methodName":"create","snippet":"resource \"cloudflare_ai_search_instance\" \"example_ai_search_instance\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n id = \"my-ai-search\"\n ai_gateway_id = \"ai_gateway_id\"\n aisearch_model = \"ai_search_model\"\n cache = true\n cache_threshold = \"super_strict_match\"\n cache_ttl = 600\n chunk = true\n chunk_overlap = 0\n chunk_size = 64\n custom_metadata = [{\n data_type = \"text\"\n field_name = \"x\"\n }]\n embedding_model = \"embedding_model\"\n fusion_method = \"max\"\n hybrid_search_enabled = true\n index_method = {\n keyword = true\n vector = true\n }\n indexing_options = {\n keyword_tokenizer = \"porter\"\n use_ocr = true\n }\n max_num_results = 1\n metadata = {\n created_from_aisearch_wizard = true\n worker_domain = \"worker_domain\"\n }\n public_endpoint_params = {\n authorized_hosts = [\"string\"]\n chat_completions_endpoint = {\n disabled = true\n }\n custom_domains = [\"search.example.com\"]\n default_domain_enabled = true\n enabled = true\n mcp = {\n description = \"description\"\n disabled = true\n }\n rate_limit = {\n period_ms = 60000\n requests = 1\n technique = \"fixed\"\n }\n search_endpoint = {\n disabled = true\n }\n }\n reranking = true\n reranking_model = \"reranking_model\"\n retrieval_options = {\n boost_by = [{\n field = \"timestamp\"\n direction = \"desc\"\n }]\n keyword_match_mode = \"and\"\n }\n rewrite_model = \"rewrite_model\"\n rewrite_query = true\n score_threshold = 0\n source = \"source\"\n source_params = {\n exclude_items = [\"/admin/**\", \"/private/**\", \"**\\\\temp\\\\**\"]\n include_items = [\"/blog/**\", \"/docs/**/*.html\", \"**\\\\blog\\\\**.html\"]\n prefix = \"prefix\"\n r2_jurisdiction = \"r2_jurisdiction\"\n web_crawler = {\n discover_options = {\n depth = 5\n include_external_links = false\n include_subdomains = false\n limit = 10000\n max_age = 86400\n source = \"all\"\n }\n parse_options = {\n content_selector = [{\n path = \"**/blog/**\"\n selector = \"article div.post-body\"\n }, {\n path = \"**/docs/**\"\n selector = \"main\"\n }]\n include_headers = {\n cache-control = \"no-cache, no-store\"\n }\n include_images = true\n specific_sitemaps = [\"https://example.com/sitemap.xml\", \"https://example.com/blog-sitemap.xml\"]\n use_browser_rendering = true\n }\n parse_type = \"sitemap\"\n }\n }\n sync_interval = 900\n token_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n type = \"r2\"\n}\n","required":[{"name":"id","type":"String","description":"AI Search instance ID. Lowercase alphanumeric, hyphens, and underscores.","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"type","type":"String","description":"Source type. When omitted or null with a non-blank source, HTTP(S) URLs infer web-crawler and existing R2 bucket names infer r2. A missing or blank source without a type uses managed upload-only storage.","requiresReplace":true},{"name":"hybrid_search_enabled","type":"Bool","description":"Deprecated — use index_method instead. Defaults to true for new instances; set false to create a vector-only instance.","deprecated":"Deprecated.","requiresReplace":true},{"name":"ai_gateway_id","type":"String"},{"name":"aisearch_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"chunk_size","type":"Int64"},{"name":"embedding_model","type":"String"},{"name":"reranking_model","type":"String"},{"name":"rewrite_model","type":"String","description":"A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model."},{"name":"source","type":"String"},{"name":"summarization_model","type":"String"},{"name":"system_prompt_aisearch","type":"String"},{"name":"system_prompt_index_summarization","type":"String"},{"name":"system_prompt_rewrite_query","type":"String"},{"name":"token_id","type":"String"},{"name":"custom_metadata","type":"List[Attributes]","children":[{"name":"data_type","type":"String"},{"name":"field_name","type":"String"}]},{"name":"metadata","type":"Attributes","children":[{"name":"created_from_aisearch_wizard","type":"Bool"},{"name":"worker_domain","type":"String"}]},{"name":"retrieval_options","type":"Attributes","children":[{"name":"boost_by","type":"List[Attributes]","description":"Metadata fields to boost search results by. Each entry specifies a metadata field and an optional direction. Direction defaults to 'asc' for numeric/datetime fields and 'exists' for text/boolean fields. Fields must match 'timestamp' or a defined custom_metadata field.","children":[{"name":"field","type":"String","description":"Metadata field name to boost by. Use 'timestamp' for document freshness, or any custom_metadata field. Numeric and datetime fields support all four directions (asc, desc, exists, not_exists); text/boolean fields only support exists/not_exists."},{"name":"direction","type":"String","description":"Boost direction. 'desc' = higher values rank higher (e.g. newer timestamps). 'asc' = lower values rank higher. 'exists' = boost chunks that have the field. 'not_exists' = boost chunks that lack the field. Optional — defaults to 'asc' for numeric/datetime fields, 'exists' for text/boolean fields."}]},{"name":"keyword_match_mode","type":"String","description":"Controls which documents are candidates for BM25 scoring. 'and' restricts candidates to documents containing all query terms; 'or' includes any document containing at least one term, ranked by BM25 relevance. When omitted on an update, the existing stored value is preserved; when never set, search falls back to 'and'."}]},{"name":"cache","type":"Bool"},{"name":"cache_threshold","type":"String"},{"name":"cache_ttl","type":"Float64","description":"Cache entry TTL in seconds. Allowed values: 600 (10min), 1800 (30min), 3600 (1h), 7200 (2h), 21600 (6h), 43200 (12h), 86400 (24h), 172800 (48h), 259200 (72h), 518400 (6d)."},{"name":"chunk","type":"Bool"},{"name":"chunk_overlap","type":"Int64"},{"name":"fusion_method","type":"String"},{"name":"max_num_results","type":"Int64"},{"name":"paused","type":"Bool"},{"name":"reranking","type":"Bool"},{"name":"rewrite_query","type":"Bool"},{"name":"score_threshold","type":"Float64"},{"name":"summarization","type":"Bool"},{"name":"sync_interval","type":"Float64","description":"Interval between automatic syncs, in seconds. Allowed values: 900 (15min), 1800 (30min), 3600 (1h), 7200 (2h), 14400 (4h), 21600 (6h), 43200 (12h), 86400 (24h)."},{"name":"index_method","type":"Attributes","description":"Controls which storage backends are used during indexing. Defaults to vector and keyword indexing for new instances.","children":[{"name":"keyword","type":"Bool","description":"Enable keyword (BM25) storage backend."},{"name":"vector","type":"Bool","description":"Enable vector (embedding) storage backend."}]},{"name":"indexing_options","type":"Attributes","children":[{"name":"keyword_tokenizer","type":"String","description":"Tokenizer used for keyword search indexing. porter provides word-level tokenization with Porter stemming (good for natural language queries). trigram enables character-level substring matching (good for partial matches, code, identifiers). Changing this triggers a full re-index. Defaults to porter."},{"name":"use_ocr","type":"Bool","description":"Enables OCR ingestion for PDFs and images. Changing this triggers a full re-index. Defaults to false."}]},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]},{"name":"source_params","type":"Attributes","children":[{"name":"exclude_items","type":"List[String]","description":"List of path patterns to exclude. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /admin/** matches /admin/users and /admin/settings/advanced). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"include_items","type":"List[String]","description":"List of path patterns to include. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /blog/** matches /blog/post and /blog/2024/post). Most accounts are limited to 10 rules; contact support to raise it."},{"name":"prefix","type":"String"},{"name":"r2_jurisdiction","type":"String"},{"name":"web_crawler","type":"Attributes","children":[{"name":"discover_options","type":"Attributes","description":"Options for parse_type 'discover', where Browser Run discovers URLs by link following and sitemaps. Ignored for 'sitemap'.","children":[{"name":"depth","type":"Float64","description":"Maximum link-follow depth from the seed URL."},{"name":"include_external_links","type":"Bool","description":"Follow links that point outside the source domain. Must stay `false` — discover crawls are restricted to the zone you own."},{"name":"include_subdomains","type":"Bool","description":"Follow links to subdomains of the source host."},{"name":"limit","type":"Float64","description":"Maximum number of pages to crawl (1-100000)."},{"name":"max_age","type":"Float64","description":"Maximum content age in seconds to accept (0–604800)."},{"name":"source","type":"String","description":"Where the crawler looks for URLs: 'sitemaps' reads sitemap XML only, 'links' follows page links only, 'all' does both."}]},{"name":"parse_options","type":"Attributes","children":[{"name":"content_selector","type":"List[Attributes]","description":"List of path-to-selector mappings for extracting specific content from crawled pages. Each entry pairs a URL glob pattern with a CSS selector. The first matching path wins. Only the matched HTML fragment is stored and indexed. Omit the field to disable content selection — empty arrays are rejected.","children":[{"name":"path","type":"String","description":"Glob pattern to match against the page URL path. Uses standard glob syntax: * matches within a segment, ** crosses directories."},{"name":"selector","type":"String","description":"CSS selector to extract content from pages matching the path pattern. Must not contain disallowed characters (;, `, $, {, }, \\). Must target a single element; if multiple elements match, the selector is ignored and the full page is used."}]},{"name":"include_headers","type":"Map[String]","description":"Up to 5 custom HTTP headers sent with each crawl request. Names must be RFC-7230 token characters (no spaces, colons, or control characters); values must be HTAB + printable ASCII (no CR/LF)."},{"name":"include_images","type":"Bool"},{"name":"specific_sitemaps","type":"List[String]","description":"List of specific sitemap URLs to use for crawling. Only valid when parse_type is 'sitemap'."},{"name":"use_browser_rendering","type":"Bool"}]},{"name":"parse_type","type":"String","description":"How URLs are discovered. 'sitemap' reads XML sitemaps; 'discover' follows links recursively and requires the source to be a Verified zone on this account."}]}]}],"computed":[{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"enable","type":"Bool"},{"name":"engine_version","type":"Float64"},{"name":"last_activity","type":"Time"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"},{"name":"namespace","type":"String"},{"name":"public_endpoint_id","type":"String"},{"name":"status","type":"String"}]}]},"post /accounts/{}/ai-search/namespaces":{"operationId":"ai-search-create-namespace","declarations":[{"kind":"resource","name":"cloudflare_ai_search_namespace","stainlessResource":"ai_search.namespaces","methodName":"create","snippet":"resource \"cloudflare_ai_search_namespace\" \"example_ai_search_namespace\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n name = \"name\"\n description = \"Production environment\"\n public_endpoint_params = {\n authorized_hosts = [\"string\"]\n chat_completions_endpoint = {\n disabled = true\n }\n custom_domains = [\"search.example.com\"]\n default_domain_enabled = true\n enabled = true\n instances_allowed = [\"docs\", \"blog\"]\n mcp = {\n description = \"description\"\n disabled = true\n }\n rate_limit = {\n period_ms = 60000\n requests = 1\n technique = \"fixed\"\n }\n search_endpoint = {\n disabled = true\n }\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","requiresReplace":true}],"optional":[{"name":"description","type":"String","description":"Optional description for the namespace. Max 256 characters."},{"name":"public_endpoint_params","type":"Attributes","children":[{"name":"authorized_hosts","type":"List[String]"},{"name":"chat_completions_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable chat completions endpoint for this public endpoint"}]},{"name":"custom_domains","type":"List[String]","description":"Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)."},{"name":"default_domain_enabled","type":"Bool","description":"When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true."},{"name":"enabled","type":"Bool"},{"name":"instances_allowed","type":"List[String]","description":"Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit."},{"name":"mcp","type":"Attributes","children":[{"name":"description","type":"String"},{"name":"disabled","type":"Bool","description":"Disable MCP endpoint for this public endpoint"}]},{"name":"rate_limit","type":"Attributes","children":[{"name":"period_ms","type":"Int64"},{"name":"requests","type":"Int64"},{"name":"technique","type":"String"}]},{"name":"search_endpoint","type":"Attributes","children":[{"name":"disabled","type":"Bool","description":"Disable search endpoint for this public endpoint"}]}]}],"computed":[{"name":"created_at","type":"Time"},{"name":"public_endpoint_id","type":"String"}]}]},"post /accounts/{}/ai-search/tokens":{"operationId":"ai-search-create-tokens","declarations":[{"kind":"resource","name":"cloudflare_ai_search_token","stainlessResource":"ai_search.tokens","methodName":"create","snippet":"resource \"cloudflare_ai_search_token\" \"example_ai_search_token\" {\n account_id = \"c3dc5f0b34a14ff8e1b3ec04895e1b22\"\n cf_api_id = \"a1b2c3d4e5f6\"\n cf_api_key = \"abc123\"\n name = \"my-token\"\n legacy = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"cf_api_id","type":"String"},{"name":"cf_api_key","type":"String","sensitive":true},{"name":"name","type":"String"}],"optional":[{"name":"legacy","type":"Bool"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"created_by","type":"String"},{"name":"enabled","type":"Bool"},{"name":"modified_at","type":"Time"},{"name":"modified_by","type":"String"}]}]},"post /accounts/{}/alerting/v3/destinations/webhooks":{"operationId":"notification-webhooks-create-a-webhook","declarations":[{"kind":"resource","name":"cloudflare_notification_policy_webhooks","stainlessResource":"alerting.destinations.webhooks","methodName":"create","snippet":"resource \"cloudflare_notification_policy_webhooks\" \"example_notification_policy_webhooks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Slack Webhook\"\n url = \"https://hooks.slack.com/services/Ds3fdBFbV/456464Gdd\"\n secret = \"secret\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account id","requiresReplace":true},{"name":"name","type":"String","description":"The name of the webhook destination. This will be included in the request body when you receive a webhook notification."},{"name":"url","type":"String","description":"The POST endpoint to call when dispatching a notification."}],"optional":[{"name":"secret","type":"String","description":"Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.","sensitive":true}],"computed":[{"name":"id","type":"String","description":"UUID"},{"name":"created_at","type":"Time","description":"Timestamp of when the webhook destination was created."},{"name":"last_failure","type":"Time","description":"Timestamp of the last time an attempt to dispatch a notification to this webhook failed."},{"name":"last_success","type":"Time","description":"Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook."},{"name":"type","type":"String","description":"Type of webhook endpoint."}]}]},"post /accounts/{}/alerting/v3/policies":{"operationId":"notification-policies-create-a-notification-policy","declarations":[{"kind":"resource","name":"cloudflare_notification_policy","stainlessResource":"alerting.policies","methodName":"create","snippet":"resource \"cloudflare_notification_policy\" \"example_notification_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n alert_type = \"universal_ssl_event_type\"\n enabled = true\n mechanisms = {\n email = [{\n id = \"id\"\n }]\n pagerduty = [{\n id = \"f174e90afafe4643bbbc4a0ed4fc8415\"\n }]\n webhooks = [{\n id = \"f174e90afafe4643bbbc4a0ed4fc8415\"\n }]\n }\n name = \"SSL Notification Event Policy\"\n alert_interval = \"30m\"\n description = \"Something describing the policy.\"\n filters = {\n actions = [\"string\"]\n affected_asns = [\"string\"]\n affected_components = [\"string\"]\n affected_locations = [\"string\"]\n airport_code = [\"string\"]\n alert_trigger_preferences = [\"string\"]\n alert_trigger_preferences_value = [\"string\"]\n enabled = [\"string\"]\n environment = [\"string\"]\n event = [\"string\"]\n event_source = [\"string\"]\n event_type = [\"string\"]\n group_by = [\"string\"]\n health_check_id = [\"string\"]\n incident_impact = [\"INCIDENT_IMPACT_NONE\"]\n input_id = [\"string\"]\n insight_class = [\"string\"]\n limit = [\"string\"]\n logo_tag = [\"string\"]\n megabits_per_second = [\"string\"]\n new_health = [\"string\"]\n new_status = [\"string\"]\n packets_per_second = [\"string\"]\n pool_id = [\"string\"]\n pop_names = [\"string\"]\n product = [\"string\"]\n project_id = [\"string\"]\n protocol = [\"string\"]\n query_tag = [\"string\"]\n requests_per_second = [\"string\"]\n selectors = [\"string\"]\n services = [\"string\"]\n slo = [\"99.9\"]\n status = [\"string\"]\n target_hostname = [\"string\"]\n target_ip = [\"string\"]\n target_zone_name = [\"string\"]\n token_id = [\"x\"]\n traffic_exclusions = [\"security_events\"]\n tunnel_id = [\"string\"]\n tunnel_name = [\"string\"]\n type = [\"string\"]\n where = [\"string\"]\n zones = [\"string\"]\n }\n}\n","required":[{"name":"account_id","type":"String","description":"The account id","requiresReplace":true},{"name":"alert_type","type":"String","description":"Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values."},{"name":"name","type":"String","description":"Name of the policy."},{"name":"mechanisms","type":"Attributes","description":"List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.","children":[{"name":"email","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The email address"}]},{"name":"pagerduty","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]},{"name":"webhooks","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"UUID"}]}]}],"optional":[{"name":"alert_interval","type":"String","description":"Optional specification of how often to re-alert from the same incident, not support on all alert types."},{"name":"description","type":"String","description":"Optional description for the Notification policy."},{"name":"filters","type":"Attributes","description":"Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.","children":[{"name":"actions","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"affected_asns","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"affected_components","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"affected_locations","type":"List[String]","description":"Used for configuring radar_notification"},{"name":"airport_code","type":"List[String]","description":"Used for configuring maintenance_event_notification"},{"name":"alert_trigger_preferences","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"alert_trigger_preferences_value","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"enabled","type":"List[String]","description":"Used for configuring load_balancing_pool_enablement_alert"},{"name":"environment","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"event_source","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"event_type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"group_by","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"health_check_id","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"incident_impact","type":"List[String]","description":"Used for configuring incident_alert"},{"name":"input_id","type":"List[String]","description":"Used for configuring stream_live_notifications"},{"name":"insight_class","type":"List[String]","description":"Used for configuring security_insights_alert"},{"name":"limit","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"logo_tag","type":"List[String]","description":"Used for configuring logo_match_alert"},{"name":"megabits_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"new_health","type":"List[String]","description":"Used for configuring load_balancing_health_alert"},{"name":"new_status","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"packets_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"pool_id","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"pop_names","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"product","type":"List[String]","description":"Used for configuring billing_usage_alert"},{"name":"project_id","type":"List[String]","description":"Used for configuring pages_event_alert"},{"name":"protocol","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"query_tag","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"requests_per_second","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"selectors","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"services","type":"List[String]","description":"Used for configuring clickhouse_alert_fw_ent_anomaly"},{"name":"slo","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"status","type":"List[String]","description":"Used for configuring health_check_status_notification"},{"name":"target_hostname","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"target_ip","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l4_alert"},{"name":"target_zone_name","type":"List[String]","description":"Used for configuring advanced_ddos_attack_l7_alert"},{"name":"token_id","type":"List[String]","description":"Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens."},{"name":"traffic_exclusions","type":"List[String]","description":"Used for configuring traffic_anomalies_alert"},{"name":"tunnel_id","type":"List[String]","description":"Used for configuring tunnel_health_event"},{"name":"tunnel_name","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"type","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"where","type":"List[String]","description":"Usage depends on specific alert type"},{"name":"zones","type":"List[String]","description":"Usage depends on specific alert type"}]},{"name":"enabled","type":"Bool","description":"Whether or not the Notification policy is enabled."}],"computed":[{"name":"id","type":"String","description":"UUID"},{"name":"created","type":"Time"},{"name":"modified","type":"Time"}]}]},"post /accounts/{}/calls/apps":{"operationId":"calls-apps-create-a-new-app","declarations":[{"kind":"resource","name":"cloudflare_calls_sfu_app","stainlessResource":"calls.sfu","methodName":"create","snippet":"resource \"cloudflare_calls_sfu_app\" \"example_calls_sfu_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"production-realtime-app\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"app_id","type":"String","description":"A Cloudflare-generated unique identifier for a item.","requiresReplace":true},{"name":"name","type":"String","description":"A short description of a Realtime SFU app, not shown to end users."}],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"secret","type":"String","description":"Bearer token","sensitive":true},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"post /accounts/{}/calls/turn_keys":{"operationId":"calls-turn-key-create","declarations":[{"kind":"resource","name":"cloudflare_calls_turn_app","stainlessResource":"calls.turn","methodName":"create","snippet":"resource \"cloudflare_calls_turn_app\" \"example_calls_turn_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-turn-key\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"key_id","type":"String","description":"A Cloudflare-generated unique identifier for a item.","requiresReplace":true},{"name":"name","type":"String","description":"A short description of a TURN key, not shown to end users."}],"computed":[{"name":"created","type":"Time","description":"The date and time the item was created."},{"name":"key","type":"String","description":"Bearer token","sensitive":true},{"name":"modified","type":"Time","description":"The date and time the item was last modified."},{"name":"uid","type":"String","description":"A Cloudflare-generated unique identifier for a item."}]}]},"post /accounts/{}/cfd_tunnel":{"operationId":"cloudflare-tunnel-create-a-cloudflare-tunnel","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared","stainlessResource":"zero_trust.tunnels.cloudflared","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared\" \"example_zero_trust_tunnel_cloudflared\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"blog\"\n config_src = \"cloudflare\"\n tunnel_secret = \"AQIDBAUGBwgBAgMEBQYHCAECAwQFBgcIAQIDBAUGBwg=\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."}],"optional":[{"name":"config_src","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard.","requiresReplace":true},{"name":"tunnel_secret","type":"String","description":"Sets the password required to run a locally-managed tunnel. Must be at least 32 bytes and encoded as a base64 string.","sensitive":true}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"remote_config","type":"Bool","description":"If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.","deprecated":"Use the config_src field instead."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"post /accounts/{}/challenges/widgets":{"operationId":"accounts-turnstile-widget-create","declarations":[{"kind":"resource","name":"cloudflare_turnstile_widget","stainlessResource":"turnstile.widgets","methodName":"create","snippet":"resource \"cloudflare_turnstile_widget\" \"example_turnstile_widget\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domains = [\"203.0.113.1\", \"cloudflare.com\", \"blog.example.com\"]\n mode = \"invisible\"\n name = \"blog.cloudflare.com login form\"\n bot_fight_mode = false\n clearance_level = \"interactive\"\n ephemeral_id = false\n offlabel = false\n region = \"world\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"mode","type":"String","description":"Widget Mode"},{"name":"name","type":"String","description":"Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used.\n"},{"name":"domains","type":"List[String]"}],"optional":[{"name":"bot_fight_mode","type":"Bool","description":"If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only).\n"},{"name":"clearance_level","type":"String","description":"If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\n"},{"name":"ephemeral_id","type":"Bool","description":"Return the Ephemeral ID in /siteverify (ENT only).\n"},{"name":"offlabel","type":"Bool","description":"Do not show any Cloudflare branding on the widget (ENT only).\n"},{"name":"region","type":"String","description":"Region where this widget can be used. This cannot be changed after creation.\n"}],"computed":[{"name":"id","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"sitekey","type":"String","description":"Unique identifier for a Turnstile widget."},{"name":"created_on","type":"Time","description":"When the widget was created."},{"name":"deployed_via","type":"String","description":"Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\n"},{"name":"last_modified_via","type":"String","description":"Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\n"},{"name":"modified_on","type":"Time","description":"When the widget was modified."},{"name":"secret","type":"String","description":"Secret key for this widget.","sensitive":true}]}]},"post /accounts/{}/cloudforce-one/requests":{"operationId":"cloudforce-one-request-list","declarations":[{"kind":"list-data-source","name":"cloudflare_cloudforce_one_requests","stainlessResource":"cloudforce_one.requests","methodName":"list","snippet":"data \"cloudflare_cloudforce_one_requests\" \"example_cloudforce_one_requests\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n page = 0\n per_page = 10\n completed_after = \"2022-01-01T00:00:00Z\"\n completed_before = \"2024-01-01T00:00:00Z\"\n created_after = \"2022-01-01T00:00:00Z\"\n created_before = \"2024-01-01T00:00:00Z\"\n request_type = \"Victomology\"\n sort_by = \"created\"\n sort_order = \"asc\"\n status = \"open\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier."},{"name":"page","type":"Int64","description":"Page number of results."},{"name":"per_page","type":"Int64","description":"Number of results per page."}],"optional":[{"name":"completed_after","type":"Time","description":"Retrieve requests completed after this time."},{"name":"completed_before","type":"Time","description":"Retrieve requests completed before this time."},{"name":"created_after","type":"Time","description":"Retrieve requests created after this time."},{"name":"created_before","type":"Time","description":"Retrieve requests created before this time."},{"name":"request_type","type":"String","description":"Requested information from request."},{"name":"sort_by","type":"String","description":"Field to sort results by."},{"name":"sort_order","type":"String","description":"Sort order (asc or desc)."},{"name":"status","type":"String","description":"Request Status."},{"name":"max_items","type":"Int64","description":"Max items to fetch, default: 1000"}],"computed":[{"name":"result","type":"List[Attributes]","description":"The items returned by the data source","children":[{"name":"id","type":"String","description":"UUID."},{"name":"created","type":"Time","description":"Request creation time."},{"name":"priority","type":"String"},{"name":"request","type":"String","description":"Requested information from request."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"updated","type":"Time","description":"Request last updated time."},{"name":"completed","type":"Time","description":"Request completion time."},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"status","type":"String","description":"Request Status."},{"name":"tokens","type":"Int64","description":"Tokens for the request."}]}]}]},"post /accounts/{}/cloudforce-one/requests/{}/asset":{"operationId":"cloudforce-one-request-asset-list","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request_asset","stainlessResource":"cloudforce_one.requests.assets","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request_asset\" \"example_cloudforce_one_request_asset\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n page = 0\n per_page = 10\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"request_id","type":"String","description":"UUID.","requiresReplace":true},{"name":"page","type":"Int64","description":"Page number of results.","requiresReplace":true},{"name":"per_page","type":"Int64","description":"Number of results per page.","requiresReplace":true}],"optional":[{"name":"source","type":"String","description":"Asset file to upload."}],"computed":[{"name":"id","type":"Int64","description":"Asset ID."},{"name":"created","type":"Time","description":"Defines the asset creation time."},{"name":"description","type":"String","description":"Asset description."},{"name":"file_type","type":"String","description":"Asset file type."},{"name":"name","type":"String","description":"Asset name."}]}]},"post /accounts/{}/cloudforce-one/requests/{}/message":{"operationId":"cloudforce-one-request-message-list","declarations":[{"kind":"data-source","name":"cloudflare_cloudforce_one_request_message","stainlessResource":"cloudforce_one.requests.message","methodName":"get","snippet":"data \"cloudflare_cloudforce_one_request_message\" \"example_cloudforce_one_request_message\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n page = 0\n per_page = 10\n after = \"2019-12-27T18:11:19.117Z\"\n before = \"2024-01-01T00:00:00Z\"\n sort_by = \"created\"\n sort_order = \"asc\"\n}\n","required":[{"name":"request_id","type":"String","description":"UUID."},{"name":"account_id","type":"String","description":"Identifier."},{"name":"page","type":"Int64","description":"Page number of results."},{"name":"per_page","type":"Int64","description":"Number of results per page."}],"optional":[{"name":"after","type":"Time","description":"Retrieve mes ges created after this time."},{"name":"before","type":"Time","description":"Retrieve messages created before this time."},{"name":"sort_by","type":"String","description":"Field to sort results by."},{"name":"sort_order","type":"String","description":"Sort order (asc or desc)."}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"author","type":"String","description":"Author of message."},{"name":"content","type":"String","description":"Content of message."},{"name":"created","type":"Time","description":"Defines the message creation time."},{"name":"is_follow_on_request","type":"Bool","description":"Whether the message is a follow-on request."},{"name":"updated","type":"Time","description":"Defines the message last updated time."}]}]},"post /accounts/{}/cloudforce-one/requests/{}/message/new":{"operationId":"cloudforce-one-request-message-new","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request_message","stainlessResource":"cloudforce_one.requests.message","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request_message\" \"example_cloudforce_one_request_message\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n content = \"Can you elaborate on the type of DoS that occurred?\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"request_id","type":"String","description":"UUID.","requiresReplace":true}],"optional":[{"name":"content","type":"String","description":"Content of message."}],"computed":[{"name":"id","type":"Int64","description":"Message ID."},{"name":"author","type":"String","description":"Author of message."},{"name":"created","type":"Time","description":"Defines the message creation time."},{"name":"is_follow_on_request","type":"Bool","description":"Whether the message is a follow-on request."},{"name":"updated","type":"Time","description":"Defines the message last updated time."}]}]},"post /accounts/{}/cloudforce-one/requests/new":{"operationId":"cloudforce-one-request-new","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request","stainlessResource":"cloudforce_one.requests","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request\" \"example_cloudforce_one_request\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n content = \"What regions were most effected by the recent DoS?\"\n priority = \"routine\"\n request_type = \"Victomology\"\n summary = \"DoS attack\"\n tlp = \"clear\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"content","type":"String","description":"Request content."},{"name":"priority","type":"String","description":"Priority for analyzing the request."},{"name":"request_type","type":"String","description":"Requested information from request."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"post /accounts/{}/cloudforce-one/requests/priority/new":{"operationId":"cloudforce-one-priority-new","declarations":[{"kind":"resource","name":"cloudflare_cloudforce_one_request_priority","stainlessResource":"cloudforce_one.requests.priority","methodName":"create","snippet":"resource \"cloudflare_cloudforce_one_request_priority\" \"example_cloudforce_one_request_priority\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n labels = [\"DoS\", \"CVE\"]\n priority = 1\n requirement = \"DoS attacks carried out by CVEs\"\n tlp = \"clear\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"priority","type":"Int64","description":"Priority."},{"name":"requirement","type":"String","description":"Requirement."},{"name":"tlp","type":"String","description":"The CISA defined Traffic Light Protocol (TLP)."},{"name":"labels","type":"List[String]","description":"List of labels."}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"completed","type":"Time"},{"name":"content","type":"String","description":"Request content."},{"name":"created","type":"Time"},{"name":"message_tokens","type":"Int64","description":"Tokens for the request messages."},{"name":"readable_id","type":"String","description":"Readable Request ID."},{"name":"request","type":"String","description":"Requested information from request."},{"name":"status","type":"String","description":"Request Status."},{"name":"summary","type":"String","description":"Brief description of the request."},{"name":"tokens","type":"Int64","description":"Tokens for the request."},{"name":"updated","type":"Time"}]}]},"post /accounts/{}/connectivity/directory/services":{"operationId":"connectivity-services-post","declarations":[{"kind":"resource","name":"cloudflare_connectivity_directory_service","stainlessResource":"connectivity.directory.services","methodName":"create","snippet":"resource \"cloudflare_connectivity_directory_service\" \"example_connectivity_directory_service\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n host = {\n ipv4 = \"10.0.0.1\"\n network = {\n tunnel_id = \"0191dce4-9ab4-7fce-b660-8e5dec5172da\"\n }\n }\n name = \"web-app\"\n type = \"http\"\n http_port = 8080\n https_port = 8443\n tls_settings = {\n cert_verification_mode = \"verify_full\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier","requiresReplace":true},{"name":"name","type":"String"},{"name":"type","type":"String"},{"name":"host","type":"Attributes","children":[{"name":"ipv4","type":"String"},{"name":"network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"}]},{"name":"ipv6","type":"String"},{"name":"hostname","type":"String"},{"name":"resolver_network","type":"Attributes","children":[{"name":"tunnel_id","type":"String"},{"name":"resolver_ips","type":"List[String]"}]}]}],"optional":[{"name":"app_protocol","type":"String"},{"name":"http_port","type":"Int64"},{"name":"https_port","type":"Int64"},{"name":"tcp_port","type":"Int64"},{"name":"tls_settings","type":"Attributes","description":"TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.","children":[{"name":"cert_verification_mode","type":"String","description":"TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all"}]}],"computed":[{"name":"id","type":"String"},{"name":"service_id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/d1/database":{"operationId":"d1-create-database","declarations":[{"kind":"resource","name":"cloudflare_d1_database","stainlessResource":"d1.database","methodName":"create","snippet":"resource \"cloudflare_d1_database\" \"example_d1_database\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-database\"\n jurisdiction = \"eu\"\n primary_location_hint = \"wnam\"\n read_replication = {\n mode = \"auto\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"name","type":"String","description":"D1 database name.","requiresReplace":true}],"optional":[{"name":"jurisdiction","type":"String","description":"Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored.","requiresReplace":true},{"name":"primary_location_hint","type":"String","description":"Specify the region to create the D1 primary, if available. If this option is omitted, the D1 will be created as close as possible to the current user.","requiresReplace":true},{"name":"read_replication","type":"Attributes","description":"Configuration for D1 read replication.","children":[{"name":"mode","type":"String","description":"The read replication mode for the database. Use 'auto' to create replicas and allow D1 automatically place them around the world, or 'disabled' to not use any database replicas (it can take a few hours for all replicas to be deleted)."}]}],"computed":[{"name":"id","type":"String","description":"D1 database identifier (UUID)."},{"name":"uuid","type":"String","description":"D1 database identifier (UUID)."},{"name":"created_at","type":"Time","description":"Specifies the timestamp the resource was created as an ISO8601 string."},{"name":"file_size","type":"Float64","description":"The D1 database's size, in bytes."},{"name":"num_tables","type":"Float64","description":"The number of tables in the D1 database. This count is no longer accurate and should not be relied upon.","deprecated":"Deprecated."},{"name":"version","type":"String"}]}]},"post /accounts/{}/data-security/posture/policies":{"operationId":"CreatePolicy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_casb_policy","stainlessResource":"zero_trust.casb.posture.policies","methodName":"create","snippet":"resource \"cloudflare_zero_trust_casb_policy\" \"example_zero_trust_casb_policy\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n actions = {\n remediation_types = [{\n remediation_type_id = \"5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a\"\n }]\n webhook_configs = [{\n webhook_config_id = \"3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e\"\n }]\n }\n applies_to_all_integrations = false\n display_name = \"Auto-remediate public files\"\n enabled = true\n finding_type_id = \"5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a\"\n description = \"Automatically remove public access from files when detected\"\n integration_ids = [\"497f6eca-6276-4993-bfeb-53cbbbba6f08\"]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"finding_type_id","type":"String","description":"The finding type this policy is associated with. All remediation actions must match this finding type.","requiresReplace":true},{"name":"applies_to_all_integrations","type":"Bool","description":"When true, the policy applies to all integrations for the account. When false, integration_ids must be provided."},{"name":"display_name","type":"String","description":"Display name for the policy configuration."},{"name":"enabled","type":"Bool","description":"Boolean specifying if the policy is enabled or disabled."},{"name":"actions","type":"Attributes","description":"Actions to execute when this policy is triggered, grouped by action type.\nA policy must contain at least one action across all groups and may include\nat most one remediation.","children":[{"name":"remediation_types","type":"List[Attributes]","description":"Remediation actions to execute (at most one).","children":[{"name":"remediation_type_id","type":"String","description":"The ID of the remediation type to execute."}]},{"name":"webhook_configs","type":"List[Attributes]","description":"Webhook actions to execute.","children":[{"name":"webhook_config_id","type":"String","description":"The ID of the webhook configuration to use."}]}]}],"optional":[{"name":"description","type":"String","description":"Optional description of what this policy does."},{"name":"integration_ids","type":"List[String]","description":"The integrations this policy applies to. Required when applies_to_all_integrations is false."}],"computed":[{"name":"id","type":"String","description":"Unique identifier for the policy configuration."},{"name":"created_at","type":"Time","description":"Timestamp when the policy was created."},{"name":"disabled_at","type":"Time","description":"Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled."},{"name":"last_triggered_at","type":"Time","description":"Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints."},{"name":"updated_at","type":"Time","description":"Timestamp when the policy was last updated."}]}]},"post /accounts/{}/data-security/posture/webhooks":{"operationId":"CreateWebhook","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_casb_webhook","stainlessResource":"zero_trust.casb.posture.webhooks","methodName":"create","snippet":"resource \"cloudflare_zero_trust_casb_webhook\" \"example_zero_trust_casb_webhook\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n authentication_type = \"Bearer Auth\"\n destination_url = \"https://example.com/webhook\"\n label = \"Send to Slack\"\n headers = [{\n key = \"Authorization\"\n value = \"Bearer token123\"\n }, {\n key = \"X-Custom-Header\"\n value = \"value\"\n }]\n signing_secret = \"my-secret-key\"\n status = \"enabled\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"authentication_type","type":"String","description":"Type of authentication used for the webhook."},{"name":"destination_url","type":"String","description":"Target URL for the webhook configuration. Where resulting data will be sent."},{"name":"label","type":"String","description":"Account-specified display label for the webhook configuration."}],"optional":[{"name":"signing_secret","type":"String","description":"Secret key used for HMAC signing when authentication_type is \"HMAC-Signing\".","sensitive":true},{"name":"headers","type":"List[Attributes]","description":"List of custom headers to include in webhook requests.","children":[{"name":"key","type":"String","description":"Header key name."},{"name":"value","type":"String","description":"Header value. Required on Create and Evaluate. On Update, omit or set to null to keep existing value.","sensitive":true}]},{"name":"status","type":"String","description":"Status of the webhook configuration. Defaults to enabled when omitted."}],"computed":[{"name":"id","type":"String","description":"Unique identifier for the specific webhook configuration."},{"name":"created_at","type":"Time","description":"Timestamp when the webhook configuration was created."},{"name":"updated_at","type":"Time","description":"Timestamp when the webhook configuration was last updated."},{"name":"version","type":"Int64","description":"Version number of the configuration."}]}]},"post /accounts/{}/devices/deployment-groups":{"operationId":"create-deployment-group","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_deployment_groups","stainlessResource":"zero_trust.devices.deployment_groups","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_deployment_groups\" \"example_zero_trust_device_deployment_groups\" {\n account_id = \"account_id\"\n name = \"Engineering Ring 0\"\n version_config = [{\n target_environment = \"windows\"\n version = \"2026.6.234.0\"\n }]\n policy_ids = [\"string\"]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for the deployment group."},{"name":"version_config","type":"List[Attributes]","description":"Contains at least one version configuration.","children":[{"name":"target_environment","type":"String","description":"The target environment for the client version (e.g., windows, macos)."},{"name":"version","type":"String","description":"The specific client version to deploy."}]}],"optional":[{"name":"policy_ids","type":"List[String]","description":"Contains an optional list of policy IDs assigned to a group."}],"computed":[{"name":"id","type":"String","description":"The ID of the deployment group."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was created."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the deployment group was last updated."}]}]},"post /accounts/{}/devices/ip-profiles":{"operationId":"create-ip-profile","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_ip_profile","stainlessResource":"zero_trust.devices.ip_profiles","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_ip_profile\" \"example_zero_trust_device_ip_profile\" {\n account_id = \"account_id\"\n match = \"identity.email == \\\"test@cloudflare.com\\\"\"\n name = \"IPv4 Cloudflare Source IPs\"\n precedence = 100\n subnet_id = \"b70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n description = \"example comment\"\n enabled = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"match","type":"String","description":"The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"."},{"name":"name","type":"String","description":"A user-friendly name for the Device IP profile."},{"name":"precedence","type":"Int64","description":"The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field."},{"name":"subnet_id","type":"String","description":"The ID of the Subnet."}],"optional":[{"name":"description","type":"String","description":"An optional description of the Device IP profile."},{"name":"enabled","type":"Bool","description":"Whether the Device IP profile will be applied to matching devices."}],"computed":[{"name":"id","type":"String","description":"The ID of the Device IP profile."},{"name":"created_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was created."},{"name":"updated_at","type":"String","description":"The RFC3339Nano timestamp when the Device IP profile was last updated."}]}]},"post /accounts/{}/devices/networks":{"operationId":"device-managed-networks-create-device-managed-network","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_managed_networks","stainlessResource":"zero_trust.devices.networks","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_managed_networks\" \"example_zero_trust_device_managed_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n config = {\n tls_sockaddr = \"foo.bar:1234\"\n sha256 = \"b5bb9d8014a0f9b1d61e21e796d78dccdf1352f23cd32812f4850b878ae4944c\"\n }\n name = \"managed-network-1\"\n type = \"tls\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the device managed network. This name must be unique."},{"name":"type","type":"String","description":"The type of device managed network."},{"name":"config","type":"Attributes","description":"The configuration object containing information for the WARP client to detect the managed network.","children":[{"name":"tls_sockaddr","type":"String","description":"A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host."},{"name":"sha256","type":"String","description":"The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"network_id","type":"String","description":"API UUID."}]}]},"post /accounts/{}/devices/policy":{"operationId":"devices-create-device-settings-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_custom_profile","stainlessResource":"zero_trust.devices.policies.custom","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_custom_profile\" \"example_zero_trust_device_custom_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Allow Developers\"\n allow_mode_switch = true\n allow_updates = true\n allowed_to_leave = true\n auto_connect = 0\n browser_extension_config = {\n proxy_control = \"unlocked\"\n proxy_enabled = true\n }\n captive_portal = 180\n default = false\n description = \"Policy for test teams.\"\n disable_auto_fallback = true\n dns_search_suffixes = [{\n suffix = \"internal.corp\"\n description = \"Example internal domains\"\n }]\n enabled = true\n exclude = [{\n address = \"192.0.2.0/24\"\n description = \"Exclude testing domains from the tunnel\"\n }]\n exclude_office_ips = true\n global_acceleration = {\n api_endpoints = [\"198.51.100.1:443\"]\n enabled = true\n masque_endpoints = [\"198.51.100.1:443\"]\n wireguard_endpoints = [\"198.51.100.1:2408\"]\n autoswitch = true\n }\n include = [{\n address = \"192.0.2.0/24\"\n description = \"Include testing domains in the tunnel\"\n }]\n lan_allow_minutes = 30\n lan_allow_subnet_size = 24\n match = \"identity.email == \\\"test@cloudflare.com\\\"\"\n precedence = 100\n profile_type = \"warp\"\n register_interface_ip_with_dns = true\n sccm_vpn_boundary_support = false\n service_mode_v2 = {\n mode = \"proxy\"\n port = 3000\n }\n support_url = \"https://1.1.1.1/help\"\n switch_locked = true\n tunnel_protocol = \"wireguard\"\n uninstall_protection = false\n virtual_networks = {\n allowed = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n default = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the device settings profile."}],"optional":[{"name":"profile_type","type":"String","description":"The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.","requiresReplace":true},{"name":"lan_allow_minutes","type":"Float64","description":"The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset."},{"name":"lan_allow_subnet_size","type":"Float64","description":"The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset."},{"name":"match","type":"String","description":"The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"."},{"name":"precedence","type":"Float64","description":"The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field."},{"name":"browser_extension_config","type":"Attributes","description":"Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.","children":[{"name":"proxy_control","type":"String","description":"Whether the user may disable the browser extension proxy."},{"name":"proxy_enabled","type":"Bool","description":"Whether the browser extension proxy is active."}]},{"name":"virtual_networks","type":"Attributes","description":"Virtual network access settings for the device.","children":[{"name":"allowed","type":"List[String]","description":"List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required."},{"name":"default","type":"String","description":"The default virtual network ID. Must be included in the `allowed` list."}]},{"name":"allow_mode_switch","type":"Bool","description":"Whether to allow the user to switch WARP between modes."},{"name":"allow_updates","type":"Bool","description":"Whether to receive update notifications when a new version of the client is available."},{"name":"allowed_to_leave","type":"Bool","description":"Whether to allow devices to leave the organization."},{"name":"auto_connect","type":"Float64","description":"The amount of time in seconds to reconnect after having been disabled."},{"name":"captive_portal","type":"Float64","description":"Turn on the captive portal after the specified amount of time."},{"name":"default","type":"Bool","description":"Whether the policy is the account default. WARP group profiles cannot set this field."},{"name":"description","type":"String","description":"A description of the policy."},{"name":"disable_auto_fallback","type":"Bool","description":"If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`."},{"name":"enabled","type":"Bool","description":"Whether the policy will be applied to matching devices."},{"name":"exclude_office_ips","type":"Bool","description":"Whether to add Microsoft IPs to Split Tunnel exclusions."},{"name":"register_interface_ip_with_dns","type":"Bool","description":"Determines if the operating system will register WARP's local interface IP with your on-premises DNS server."},{"name":"sccm_vpn_boundary_support","type":"Bool","description":"Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)."},{"name":"support_url","type":"String","description":"The URL to launch when the Send Feedback button is clicked."},{"name":"switch_locked","type":"Bool","description":"Whether to allow the user to turn off the WARP switch and disconnect the client."},{"name":"tunnel_protocol","type":"String","description":"Determines which tunnel protocol to use."},{"name":"uninstall_protection","type":"Bool","description":"Determines whether uninstalling the WARP client requires an override code. (Windows only)."},{"name":"dns_search_suffixes","type":"List[Attributes]","description":"List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.","children":[{"name":"suffix","type":"String","description":"The DNS search suffix to append when resolving short hostnames."},{"name":"description","type":"String","description":"A description of the DNS search suffix."}]},{"name":"exclude","type":"List[Attributes]","description":"List of routes excluded in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to exclude from the tunnel. If `host` is present, `address` must not be present."}]},{"name":"global_acceleration","type":"Attributes","description":"Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.","children":[{"name":"api_endpoints","type":"List[String]","description":"IP:port entries for the API endpoints."},{"name":"enabled","type":"Bool","description":"Global acceleration settings are used only when \"enabled\"."},{"name":"masque_endpoints","type":"List[String]","description":"IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"wireguard_endpoints","type":"List[String]","description":"IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided."},{"name":"autoswitch","type":"Bool","description":"Automatically switch Global Acceleration regions based on device location. Defaults to false when not provided."}]},{"name":"include","type":"List[Attributes]","description":"List of routes included in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.","children":[{"name":"address","type":"String","description":"The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present."},{"name":"description","type":"String","description":"A description of the Split Tunnel item, displayed in the client UI."},{"name":"host","type":"String","description":"The domain name to include in the tunnel. If `host` is present, `address` must not be present."}]},{"name":"service_mode_v2","type":"Attributes","children":[{"name":"mode","type":"String","description":"The mode to run the WARP client under."},{"name":"port","type":"Float64","description":"The port number when used with proxy mode."}]}],"computed":[{"name":"id","type":"String"},{"name":"policy_id","type":"String"},{"name":"gateway_unique_id","type":"String"},{"name":"fallback_domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]},{"name":"target_tests","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The id of the DEX test targeting this policy."},{"name":"name","type":"String","description":"The name of the DEX test targeting this policy."}]}]}]},"post /accounts/{}/devices/posture":{"operationId":"device-posture-rules-create-device-posture-rule","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_posture_rule","stainlessResource":"zero_trust.devices.posture","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_posture_rule\" \"example_zero_trust_device_posture_rule\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Admin Serial Numbers\"\n type = \"file\"\n description = \"The rule for admin serial numbers\"\n expiration = \"1h\"\n input = {\n operating_system = \"linux\"\n path = \"/bin/cat\"\n exists = true\n sha256 = \"https://api.us-2.crowdstrike.com\"\n thumbprint = \"0aabab210bdb998e9cf45da2c9ce352977ab531c681b74cf1e487be1bbe9fe6e\"\n }\n match = [{\n platform = \"windows\"\n }]\n schedule = \"1h\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the device posture rule."},{"name":"type","type":"String","description":"The type of device posture rule."}],"optional":[{"name":"description","type":"String","description":"The description of the device posture rule."},{"name":"expiration","type":"String","description":"Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client."},{"name":"schedule","type":"String","description":"Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`."},{"name":"input","type":"Attributes","description":"The value to be checked against.","children":[{"name":"operating_system","type":"String","description":"Operating system."},{"name":"path","type":"String","description":"File path."},{"name":"exists","type":"Bool","description":"Whether or not file exists."},{"name":"sha256","type":"String","description":"SHA-256."},{"name":"thumbprint","type":"String","description":"Signing certificate thumbprint."},{"name":"id","type":"String","description":"List ID."},{"name":"domain","type":"String","description":"Domain."},{"name":"operator","type":"String","description":"Operator."},{"name":"version","type":"String","description":"Version of OS."},{"name":"os_distro_name","type":"String","description":"Operating System Distribution Name (linux only)."},{"name":"os_distro_revision","type":"String","description":"Version of OS Distribution (linux only)."},{"name":"os_version_extra","type":"String","description":"Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version."},{"name":"enabled","type":"Bool","description":"Enabled."},{"name":"check_disks","type":"List[String]","description":"List of volume names to be checked for encryption."},{"name":"require_all","type":"Bool","description":"Whether to check all disks for encryption."},{"name":"certificate_id","type":"String","description":"UUID of Cloudflare managed certificate."},{"name":"cn","type":"String","description":"Common Name that is protected by the certificate."},{"name":"check_private_key","type":"Bool","description":"Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key."},{"name":"extended_key_usage","type":"List[String]","description":"List of values indicating purposes for which the certificate public key can be used."},{"name":"locations","type":"Attributes","children":[{"name":"paths","type":"List[String]","description":"List of paths to check for client certificate on linux."},{"name":"trust_stores","type":"List[String]","description":"List of trust stores to check for client certificate."}]},{"name":"subject_alternative_names","type":"List[String]","description":"List of certificate Subject Alternative Names."},{"name":"update_window_days","type":"Float64","description":"Number of days that the antivirus should be updated within."},{"name":"compliance_status","type":"String","description":"Compliance Status."},{"name":"connection_id","type":"String","description":"Posture Integration ID."},{"name":"last_seen","type":"String","description":"For more details on last seen, please refer to the Crowdstrike documentation."},{"name":"os","type":"String","description":"Os Version."},{"name":"overall","type":"String","description":"Overall."},{"name":"sensor_config","type":"String","description":"SensorConfig."},{"name":"state","type":"String","description":"For more details on state, please refer to the Crowdstrike documentation."},{"name":"version_operator","type":"String","description":"Version Operator."},{"name":"auth_state","type":"List[String]","description":"The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states."},{"name":"count_operator","type":"String","description":"Count Operator."},{"name":"issue_count","type":"String","description":"The Number of Issues."},{"name":"eid_last_seen","type":"String","description":"For more details on eid last seen, refer to the Tanium documentation."},{"name":"risk_level","type":"String","description":"For more details on risk level, refer to the Tanium documentation."},{"name":"score_operator","type":"String","description":"Score Operator."},{"name":"total_score","type":"Float64","description":"For more details on total score, refer to the Tanium documentation."},{"name":"active_threats","type":"Float64","description":"The Number of active threats."},{"name":"infected","type":"Bool","description":"Whether device is infected."},{"name":"is_active","type":"Bool","description":"Whether device is active."},{"name":"network_status","type":"String","description":"Network status of device."},{"name":"operational_state","type":"String","description":"Agent operational state."},{"name":"score","type":"Float64","description":"A value between 0-100 assigned to devices set by the 3rd party posture provider."}]},{"name":"match","type":"List[Attributes]","description":"The conditions that the client must match to run the rule.","children":[{"name":"platform","type":"String"}]}],"computed":[{"name":"id","type":"String","description":"API UUID."},{"name":"enabled","type":"Bool","description":"Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise."}]}]},"post /accounts/{}/devices/posture/integration":{"operationId":"device-posture-integrations-create-device-posture-integration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_posture_integration","stainlessResource":"zero_trust.devices.posture.integrations","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_posture_integration\" \"example_zero_trust_device_posture_integration\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n config = {\n api_url = \"https://as123.awmdm.com/API\"\n auth_url = \"https://na.uemauth.workspaceone.com/connect/token\"\n client_id = \"example client id\"\n client_secret = \"example client secret\"\n }\n interval = \"10m\"\n name = \"My Workspace One Integration\"\n type = \"workspace_one\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"interval","type":"String","description":"The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)."},{"name":"name","type":"String","description":"The name of the device posture integration."},{"name":"type","type":"String","description":"The type of device posture integration."},{"name":"config","type":"Attributes","description":"The configuration object containing third-party integration information.","children":[{"name":"api_url","type":"String","description":"The Workspace One API URL provided in the Workspace One Admin Dashboard."},{"name":"auth_url","type":"String","description":"The Workspace One Authorization URL depending on your region."},{"name":"client_id","type":"String","description":"The Workspace One client ID provided in the Workspace One Admin Dashboard."},{"name":"client_secret","type":"String","description":"The Workspace One client secret provided in the Workspace One Admin Dashboard.","sensitive":true},{"name":"customer_id","type":"String","description":"The Crowdstrike customer ID."},{"name":"client_key","type":"String","description":"The Uptycs client secret.","sensitive":true},{"name":"access_client_id","type":"String","description":"If present, this id will be passed in the `CF-Access-Client-ID` header when hitting the `api_url`."},{"name":"access_client_secret","type":"String","description":"If present, this secret will be passed in the `CF-Access-Client-Secret` header when hitting the `api_url`.","sensitive":true}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"API UUID."}]}]},"post /accounts/{}/dex/devices/dex_tests":{"operationId":"device-dex-test-create-device-dex-test","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dex_test","stainlessResource":"zero_trust.devices.dex_tests","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dex_test\" \"example_zero_trust_dex_test\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n data = {\n host = \"https://dash.cloudflare.com\"\n kind = \"http\"\n method = \"GET\"\n }\n enabled = true\n interval = \"30m\"\n name = \"HTTP dash health check\"\n description = \"Checks the dash endpoint every 30 minutes\"\n target_policies = [{\n id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n default = true\n name = \"name\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Determines whether or not the test is active."},{"name":"interval","type":"String","description":"How often the test will run."},{"name":"name","type":"String","description":"The name of the DEX test. Must be unique."},{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]}],"optional":[{"name":"description","type":"String","description":"Additional details about the test."},{"name":"target_policies","type":"List[Attributes]","description":"DEX rules targeted by this test","children":[{"name":"id","type":"String","description":"The id of the DEX rule."},{"name":"default","type":"Bool","description":"Whether the DEX rule is the account default."},{"name":"name","type":"String","description":"The name of the DEX rule."}]}],"computed":[{"name":"id","type":"String","description":"The unique identifier for the test."},{"name":"test_id","type":"String","description":"The unique identifier for the test."},{"name":"created","type":"Time","description":"Date the test was created, in RFC 3339 format."},{"name":"targeted","type":"Bool"},{"name":"updated","type":"Time","description":"Date the test was last updated, in RFC 3339 format."}]}]},"post /accounts/{}/dex/rules":{"operationId":"create-dex-rule","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dex_rule","stainlessResource":"zero_trust.dex.rules","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dex_rule\" \"example_zero_trust_dex_rule\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n match = \"match\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","description":"Unique identifier linked to an account.","requiresReplace":true},{"name":"match","type":"String","description":"The wirefilter expression to match."},{"name":"name","type":"String","description":"The name of the Rule."}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String","description":"API Resource UUID tag."},{"name":"created_at","type":"String"},{"name":"updated_at","type":"String"},{"name":"targeted_tests","type":"List[Attributes]","children":[{"name":"data","type":"Attributes","description":"The configuration object which contains the details for the WARP client to conduct the test.","children":[{"name":"host","type":"String","description":"The desired endpoint to test."},{"name":"kind","type":"String","description":"The type of test."},{"name":"method","type":"String","description":"The HTTP request method type."}]},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"test_id","type":"String"}]}]}]},"post /accounts/{}/dlp/data_classes":{"operationId":"dlp-data-classes-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_data_class","stainlessResource":"zero_trust.dlp.data_classes","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_data_class\" \"example_zero_trust_dlp_data_class\" {\n account_id = \"account_id\"\n data_tags = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n expression = \"expression\"\n name = \"name\"\n sensitivity_levels = [{\n group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"expression","type":"String"},{"name":"name","type":"String"},{"name":"data_tags","type":"List[String]"},{"name":"sensitivity_levels","type":"List[Attributes]","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/data_tag_categories":{"operationId":"dlp-data-tag-categories-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_data_tag_category","stainlessResource":"zero_trust.dlp.data_tag_categories","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_data_tag_category\" \"example_zero_trust_dlp_data_tag_category\" {\n account_id = \"account_id\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"template_id","type":"String","requiresReplace":true},{"name":"description","type":"String"},{"name":"tags","type":"List[Attributes]","description":"Tags to create with the category. Mutually exclusive with `template_id`.","children":[{"name":"name","type":"String"},{"name":"description","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/data_tag_categories/{}/data_tags":{"operationId":"dlp-data-tags-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_data_tag","stainlessResource":"zero_trust.dlp.data_tag_categories.data_tags","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_data_tag\" \"example_zero_trust_dlp_data_tag\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"category_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/datasets":{"operationId":"dlp-datasets-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_dataset","stainlessResource":"zero_trust.dlp.datasets","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_dataset\" \"example_zero_trust_dlp_dataset\" {\n account_id = \"account_id\"\n name = \"name\"\n case_sensitive = true\n description = \"description\"\n encoding_version = 0\n secret = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"dataset_id","type":"String","requiresReplace":true},{"name":"encoding_version","type":"Int64","description":"Dataset encoding version\n\nNon-secret custom word lists with no header are always version 1.\nSecret EDM lists with no header are version 1.\nMulticolumn CSV with headers are version 2.\nOmitting this field provides the default value 0, which is interpreted\nthe same as 1.","requiresReplace":true},{"name":"secret","type":"Bool","description":"Generate a secret dataset.\n\nIf true, the response will include a secret to use with the EDM encoder.\nIf false, the response has no secret and the dataset is uploaded in plaintext.","requiresReplace":true},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if `secret` is true or undefined"},{"name":"description","type":"String","description":"The description of the dataset."}],"computed":[{"name":"created_at","type":"Time"},{"name":"id","type":"String"},{"name":"max_cells","type":"Int64"},{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"version","type":"Int64","description":"The version to use when uploading the dataset."},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"dataset","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"columns","type":"List[Attributes]","children":[{"name":"entry_id","type":"String"},{"name":"header_name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"upload_status","type":"String"}]},{"name":"created_at","type":"Time"},{"name":"encoding_version","type":"Int64"},{"name":"name","type":"String"},{"name":"num_cells","type":"Int64"},{"name":"secret","type":"Bool"},{"name":"status","type":"String"},{"name":"updated_at","type":"Time","description":"Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads."},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]},{"name":"case_sensitive","type":"Bool"},{"name":"description","type":"String","description":"The description of the dataset."}]},{"name":"uploads","type":"List[Attributes]","children":[{"name":"num_cells","type":"Int64"},{"name":"status","type":"String"},{"name":"version","type":"Int64"}]}]}]},"post /accounts/{}/dlp/entries":{"operationId":"dlp-entries-create-entry","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_custom_entry","stainlessResource":"zero_trust.dlp.entries.custom","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_custom_entry\" \"example_zero_trust_dlp_custom_entry\" {\n account_id = \"account_id\"\n enabled = true\n name = \"name\"\n pattern = {\n regex = \"regex\"\n validation = \"luhn\"\n }\n description = \"description\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]}],"optional":[{"name":"profile_id","type":"String","requiresReplace":true},{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]},{"kind":"resource","name":"cloudflare_zero_trust_dlp_entry","stainlessResource":"zero_trust.dlp.entries","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_entry\" \"example_zero_trust_dlp_entry\" {\n account_id = \"account_id\"\n enabled = true\n name = \"name\"\n pattern = {\n regex = \"regex\"\n validation = \"luhn\"\n }\n description = \"description\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]}],"optional":[{"name":"profile_id","type":"String","requiresReplace":true},{"name":"description","type":"String"},{"name":"type","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"secret","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"post /accounts/{}/dlp/entries/integration":{"operationId":"dlp-entries-create-integration-entry","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_integration_entry","stainlessResource":"zero_trust.dlp.entries.integration","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_integration_entry\" \"example_zero_trust_dlp_integration_entry\" {\n account_id = \"account_id\"\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"entry_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"}],"optional":[{"name":"profile_id","type":"String","description":"This field is not used as the owning profile.\nFor predefined entries it is already set to a predefined profile.","requiresReplace":true}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"post /accounts/{}/dlp/entries/predefined":{"operationId":"dlp-entries-create-predefined-entry","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_predefined_entry","stainlessResource":"zero_trust.dlp.entries.predefined","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_predefined_entry\" \"example_zero_trust_dlp_predefined_entry\" {\n account_id = \"account_id\"\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"entry_id","type":"String","requiresReplace":true},{"name":"enabled","type":"Bool"}],"optional":[{"name":"profile_id","type":"String","description":"This field is not used as the owning profile.\nFor predefined entries it is already set to a predefined profile.","requiresReplace":true}],"computed":[{"name":"id","type":"String"},{"name":"case_sensitive","type":"Bool","description":"Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true"},{"name":"created_at","type":"Time"},{"name":"deprecated","type":"Bool","description":"Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true."},{"name":"description","type":"String"},{"name":"name","type":"String"},{"name":"secret","type":"Bool"},{"name":"type","type":"String"},{"name":"updated_at","type":"Time"},{"name":"upload_status","type":"String"},{"name":"word_list","type":"List[String]"},{"name":"confidence","type":"Attributes","children":[{"name":"ai_context_available","type":"Bool","description":"Indicates whether this entry has AI remote service validation."},{"name":"available","type":"Bool","description":"Indicates whether this entry has any form of validation that is not an AI remote service."}]},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"profiles","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"name","type":"String"}]},{"name":"variant","type":"Attributes","description":"A Predefined AI prompt classification topic entry.","children":[{"name":"topic_type","type":"String"},{"name":"type","type":"String"},{"name":"description","type":"String","description":"A customer-facing explanation of what this predefined AI prompt topic represents."}]}]}]},"post /accounts/{}/dlp/profiles/custom":{"operationId":"dlp-profiles-create-custom-profiles","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_custom_profile","stainlessResource":"zero_trust.dlp.profiles.custom","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_custom_profile\" \"example_zero_trust_dlp_custom_profile\" {\n account_id = \"account_id\"\n name = \"name\"\n ai_context_enabled = true\n allowed_match_count = 5\n confidence_threshold = \"confidence_threshold\"\n context_awareness = {\n enabled = true\n skip = {\n files = true\n }\n }\n data_classes = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n data_tags = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n description = \"description\"\n ocr_enabled = true\n sensitivity_levels = [{\n group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n shared_entries = [{\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"description","type":"String","description":"The description of the profile."},{"name":"data_classes","type":"List[String]","description":"Data class IDs to associate with the profile."},{"name":"data_tags","type":"List[String]","description":"Data tag IDs to associate with the profile."},{"name":"context_awareness","type":"Attributes","description":"Scan the context of predefined entries to only return matches surrounded by keywords.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"If true, scan the context of predefined entries to only return matches surrounded by keywords."},{"name":"skip","type":"Attributes","description":"Content types to exclude from context analysis and return all matches.","children":[{"name":"files","type":"Bool","description":"If the content type is a file, skip context analysis and return all matches."}]}]},{"name":"entries","type":"List[Attributes]","children":[{"name":"enabled","type":"Bool"},{"name":"name","type":"String"},{"name":"pattern","type":"Attributes","children":[{"name":"regex","type":"String"},{"name":"validation","type":"String","deprecated":"Deprecated."}]},{"name":"description","type":"String"},{"name":"words","type":"List[String]"}]},{"name":"sensitivity_levels","type":"List[Attributes]","description":"Sensitivity levels to associate with the profile.","children":[{"name":"group_id","type":"String"},{"name":"level_id","type":"String"}]},{"name":"shared_entries","type":"List[Attributes]","description":"Entries from other profiles (e.g. pre-defined Cloudflare profiles, or your Microsoft Information Protection profiles).","children":[{"name":"enabled","type":"Bool"},{"name":"entry_id","type":"String"}]},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64","description":"Related DLP policies will trigger when the match count exceeds the number set."},{"name":"confidence_threshold","type":"String"},{"name":"ocr_enabled","type":"Bool"}],"computed":[{"name":"id","type":"String","description":"The id of the profile (uuid)."},{"name":"created_at","type":"Time","description":"When the profile was created."},{"name":"integration_id","type":"String"},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."},{"name":"type","type":"String"},{"name":"updated_at","type":"Time","description":"When the profile was lasted updated."}]}]},"post /accounts/{}/dlp/sensitivity_groups":{"operationId":"dlp-sensitivity-groups-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_sensitivity_group","stainlessResource":"zero_trust.dlp.sensitivity_groups","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_sensitivity_group\" \"example_zero_trust_dlp_sensitivity_group\" {\n account_id = \"account_id\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"template_id","type":"String","requiresReplace":true},{"name":"description","type":"String"},{"name":"levels","type":"List[Attributes]","description":"Levels to create with the group. Mutually exclusive with `template_id`.","children":[{"name":"name","type":"String"},{"name":"description","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dlp/sensitivity_groups/{}/levels":{"operationId":"dlp-sensitivity-levels-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_sensitivity_level","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dlp_sensitivity_level\" \"example_zero_trust_dlp_sensitivity_level\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n name = \"name\"\n description = \"description\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"sensitivity_group_id","type":"String","requiresReplace":true},{"name":"name","type":"String"}],"optional":[{"name":"description","type":"String"}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/dls/regional_services/prefix_bindings":{"operationId":"publicCreatePrefixBinding","declarations":[{"kind":"resource","name":"cloudflare_dls_prefix_binding","stainlessResource":"dls.regional_services.prefix_bindings","methodName":"create","snippet":"resource \"cloudflare_dls_prefix_binding\" \"example_dls_prefix_binding\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cidr = \"10.0.1.0/24\"\n prefix_id = \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n region_key = \"eu\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier of a Cloudflare account.","requiresReplace":true},{"name":"cidr","type":"String","description":"IP prefix in CIDR notation to bind.","requiresReplace":true},{"name":"prefix_id","type":"String","description":"The ID of the parent IP prefix that contains the CIDR.","requiresReplace":true},{"name":"region_key","type":"String","description":"Region key from managed regions (e.g., \"us\", \"eu\")."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The ID of the binding."}]}]},"post /accounts/{}/dns_firewall":{"operationId":"dns-firewall-create-dns-firewall-cluster","declarations":[{"kind":"resource","name":"cloudflare_dns_firewall","stainlessResource":"dns_firewall","methodName":"create","snippet":"resource \"cloudflare_dns_firewall\" \"example_dns_firewall\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Awesome DNS Firewall cluster\"\n upstream_ips = [\"192.0.2.1\", \"198.51.100.1\", \"2001:DB8:100::CF\"]\n attack_mitigation = {\n enabled = true\n only_when_upstream_unhealthy = false\n }\n deprecate_any_requests = true\n dns_firewall_ip_count = 2\n ecs_fallback = false\n maximum_cache_ttl = 900\n minimum_cache_ttl = 60\n negative_cache_ttl = 900\n ratelimit = 600\n retries = 2\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"DNS Firewall cluster name"},{"name":"upstream_ips","type":"Set[String]"}],"optional":[{"name":"dns_firewall_ip_count","type":"Int64","description":"Number of IPv4 addresses to assign to the DNS Firewall cluster. Only used during cluster creation and cannot be changed later.","requiresReplace":true},{"name":"deprecate_any_requests","type":"Bool","description":"Whether to refuse to answer queries for the ANY type"},{"name":"ecs_fallback","type":"Bool","description":"Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent"},{"name":"negative_cache_ttl","type":"Float64","description":"This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"ratelimit","type":"Float64","description":"Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting."},{"name":"maximum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n"},{"name":"minimum_cache_ttl","type":"Float64","description":"By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons.\n"},{"name":"retries","type":"Float64","description":"Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)"},{"name":"attack_mitigation","type":"Attributes","description":"Attack mitigation settings","children":[{"name":"enabled","type":"Bool","description":"When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers"},{"name":"only_when_upstream_unhealthy","type":"Bool","description":"Only mitigate attacks when upstream servers seem unhealthy"}]}],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"Last modification of DNS Firewall cluster"},{"name":"dns_firewall_ips","type":"Set[String]"}]}]},"post /accounts/{}/dns_settings/views":{"operationId":"dns-views-for-an-account-create-internal-dns-views","declarations":[{"kind":"resource","name":"cloudflare_account_dns_settings_internal_view","stainlessResource":"dns.settings.account.views","methodName":"create","snippet":"resource \"cloudflare_account_dns_settings_internal_view\" \"example_account_dns_settings_internal_view\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my view\"\n zones = [\"372e67954025e0ba6aaa6d586b9e0b59\"]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"The name of the view."},{"name":"zones","type":"Set[String]","description":"The list of zones linked to this view."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier."},{"name":"created_time","type":"Time","description":"When the view was created."},{"name":"modified_time","type":"Time","description":"When the view was last modified."}]}]},"post /accounts/{}/email-security/settings/allow_policies":{"operationId":"email_security_create_allow_policy","declarations":[{"kind":"resource","name":"cloudflare_email_security_allow_policy","stainlessResource":"email_security.settings.allow_policies","methodName":"create","snippet":"resource \"cloudflare_email_security_allow_policy\" \"example_email_security_allow_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_acceptable_sender = false\n is_exempt_recipient = false\n is_regex = false\n is_trusted_sender = true\n pattern = \"test@example.com\"\n pattern_type = \"EMAIL\"\n verify_sender = true\n comments = \"Trust all messages send from test@example.com\"\n is_recipient = false\n is_sender = true\n is_spoof = false\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"is_acceptable_sender","type":"Bool","description":"Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply."},{"name":"is_exempt_recipient","type":"Bool","description":"Bypasses all detections for messages to this recipient."},{"name":"is_regex","type":"Bool"},{"name":"is_trusted_sender","type":"Bool","description":"Bypasses all detections and link following for messages from this sender."},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"},{"name":"verify_sender","type":"Bool","description":"Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication."}],"optional":[{"name":"comments","type":"String"},{"name":"is_recipient","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.","deprecated":"Use `is_exempt_recipient` instead."},{"name":"is_sender","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_trusted_sender` instead."},{"name":"is_spoof","type":"Bool","description":"Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.","deprecated":"Use `is_acceptable_sender` instead."}],"computed":[{"name":"id","type":"String","description":"Allow policy identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email-security/settings/block_senders":{"operationId":"email_security_create_blocked_sender","declarations":[{"kind":"resource","name":"cloudflare_email_security_block_sender","stainlessResource":"email_security.settings.block_senders","methodName":"create","snippet":"resource \"cloudflare_email_security_block_sender\" \"example_email_security_block_sender\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_regex = false\n pattern = \"test@example.com\"\n pattern_type = \"EMAIL\"\n comments = \"Block sender with email test@example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal value."},{"name":"pattern","type":"String","description":"The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents."},{"name":"pattern_type","type":"String","description":"Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\n"}],"optional":[{"name":"comments","type":"String"}],"computed":[{"name":"id","type":"String","description":"Blocked sender pattern identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email-security/settings/domains":{"operationId":"email_security_create_domains","declarations":[{"kind":"resource","name":"cloudflare_email_security_domain","stainlessResource":"email_security.settings.domains","methodName":"create","snippet":"resource \"cloudflare_email_security_domain\" \"example_email_security_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n allowed_delivery_modes = [\"DIRECT\"]\n domain = \"domain\"\n drop_dispositions = [\"MALICIOUS\"]\n ip_restrictions = [\"192.0.2.0/24\", \"2001:db8::/32\"]\n regions = [\"GLOBAL\"]\n folder = \"AllItems\"\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n lookback_hops = 1\n require_tls_inbound = true\n require_tls_outbound = true\n transport = \"transport\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"domain","type":"String","description":"The email domain to protect.","requiresReplace":true},{"name":"allowed_delivery_modes","type":"Set[String]","description":"Delivery modes to onboard the domain through."},{"name":"drop_dispositions","type":"Set[String]","description":"Dispositions to drop instead of delivering, e.g. `[\"MALICIOUS\", \"SPAM\"]`."},{"name":"ip_restrictions","type":"Set[String]","description":"Source IP ranges mail is accepted from. Any other source is rejected."},{"name":"regions","type":"Set[String]","description":"Regions that process messages for this domain, e.g. `[\"GLOBAL\"]` or `[\"US\"]`."}],"optional":[{"name":"integration_id","type":"String","description":"Identifier of the CASB integration that authorizes this domain. The integration also enables API scanning, post-delivery actions, and directory sync."},{"name":"transport","type":"String","description":"The mail transport hostname for MX/Inline delivery — the MX record Cloudflare delivers email to (e.g. `mx.example.com`)."},{"name":"folder","type":"String","description":"The mailbox folder to scan, for API-scanning domains."},{"name":"lookback_hops","type":"Int64","description":"Number of hops to trace back through received headers when reconstructing the original message (1-20)."},{"name":"require_tls_inbound","type":"Bool","description":"Require TLS on inbound connections."},{"name":"require_tls_outbound","type":"Bool","description":"Require TLS on outbound connections."}],"computed":[{"name":"id","type":"String","description":"Domain identifier."},{"name":"created_at","type":"Time"},{"name":"dmarc_status","type":"String"},{"name":"inbox_provider","type":"String"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"},{"name":"o365_tenant_id","type":"String"},{"name":"spf_status","type":"String"},{"name":"status","type":"String"},{"name":"authorization","type":"Attributes","children":[{"name":"authorized","type":"Bool"},{"name":"timestamp","type":"Time"},{"name":"status_message","type":"String"}]},{"name":"emails_processed","type":"Attributes","children":[{"name":"timestamp","type":"Time"},{"name":"total_emails_processed","type":"Int64"},{"name":"total_emails_processed_previous","type":"Int64"}]}]}]},"post /accounts/{}/email-security/settings/impersonation_registry":{"operationId":"email_security_create_impersonation_registry","declarations":[{"kind":"resource","name":"cloudflare_email_security_impersonation_registry","stainlessResource":"email_security.settings.impersonation_registry","methodName":"create","snippet":"resource \"cloudflare_email_security_impersonation_registry\" \"example_email_security_impersonation_registry\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"john.doe@example.com\"\n is_email_regex = false\n name = \"John Doe\"\n comments = \"comments\"\n directory_id = 0\n directory_node_id = 0\n external_directory_node_id = \"external_directory_node_id\"\n provenance = \"A1S_INTERNAL\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"email","type":"String","description":"Email address (or pattern) of the protected identity."},{"name":"is_email_regex","type":"Bool","description":"Whether `email` is a regular expression instead of a literal address."},{"name":"name","type":"String","description":"Display name of the protected identity."}],"optional":[{"name":"comments","type":"String","description":"Optional note describing the entry."},{"name":"directory_id","type":"Int64","description":"Identifier of the directory the entry was synced from, when directory-synced."},{"name":"directory_node_id","type":"Int64","description":"Identifier of the directory node the entry was synced from, when directory-synced."},{"name":"external_directory_node_id","type":"String","description":"Deprecated. External identifier of the directory node.","deprecated":"This field is deprecated."},{"name":"provenance","type":"String","description":"Source the entry was created from."}],"computed":[{"name":"id","type":"String","description":"Impersonation registry entry identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email-security/settings/trusted_domains":{"operationId":"email_security_create_trusted_domain","declarations":[{"kind":"resource","name":"cloudflare_email_security_trusted_domains","stainlessResource":"email_security.settings.trusted_domains","methodName":"create","snippet":"resource \"cloudflare_email_security_trusted_domains\" \"example_email_security_trusted_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_recent = true\n is_regex = false\n is_similarity = false\n pattern = \"example.com\"\n comments = \"Trusted partner domain\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"is_recent","type":"Bool","description":"Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition."},{"name":"is_regex","type":"Bool","description":"Whether `pattern` is a regular expression instead of a literal domain."},{"name":"is_similarity","type":"Bool","description":"Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition."},{"name":"pattern","type":"String","description":"The domain pattern to trust, e.g. `example.com`."}],"optional":[{"name":"comments","type":"String"}],"computed":[{"name":"id","type":"String","description":"Trusted domain identifier."},{"name":"created_at","type":"Time"},{"name":"last_modified","type":"Time","description":"Deprecated, use `modified_at` instead. End of life: November 1, 2026.","deprecated":"Use `modified_at` instead."},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/email/routing/addresses":{"operationId":"email-routing-destination-addresses-create-a-destination-address","declarations":[{"kind":"resource","name":"cloudflare_email_routing_address","stainlessResource":"email_routing.addresses","methodName":"create","snippet":"resource \"cloudflare_email_routing_address\" \"example_email_routing_address\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"user@example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"email","type":"String","description":"The contact email address of the user.","requiresReplace":true}],"optional":[{"name":"status","type":"String","description":"Destination address status. Non-admin callers may only set verified addresses back to unverified; setting to verified requires admin privileges."}],"computed":[{"name":"id","type":"String","description":"Destination address identifier."},{"name":"created","type":"Time","description":"The date and time the destination address has been created."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"tag","type":"String","description":"Destination address tag. (Deprecated, replaced by destination address identifier)","deprecated":"Deprecated."},{"name":"verified","type":"Time","description":"The date and time the destination address has been verified. Null means not verified yet."}]}]},"post /accounts/{}/flagship/apps":{"operationId":"flagship_create_app","declarations":[{"kind":"resource","name":"cloudflare_flagship_app","stainlessResource":"flagship.apps","methodName":"create","snippet":"resource \"cloudflare_flagship_app\" \"example_flagship_app\" {\n account_id = \"account_id\"\n name = \"x\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app.","requiresReplace":true},{"name":"name","type":"String","description":"Name of the Flagship app (1–64 letters, numbers, hyphens, or underscores)."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"String"},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String","description":"Email of the actor who last modified the app, or `unknown` when unavailable."}]}]},"post /accounts/{}/flagship/apps/{}/flags":{"operationId":"flagship_create_flag","declarations":[{"kind":"resource","name":"cloudflare_flagship_flag","stainlessResource":"flagship.apps.flags","methodName":"create","snippet":"resource \"cloudflare_flagship_flag\" \"example_flagship_flag\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n default_variation = \"x\"\n enabled = true\n key = \"x\"\n rules = [{\n conditions = [{\n attribute = \"x\"\n operator = \"equals\"\n value = \"string\"\n }]\n priority = 1\n serve_variation = \"x\"\n rollout = {\n percentage = 0\n attribute = \"x\"\n }\n }]\n variations = {\n foo = \"string\"\n }\n description = \"description\"\n type = \"boolean\"\n}\n","required":[{"name":"key","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls.","requiresReplace":true},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the Flagship app.","requiresReplace":true},{"name":"app_id","type":"String","description":"Flagship app ID returned when the app was created.","requiresReplace":true},{"name":"default_variation","type":"String","description":"Variation the API serves when the flag is off, or when it's on but no rule matches the context. Must be a key in `variations`."},{"name":"enabled","type":"Bool","description":"When false, the flag bypasses all rules and always serves `default_variation`."},{"name":"variations","type":"Map[String]","description":"Map of variation name to value. All values share the same type (boolean, string, number, or JSON object/array), and each serialized value stays within 10KB."},{"name":"rules","type":"List[Attributes]","description":"Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.","children":[{"name":"conditions","type":"List[Attributes]","description":"Conditions the context must satisfy for this rule to match. An empty array matches all contexts.","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[Attributes]","children":[{"name":"attribute","type":"String"},{"name":"operator","type":"String"},{"name":"value","type":"String"},{"name":"clauses","type":"List[String]"},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"logical_operator","type":"String"}]},{"name":"priority","type":"Int64","description":"Evaluation order: the API evaluates rules with lower numbers first. Must be unique across the flag's rules."},{"name":"serve_variation","type":"String","description":"Variation the API serves when this rule matches. Must be a key in `variations`."},{"name":"rollout","type":"Attributes","children":[{"name":"percentage","type":"Float64","description":"Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)."},{"name":"attribute","type":"String","description":"Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request."}]}]}],"optional":[{"name":"description","type":"String","description":"Optional operator-facing description. It does not affect flag evaluation."},{"name":"type","type":"String","description":"Deprecated compatibility field. Omit it; the API ignores this value and infers the type from the flag's variations.","deprecated":"Deprecated."}],"computed":[{"name":"id","type":"String","description":"Unique identifier for the flag within an app. Used in all evaluation and SDK calls.","requiresReplace":true},{"name":"updated_at","type":"String"},{"name":"updated_by","type":"String"}]}]},"post /accounts/{}/gateway/certificates":{"operationId":"zero-trust-certificates-create-zero-trust-certificate","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_certificate","stainlessResource":"zero_trust.gateway.certificates","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_certificate\" \"example_zero_trust_gateway_certificate\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n validity_period_days = 1826\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}],"optional":[{"name":"validity_period_days","type":"Int64","description":"Sets the certificate validity period in days (range: 1-10,950 days / ~30 years). Defaults to 1,825 days (5 years). **Important**: This field is only settable during the certificate creation. Certificates becomes immutable after creation - use the `/activate` and `/deactivate` endpoints to manage certificate lifecycle.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Identify the certificate with a UUID.","requiresReplace":true},{"name":"binding_status","type":"String","description":"Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state."},{"name":"certificate","type":"String","description":"Provide the CA certificate (read-only)."},{"name":"created_at","type":"Time"},{"name":"expires_on","type":"Time"},{"name":"fingerprint","type":"String","description":"Provide the SHA256 fingerprint of the certificate (read-only)."},{"name":"in_use","type":"Bool","description":"Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)."},{"name":"issuer_org","type":"String","description":"Indicate the organization that issued the certificate (read-only)."},{"name":"issuer_raw","type":"String","description":"Provide the entire issuer field of the certificate (read-only)."},{"name":"type","type":"String","description":"Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed."},{"name":"updated_at","type":"Time"},{"name":"uploaded_on","type":"Time"}]}]},"post /accounts/{}/gateway/lists":{"operationId":"zero-trust-lists-create-zero-trust-list","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_list","stainlessResource":"zero_trust.gateway.lists","methodName":"create","snippet":"resource \"cloudflare_zero_trust_list\" \"example_zero_trust_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Admin Serial Numbers\"\n type = \"SERIAL\"\n description = \"The serial numbers for administrators\"\n items = [{\n description = \"Austin office IP\"\n value = \"8GE8721REF\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"type","type":"String","description":"Specify the list type.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the list name."}],"optional":[{"name":"items","type":"Set[Attributes]","description":"Add items to the list.","children":[{"name":"description","type":"String","description":"Provide the list item description (optional)."},{"name":"value","type":"String","description":"Specify the item value."}]},{"name":"description","type":"String","description":"Provide the list description."}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"list_count","type":"Float64","description":"Indicate the number of items in the list."},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/gateway/locations":{"operationId":"zero-trust-gateway-locations-create-zero-trust-gateway-location","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dns_location","stainlessResource":"zero_trust.gateway.locations","methodName":"create","snippet":"resource \"cloudflare_zero_trust_dns_location\" \"example_zero_trust_dns_location\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Austin Office Location\"\n client_default = false\n dns_destination_ips_id = \"0e4a32c6-6fb8-4858-9296-98f51631e8e6\"\n ecs_support = false\n endpoints = {\n doh = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n require_token = true\n }\n dot = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n }\n ipv4 = {\n enabled = true\n }\n ipv6 = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n }\n }\n max_ttl = {\n mode = \"override\"\n ttl_secs = 3600\n }\n networks = [{\n network = \"192.0.2.1/32\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the location name."}],"optional":[{"name":"endpoints","type":"Attributes","description":"Configure the destination endpoints for this location.","children":[{"name":"doh","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOH endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]},{"name":"require_token","type":"Bool","description":"Specify whether the DOH endpoint requires user identity authentication."}]},{"name":"dot","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the DOT endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IP address or IP CIDR."}]}]},{"name":"ipv4","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPv4 endpoint is enabled for this location."}]},{"name":"ipv6","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicate whether the IPV6 endpoint is enabled for this location."},{"name":"networks","type":"List[Attributes]","description":"Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv6 address or IPv6 CIDR."}]}]}]},{"name":"max_ttl","type":"Attributes","description":"Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.","children":[{"name":"mode","type":"String","description":"`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged."},{"name":"ttl_secs","type":"Int64","description":"Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`."}]},{"name":"networks","type":"List[Attributes]","description":"Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.","children":[{"name":"network","type":"String","description":"Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24."}]},{"name":"client_default","type":"Bool","description":"Indicate whether this location is the default location."},{"name":"dns_destination_ips_id","type":"String","description":"Specify the identifier of the pair of IPv4 addresses assigned to this location. When creating a location, if this field is absent or set to null, the pair of shared IPv4 addresses (0e4a32c6-6fb8-4858-9296-98f51631e8e6) is auto-assigned. When updating a location, if this field is absent or set to null, the pre-assigned pair remains unchanged."},{"name":"ecs_support","type":"Bool","description":"Indicate whether the location must resolve EDNS queries."}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"dns_destination_ipv6_block_id","type":"String","description":"Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block."},{"name":"doh_subdomain","type":"String","description":"Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value."},{"name":"ip","type":"String","description":"Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location."},{"name":"ipv4_destination","type":"String","description":"Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"ipv4_destination_backup","type":"String","description":"Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only."},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/gateway/pacfiles":{"operationId":"zero-trust-gateway-pacfiles-create-pacfile","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_pacfile","stainlessResource":"zero_trust.gateway.pacfiles","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_pacfile\" \"example_zero_trust_gateway_pacfile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n contents = \"function FindProxyForURL(url, host) { return \\\"DIRECT\\\"; }\"\n name = \"Devops team\"\n description = \"PAC file for Devops team\"\n slug = \"pac_devops\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"contents","type":"String","description":"Actual contents of the PAC file"},{"name":"name","type":"String","description":"Name of the PAC file."}],"optional":[{"name":"slug","type":"String","description":"URL-friendly version of the PAC file name. If not provided, it will be auto-generated","requiresReplace":true},{"name":"description","type":"String","description":"Detailed description of the PAC file."}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"},{"name":"url","type":"String","description":"Unique URL to download the PAC file."}]}]},"post /accounts/{}/gateway/proxy_endpoints":{"operationId":"zero-trust-gateway-proxy-endpoints-create-proxy-endpoint","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_proxy_endpoint","stainlessResource":"zero_trust.gateway.proxy_endpoints","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_proxy_endpoint\" \"example_zero_trust_gateway_proxy_endpoint\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Devops team\"\n kind = \"ip\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the name of the proxy endpoint."}],"optional":[{"name":"kind","type":"String","description":"The proxy endpoint kind","requiresReplace":true},{"name":"ips","type":"List[String]","description":"Specify the list of CIDRs to restrict ingress connections."}],"computed":[{"name":"id","type":"String"},{"name":"created_at","type":"Time"},{"name":"subdomain","type":"String","description":"Specify the subdomain to use as the destination in the proxy client."},{"name":"updated_at","type":"Time"}]}]},"post /accounts/{}/gateway/rules":{"operationId":"zero-trust-gateway-rules-create-zero-trust-gateway-rule","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_policy","stainlessResource":"zero_trust.gateway.rules","methodName":"create","snippet":"resource \"cloudflare_zero_trust_gateway_policy\" \"example_zero_trust_gateway_policy\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n action = \"allow\"\n name = \"block bad websites\"\n description = \"Block bad websites based on their host name.\"\n device_posture = \"any(device_posture.checks.passed[*] in {\\\"1308749e-fcfb-4ebc-b051-fe022b632644\\\"})\"\n enabled = true\n expiration = {\n expires_at = \"2014-01-01T05:20:20Z\"\n duration = 10\n }\n filters = [\"http\"]\n identity = \"any(identity.groups.name[*] in {\\\"finance\\\"})\"\n precedence = 0\n rule_settings = {\n add_headers = {\n My-Next-Header = [\"foo\", \"bar\"]\n X-Custom-Header-Name = [\"somecustomvalue\"]\n }\n allow_child_bypass = false\n audit_ssh = {\n command_logging = false\n }\n biso_admin_controls = {\n copy = \"remote_only\"\n dcp = true\n dd = true\n dk = true\n download = \"enabled\"\n dp = false\n du = true\n keyboard = \"enabled\"\n paste = \"enabled\"\n printing = \"enabled\"\n upload = \"enabled\"\n version = \"v1\"\n wm_id = \"475345dc-5299-4b6e-8f6a-3d3e4c8e9f1a\"\n }\n block_page = {\n target_uri = \"https://example.com\"\n include_context = true\n }\n block_page_enabled = true\n block_reason = \"This website is a security risk\"\n bypass_parent_rule = false\n check_session = {\n duration = \"300s\"\n enforce = true\n }\n delete_headers = [\"X-Old-Header\", \"X-Remove-Me\"]\n dns_resolvers = {\n ipv4 = [{\n ip = \"2.2.2.2\"\n port = 5053\n route_through_private_network = true\n vnet_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }]\n ipv6 = [{\n ip = \"2001:DB8::\"\n port = 5053\n route_through_private_network = true\n vnet_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }]\n }\n egress = {\n ipv4 = \"192.0.2.2\"\n ipv4_fallback = \"192.0.2.3\"\n ipv6 = \"2001:DB8::/64\"\n }\n forensic_copy = {\n enabled = true\n }\n ignore_cname_category_matches = true\n insecure_disable_dnssec_validation = false\n ip_categories = true\n ip_indicator_feeds = true\n l4override = {\n ip = \"1.1.1.1\"\n port = 0\n }\n notification_settings = {\n enabled = true\n include_context = true\n msg = \"msg\"\n support_url = \"support_url\"\n }\n override_host = \"example.com\"\n override_ips = [\"1.1.1.1\", \"2.2.2.2\"]\n payload_log = {\n enabled = true\n }\n quarantine = {\n file_types = [\"exe\"]\n }\n redirect = {\n target_uri = \"https://example.com\"\n include_context = true\n preserve_path_and_query = true\n }\n resolve_dns_internally = {\n fallback = \"none\"\n view_id = \"view_id\"\n }\n resolve_dns_through_cloudflare = true\n set_headers = {\n X-User-Identity = [\"user=@{identity.name}\"]\n }\n untrusted_cert = {\n action = \"error\"\n }\n }\n schedule = {\n fri = \"08:00-12:30,13:30-17:00\"\n mon = \"08:00-12:30,13:30-17:00\"\n sat = \"08:00-12:30,13:30-17:00\"\n sun = \"08:00-12:30,13:30-17:00\"\n thu = \"08:00-12:30,13:30-17:00\"\n time_zone = \"America/New York\"\n tue = \"08:00-12:30,13:30-17:00\"\n wed = \"08:00-12:30,13:30-17:00\"\n }\n traffic = \"http.request.uri matches \\\".*a/partial/uri.*\\\" and http.request.host in $01302951-49f9-47c9-a400-0297e60b6a10\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"action","type":"String","description":"Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`."},{"name":"name","type":"String","description":"Specify the rule name."}],"optional":[{"name":"description","type":"String","description":"Specify the rule description."},{"name":"filters","type":"List[String]","description":"Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value."},{"name":"device_posture","type":"String","description":"Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"enabled","type":"Bool","description":"Specify whether the rule is enabled."},{"name":"identity","type":"String","description":"Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"precedence","type":"Int64","description":"Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform."},{"name":"traffic","type":"String","description":"Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response."},{"name":"expiration","type":"Attributes","description":"Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.","children":[{"name":"expires_at","type":"Time","description":"Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time."},{"name":"duration","type":"Int64","description":"Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule."},{"name":"expired","type":"Bool","description":"Indicates whether the policy is expired."}]},{"name":"rule_settings","type":"Attributes","description":"Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.","children":[{"name":"add_headers","type":"Map[List[String]]","description":"Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"allow_child_bypass","type":"Bool","description":"Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules."},{"name":"audit_ssh","type":"Attributes","description":"Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.","children":[{"name":"command_logging","type":"Bool","description":"Enable SSH command logging."}]},{"name":"biso_admin_controls","type":"Attributes","description":"Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.","children":[{"name":"copy","type":"String","description":"Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\"."},{"name":"dcp","type":"Bool","description":"Set to false to enable copy-pasting. Only applies when `version == \"v1\"`."},{"name":"dd","type":"Bool","description":"Set to false to enable downloading. Only applies when `version == \"v1\"`."},{"name":"dk","type":"Bool","description":"Set to false to enable keyboard usage. Only applies when `version == \"v1\"`."},{"name":"download","type":"String","description":"Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\"."},{"name":"dp","type":"Bool","description":"Set to false to enable printing. Only applies when `version == \"v1\"`."},{"name":"du","type":"Bool","description":"Set to false to enable uploading. Only applies when `version == \"v1\"`."},{"name":"keyboard","type":"String","description":"Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\"."},{"name":"paste","type":"String","description":"Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\"."},{"name":"printing","type":"String","description":"Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\"."},{"name":"upload","type":"String","description":"Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\"."},{"name":"version","type":"String","description":"Indicate which version of the browser isolation controls should apply."},{"name":"wm_id","type":"String","description":"Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser."}]},{"name":"block_page","type":"Attributes","description":"Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."}]},{"name":"block_page_enabled","type":"Bool","description":"Enable the custom block page. Settable only for `dns` rules with action `block`."},{"name":"block_reason","type":"String","description":"Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`."},{"name":"bypass_parent_rule","type":"Bool","description":"Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules."},{"name":"check_session","type":"Attributes","description":"Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.","children":[{"name":"duration","type":"String","description":"Sets the required session freshness threshold. The API returns a normalized version of this value."},{"name":"enforce","type":"Bool","description":"Enable session enforcement."}]},{"name":"delete_headers","type":"List[String]","description":"Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`."},{"name":"dns_resolvers","type":"Attributes","description":"Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"ipv4","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv4 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]},{"name":"ipv6","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"Specify the IPv6 address of the upstream resolver."},{"name":"port","type":"Int64","description":"Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified."},{"name":"route_through_private_network","type":"Bool","description":"Indicate whether to connect to this resolver over a private network. Must set when vnet_id set."},{"name":"vnet_id","type":"String","description":"Specify an optional virtual network for this resolver. Uses default virtual network id if omitted."}]}]},{"name":"egress","type":"Attributes","description":"Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.","children":[{"name":"ipv4","type":"String","description":"Specify the IPv4 address to use for egress."},{"name":"ipv4_fallback","type":"String","description":"Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs."},{"name":"ipv6","type":"String","description":"Specify the IPv6 range to use for egress."}]},{"name":"forensic_copy","type":"Attributes","description":"Configure whether a copy of the HTTP request will be sent to storage when the rule matches.","children":[{"name":"enabled","type":"Bool","description":"Enable sending the copy to storage."}]},{"name":"ignore_cname_category_matches","type":"Bool","description":"Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules."},{"name":"insecure_disable_dnssec_validation","type":"Bool","description":"Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules."},{"name":"ip_categories","type":"Bool","description":"Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules."},{"name":"ip_indicator_feeds","type":"Bool","description":"Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules."},{"name":"l4override","type":"Attributes","description":"Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.","children":[{"name":"ip","type":"String","description":"Defines the IPv4 or IPv6 address."},{"name":"port","type":"Int64","description":"Defines a port number to use for TCP/UDP overrides."}]},{"name":"notification_settings","type":"Attributes","description":"Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.","children":[{"name":"enabled","type":"Bool","description":"Enable notification."},{"name":"include_context","type":"Bool","description":"Indicates whether to pass the context information as query parameters."},{"name":"msg","type":"String","description":"Customize the message shown in the notification."},{"name":"support_url","type":"String","description":"Defines an optional URL to direct users to additional information. If unset, the notification opens a block page."}]},{"name":"override_host","type":"String","description":"Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"override_ips","type":"List[String]","description":"Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`."},{"name":"payload_log","type":"Attributes","description":"Configure DLP payload logging. Settable only for `http` rules.","children":[{"name":"enabled","type":"Bool","description":"Enable DLP payload logging for this rule."}]},{"name":"quarantine","type":"Attributes","description":"Configure settings that apply to quarantine rules. Settable only for `http` rules.","children":[{"name":"file_types","type":"List[String]","description":"Specify the types of files to sandbox."}]},{"name":"redirect","type":"Attributes","description":"Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.","children":[{"name":"target_uri","type":"String","description":"Specify the URI to which the user is redirected."},{"name":"include_context","type":"Bool","description":"Specify whether to pass the context information as query parameters."},{"name":"preserve_path_and_query","type":"Bool","description":"Specify whether to append the path and query parameters from the original request to target_uri."}]},{"name":"resolve_dns_internally","type":"Attributes","description":"Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.","children":[{"name":"fallback","type":"String","description":"Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries."},{"name":"view_id","type":"String","description":"Specify the internal DNS view identifier to pass to the internal DNS service."}]},{"name":"resolve_dns_through_cloudflare","type":"Bool","description":"Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules."},{"name":"set_headers","type":"Map[List[String]]","description":"Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`."},{"name":"untrusted_cert","type":"Attributes","description":"Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.","children":[{"name":"action","type":"String","description":"Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526."}]}]},{"name":"schedule","type":"Attributes","description":"Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.","children":[{"name":"fri","type":"String","description":"Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"mon","type":"String","description":"Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sat","type":"String","description":"Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"sun","type":"String","description":"Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"thu","type":"String","description":"Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"time_zone","type":"String","description":"Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location."},{"name":"tue","type":"String","description":"Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."},{"name":"wed","type":"String","description":"Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used."}]}],"computed":[{"name":"id","type":"String","description":"Identify the API resource with a UUID."},{"name":"created_at","type":"Time"},{"name":"deleted_at","type":"Time","description":"Indicate the date of deletion, if any."},{"name":"read_only","type":"Bool","description":"Indicate that this rule is shared via the Orgs API and read only."},{"name":"sharable","type":"Bool","description":"Indicate that this rule is sharable via the Orgs API."},{"name":"source_account","type":"String","description":"Provide the account tag of the account that created the rule."},{"name":"updated_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicate the version number of the rule(read-only)."},{"name":"warning_status","type":"String","description":"Indicate a warning for a misconfigured rule, if any."}]}]},"post /accounts/{}/hyperdrive/configs":{"operationId":"create-hyperdrive","declarations":[{"kind":"resource","name":"cloudflare_hyperdrive_config","stainlessResource":"hyperdrive.configs","methodName":"create","snippet":"resource \"cloudflare_hyperdrive_config\" \"example_hyperdrive_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example-hyperdrive\"\n origin = {\n database = \"postgres\"\n host = \"database.example.com\"\n password = \"password\"\n port = 5432\n scheme = \"postgres\"\n user = \"postgres\"\n }\n caching = {\n disabled = true\n max_age = 0\n stale_while_revalidate = 0\n }\n integration = {\n\n }\n mtls = {\n ca_certificate_id = \"00000000-0000-0000-0000-0000000000\"\n mtls_certificate_id = \"00000000-0000-0000-0000-0000000000\"\n sslmode = \"verify-full\"\n }\n origin_connection_limit = 60\n}\n","required":[{"name":"account_id","type":"String","description":"Define configurations using a unique string identifier.","requiresReplace":true},{"name":"name","type":"String","description":"The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API."}],"optional":[{"name":"integration","type":"unknown","requiresReplace":true},{"name":"origin_connection_limit","type":"Int64","description":"The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit.\n"},{"name":"caching","type":"Attributes","children":[{"name":"disabled","type":"Bool"},{"name":"max_age","type":"Int64"},{"name":"stale_while_revalidate","type":"Int64"}]},{"name":"mtls","type":"Attributes","description":"mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.","children":[{"name":"ca_certificate_id","type":"String","description":"Define CA certificate ID obtained after uploading CA cert."},{"name":"mtls_certificate_id","type":"String","description":"Define mTLS certificate ID obtained after uploading client cert."},{"name":"sslmode","type":"String","description":"PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate."}]},{"name":"origin","type":"Attributes","description":"Combines database connection fields with exactly one supported network location.","children":[{"name":"database","type":"String","description":"Set the name of your origin database."},{"name":"host","type":"String","description":"Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed."},{"name":"password","type":"String","description":"Set the password needed to access your origin database. The API never returns this write-only value.","sensitive":true},{"name":"port","type":"Int64","description":"Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified."},{"name":"scheme","type":"String","description":"Specifies the URL scheme used to connect to your origin database."},{"name":"user","type":"String","description":"Set the user of your origin database."},{"name":"access_client_id","type":"String","description":"Defines the Client ID of the Access token to use when connecting to the origin database."},{"name":"access_client_secret","type":"String","description":"Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.","sensitive":true},{"name":"service_id","type":"String","description":"The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database."}]}],"computed":[{"name":"id","type":"String","description":"Define configurations using a unique string identifier."},{"name":"created_on","type":"Time","description":"Defines the creation time of the Hyperdrive configuration."},{"name":"modified_on","type":"Time","description":"Defines the last modified time of the Hyperdrive configuration."},{"name":"restarted_on","type":"Time","description":"Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted."}]}]},"post /accounts/{}/iam/user_groups":{"operationId":"account-user-group-create","declarations":[{"kind":"resource","name":"cloudflare_user_group","stainlessResource":"iam.user_groups","methodName":"create","snippet":"resource \"cloudflare_user_group\" \"example_user_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My New User Group\"\n policies = [{\n access = \"allow\"\n permission_groups = [{\n id = \"c8fed203ed3043cba015a93ad1616f1f\"\n }, {\n id = \"82e64a83756745bbbb1c9c2701bf816b\"\n }]\n resource_groups = [{\n id = \"6d7f2f5f5b1d4a0e9081fdc98d432fd1\"\n }]\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"name","type":"String","description":"Name of the User group."}],"optional":[{"name":"policies","type":"List[Attributes]","description":"Policies attached to the User group","children":[{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Permission Group identifier tag."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A set of resource groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Resource Group identifier tag."}]}]}],"computed":[{"name":"id","type":"String","description":"User Group identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the user group"},{"name":"modified_on","type":"Time","description":"Last time the user group was modified."}]}]},"post /accounts/{}/iam/user_groups/{}/members":{"operationId":"account-user-group-member-create","declarations":[{"kind":"resource","name":"cloudflare_user_group_members","stainlessResource":"iam.user_groups.members","methodName":"create","snippet":"resource \"cloudflare_user_group_members\" \"example_user_group_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n members = [{\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n }]\n}\n","required":[{"name":"user_group_id","type":"String","description":"User Group identifier tag.","requiresReplace":true},{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"members","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"The identifier of an existing account Member."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"User Group identifier tag.","requiresReplace":true}]}]},"post /accounts/{}/images/v1/variants":{"operationId":"cloudflare-images-variants-create-a-variant","declarations":[{"kind":"resource","name":"cloudflare_image_variant","stainlessResource":"images.v1.variants","methodName":"create","snippet":"resource \"cloudflare_image_variant\" \"example_image_variant\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"hero\"\n options = {\n fit = \"scale-down\"\n height = 768\n metadata = \"none\"\n width = 1366\n }\n never_require_signed_urls = true\n}\n","required":[{"name":"id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"options","type":"Attributes","description":"Allows you to define image resizing sizes for different use cases.","children":[{"name":"fit","type":"String","description":"The fit property describes how the width and height dimensions should be interpreted."},{"name":"height","type":"Float64","description":"Maximum height in image pixels."},{"name":"metadata","type":"String","description":"What EXIF data should be preserved in the output image."},{"name":"width","type":"Float64","description":"Maximum width in image pixels."}]}],"optional":[{"name":"never_require_signed_urls","type":"Bool","description":"Indicates whether the variant can access an image without a signature, regardless of image access control."}],"computed":[{"name":"variant","type":"Attributes","children":[{"name":"id","type":"String"},{"name":"options","type":"Attributes","description":"Allows you to define image resizing sizes for different use cases.","children":[{"name":"fit","type":"String","description":"The fit property describes how the width and height dimensions should be interpreted."},{"name":"height","type":"Float64","description":"Maximum height in image pixels."},{"name":"metadata","type":"String","description":"What EXIF data should be preserved in the output image."},{"name":"width","type":"Float64","description":"Maximum width in image pixels."}]},{"name":"never_require_signed_urls","type":"Bool","description":"Indicates whether the variant can access an image without a signature, regardless of image access control."}]}]}]},"post /accounts/{}/infrastructure/targets":{"operationId":"infra-targets-post","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_infrastructure_target","stainlessResource":"zero_trust.access.infrastructure.targets","methodName":"create","snippet":"resource \"cloudflare_zero_trust_access_infrastructure_target\" \"example_zero_trust_access_infrastructure_target\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"infra-access-target\"\n ip = {\n ipv4 = {\n ip_addr = \"187.26.29.249\"\n virtual_network_id = \"c77b744e-acc8-428f-9257-6878c046ed55\"\n }\n ipv6 = {\n ip_addr = \"64c0:64e8:f0b4:8dbf:7104:72b0:ec8f:f5e0\"\n virtual_network_id = \"c77b744e-acc8-428f-9257-6878c046ed55\"\n }\n }\n tags = {\n foo = \"string\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier","requiresReplace":true},{"name":"hostname","type":"String","description":"A non-unique field that refers to a target. Case insensitive, maximum\nlength of 255 characters, supports the use of special characters dash\nand period, does not support spaces, and must start and end with an\nalphanumeric character."},{"name":"ip","type":"Attributes","description":"The IPv4/IPv6 address that identifies where to reach a target","children":[{"name":"ipv4","type":"Attributes","description":"The target's IPv4 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]},{"name":"ipv6","type":"Attributes","description":"The target's IPv6 address","children":[{"name":"ip_addr","type":"String","description":"IP address of the target"},{"name":"virtual_network_id","type":"String","description":"(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used."}]}]}],"optional":[{"name":"tags","type":"Map[String]","description":"Optional tags to associate with the target. Keys and values are\nuser-defined strings."}],"computed":[{"name":"id","type":"String","description":"Target identifier"},{"name":"created_at","type":"Time","description":"Date and time at which the target was created"},{"name":"modified_at","type":"Time","description":"Date and time at which the target was modified"}]}]},"post /accounts/{}/load_balancers/monitor_groups":{"operationId":"account-load-balancer-monitor-groups-create-monitor-group","declarations":[{"kind":"resource","name":"cloudflare_load_balancer_monitor_group","stainlessResource":"load_balancers.monitor_groups","methodName":"create","snippet":"resource \"cloudflare_load_balancer_monitor_group\" \"example_load_balancer_monitor_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n description = \"Primary datacenter monitors\"\n members = [{\n enabled = true\n monitor_id = \"monitor_id\"\n monitoring_only = false\n must_be_healthy = true\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"description","type":"String","description":"A short description of the monitor group"},{"name":"members","type":"Set[Attributes]","description":"List of monitors in this group","children":[{"name":"enabled","type":"Bool","description":"Whether this monitor is enabled in the group"},{"name":"monitor_id","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitoring_only","type":"Bool","description":"Whether this monitor is used for monitoring only (does not affect pool health)"},{"name":"must_be_healthy","type":"Bool","description":"Whether this monitor must be healthy for the pool to be considered healthy"},{"name":"created_at","type":"Time","description":"The timestamp of when the monitor was added to the group"},{"name":"updated_at","type":"Time","description":"The timestamp of when the monitor group member was last updated"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"created_on","type":"Time","description":"The timestamp of when the monitor group was created"},{"name":"modified_on","type":"Time","description":"The timestamp of when the monitor group was last updated"}]}]},"post /accounts/{}/load_balancers/monitors":{"operationId":"account-load-balancer-monitors-create-monitor","declarations":[{"kind":"resource","name":"cloudflare_load_balancer_monitor","stainlessResource":"load_balancers.monitors","methodName":"create","snippet":"resource \"cloudflare_load_balancer_monitor\" \"example_load_balancer_monitor\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n allow_insecure = true\n consecutive_down = 0\n consecutive_up = 0\n description = \"Login page monitor\"\n expected_body = \"alive\"\n expected_codes = \"2xx\"\n follow_redirects = true\n header = {\n Host = [\"example.com\"]\n X-App-ID = [\"abc123\"]\n }\n interval = 0\n method = \"GET\"\n path = \"/health\"\n port = 0\n probe_zone = \"example.com\"\n retries = 0\n timeout = 0\n type = \"https\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"consecutive_down","type":"Int64","description":"To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times."},{"name":"consecutive_up","type":"Int64","description":"To be marked healthy the monitored origin must pass this healthcheck N consecutive times."},{"name":"port","type":"Int64","description":"The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors."},{"name":"description","type":"String","description":"Object description."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"expected_codes","type":"String","description":"The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations."},{"name":"method","type":"String","description":"The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks."},{"name":"path","type":"String","description":"The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"probe_zone","type":"String","description":"Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'."}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}]},"post /accounts/{}/load_balancers/pools":{"operationId":"account-load-balancer-pools-create-pool","declarations":[{"kind":"resource","name":"cloudflare_load_balancer_pool","stainlessResource":"load_balancers.pools","methodName":"create","snippet":"resource \"cloudflare_load_balancer_pool\" \"example_load_balancer_pool\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"primary-dc-1\"\n origins = [{\n address = \"0.0.0.0\"\n enabled = true\n flatten_cname = true\n header = {\n host = [\"example.com\"]\n }\n name = \"app-server-1\"\n port = 0\n virtual_network_id = \"a5624d4e-044a-4ff0-b3e1-e2465353d4b4\"\n weight = 0.6\n }]\n description = \"Primary data center - Provider XYZ\"\n enabled = false\n latitude = 0\n load_shedding = {\n default_percent = 0\n default_policy = \"random\"\n session_percent = 0\n session_policy = \"hash\"\n }\n longitude = 0\n minimum_origins = 0\n monitor = \"monitor\"\n monitor_group = \"monitor_group\"\n notification_email = \"someone@example.com,sometwo@example.com\"\n notification_filter = {\n origin = {\n disable = true\n healthy = true\n }\n pool = {\n disable = true\n healthy = false\n }\n }\n origin_steering = {\n policy = \"random\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed."},{"name":"origins","type":"Set[Attributes]","description":"The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.","children":[{"name":"address","type":"String","description":"The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set."},{"name":"disabled_at","type":"Time","description":"This field shows up only if the origin is disabled. This field is set with the time the origin was disabled."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool."},{"name":"flatten_cname","type":"Bool","description":"Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting."},{"name":"header","type":"Attributes","description":"The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.","children":[{"name":"host","type":"List[String]","description":"The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin."}]},{"name":"name","type":"String","description":"A human-identifiable name for the origin."},{"name":"port","type":"Int64","description":"The port for upstream connections. A value of 0 means the default port for the protocol will be used."},{"name":"virtual_network_id","type":"String","description":"The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account."},{"name":"weight","type":"Float64","description":"The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections."}]}],"optional":[{"name":"latitude","type":"Float64","description":"The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set."},{"name":"longitude","type":"Float64","description":"The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set."},{"name":"monitor","type":"String","description":"The ID of the Monitor to use for checking the health of origins within this pool."},{"name":"monitor_group","type":"String","description":"The ID of the Monitor Group to use for checking the health of origins within this pool."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means every Cloudflare data center."},{"name":"health_sources","type":"List[String]","description":"A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions."},{"name":"description","type":"String","description":"A human-readable description of the pool."},{"name":"enabled","type":"Bool","description":"Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)."},{"name":"minimum_origins","type":"Int64","description":"The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool."},{"name":"notification_email","type":"String","description":"This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list."},{"name":"load_shedding","type":"Attributes","description":"Configures load shedding policies and percentages for the pool.","children":[{"name":"default_percent","type":"Float64","description":"The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity."},{"name":"default_policy","type":"String","description":"The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs."},{"name":"session_percent","type":"Float64","description":"The percent of existing sessions to shed from the pool, according to the session policy."},{"name":"session_policy","type":"String","description":"Only the hash policy is supported for existing sessions (to avoid exponential decay)."}]},{"name":"notification_filter","type":"Attributes","description":"Filter pool and origin health notifications by resource type or health status. Use null to reset.","children":[{"name":"origin","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]},{"name":"pool","type":"Attributes","description":"Filter options for a particular resource type (pool or origin). Use null to reset.","children":[{"name":"disable","type":"Bool","description":"If set true, disable notifications for this type of resource (pool or origin)."},{"name":"healthy","type":"Bool","description":"If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)."}]}]},{"name":"origin_steering","type":"Attributes","description":"Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.","children":[{"name":"policy","type":"String","description":"The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"String"},{"name":"disabled_at","type":"Time","description":"This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at."},{"name":"modified_on","type":"String"},{"name":"networks","type":"List[String]","description":"List of networks where Load Balancer or Pool is enabled."}]}]},"post /accounts/{}/magic/bgp/filter_profiles":{"operationId":"magic-bgp-create-filter-profile","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_bgp_filter_profile","stainlessResource":"magic_transit.bgp_filter_profiles","methodName":"create","snippet":"resource \"cloudflare_magic_wan_bgp_filter_profile\" \"example_magic_wan_bgp_filter_profile\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n match_action = \"allow\"\n name = \"Allowed On-Prem Imports\"\n targets = [\"10.0.0.0/8{8,32}\"]\n description = \"Allowed corporate subnets from on-premises\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"match_action","type":"String","description":"Action to take when a route matches one of the targets in this profile"},{"name":"name","type":"String","description":"Friendly name for the filter profile"},{"name":"targets","type":"List[String]","description":"List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N."}],"optional":[{"name":"description","type":"String","description":"Description of the filter profile"}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]},"post /accounts/{}/magic/cf1_sites":{"operationId":"magic-cf1-sites-create-cf1-sites","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_cf1_site","stainlessResource":"magic_transit.cf1_sites","methodName":"create","snippet":"resource \"cloudflare_magic_transit_cf1_site\" \"example_magic_transit_cf1_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n body = [{\n name = \"Pad 34\"\n description = \"Launch Pad 34\"\n location = {\n lat = 28.521339842093845\n long = -80.56092644815843\n name = \"Cape Canaveral\"\n }\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"body","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]},{"name":"modified_on","type":"Time"}]}],"optional":[{"name":"description","type":"String","description":"A human-provided description of the CF1 Site."},{"name":"name","type":"String","description":"A human-provided name describing the CF1 Site that should be unique within the account."},{"name":"location","type":"Attributes","children":[{"name":"lat","type":"Float64","description":"Latitude of the CF1 Site."},{"name":"long","type":"Float64","description":"Longitude of the CF1 Site."},{"name":"name","type":"String","description":"Name of nearest town, city, or village."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]},"post /accounts/{}/magic/connectors":{"operationId":"mconn-connectors-create","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_connector","stainlessResource":"magic_transit.connectors","methodName":"create","snippet":"resource \"cloudflare_magic_transit_connector\" \"example_magic_transit_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n device = {\n id = \"id\"\n provision_license = true\n serial_number = \"serial_number\"\n }\n activated = true\n interrupt_window_days_of_week = [\"Sunday\"]\n interrupt_window_duration_hours = 1\n interrupt_window_embargo_dates = [\"string\"]\n interrupt_window_hour_of_day = 0\n notes = \"notes\"\n timezone = \"timezone\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"device","type":"Attributes","description":"Exactly one of id, serial_number, or provision_license must be provided.","requiresReplace":true,"children":[{"name":"id","type":"String"},{"name":"provision_license","type":"Bool","description":"When true, create and provision a new licence key for the connector."},{"name":"serial_number","type":"String"}]}],"optional":[{"name":"provision_license","type":"Bool","description":"When true, regenerate license key for the connector."},{"name":"activated","type":"Bool"},{"name":"interrupt_window_duration_hours","type":"Float64"},{"name":"interrupt_window_hour_of_day","type":"Float64"},{"name":"notes","type":"String"},{"name":"timezone","type":"String"},{"name":"interrupt_window_days_of_week","type":"List[String]","description":"Allowed days of the week for upgrades. Default is all days."},{"name":"interrupt_window_embargo_dates","type":"List[String]","description":"List of dates (YYYY-MM-DD) when upgrades are blocked."}],"computed":[{"name":"id","type":"String"},{"name":"last_heartbeat","type":"String"},{"name":"last_seen_version","type":"String"},{"name":"last_updated","type":"String"},{"name":"license_key","type":"String"}]}]},"post /accounts/{}/magic/gre_tunnels":{"operationId":"magic-gre-tunnels-create-gre-tunnels","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_gre_tunnel","stainlessResource":"magic_transit.gre_tunnels","methodName":"create","snippet":"resource \"cloudflare_magic_wan_gre_tunnel\" \"example_magic_wan_gre_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cloudflare_gre_endpoint = \"203.0.113.1\"\n customer_gre_endpoint = \"203.0.113.1\"\n interface_address = \"192.0.2.0/31\"\n name = \"GRE_1\"\n automatic_return_routing = true\n bgp = {\n customer_asn = 0\n export_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n extra_prefixes = [\"string\"]\n import_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n md5_key = \"md5_key\"\n }\n description = \"Tunnel for ISP X\"\n health_check = {\n direction = \"bidirectional\"\n enabled = true\n rate = \"low\"\n target = {\n saved = \"203.0.113.1\"\n }\n type = \"request\"\n }\n interface_address6 = \"2606:54c1:7:0:a9fe:12d2:1:200/127\"\n mtu = 0\n ttl = 0\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."}],"optional":[{"name":"bgp","type":"Attributes","requiresReplace":true,"children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"modified","type":"Bool"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"gre_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."}]},{"name":"modified_gre_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_gre_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the GRE tunnel."},{"name":"customer_gre_endpoint","type":"String","description":"The IP address assigned to the customer side of the GRE tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"description","type":"String","description":"An optional description of the GRE tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"mtu","type":"Int64","description":"Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576."},{"name":"ttl","type":"Int64","description":"Time To Live (TTL) in number of hops of the GRE tunnel."}]}]}]},"post /accounts/{}/magic/ipsec_tunnels":{"operationId":"magic-ipsec-tunnels-create-ipsec-tunnels","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_ipsec_tunnel","stainlessResource":"magic_transit.ipsec_tunnels","methodName":"create","snippet":"resource \"cloudflare_magic_wan_ipsec_tunnel\" \"example_magic_wan_ipsec_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cloudflare_endpoint = \"203.0.113.1\"\n interface_address = \"192.0.2.0/31\"\n name = \"IPsec_1\"\n automatic_return_routing = true\n bgp = {\n customer_asn = 0\n export_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n extra_prefixes = [\"string\"]\n import_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n md5_key = \"md5_key\"\n }\n custom_remote_identities = {\n fqdn_id = \"fqdn_id\"\n }\n customer_endpoint = \"203.0.113.1\"\n description = \"Tunnel for ISP X\"\n health_check = {\n direction = \"bidirectional\"\n enabled = true\n rate = \"low\"\n target = {\n saved = \"203.0.113.1\"\n }\n type = \"request\"\n }\n interface_address6 = \"2606:54c1:7:0:a9fe:12d2:1:200/127\"\n psk = \"O3bwKSjnaoCxDoUxjcq4Rk8ZKkezQUiy\"\n replay_protection = false\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."}],"optional":[{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"psk","type":"String","description":"A randomly generated or provided string for use in the IPsec tunnel.","sensitive":true},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"modified","type":"Bool"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"ipsec_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."}]},{"name":"modified_ipsec_tunnel","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"cloudflare_endpoint","type":"String","description":"The IP address assigned to the Cloudflare side of the IPsec tunnel."},{"name":"interface_address","type":"String","description":"A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255."},{"name":"name","type":"String","description":"The name of the IPsec tunnel. The name cannot share a name with other tunnels."},{"name":"allow_null_cipher","type":"Bool","description":"When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)."},{"name":"automatic_return_routing","type":"Bool","description":"True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected."},{"name":"bgp","type":"Attributes","children":[{"name":"customer_asn","type":"Int64","description":"ASN used on the customer end of the BGP session"},{"name":"export_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes advertised to the customer."},{"name":"extra_prefixes","type":"List[String]","description":"Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table."},{"name":"import_filter_id","type":"String","description":"ID of the BGP filter profile applied to routes received from the customer."},{"name":"md5_key","type":"String","description":"MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected."}]},{"name":"bgp_status","type":"Attributes","children":[{"name":"state","type":"String"},{"name":"tcp_established","type":"Bool"},{"name":"updated_at","type":"Time"},{"name":"bgp_state","type":"String"},{"name":"cf_speaker_ip","type":"String"},{"name":"cf_speaker_port","type":"Int64"},{"name":"customer_speaker_ip","type":"String"},{"name":"customer_speaker_port","type":"Int64"}]},{"name":"created_on","type":"Time","description":"The date and time the tunnel was created."},{"name":"custom_remote_identities","type":"Attributes","children":[{"name":"fqdn_id","type":"String","description":"A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint."}]},{"name":"customer_endpoint","type":"String","description":"The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work."},{"name":"description","type":"String","description":"An optional description forthe IPsec tunnel."},{"name":"health_check","type":"Attributes","children":[{"name":"direction","type":"String","description":"The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel."},{"name":"enabled","type":"Bool","description":"Determines whether to run healthchecks for a tunnel."},{"name":"rate","type":"String","description":"How frequent the health check is run. The default value is `mid`."},{"name":"target","type":"Attributes","description":"The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.","children":[{"name":"effective","type":"String","description":"The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests."},{"name":"saved","type":"String","description":"The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used."}]},{"name":"type","type":"String","description":"The type of healthcheck to run, reply or request. The default value is `reply`."}]},{"name":"interface_address6","type":"String","description":"A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127"},{"name":"modified_on","type":"Time","description":"The date and time the tunnel was last modified."},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]},{"name":"replay_protection","type":"Bool","description":"If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction."}]},{"name":"psk_metadata","type":"Attributes","description":"The PSK metadata that includes when the PSK was generated.","children":[{"name":"last_generated_on","type":"Time","description":"The date and time the tunnel was last modified."}]}]}]},"post /accounts/{}/magic/routes":{"operationId":"magic-static-routes-create-routes","declarations":[{"kind":"resource","name":"cloudflare_magic_wan_static_route","stainlessResource":"magic_transit.routes","methodName":"create","snippet":"resource \"cloudflare_magic_wan_static_route\" \"example_magic_wan_static_route\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n nexthop = \"203.0.113.1\"\n prefix = \"192.0.2.0/24\"\n priority = 0\n description = \"New route for new prefix 203.0.113.1\"\n scope = {\n colo_names = [\"den01\"]\n colo_regions = [\"APAC\"]\n }\n weight = 0\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."}],"optional":[{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"modified","type":"Bool"},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"modified_route","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."}]},{"name":"route","type":"Attributes","children":[{"name":"id","type":"String","description":"Identifier"},{"name":"nexthop","type":"String","description":"The next-hop IP Address for the static route."},{"name":"prefix","type":"String","description":"IP Prefix in Classless Inter-Domain Routing format."},{"name":"priority","type":"Int64","description":"Priority of the static route."},{"name":"created_on","type":"Time","description":"When the route was created."},{"name":"description","type":"String","description":"An optional human provided description of the static route."},{"name":"modified_on","type":"Time","description":"When the route was last modified."},{"name":"scope","type":"Attributes","description":"Used only for ECMP routes.","children":[{"name":"colo_names","type":"List[String]","description":"List of colo names for the ECMP scope."},{"name":"colo_regions","type":"List[String]","description":"List of colo regions for the ECMP scope."}]},{"name":"weight","type":"Int64","description":"Optional weight of the ECMP scope - if provided."}]}]}]},"post /accounts/{}/magic/sites":{"operationId":"magic-sites-create-site","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site","stainlessResource":"magic_transit.sites","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site\" \"example_magic_transit_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"site_1\"\n connector_id = \"ac60d3d0435248289d446cedd870bcf4\"\n description = \"description\"\n ha_mode = true\n location = {\n lat = \"37.6192\"\n lon = \"122.3816\"\n }\n secondary_connector_id = \"8d67040d3835dbcf46ce29da440dc482\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"name","type":"String","description":"The name of the site."}],"optional":[{"name":"connector_id","type":"String","description":"Magic Connector identifier tag."},{"name":"description","type":"String"},{"name":"ha_mode","type":"Bool","description":"Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode."},{"name":"secondary_connector_id","type":"String","description":"Magic Connector identifier tag. Used when high availability mode is on."},{"name":"location","type":"Attributes","description":"Location of site in latitude and longitude.","children":[{"name":"lat","type":"String","description":"Latitude"},{"name":"lon","type":"String","description":"Longitude"}]}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/magic/sites/{}/acls":{"operationId":"magic-site-acls-create-acl","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site_acl","stainlessResource":"magic_transit.sites.acls","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site_acl\" \"example_magic_transit_site_acl\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lan_1 = {\n lan_id = \"lan_id\"\n lan_name = \"lan_name\"\n port_ranges = [\"8080-9000\"]\n ports = [1]\n subnets = [\"192.0.2.1\"]\n }\n lan_2 = {\n lan_id = \"lan_id\"\n lan_name = \"lan_name\"\n port_ranges = [\"8080-9000\"]\n ports = [1]\n subnets = [\"192.0.2.1\"]\n }\n name = \"PIN Pad - Cash Register\"\n description = \"Allows local traffic between PIN pads and cash register.\"\n forward_locally = true\n protocols = [\"tcp\"]\n unidirectional = true\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"site_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"name","type":"String","description":"The name of the ACL."},{"name":"lan_1","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]},{"name":"lan_2","type":"Attributes","children":[{"name":"lan_id","type":"String","description":"The identifier for the LAN you want to create an ACL policy with."},{"name":"lan_name","type":"String","description":"The name of the LAN based on the provided lan_id."},{"name":"port_ranges","type":"List[String]","description":"Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed."},{"name":"ports","type":"List[Int64]","description":"Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed."},{"name":"subnets","type":"List[String]","description":"Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed."}]}],"optional":[{"name":"description","type":"String","description":"Description for the ACL."},{"name":"forward_locally","type":"Bool","description":"The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false."},{"name":"unidirectional","type":"Bool","description":"The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false."},{"name":"protocols","type":"List[String]"}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/magic/sites/{}/lans":{"operationId":"magic-site-lans-create-lan","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site_lan","stainlessResource":"magic_transit.sites.lans","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site_lan\" \"example_magic_transit_site_lan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bond_id = 2\n ha_link = true\n is_breakout = true\n is_prioritized = true\n name = \"name\"\n nat = {\n static_prefix = \"192.0.2.0/24\"\n }\n physport = 1\n routed_subnets = [{\n next_hop = \"192.0.2.1\"\n prefix = \"192.0.2.0/24\"\n nat = {\n static_prefix = \"192.0.2.0/24\"\n }\n }]\n static_addressing = {\n address = \"192.0.2.0/24\"\n dhcp_relay = {\n server_addresses = [\"192.0.2.1\"]\n }\n dhcp_server = {\n dhcp_options = [{\n code = 66\n type = \"ip\"\n value = \"10.20.30.40\"\n }]\n dhcp_pool_end = \"192.0.2.1\"\n dhcp_pool_start = \"192.0.2.1\"\n dns_server = \"192.0.2.1\"\n dns_servers = [\"192.0.2.1\"]\n reservations = {\n \"00:11:22:33:44:55\" = \"192.0.2.100\"\n \"AA:BB:CC:DD:EE:FF\" = \"192.168.1.101\"\n }\n }\n secondary_address = \"192.0.2.0/24\"\n virtual_address = \"192.0.2.0/24\"\n }\n vlan_tag = 42\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"site_id","type":"String","description":"Identifier","requiresReplace":true}],"optional":[{"name":"bond_id","type":"Int64"},{"name":"ha_link","type":"Bool","description":"mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link."},{"name":"is_breakout","type":"Bool","description":"mark true to use this LAN for source-based breakout traffic"},{"name":"is_prioritized","type":"Bool","description":"mark true to use this LAN for source-based prioritized traffic"},{"name":"name","type":"String"},{"name":"physport","type":"Int64"},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"routed_subnets","type":"List[Attributes]","children":[{"name":"next_hop","type":"String","description":"A valid IPv4 address."},{"name":"prefix","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"nat","type":"Attributes","children":[{"name":"static_prefix","type":"String","description":"A valid CIDR notation representing an IP range."}]}]},{"name":"static_addressing","type":"Attributes","description":"If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"dhcp_relay","type":"Attributes","children":[{"name":"server_addresses","type":"List[String]","description":"List of DHCP server IPs."}]},{"name":"dhcp_server","type":"Attributes","children":[{"name":"dhcp_options","type":"List[Attributes]","description":"Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.","children":[{"name":"code","type":"Int64","description":"DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration."},{"name":"type","type":"String","description":"The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\n"},{"name":"value","type":"String","description":"The option value, interpreted according to the type field."}]},{"name":"dhcp_pool_end","type":"String","description":"A valid IPv4 address."},{"name":"dhcp_pool_start","type":"String","description":"A valid IPv4 address."},{"name":"dns_server","type":"String","description":"A valid IPv4 address.","deprecated":"Deprecated."},{"name":"dns_servers","type":"List[String]"},{"name":"reservations","type":"Map[String]","description":"Mapping of MAC addresses to IP addresses"}]},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"virtual_address","type":"String","description":"A valid CIDR notation representing an IP range."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/magic/sites/{}/wans":{"operationId":"magic-site-wans-create-wan","declarations":[{"kind":"resource","name":"cloudflare_magic_transit_site_wan","stainlessResource":"magic_transit.sites.wans","methodName":"create","snippet":"resource \"cloudflare_magic_transit_site_wan\" \"example_magic_transit_site_wan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n physport = 1\n health_check_rate = \"low\"\n load_balance_inner_flows = true\n name = \"name\"\n priority = 0\n static_addressing = {\n address = \"192.0.2.0/24\"\n gateway_address = \"192.0.2.1\"\n secondary_address = \"192.0.2.0/24\"\n }\n vlan_tag = 42\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"site_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"physport","type":"Int64"}],"optional":[{"name":"name","type":"String"},{"name":"priority","type":"Int64"},{"name":"vlan_tag","type":"Int64","description":"VLAN ID. Use zero for untagged."},{"name":"static_addressing","type":"Attributes","description":"(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.","children":[{"name":"address","type":"String","description":"A valid CIDR notation representing an IP range."},{"name":"gateway_address","type":"String","description":"A valid IPv4 address."},{"name":"secondary_address","type":"String","description":"A valid CIDR notation representing an IP range."}]},{"name":"health_check_rate","type":"String","description":"Magic WAN health check rate for tunnels created on this link. The default value is `mid`."},{"name":"load_balance_inner_flows","type":"Bool"}],"computed":[{"name":"id","type":"String","description":"Identifier"}]}]},"post /accounts/{}/members":{"operationId":"account-members-add-member","declarations":[{"kind":"resource","name":"cloudflare_account_member","stainlessResource":"accounts.members","methodName":"create","snippet":"resource \"cloudflare_account_member\" \"example_account_member\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"user@example.com\"\n roles = [\"3536bcfad5faccb999b47003c79917fb\"]\n status = \"accepted\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"email","type":"String","description":"The contact email address of the user.","requiresReplace":true}],"optional":[{"name":"status","type":"String","description":"Status of the member invitation. If not provided during creation, defaults to 'pending'.\nChanging from 'accepted' back to 'pending' will trigger a replacement of the member resource in Terraform.\n","requiresReplace":true},{"name":"roles","type":"List[String]","description":"Array of roles associated with this member."},{"name":"policies","type":"List[Attributes]","description":"Array of policies associated with this member.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"access","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the group."}]},{"name":"resource_groups","type":"List[Attributes]","description":"A list of resource groups that the policy applies to.","children":[{"name":"id","type":"String","description":"Identifier of the group."}]}]}],"computed":[{"name":"id","type":"String","description":"Membership identifier tag."},{"name":"user","type":"Attributes","description":"Details of the user associated to the membership.","children":[{"name":"email","type":"String","description":"The contact email address of the user."},{"name":"id","type":"String","description":"Identifier"},{"name":"first_name","type":"String","description":"User's first name"},{"name":"last_name","type":"String","description":"User's last name"},{"name":"two_factor_authentication_enabled","type":"Bool","description":"Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication."}]}]}]},"post /accounts/{}/mnm/config":{"operationId":"magic-network-monitoring-configuration-create-account-configuration","declarations":[{"kind":"resource","name":"cloudflare_magic_network_monitoring_configuration","stainlessResource":"magic_network_monitoring.configs","methodName":"create","snippet":"resource \"cloudflare_magic_network_monitoring_configuration\" \"example_magic_network_monitoring_configuration\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n default_sampling = 1\n name = \"cloudflare user\\'s account\"\n router_ips = [\"203.0.113.1\"]\n warp_devices = [{\n id = \"5360368d-b351-4791-abe1-93550dabd351\"\n name = \"My warp device\"\n router_ip = \"203.0.113.1\"\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The account name."}],"optional":[{"name":"router_ips","type":"List[String]"},{"name":"warp_devices","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for the warp device."},{"name":"name","type":"String","description":"Name of the warp device."},{"name":"router_ip","type":"String","description":"IPv4 CIDR of the router sourcing flow data associated with this warp device. Only /32 addresses are currently supported."}]},{"name":"default_sampling","type":"Float64","description":"Fallback sampling rate of flow messages being sent in packets per second. This should match the packet sampling rate configured on the router."}],"computed":[]}]},"post /accounts/{}/mnm/rules":{"operationId":"magic-network-monitoring-rules-create-rules","declarations":[{"kind":"resource","name":"cloudflare_magic_network_monitoring_rule","stainlessResource":"magic_network_monitoring.rules","methodName":"create","snippet":"resource \"cloudflare_magic_network_monitoring_rule\" \"example_magic_network_monitoring_rule\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n automatic_advertisement = true\n name = \"my_rule_1\"\n prefixes = [\"203.0.113.1/32\"]\n type = \"zscore\"\n bandwidth_threshold = 1000\n duration = \"1m\"\n packet_threshold = 10000\n prefix_match = \"exact\"\n zscore_sensitivity = \"high\"\n zscore_target = \"bits\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"automatic_advertisement","type":"Bool","description":"Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit."},{"name":"name","type":"String","description":"The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters."},{"name":"type","type":"String","description":"MNM rule type."},{"name":"prefixes","type":"List[String]"}],"optional":[{"name":"bandwidth_threshold","type":"Float64","description":"The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"packet_threshold","type":"Float64","description":"The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum."},{"name":"prefix_match","type":"String","description":"Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule."},{"name":"zscore_sensitivity","type":"String","description":"Level of sensitivity set for zscore rules."},{"name":"zscore_target","type":"String","description":"Target of the zscore rule analysis."},{"name":"duration","type":"String","description":"The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"]."}],"computed":[{"name":"id","type":"String","description":"The id of the rule. Must be unique."}]}]},"post /accounts/{}/moq/relays":{"operationId":"moq-relays-create","declarations":[{"kind":"resource","name":"cloudflare_moq_relay","stainlessResource":"moq.relays","methodName":"create","snippet":"resource \"cloudflare_moq_relay\" \"example_moq_relay\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production Live Stream\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Human-readable name for the relay."}],"optional":[{"name":"config","type":"Attributes","children":[{"name":"upstreams","type":"Attributes","description":"Upstreams are external MOQT server publishers that a relay falls back\nto when it has no local publisher for a requested namespace/track.\n","children":[{"name":"enabled","type":"Bool"},{"name":"upstreams","type":"List[Attributes]","description":"Ordered list of upstream MOQT server publishers. Each entry is an\nobject (not a bare string) so per-upstream configuration can be\nadded in the future without another breaking change.\n","children":[{"name":"url","type":"String","description":"Upstream MOQT server publisher URL. Must be an absolute URL with a\nhost and a scheme the relay can dial: moqt:// (raw QUIC) or https://\n(WebTransport). Validated on update (PUT); rejected with 21013.\n"}]}]}]}],"computed":[{"name":"id","type":"String","description":"Server-generated unique identifier (32 hex chars)."},{"name":"uid","type":"String","description":"Server-generated unique identifier (32 hex chars)."},{"name":"created","type":"Time"},{"name":"modified","type":"Time"},{"name":"status","type":"String","description":"\"connected\" when active, omitted otherwise."},{"name":"issuers","type":"List[Attributes]","description":"Token collection (discriminated union on `type`). On create this\nholds the auto-created default pair, each including its one-time\nsecret.\n","children":[{"name":"cloudflare_tokens","type":"List[Attributes]","description":"Always present ([] when empty).","children":[{"name":"created","type":"Time"},{"name":"expires","type":"Time","description":"Mandatory; no more than 1 year after `created`."},{"name":"jti","type":"String","description":"Token identity and registry key (32 hex chars)."},{"name":"operations","type":"List[String]","description":"Signed allowlist of what the token may do. V1 coarse roles; the array\nform extends to fine-grained MoQT message names later without a\nbreaking change.\n"},{"name":"label","type":"String","description":"Optional, customer-set."},{"name":"secret","type":"String","description":"The signed JWT. Present ONLY in create / auto-create responses (shown\nonce); never returned by list, never stored.\n","sensitive":true}]},{"name":"issuer","type":"String"},{"name":"type","type":"String"}]}]}]},"post /accounts/{}/oauth_clients":{"operationId":"oauth-clients-create","declarations":[{"kind":"resource","name":"cloudflare_oauth_client","stainlessResource":"iam.oauth_clients","methodName":"create","snippet":"resource \"cloudflare_oauth_client\" \"example_oauth_client\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n client_name = \"My OAuth App\"\n grant_types = [\"authorization_code\", \"refresh_token\"]\n redirect_uris = [\"https://example.com/callback\"]\n response_types = [\"code\"]\n scopes = [\"account.read\"]\n token_endpoint_auth_method = \"client_secret_post\"\n allowed_cors_origins = [\"https://example.com\"]\n client_uri = \"https://example.com\"\n logo_uri = \"https://example.com/logo.png\"\n optional_scopes = [\"account.write\"]\n policy_uri = \"https://example.com/privacy\"\n post_logout_redirect_uris = [\"https://example.com/logout\"]\n tos_uri = \"https://example.com/tos\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"client_name","type":"String","description":"Human-readable name of the OAuth client."},{"name":"token_endpoint_auth_method","type":"String","description":"The authentication method the client uses at the token endpoint."},{"name":"grant_types","type":"List[String]","description":"Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally."},{"name":"redirect_uris","type":"List[String]","description":"Array of allowed redirect URIs for the client."},{"name":"response_types","type":"List[String]","description":"Array of OAuth response types the client is allowed to use."},{"name":"scopes","type":"List[String]","description":"Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`."}],"optional":[{"name":"oauth_client_id","type":"String","description":"The unique identifier for an OAuth client.","requiresReplace":true},{"name":"client_uri","type":"String","description":"URL of the home page of the client."},{"name":"logo_uri","type":"String","description":"URL of the client's logo."},{"name":"policy_uri","type":"String","description":"URL that points to a privacy policy document."},{"name":"tos_uri","type":"String","description":"URL that points to a terms of service document."},{"name":"visibility","type":"String","description":"Promote the OAuth client from private to public visibility. Only `public` is accepted; demotion to `private` is not supported. Promotion requires a non-empty client name, logo URI, verified client URI host, and at least one non-identity scope."},{"name":"allowed_cors_origins","type":"List[String]","description":"Array of allowed CORS origins."},{"name":"optional_scopes","type":"List[String]","description":"Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional."},{"name":"post_logout_redirect_uris","type":"List[String]","description":"Array of allowed post-logout redirect URIs."}],"computed":[{"name":"client_id","type":"String","description":"The unique identifier for an OAuth client."},{"name":"client_secret","type":"String","description":"The client secret. This is the only time the secret is returned in a response.","sensitive":true},{"name":"created_at","type":"Time","description":"Timestamp when the OAuth client was created."},{"name":"has_rotated_secret","type":"Bool","description":"Indicates whether the client has a rotated secret that has not yet been deleted."},{"name":"promoted_at","type":"Time","description":"Timestamp when the OAuth client was promoted to public visibility."},{"name":"updated_at","type":"Time","description":"Timestamp when the OAuth client was last updated."},{"name":"client_uri_verification","type":"Attributes","description":"Client URI domain control verification state.","children":[{"name":"status","type":"String","description":"Current verification status for the client URI host."},{"name":"text","type":"String","description":"Exact TXT record value that must be added to DNS to prove ownership of the client URI host."}]}]}]},"post /accounts/{}/pages/projects":{"operationId":"pages-project-create-project","declarations":[{"kind":"resource","name":"cloudflare_pages_project","stainlessResource":"pages.projects","methodName":"create","snippet":"resource \"cloudflare_pages_project\" \"example_pages_project\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-pages-app\"\n production_branch = \"main\"\n build_config = {\n build_caching = true\n build_command = \"npm run build\"\n destination_dir = \"build\"\n root_dir = \"/\"\n web_analytics_tag = \"cee1c73f6e4743d0b5e6bb1a0bcaabcc\"\n web_analytics_token = \"021e1057c18547eca7b79f2516f06o7x\"\n }\n deployment_configs = {\n preview = {\n ai_bindings = {\n AI_BINDING = {\n project_id = \"some-project-id\"\n }\n }\n always_use_latest_compatibility_date = false\n analytics_engine_datasets = {\n ANALYTICS_ENGINE_BINDING = {\n dataset = \"api_analytics\"\n }\n }\n browsers = {\n BROWSER = {\n\n }\n }\n build_image_major_version = 3\n compatibility_date = \"2025-01-01T00:00:00Z\"\n compatibility_flags = [\"url_standard\"]\n d1_databases = {\n D1_BINDING = {\n id = \"445e2955-951a-43f8-a35b-a4d0c8138f63\"\n }\n }\n durable_object_namespaces = {\n DO_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n env_vars = {\n foo = {\n type = \"plain_text\"\n value = \"hello world\"\n }\n }\n fail_open = true\n hyperdrive_bindings = {\n HYPERDRIVE = {\n id = \"a76a99bc342644deb02c38d66082262a\"\n }\n }\n kv_namespaces = {\n KV_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n limits = {\n cpu_ms = 100\n }\n mtls_certificates = {\n MTLS = {\n certificate_id = \"d7cdd17c-916f-4cb7-aabe-585eb382ec4e\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n queue_producers = {\n QUEUE_PRODUCER_BINDING = {\n name = \"some-queue\"\n }\n }\n r2_buckets = {\n R2_BINDING = {\n name = \"some-bucket\"\n jurisdiction = \"eu\"\n }\n }\n services = {\n SERVICE_BINDING = {\n service = \"example-worker\"\n entrypoint = \"MyHandler\"\n environment = \"production\"\n }\n }\n usage_model = \"standard\"\n vectorize_bindings = {\n VECTORIZE = {\n index_name = \"my_index\"\n }\n }\n wrangler_config_hash = \"abc123def456\"\n }\n production = {\n ai_bindings = {\n AI_BINDING = {\n project_id = \"some-project-id\"\n }\n }\n always_use_latest_compatibility_date = false\n analytics_engine_datasets = {\n ANALYTICS_ENGINE_BINDING = {\n dataset = \"api_analytics\"\n }\n }\n browsers = {\n BROWSER = {\n\n }\n }\n build_image_major_version = 3\n compatibility_date = \"2025-01-01T00:00:00Z\"\n compatibility_flags = [\"url_standard\"]\n d1_databases = {\n D1_BINDING = {\n id = \"445e2955-951a-43f8-a35b-a4d0c8138f63\"\n }\n }\n durable_object_namespaces = {\n DO_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n env_vars = {\n foo = {\n type = \"plain_text\"\n value = \"hello world\"\n }\n }\n fail_open = true\n hyperdrive_bindings = {\n HYPERDRIVE = {\n id = \"a76a99bc342644deb02c38d66082262a\"\n }\n }\n kv_namespaces = {\n KV_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n limits = {\n cpu_ms = 100\n }\n mtls_certificates = {\n MTLS = {\n certificate_id = \"d7cdd17c-916f-4cb7-aabe-585eb382ec4e\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n queue_producers = {\n QUEUE_PRODUCER_BINDING = {\n name = \"some-queue\"\n }\n }\n r2_buckets = {\n R2_BINDING = {\n name = \"some-bucket\"\n jurisdiction = \"eu\"\n }\n }\n services = {\n SERVICE_BINDING = {\n service = \"example-worker\"\n entrypoint = \"MyHandler\"\n environment = \"production\"\n }\n }\n usage_model = \"standard\"\n vectorize_bindings = {\n VECTORIZE = {\n index_name = \"my_index\"\n }\n }\n wrangler_config_hash = \"abc123def456\"\n }\n }\n source = {\n config = {\n deployments_enabled = true\n owner = \"my-org\"\n owner_id = \"12345678\"\n path_excludes = [\"string\"]\n path_includes = [\"string\"]\n pr_comments_enabled = true\n preview_branch_excludes = [\"string\"]\n preview_branch_includes = [\"string\"]\n preview_deployment_setting = \"all\"\n production_branch = \"main\"\n production_deployments_enabled = true\n repo_id = \"12345678\"\n repo_name = \"my-repo\"\n }\n type = \"github\"\n }\n}\n","required":[{"name":"name","type":"String","description":"Name for the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"production_branch","type":"String","description":"Production branch of the project. Used to identify production deployments."}],"optional":[{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."},{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true}]},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"deployment_configs","type":"Attributes","description":"Configs for deployments in a project.","children":[{"name":"preview","type":"Attributes","description":"Configs for preview deploys.","children":[{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."},{"name":"environment","type":"String","description":"The Service environment."}]},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]},{"name":"production","type":"Attributes","description":"Configs for production deploys.","children":[{"name":"ai_bindings","type":"Map[Attributes]","description":"Constellation bindings used for Pages Functions.","children":[{"name":"project_id","type":"String"}]},{"name":"always_use_latest_compatibility_date","type":"Bool","description":"Whether to always use the latest compatibility date for Pages Functions."},{"name":"analytics_engine_datasets","type":"Map[Attributes]","description":"Analytics Engine bindings used for Pages Functions.","children":[{"name":"dataset","type":"String","description":"Name of the dataset."}]},{"name":"browsers","type":"Map[Attributes]","description":"Browser bindings used for Pages Functions."},{"name":"build_image_major_version","type":"Int64","description":"The major version of the build image to use for Pages Functions."},{"name":"compatibility_date","type":"String","description":"Compatibility date used for Pages Functions."},{"name":"compatibility_flags","type":"List[String]","description":"Compatibility flags used for Pages Functions."},{"name":"d1_databases","type":"Map[Attributes]","description":"D1 databases used for Pages Functions.","children":[{"name":"id","type":"String","description":"UUID of the D1 database."}]},{"name":"durable_object_namespaces","type":"Map[Attributes]","description":"Durable Object namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"fail_open","type":"Bool","description":"Whether to fail open when the deployment config cannot be applied."},{"name":"hyperdrive_bindings","type":"Map[Attributes]","description":"Hyperdrive bindings used for Pages Functions.","children":[{"name":"id","type":"String"}]},{"name":"kv_namespaces","type":"Map[Attributes]","description":"KV namespaces used for Pages Functions.","children":[{"name":"namespace_id","type":"String","description":"ID of the KV namespace."}]},{"name":"limits","type":"Attributes","description":"Limits for Pages Functions.","children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."}]},{"name":"mtls_certificates","type":"Map[Attributes]","description":"mTLS bindings used for Pages Functions.","children":[{"name":"certificate_id","type":"String"}]},{"name":"placement","type":"Attributes","description":"Placement setting used for Pages Functions.","children":[{"name":"mode","type":"String","description":"Placement mode."}]},{"name":"queue_producers","type":"Map[Attributes]","description":"Queue Producer bindings used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the Queue."}]},{"name":"r2_buckets","type":"Map[Attributes]","description":"R2 buckets used for Pages Functions.","children":[{"name":"name","type":"String","description":"Name of the R2 bucket."},{"name":"jurisdiction","type":"String","description":"Jurisdiction of the R2 bucket."}]},{"name":"services","type":"Map[Attributes]","description":"Services used for Pages Functions.","children":[{"name":"service","type":"String","description":"The Service name."},{"name":"entrypoint","type":"String","description":"The entrypoint to bind to."},{"name":"environment","type":"String","description":"The Service environment."}]},{"name":"usage_model","type":"String","description":"The usage model for Pages Functions.","deprecated":"All new projects now use the Standard usage model."},{"name":"vectorize_bindings","type":"Map[Attributes]","description":"Vectorize bindings used for Pages Functions.","children":[{"name":"index_name","type":"String"}]},{"name":"wrangler_config_hash","type":"String","description":"Hash of the Wrangler configuration used for the deployment."}]}]}],"computed":[{"name":"id","type":"String","description":"Name for the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens.","requiresReplace":true},{"name":"created_on","type":"Time","description":"When the project was created."},{"name":"framework","type":"String","description":"Framework the project is using."},{"name":"framework_version","type":"String","description":"Version of the framework the project is using."},{"name":"preview_script_name","type":"String","description":"Name of the preview script."},{"name":"production_script_name","type":"String","description":"Name of the production script."},{"name":"subdomain","type":"String","description":"The Cloudflare subdomain associated with the project."},{"name":"uses_functions","type":"Bool","description":"Whether the project uses functions."},{"name":"domains","type":"List[String]","description":"A list of associated custom domains for the project."},{"name":"canonical_deployment","type":"Attributes","description":"Most recent production deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]},{"name":"latest_deployment","type":"Attributes","description":"Most recent deployment of the project.","children":[{"name":"id","type":"String","description":"Id of the deployment."},{"name":"aliases","type":"List[String]","description":"A list of alias URLs pointing to this deployment."},{"name":"build_config","type":"Attributes","description":"Configs for the project build process.","children":[{"name":"web_analytics_tag","type":"String","description":"The classifying tag for analytics."},{"name":"web_analytics_token","type":"String","description":"The auth token for analytics.","sensitive":true},{"name":"build_caching","type":"Bool","description":"Enable build caching for the project."},{"name":"build_command","type":"String","description":"Command used to build project."},{"name":"destination_dir","type":"String","description":"Assets output directory of the build."},{"name":"root_dir","type":"String","description":"Directory to run the command."}]},{"name":"created_on","type":"Time","description":"When the deployment was created."},{"name":"deployment_trigger","type":"Attributes","description":"Info about what caused the deployment.","children":[{"name":"metadata","type":"Attributes","description":"Additional info about the trigger.","children":[{"name":"branch","type":"String","description":"Where the trigger happened."},{"name":"commit_dirty","type":"Bool","description":"Whether the deployment trigger commit was dirty."},{"name":"commit_hash","type":"String","description":"Hash of the deployment trigger commit."},{"name":"commit_message","type":"String","description":"Message of the deployment trigger commit."}]},{"name":"type","type":"String","description":"What caused the deployment."}]},{"name":"env_vars","type":"Map[Attributes]","description":"Environment variables used for builds and Pages Functions.","children":[{"name":"type","type":"String"},{"name":"value","type":"String","description":"Environment variable value.","sensitive":true}]},{"name":"environment","type":"String","description":"Type of deploy."},{"name":"is_skipped","type":"Bool","description":"Whether the deployment was skipped."},{"name":"latest_stage","type":"Attributes","description":"The status of the deployment.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"modified_on","type":"Time","description":"When the deployment was last modified."},{"name":"project_id","type":"String","description":"Id of the project."},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens."},{"name":"short_id","type":"String","description":"Short Id (8 character) of the deployment."},{"name":"source","type":"Attributes","description":"Configs for the project source control.","children":[{"name":"config","type":"Attributes","children":[{"name":"deployments_enabled","type":"Bool","description":"Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.\n","deprecated":"Use `production_deployments_enabled` and `preview_deployment_setting` for more granular control."},{"name":"owner","type":"String","description":"The owner of the repository."},{"name":"owner_id","type":"String","description":"The owner ID of the repository."},{"name":"path_excludes","type":"List[String]","description":"A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"path_includes","type":"List[String]","description":"A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported."},{"name":"pr_comments_enabled","type":"Bool","description":"Whether to enable PR comments."},{"name":"preview_branch_excludes","type":"List[String]","description":"A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_branch_includes","type":"List[String]","description":"A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`."},{"name":"preview_deployment_setting","type":"String","description":"Controls whether commits to preview branches trigger a preview deployment."},{"name":"production_branch","type":"String","description":"The production branch of the repository."},{"name":"production_deployments_enabled","type":"Bool","description":"Whether to trigger a production deployment on commits to the production branch."},{"name":"repo_id","type":"String","description":"The ID of the repository."},{"name":"repo_name","type":"String","description":"The name of the repository."}]},{"name":"type","type":"String","description":"The source control management provider."}]},{"name":"stages","type":"List[Attributes]","description":"List of past stages.","children":[{"name":"ended_on","type":"Time","description":"When the stage ended."},{"name":"name","type":"String","description":"The current build stage."},{"name":"started_on","type":"Time","description":"When the stage started."},{"name":"status","type":"String","description":"State of the current stage."}]},{"name":"url","type":"String","description":"The live URL to view this deployment."},{"name":"skip_reason","type":"String","description":"Why the deployment was skipped."},{"name":"uses_functions","type":"Bool","description":"Whether the deployment uses functions."}]}]}]},"post /accounts/{}/pages/projects/{}/domains":{"operationId":"pages-domains-add-domain","declarations":[{"kind":"resource","name":"cloudflare_pages_domain","stainlessResource":"pages.projects.domains","methodName":"create","snippet":"resource \"cloudflare_pages_domain\" \"example_pages_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n name = \"example.com\"\n}\n","required":[{"name":"name","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"project_name","type":"String","description":"Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Fully qualified domain name for the Pages project, such as `example.com`.","requiresReplace":true},{"name":"certificate_authority","type":"String"},{"name":"created_on","type":"String"},{"name":"domain_id","type":"String"},{"name":"status","type":"String"},{"name":"zone_tag","type":"String"},{"name":"validation_data","type":"Attributes","children":[{"name":"method","type":"String"},{"name":"status","type":"String"},{"name":"error_message","type":"String"},{"name":"txt_name","type":"String"},{"name":"txt_value","type":"String"}]},{"name":"verification_data","type":"Attributes","children":[{"name":"status","type":"String"},{"name":"error_message","type":"String"}]}]}]},"post /accounts/{}/pipelines/v1/pipelines":{"operationId":"postV4AccountsByAccount_idPipelinesV1Pipelines","declarations":[{"kind":"resource","name":"cloudflare_pipeline","stainlessResource":"pipelines","methodName":"create_v1","snippet":"resource \"cloudflare_pipeline\" \"example_pipeline\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_pipeline\"\n sql = \"insert into sink select * from source;\"\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account.","requiresReplace":true},{"name":"name","type":"String","description":"Specifies the name of the Pipeline.","requiresReplace":true},{"name":"sql","type":"String","description":"Specifies SQL for the Pipeline processing flow.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Indicates a unique identifier for this pipeline.","requiresReplace":true},{"name":"created_at","type":"String"},{"name":"failure_reason","type":"String","description":"Indicates the reason for the failure of the Pipeline."},{"name":"modified_at","type":"String"},{"name":"status","type":"String","description":"Indicates the current status of the Pipeline."},{"name":"tables","type":"List[Attributes]","description":"List of streams and sinks used by this pipeline.","children":[{"name":"id","type":"String","description":"Unique identifier for the connection (stream or sink)."},{"name":"latest","type":"Int64","description":"Latest available version of the connection."},{"name":"name","type":"String","description":"Name of the connection."},{"name":"type","type":"String","description":"Type of the connection."},{"name":"version","type":"Int64","description":"Current version of the connection used by this pipeline."}]}]}]},"post /accounts/{}/pipelines/v1/sinks":{"operationId":"postV4AccountsByAccount_idPipelinesV1Sinks","declarations":[{"kind":"resource","name":"cloudflare_pipeline_sink","stainlessResource":"pipelines.sinks","methodName":"create","snippet":"resource \"cloudflare_pipeline_sink\" \"example_pipeline_sink\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_sink\"\n type = \"r2\"\n config = {\n account_id = \"account_id\"\n bucket = \"bucket\"\n credentials = {\n access_key_id = \"access_key_id\"\n secret_access_key = \"secret_access_key\"\n }\n file_naming = {\n prefix = \"prefix\"\n strategy = \"serial\"\n suffix = \"suffix\"\n }\n jurisdiction = \"jurisdiction\"\n partitioning = {\n time_pattern = \"year=%Y/month=%m/day=%d/hour=%H\"\n }\n path = \"path\"\n rolling_policy = {\n file_size_bytes = 0\n inactivity_seconds = 1\n interval_seconds = 1\n }\n }\n format = {\n type = \"json\"\n compression = \"uncompressed\"\n decimal_encoding = \"number\"\n timestamp_format = \"rfc3339\"\n unstructured = true\n }\n schema = {\n fields = [{\n type = \"int32\"\n metadata_key = \"metadata_key\"\n name = \"name\"\n required = true\n sql_name = \"sql_name\"\n }]\n inferred = true\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account.","requiresReplace":true},{"name":"name","type":"String","description":"Defines the name of the Sink.","requiresReplace":true},{"name":"type","type":"String","description":"Specifies the type of sink.","requiresReplace":true}],"optional":[{"name":"config","type":"Attributes","description":"Defines the configuration of the R2 Sink.","requiresReplace":true,"children":[{"name":"account_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"bucket","type":"String","description":"R2 Bucket to write to"},{"name":"credentials","type":"Attributes","children":[{"name":"access_key_id","type":"String","description":"Cloudflare Account ID for the bucket"},{"name":"secret_access_key","type":"String","description":"Cloudflare Account ID for the bucket","sensitive":true}]},{"name":"file_naming","type":"Attributes","description":"Controls filename prefix/suffix and strategy.","children":[{"name":"prefix","type":"String","description":"The prefix to use in file name. i.e prefix-.parquet"},{"name":"strategy","type":"String","description":"Filename generation strategy."},{"name":"suffix","type":"String","description":"This will overwrite the default file suffix. i.e .parquet, use with caution"}]},{"name":"jurisdiction","type":"String","description":"Jurisdiction this bucket is hosted in"},{"name":"partitioning","type":"Attributes","description":"Data-layout partitioning for sinks.","children":[{"name":"time_pattern","type":"String","description":"The pattern of the date string"}]},{"name":"path","type":"String","description":"Subpath within the bucket to write to"},{"name":"rolling_policy","type":"Attributes","description":"Rolling policy for file sinks (when & why to close a file and open a new one).","children":[{"name":"file_size_bytes","type":"Int64","description":"Files will be rolled after reaching this number of bytes"},{"name":"inactivity_seconds","type":"Int64","description":"Number of seconds of inactivity to wait before rolling over to a new file"},{"name":"interval_seconds","type":"Int64","description":"Number of seconds to wait before rolling over to a new file"}]},{"name":"token","type":"String","description":"Authentication token","sensitive":true},{"name":"table_name","type":"String","description":"Table name"},{"name":"namespace","type":"String","description":"Table namespace"}]},{"name":"format","type":"Attributes","description":"Defines the output data format of a sink.","requiresReplace":true,"children":[{"name":"type","type":"String"},{"name":"compression","type":"String","description":"Specifies the compression applied to JSON sink output."},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","requiresReplace":true,"children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]}],"computed":[{"name":"id","type":"String","description":"Indicates a unique identifier for this sink.","requiresReplace":true},{"name":"created_at","type":"Time"},{"name":"modified_at","type":"Time"}]}]},"post /accounts/{}/pipelines/v1/streams":{"operationId":"postV4AccountsByAccount_idPipelinesV1Streams","declarations":[{"kind":"resource","name":"cloudflare_pipeline_stream","stainlessResource":"pipelines.streams","methodName":"create","snippet":"resource \"cloudflare_pipeline_stream\" \"example_pipeline_stream\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_stream\"\n format = {\n type = \"json\"\n decimal_encoding = \"number\"\n timestamp_format = \"rfc3339\"\n unstructured = true\n }\n http = {\n authentication = false\n enabled = true\n cors = {\n origins = [\"string\"]\n }\n }\n schema = {\n fields = [{\n type = \"int32\"\n metadata_key = \"metadata_key\"\n name = \"name\"\n required = true\n sql_name = \"sql_name\"\n }]\n inferred = true\n }\n worker_binding = {\n enabled = true\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specifies the public ID of the account.","requiresReplace":true},{"name":"name","type":"String","description":"Specifies the name of the Stream.","requiresReplace":true}],"optional":[{"name":"format","type":"Attributes","description":"Defines the data format of the events.","requiresReplace":true,"children":[{"name":"type","type":"String"},{"name":"decimal_encoding","type":"String"},{"name":"timestamp_format","type":"String"},{"name":"unstructured","type":"Bool"},{"name":"compression","type":"String"},{"name":"row_group_bytes","type":"Int64"}]},{"name":"schema","type":"Attributes","description":"Defines the schema of the events in the data stream.","requiresReplace":true,"children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"type","type":"String"},{"name":"metadata_key","type":"String"},{"name":"name","type":"String"},{"name":"required","type":"Bool"},{"name":"sql_name","type":"String"},{"name":"unit","type":"String"}]},{"name":"inferred","type":"Bool"}]},{"name":"http","type":"Attributes","children":[{"name":"authentication","type":"Bool","description":"Indicates that authentication is required for the HTTP endpoint."},{"name":"enabled","type":"Bool","description":"Indicates that the HTTP endpoint is enabled."},{"name":"cors","type":"Attributes","description":"Specifies the CORS options for the HTTP endpoint.","children":[{"name":"origins","type":"List[String]"}]}]},{"name":"worker_binding","type":"Attributes","children":[{"name":"enabled","type":"Bool","description":"Indicates that the worker binding is enabled."}]}],"computed":[{"name":"id","type":"String","description":"Indicates a unique identifier for this stream."},{"name":"created_at","type":"Time"},{"name":"endpoint","type":"String","description":"Indicates the endpoint URL of this stream."},{"name":"modified_at","type":"Time"},{"name":"version","type":"Int64","description":"Indicates the current version of this stream."}]}]},"post /accounts/{}/queues":{"operationId":"queues-create","declarations":[{"kind":"resource","name":"cloudflare_queue","stainlessResource":"queues","methodName":"create","snippet":"resource \"cloudflare_queue\" \"example_queue\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_name = \"example-queue\"\n jurisdiction = \"eu\"\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"queue_name","type":"String"}],"optional":[{"name":"jurisdiction","type":"String"},{"name":"settings","type":"Attributes","children":[{"name":"delivery_delay","type":"Float64","description":"Number of seconds to delay delivery of all messages to consumers."},{"name":"delivery_paused","type":"Bool","description":"Indicates if message delivery to consumers is currently paused."},{"name":"message_retention_period","type":"Float64","description":"Number of seconds after which an unconsumed message will be delayed."}]}],"computed":[{"name":"id","type":"String"},{"name":"queue_id","type":"String"},{"name":"consumers_total_count","type":"Float64"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"},{"name":"producers_total_count","type":"Float64"},{"name":"consumers","type":"List[Attributes]","children":[{"name":"consumer_id","type":"String","description":"A Resource identifier."},{"name":"created_on","type":"Time"},{"name":"dead_letter_queue","type":"String","description":"Name of the dead letter queue, or empty string if not configured"},{"name":"queue_name","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]},{"name":"type","type":"String"}]},{"name":"producers","type":"List[Attributes]","children":[{"name":"script","type":"String"},{"name":"type","type":"String"},{"name":"bucket_name","type":"String"}]}]}]},"post /accounts/{}/queues/{}/consumers":{"operationId":"queues-create-consumer","declarations":[{"kind":"resource","name":"cloudflare_queue_consumer","stainlessResource":"queues.consumers","methodName":"create","snippet":"resource \"cloudflare_queue_consumer\" \"example_queue_consumer\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"my-consumer-worker\"\n type = \"worker\"\n dead_letter_queue = \"example-queue\"\n settings = {\n batch_size = 50\n max_concurrency = 10\n max_retries = 3\n max_wait_time_ms = 5000\n retry_delay = 10\n }\n}\n","required":[{"name":"account_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"queue_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"type","type":"String"}],"optional":[{"name":"consumer_id","type":"String","description":"A Resource identifier.","requiresReplace":true},{"name":"dead_letter_queue","type":"String"},{"name":"script_name","type":"String","description":"Name of a Worker"},{"name":"settings","type":"Attributes","children":[{"name":"batch_size","type":"Float64","description":"The maximum number of messages to include in a batch."},{"name":"max_concurrency","type":"Float64","description":"Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)."},{"name":"max_retries","type":"Float64","description":"The maximum number of retries"},{"name":"max_wait_time_ms","type":"Float64","description":"The number of milliseconds to wait for a batch to fill up before attempting to deliver it"},{"name":"retry_delay","type":"Float64","description":"The number of seconds to delay before making the message available for another attempt."},{"name":"visibility_timeout_ms","type":"Float64","description":"The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt."}]}],"computed":[{"name":"created_on","type":"Time"},{"name":"queue_name","type":"String"}]}]},"post /accounts/{}/r2-catalog/{}/enable":{"operationId":"enable-catalog","declarations":[{"kind":"resource","name":"cloudflare_r2_data_catalog","stainlessResource":"r2_data_catalog","methodName":"enable","snippet":"resource \"cloudflare_r2_data_catalog\" \"example_r2_data_catalog\" {\n account_id = \"0123456789abcdef0123456789abcdef\"\n bucket_name = \"my-data-bucket\"\n}\n","required":[{"name":"account_id","type":"String","description":"Use this to identify the account.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Specifies the R2 bucket name.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Use this to uniquely identify the activated catalog.","requiresReplace":true},{"name":"bucket","type":"String","description":"Specifies the associated R2 bucket name."},{"name":"credential_status","type":"String","description":"Shows the credential configuration status."},{"name":"name","type":"String","description":"Specifies the catalog name (generated from account and bucket name)."},{"name":"status","type":"String","description":"Indicates the status of the catalog."},{"name":"maintenance_config","type":"Attributes","description":"Configures maintenance for the catalog.","children":[{"name":"compaction","type":"Attributes","description":"Configures compaction for catalog maintenance.","children":[{"name":"state","type":"String","description":"Specifies the state of maintenance operations."},{"name":"target_size_mb","type":"String","description":"Sets the target file size for compaction in megabytes. Defaults to \"128\"."}]},{"name":"interval","type":"String","description":"Scheduling interval between normal table maintenance runs."},{"name":"snapshot_expiration","type":"Attributes","description":"Configures snapshot expiration settings.","children":[{"name":"max_snapshot_age","type":"String","description":"Specifies the maximum age for snapshots. The system deletes snapshots older than this age.\nFormat: where unit is d (days), h (hours), m (minutes), or s (seconds).\nExamples: \"7d\" (7 days), \"48h\" (48 hours), \"2880m\" (2,880 minutes).\nDefaults to \"7d\".\n"},{"name":"min_snapshots_to_keep","type":"Int64","description":"Specifies the minimum number of snapshots to retain. Defaults to 100."},{"name":"state","type":"String","description":"Specifies the state of maintenance operations."}]}]}]}]},"post /accounts/{}/r2/buckets":{"operationId":"r2-create-bucket","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket","stainlessResource":"r2.buckets","methodName":"create","snippet":"resource \"cloudflare_r2_bucket\" \"example_r2_bucket\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example-bucket\"\n location = \"apac\"\n storage_class = \"Standard\"\n}\n","required":[{"name":"name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true}],"optional":[{"name":"location","type":"String","description":"Location of the bucket.","requiresReplace":true},{"name":"storage_class","type":"String","description":"Storage class for newly uploaded objects, unless specified otherwise.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"creation_date","type":"String","description":"Creation timestamp."},{"name":"jurisdiction","type":"String","description":"Jurisdiction where objects in this bucket are guaranteed to be stored."}]}]},"post /accounts/{}/r2/buckets/{}/domains/custom":{"operationId":"r2-add-custom-domain","declarations":[{"kind":"resource","name":"cloudflare_r2_custom_domain","stainlessResource":"r2.buckets.domains.custom","methodName":"create","snippet":"resource \"cloudflare_r2_custom_domain\" \"example_r2_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n domain = \"prefix.example-domain.com\"\n enabled = true\n zone_id = \"36ca64a6d92827b8a6b90be344bb1bfd\"\n ciphers = [\"string\"]\n min_tls = \"1.0\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"domain","type":"String","description":"Name of the custom domain to be added.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Zone ID of the custom domain.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether to enable public bucket access at the custom domain. If undefined, the domain will be enabled."}],"optional":[{"name":"min_tls","type":"String","description":"Minimum TLS Version the custom domain will accept for incoming connections. If not set, defaults to 1.0."},{"name":"ciphers","type":"List[String]","description":"An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format."}],"computed":[{"name":"zone_name","type":"String","description":"Zone that the custom domain resides in."},{"name":"status","type":"Attributes","children":[{"name":"ownership","type":"String","description":"Ownership status of the domain."},{"name":"ssl","type":"String","description":"SSL certificate status."}]}]}]},"post /accounts/{}/resource-library/applications":{"operationId":"createResourceLibraryApplication","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_resource_library_application","stainlessResource":"zero_trust.resource_library.applications","methodName":"create","snippet":"resource \"cloudflare_zero_trust_resource_library_application\" \"example_zero_trust_resource_library_application\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostnames = [\"example.com\", \"foo.com\"]\n category_id = 12\n human_id = \"HR\"\n ip_subnets = [\"192.168.1.0/24\", \"2001:db8::/48\"]\n name = \"HR\"\n port_protocols = [\"tcp/80\", \"tcp/443\"]\n support_domains = [\"example.com\", \"foo.com\"]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"category_id","type":"Int64","description":"Returns the category ID.","requiresReplace":true},{"name":"human_id","type":"String","description":"Returns the human readable ID.","requiresReplace":true},{"name":"name","type":"String","description":"Returns the application name.","requiresReplace":true},{"name":"hostnames","type":"Set[String]","description":"Hostnames matched by the application."},{"name":"ip_subnets","type":"Set[String]","description":"IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128."},{"name":"port_protocols","type":"Set[String]","description":"Port and protocol pairs matched by the application."},{"name":"support_domains","type":"Set[String]","description":"Support domains matched by the application."}],"computed":[{"name":"id","type":"Int64","description":"Returns the application ID."},{"name":"application_confidence_score","type":"Float64","description":"Confidence score for the application. Returns -1 when no score is available."},{"name":"application_source","type":"String","description":"Returns the application source."},{"name":"application_type","type":"String","description":"Returns the application type."},{"name":"application_type_description","type":"String","description":"Returns the application type description."},{"name":"created_at","type":"String","description":"Returns the application creation time."},{"name":"gen_ai_score","type":"Float64","description":"GenAI score for the application. Returns -1 when no score is available."},{"name":"updated_at","type":"String","description":"Returns the application update time."},{"name":"version","type":"String","description":"Returns the application version."},{"name":"supported","type":"Set[String]","description":"Cloudflare products that support this application."},{"name":"application_score_composition","type":"unknown","description":"Returns the score composition breakdown for the application."}]}]},"post /accounts/{}/rules/lists":{"operationId":"lists-create-a-list","declarations":[{"kind":"resource","name":"cloudflare_list","stainlessResource":"rules.lists","methodName":"create","snippet":"resource \"cloudflare_list\" \"example_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"ip\"\n name = \"list1\"\n description = \"This is a note\"\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource.","requiresReplace":true},{"name":"kind","type":"String","description":"The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects).","requiresReplace":true},{"name":"name","type":"String","description":"An informative name for the list. Use this name in filter and rule expressions.","requiresReplace":true}],"optional":[{"name":"description","type":"String","description":"An informative summary of the list."}],"computed":[{"name":"id","type":"String","description":"The unique ID of the list."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"num_items","type":"Float64","description":"The number of items in the list."},{"name":"num_referencing_filters","type":"Float64","description":"The number of [filters](/api/resources/filters/) referencing the list."}]}]},"post /accounts/{}/rules/lists/{}/items":{"operationId":"lists-create-list-items","declarations":[{"kind":"resource","name":"cloudflare_list_item","stainlessResource":"rules.lists.items","methodName":"create","snippet":"resource \"cloudflare_list_item\" \"example_list_item\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n body = [{\n ip = \"10.0.0.1\"\n comment = \"Private IP address\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"The Account ID for this resource.","requiresReplace":true},{"name":"list_id","type":"String","description":"The unique ID of the list.","requiresReplace":true},{"name":"body","type":"List[Attributes]","children":[{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."}]}],"optional":[{"name":"item_id","type":"String","description":"Defines the unique ID of the item in the List.","requiresReplace":true}],"computed":[{"name":"asn","type":"Int64","description":"Defines a non-negative 32 bit integer."},{"name":"comment","type":"String","description":"Defines an informative summary of the list item."},{"name":"created_on","type":"String","description":"The RFC 3339 timestamp of when the list was created."},{"name":"id","type":"String","description":"Defines the unique ID of the item in the List."},{"name":"ip","type":"String","description":"An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR."},{"name":"modified_on","type":"String","description":"The RFC 3339 timestamp of when the list was last modified."},{"name":"operation_id","type":"String","description":"The unique operation ID of the asynchronous action."},{"name":"hostname","type":"Attributes","description":"Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).","children":[{"name":"url_hostname","type":"String"},{"name":"exclude_exact_hostname","type":"Bool","description":"Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains."}]},{"name":"redirect","type":"Attributes","description":"The definition of the redirect.","children":[{"name":"source_url","type":"String"},{"name":"target_url","type":"String"},{"name":"include_subdomains","type":"Bool"},{"name":"preserve_path_suffix","type":"Bool"},{"name":"preserve_query_string","type":"Bool"},{"name":"status_code","type":"Int64"},{"name":"subpath_matching","type":"Bool"}]}]}]},"post /accounts/{}/rum/site_info":{"operationId":"web-analytics-create-site","declarations":[{"kind":"resource","name":"cloudflare_web_analytics_site","stainlessResource":"rum.site_info","methodName":"create","snippet":"resource \"cloudflare_web_analytics_site\" \"example_web_analytics_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n auto_install = true\n host = \"example.com\"\n zone_tag = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"auto_install","type":"Bool","description":"If enabled, the JavaScript snippet is automatically injected for orange-clouded sites."},{"name":"enabled","type":"Bool","description":"Enables or disables RUM. This option can be used only when auto_install is set to true."},{"name":"host","type":"String","description":"The hostname to use for gray-clouded sites."},{"name":"lite","type":"Bool","description":"If enabled, the JavaScript snippet will not be injected for visitors from the EU."},{"name":"zone_tag","type":"String","description":"The zone identifier."}],"computed":[{"name":"id","type":"String","description":"The Web Analytics site identifier."},{"name":"site_tag","type":"String","description":"The Web Analytics site identifier."},{"name":"created","type":"Time"},{"name":"site_token","type":"String","description":"The Web Analytics site token."},{"name":"snippet","type":"String","description":"Encoded JavaScript snippet."},{"name":"rules","type":"List[Attributes]","description":"A list of rules.","children":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"host","type":"String","description":"The hostname the rule will be applied to."},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]","description":"The paths the rule will be applied to."},{"name":"priority","type":"Float64"}]},{"name":"ruleset","type":"Attributes","children":[{"name":"id","type":"String","description":"The Web Analytics ruleset identifier."},{"name":"enabled","type":"Bool","description":"Whether the ruleset is enabled."},{"name":"zone_name","type":"String"},{"name":"zone_tag","type":"String","description":"The zone identifier."}]}]}]},"post /accounts/{}/rum/v2/{}/rule":{"operationId":"web-analytics-create-rule","declarations":[{"kind":"resource","name":"cloudflare_web_analytics_rule","stainlessResource":"rum.rules","methodName":"create","snippet":"resource \"cloudflare_web_analytics_rule\" \"example_web_analytics_rule\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ruleset_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n host = \"example.com\"\n inclusive = true\n is_paused = false\n paths = [\"*\"]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"ruleset_id","type":"String","description":"The Web Analytics ruleset identifier.","requiresReplace":true}],"optional":[{"name":"host","type":"String"},{"name":"inclusive","type":"Bool","description":"Whether the rule includes or excludes traffic from being measured."},{"name":"is_paused","type":"Bool","description":"Whether the rule is paused or not."},{"name":"paths","type":"List[String]"}],"computed":[{"name":"id","type":"String","description":"The Web Analytics rule identifier."},{"name":"created","type":"Time"},{"name":"priority","type":"Float64"}]}]},"post /accounts/{}/secondary_dns/acls":{"operationId":"secondary-dns-(-acl)-create-acl","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_acl","stainlessResource":"dns.zone_transfers.acls","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_acl\" \"example_dns_zone_transfers_acl\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n ip_range = \"192.0.2.53/28\"\n name = \"my-acl-1\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"ip_range","type":"String","description":"Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively."},{"name":"name","type":"String","description":"The name of the acl."}],"optional":[],"computed":[{"name":"id","type":"String"}]}]},"post /accounts/{}/secondary_dns/peers":{"operationId":"secondary-dns-(-peer)-create-peer","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_peer","stainlessResource":"dns.zone_transfers.peers","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_peer\" \"example_dns_zone_transfers_peer\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n name = \"my-peer-1\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the peer."}],"optional":[{"name":"ip","type":"String","description":"IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to."},{"name":"ixfr_enable","type":"Bool","description":"Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones."},{"name":"port","type":"Float64","description":"DNS port of primary or secondary nameserver, depending on what zone this peer is linked to."},{"name":"tsig_id","type":"String","description":"TSIG authentication will be used for zone transfer if configured."}],"computed":[{"name":"id","type":"String"}]}]},"post /accounts/{}/secondary_dns/tsigs":{"operationId":"secondary-dns-(-tsig)-create-tsig","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_tsig","stainlessResource":"dns.zone_transfers.tsigs","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_tsig\" \"example_dns_zone_transfers_tsig\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n algo = \"hmac-sha512.\"\n name = \"tsig.customer.cf.\"\n secret = \"caf79a7804b04337c9c66ccd7bef9190a1e1679b5dd03d8aa10f7ad45e1a9dab92b417896c15d4d007c7c14194538d2a5d0feffdecc5a7f0e1c570cfa700837c\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"algo","type":"String","description":"TSIG algorithm."},{"name":"name","type":"String","description":"TSIG key name."},{"name":"secret","type":"String","description":"TSIG secret.","sensitive":true}],"optional":[],"computed":[{"name":"id","type":"String"}]}]},"post /accounts/{}/secrets_store/stores":{"operationId":"secrets-store-create","declarations":[{"kind":"resource","name":"cloudflare_secrets_store","stainlessResource":"secrets_store.stores","methodName":"create","snippet":"resource \"cloudflare_secrets_store\" \"example_secrets_store\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n name = \"service_x_keys\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the store.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Store Identifier.","requiresReplace":true},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."}]}]},"post /accounts/{}/secrets_store/stores/{}/secrets":{"operationId":"secrets-store-secret-create","declarations":[{"kind":"resource","name":"cloudflare_secrets_store_secret","stainlessResource":"secrets_store.stores.secrets","methodName":"create","snippet":"resource \"cloudflare_secrets_store_secret\" \"example_secrets_store_secret\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"store_id","type":"String","requiresReplace":true},{"name":"body","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"name","type":"String","description":"The name of the secret."},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."},{"name":"value","type":"String","description":"The value of the secret. Maximum 64 KiB (65,536 bytes). Note that this is 'write only' - the API never returns this value; it exists only to create or modify secrets.","sensitive":true},{"name":"comment","type":"String","description":"Freeform text describing the secret."}]}],"optional":[{"name":"comment","type":"String","description":"Freeform text describing the secret."},{"name":"value","type":"String","description":"The value of the secret. Maximum 64 KiB (65,536 bytes). Note that this is 'write only' - the API never returns this value; it exists only to create or modify secrets.","sensitive":true},{"name":"scopes","type":"List[String]","description":"The list of services that can use this secret."}],"computed":[{"name":"id","type":"String","description":"Secret identifier tag."},{"name":"created","type":"Time","description":"When the secret was created."},{"name":"modified","type":"Time","description":"When the secret was modified."},{"name":"name","type":"String","description":"The name of the secret."},{"name":"status","type":"String"}]}]},"post /accounts/{}/shares":{"operationId":"share-create","declarations":[{"kind":"resource","name":"cloudflare_share","stainlessResource":"resource_sharing","methodName":"create","snippet":"resource \"cloudflare_share\" \"example_share\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Shared WAF Managed Rule\"\n recipients = [{\n organization_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n recipient_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n }]\n resources = [{\n meta = {\n\n }\n resource_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_type = \"custom-ruleset\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier.","requiresReplace":true},{"name":"recipients","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"account_id","type":"String","description":"Deprecated alias for `recipient_account_id`. Use `recipient_account_id` instead.\nThe body field collided with the URL path parameter of the same name, which prevented SDK generators from distinguishing the source account (in the URL) from the recipient account (in the body). Both names will continue to be accepted until 2027-05-26 (see `x-sunset`).\n","deprecated":"This field has been renamed to `recipient_account_id`. Both names are accepted during the deprecation period."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"recipient_account_id","type":"String","description":"The account that will receive the share."}]},{"name":"resources","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"meta","type":"unknown","description":"Resource Metadata."},{"name":"resource_account_id","type":"String","description":"Account identifier."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_type","type":"String","description":"Resource Type."}]},{"name":"name","type":"String","description":"The name of the share."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Share identifier tag."},{"name":"account_name","type":"String","description":"The display name of an account."},{"name":"associated_recipient_count","type":"Int64","description":"The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"associating_recipient_count","type":"Int64","description":"The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"disassociated_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"disassociating_recipient_count","type":"Int64","description":"The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter."},{"name":"kind","type":"String"},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"organization_id","type":"String","description":"Organization identifier."},{"name":"status","type":"String"},{"name":"target_type","type":"String"}]}]},"post /accounts/{}/shares/{}/recipients":{"operationId":"share-recipient-create","declarations":[{"kind":"resource","name":"cloudflare_share_recipient","stainlessResource":"resource_sharing.recipients","methodName":"create","snippet":"resource \"cloudflare_share_recipient\" \"example_share_recipient\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n organization_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n recipient_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"share_id","type":"String","description":"Share identifier tag.","requiresReplace":true},{"name":"account_id","type":"String","description":"Deprecated alias for `recipient_account_id`. Use `recipient_account_id` instead.\nThe body field collided with the URL path parameter of the same name, which prevented SDK generators from distinguishing the source account (in the URL) from the recipient account (in the body). Both names will continue to be accepted until 2027-05-26 (see `x-sunset`).\n","deprecated":"This field has been renamed to `recipient_account_id`. Both names are accepted during the deprecation period.","requiresReplace":true}],"optional":[{"name":"organization_id","type":"String","description":"Organization identifier.","requiresReplace":true},{"name":"recipient_account_id","type":"String","description":"The account that will receive the share.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Share Recipient identifier tag.","requiresReplace":true},{"name":"association_status","type":"String","description":"The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\n"},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resources","type":"List[Attributes]","children":[{"name":"error","type":"String","description":"Share Recipient error message."},{"name":"resource_id","type":"String","description":"Share Resource identifier."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"terminal","type":"Bool","description":"Whether the error is terminal or will be continually retried."}]}]}]},"post /accounts/{}/shares/{}/resources":{"operationId":"share-resource-create","declarations":[{"kind":"resource","name":"cloudflare_share_resource","stainlessResource":"resource_sharing.resources","methodName":"create","snippet":"resource \"cloudflare_share_resource\" \"example_share_resource\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n meta = {\n\n }\n resource_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_type = \"custom-ruleset\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier.","requiresReplace":true},{"name":"share_id","type":"String","description":"Share identifier tag.","requiresReplace":true},{"name":"resource_account_id","type":"String","description":"Account identifier.","requiresReplace":true},{"name":"resource_id","type":"String","description":"Share Resource identifier.","requiresReplace":true},{"name":"resource_type","type":"String","description":"Resource Type.","requiresReplace":true},{"name":"meta","type":"unknown","description":"Resource Metadata."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Share Resource identifier."},{"name":"created","type":"Time","description":"When the share was created."},{"name":"modified","type":"Time","description":"When the share was modified."},{"name":"resource_version","type":"Int64","description":"Resource Version."},{"name":"status","type":"String","description":"Resource Status."}]}]},"post /accounts/{}/sso_connectors":{"operationId":"init-new-sso-connector","declarations":[{"kind":"resource","name":"cloudflare_sso_connector","stainlessResource":"iam.sso","methodName":"create","snippet":"resource \"cloudflare_sso_connector\" \"example_sso_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email_domain = \"example.com\"\n begin_verification = true\n use_fedramp_language = false\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"email_domain","type":"String","description":"Email domain of the new SSO connector","requiresReplace":true}],"optional":[{"name":"begin_verification","type":"Bool","description":"Begin the verification process after creation","requiresReplace":true},{"name":"enabled","type":"Bool","description":"SSO Connector enabled state"},{"name":"use_fedramp_language","type":"Bool","description":"Controls the display of FedRAMP language to the user during SSO login"}],"computed":[{"name":"id","type":"String","description":"SSO Connector identifier tag."},{"name":"created_on","type":"Time","description":"Timestamp for the creation of the SSO connector"},{"name":"updated_on","type":"Time","description":"Timestamp for the last update of the SSO connector"},{"name":"verification","type":"Attributes","children":[{"name":"code","type":"String","description":"DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership."},{"name":"status","type":"String","description":"The status of the verification code from the verification process."}]}]}]},"post /accounts/{}/storage/kv/namespaces":{"operationId":"workers-kv-namespace-create-a-namespace","declarations":[{"kind":"resource","name":"cloudflare_workers_kv_namespace","stainlessResource":"kv.namespaces","methodName":"create","snippet":"resource \"cloudflare_workers_kv_namespace\" \"example_workers_kv_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n title = \"My Own Namespace\"\n jurisdiction = \"eu\"\n}\n","required":[{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces.","requiresReplace":true},{"name":"title","type":"String","description":"Human-readable string name for a Workers KV namespace."}],"optional":[{"name":"jurisdiction","type":"String","description":"Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"ID of the Workers KV namespace."},{"name":"supports_url_encoding","type":"Bool","description":"True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"."}]}]},"post /accounts/{}/stream":{"operationId":"stream-videos-initiate-video-uploads-using-tus","declarations":[{"kind":"resource","name":"cloudflare_stream","stainlessResource":"stream","methodName":"create","snippet":"resource \"cloudflare_stream\" \"example_stream\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true},{"name":"creator","type":"String","description":"A user-defined identifier for the media creator."},{"name":"max_duration_seconds","type":"Int64","description":"The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown."},{"name":"scheduled_deletion","type":"Time","description":"Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time."},{"name":"uid","type":"String","description":"The unique identifier for the video. Can be used to verify the video being updated."},{"name":"upload_expiry","type":"Time","description":"The date and time when the video upload URL is no longer valid for direct user uploads."},{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin."},{"name":"public_details","type":"Attributes","description":"Public details for the video including title, share link, channel link, and logo.","children":[{"name":"channel_link","type":"String"},{"name":"logo","type":"String"},{"name":"share_link","type":"String"},{"name":"title","type":"String"}]},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing videos."},{"name":"require_signed_urls","type":"Bool","description":"Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video."},{"name":"thumbnail_timestamp_pct","type":"Float64","description":"The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video."}],"computed":[{"name":"clipped_from","type":"String","description":"The unique identifier of the source video this video was clipped from."},{"name":"created","type":"Time","description":"The date and time the media item was created."},{"name":"duration","type":"Float64","description":"The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready."},{"name":"live_input","type":"String","description":"The live input ID used to upload a video with Stream Live."},{"name":"max_size_bytes","type":"Int64","description":"The maximum size in bytes for the video upload."},{"name":"modified","type":"Time","description":"The date and time the media item was last modified."},{"name":"preview","type":"String","description":"The video's preview page URI. This field is omitted until encoding is complete."},{"name":"ready_to_stream","type":"Bool","description":"Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"ready_to_stream_at","type":"Time","description":"Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress."},{"name":"size","type":"Float64","description":"The size of the media item in bytes."},{"name":"thumbnail","type":"String","description":"The media item's thumbnail URI. This field is omitted until encoding is complete."},{"name":"uploaded","type":"Time","description":"The date and time the media item was uploaded."},{"name":"input","type":"Attributes","children":[{"name":"height","type":"Int64","description":"The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready."},{"name":"width","type":"Int64","description":"The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready."}]},{"name":"playback","type":"Attributes","children":[{"name":"dash","type":"String","description":"DASH Media Presentation Description for the video."},{"name":"hls","type":"String","description":"The HLS manifest for the video."}]},{"name":"status","type":"Attributes","description":"Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.","children":[{"name":"error_reason_code","type":"String","description":"Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use."},{"name":"error_reason_text","type":"String","description":"Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state."},{"name":"pct_complete","type":"String","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"state","type":"String","description":"Specifies the processing status for all quality levels for a video."}]},{"name":"watermark","type":"Attributes","children":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"name","type":"String","description":"A short description of the watermark profile."},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque."},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm."},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter."},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]}]},"post /accounts/{}/stream/{}/captions/{}/generate":{"operationId":"stream-subtitles/-captions-generate-caption-or-subtitle-for-language","declarations":[{"kind":"resource","name":"cloudflare_stream_caption_language","stainlessResource":"stream.captions.language","methodName":"create","snippet":"resource \"cloudflare_stream_caption_language\" \"example_stream_caption_language\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n language = \"tr\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true},{"name":"language","type":"String","description":"The language tag in BCP 47 format.","requiresReplace":true}],"optional":[{"name":"file","type":"String","description":"The WebVTT file containing the caption or subtitle content."}],"computed":[{"name":"generated","type":"Bool","description":"Whether the caption was generated via AI."},{"name":"label","type":"String","description":"The language label displayed in the native language to users."},{"name":"status","type":"String","description":"The status of a generated caption."}]}]},"post /accounts/{}/stream/{}/downloads":{"operationId":"stream-mp4-downloads-create-downloads","declarations":[{"kind":"resource","name":"cloudflare_stream_download","stainlessResource":"stream.downloads","methodName":"create","snippet":"resource \"cloudflare_stream_download\" \"example_stream_download\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"identifier","type":"String","description":"A Cloudflare-generated unique identifier for a media item.","requiresReplace":true}],"optional":[],"computed":[{"name":"audio","type":"Attributes","description":"The audio-only download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]},{"name":"default","type":"Attributes","description":"The default video download. Only present if this download type has been created.","children":[{"name":"percent_complete","type":"Float64","description":"Indicates the progress as a percentage between 0 and 100."},{"name":"status","type":"String","description":"The status of a generated download."},{"name":"url","type":"String","description":"The URL to access the generated download."}]}]}]},"post /accounts/{}/stream/keys":{"operationId":"stream-signing-keys-create-signing-keys","declarations":[{"kind":"resource","name":"cloudflare_stream_key","stainlessResource":"stream.keys","methodName":"create","snippet":"resource \"cloudflare_stream_key\" \"example_stream_key\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"created","type":"Time","description":"The date and time a signing key was created."},{"name":"jwk","type":"String","description":"The signing key in JWK format.","sensitive":true},{"name":"key_id","type":"String","description":"The unique identifier for the signing key."},{"name":"pem","type":"String","description":"The signing key in PEM format.","sensitive":true}]}]},"post /accounts/{}/stream/live_inputs":{"operationId":"stream-live-inputs-create-a-live-input","declarations":[{"kind":"resource","name":"cloudflare_stream_live_input","stainlessResource":"stream.live_inputs","methodName":"create","snippet":"resource \"cloudflare_stream_live_input\" \"example_stream_live_input\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n default_creator = \"defaultCreator\"\n delete_recording_after_days = 45\n enabled = true\n meta = {\n name = \"test stream 1\"\n }\n prefer_low_latency = true\n recording = {\n allowed_origins = [\"example.com\"]\n hide_live_viewer_count = false\n mode = \"off\"\n require_signed_urls = false\n timeout_seconds = 0\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"live_input_identifier","type":"String","description":"A unique identifier for a live input.","requiresReplace":true},{"name":"default_creator","type":"String","description":"Sets the creator ID asssociated with this live input."},{"name":"delete_recording_after_days","type":"Float64","description":"Indicates the number of days after which the live inputs recordings will be deleted. When a stream completes and the recording is ready, the value is used to calculate a scheduled deletion date for that recording. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion."},{"name":"meta","type":"unknown","description":"A user modifiable key-value store used to reference other systems of record for managing live inputs."},{"name":"enabled","type":"Bool","description":"Indicates whether the live input is enabled and can accept streams."},{"name":"prefer_low_latency","type":"Bool","description":"When enabled, the live stream is delivered using Low-Latency HLS (LL-HLS), reducing glass-to-glass latency for viewers at the cost of reduced player compatibility."},{"name":"recording","type":"Attributes","description":"Records the input to a Cloudflare Stream video. Behavior depends on the mode. In most cases, the video will initially be viewable as a live video and transition to on-demand after a condition is satisfied.","children":[{"name":"allowed_origins","type":"List[String]","description":"Lists the origins allowed to display videos created with this input. Enter allowed origin domains in an array and use `*` for wildcard subdomains. An empty array allows videos to be viewed on any origin."},{"name":"hide_live_viewer_count","type":"Bool","description":"Disables reporting the number of live viewers when this property is set to `true`."},{"name":"mode","type":"String","description":"Specifies the recording behavior for the live input. Set this value to `off` to prevent a recording. Set the value to `automatic` to begin a recording and transition to on-demand after Stream Live stops receiving input."},{"name":"require_signed_urls","type":"Bool","description":"Indicates if a video using the live input has the `requireSignedURLs` property set. Also enforces access controls on any video recording of the livestream with the live input."},{"name":"timeout_seconds","type":"Int64","description":"Determines the amount of time a live input configured in `automatic` mode should wait before a recording transitions from live to on-demand. `0` is recommended for most use cases and indicates the platform default should be used."}]}],"computed":[{"name":"created","type":"Time","description":"The date and time the live input was created."},{"name":"keys_rotated_at","type":"Time","description":"The date and time the live input keys were last rotated. Omitted for live inputs that have never had their keys rotated."},{"name":"modified","type":"Time","description":"The date and time the live input was last modified."},{"name":"status","type":"String","description":"The connection status of a live input."},{"name":"uid","type":"String","description":"A unique identifier for a live input."},{"name":"playback","type":"Attributes","description":"Details for playing a live input's broadcast using the HLS or DASH manifests. URLs reference the live input ID.","children":[{"name":"dash","type":"String","description":"The DASH manifest URL used to play live video, referencing the live input ID."},{"name":"hls","type":"String","description":"The HLS manifest URL used to play live video, referencing the live input ID."}]},{"name":"rtmps","type":"Attributes","description":"Details for streaming to an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use when streaming via RTMPS to a live input.","sensitive":true},{"name":"url","type":"String","description":"The RTMPS URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"rtmps_playback","type":"Attributes","description":"Details for playback from an live input using RTMPS.","children":[{"name":"stream_key","type":"String","description":"The secret key to use for playback via RTMPS.","sensitive":true},{"name":"url","type":"String","description":"The URL used to play live video over RTMPS.","sensitive":true}]},{"name":"srt","type":"Attributes","description":"Details for streaming to a live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use when streaming via SRT to a live input.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use when streaming via SRT."},{"name":"url","type":"String","description":"The SRT URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"srt_playback","type":"Attributes","description":"Details for playback from an live input using SRT.","children":[{"name":"passphrase","type":"String","description":"The secret key to use for playback via SRT.","sensitive":true},{"name":"stream_id","type":"String","description":"The identifier of the live input to use for playback via SRT."},{"name":"url","type":"String","description":"The URL used to play live video over SRT.","sensitive":true}]},{"name":"web_rtc","type":"Attributes","description":"Details for streaming to a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The WebRTC URL you provide to the broadcaster, which they stream live video to.","sensitive":true}]},{"name":"web_rtc_playback","type":"Attributes","description":"Details for playback from a live input using WebRTC.","children":[{"name":"url","type":"String","description":"The URL used to play live video over WebRTC.","sensitive":true}]}]}]},"post /accounts/{}/stream/watermarks":{"operationId":"stream-watermark-profile-create-watermark-profiles-via-basic-upload","declarations":[{"kind":"resource","name":"cloudflare_stream_watermark","stainlessResource":"stream.watermarks","methodName":"create","snippet":"resource \"cloudflare_stream_watermark\" \"example_stream_watermark\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Marketing Videos\"\n opacity = 0.75\n padding = 0.1\n position = \"center\"\n scale = 0.1\n url = \"https://example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"identifier","type":"String","description":"The unique identifier for a watermark profile.","requiresReplace":true},{"name":"url","type":"String","description":"URL of the watermark image to copy.","requiresReplace":true},{"name":"name","type":"String","description":"A short description of the watermark profile.","requiresReplace":true},{"name":"opacity","type":"Float64","description":"The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque.","requiresReplace":true},{"name":"padding","type":"Float64","description":"The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm.","requiresReplace":true},{"name":"position","type":"String","description":"The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter.","requiresReplace":true},{"name":"scale","type":"Float64","description":"The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video.","requiresReplace":true}],"computed":[{"name":"created","type":"Time","description":"The date and a time a watermark profile was created."},{"name":"downloaded_from","type":"String","description":"The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null."},{"name":"height","type":"Int64","description":"The height of the image in pixels."},{"name":"size","type":"Float64","description":"The size of the image in bytes."},{"name":"uid","type":"String","description":"The unique identifier for a watermark profile."},{"name":"width","type":"Int64","description":"The width of the image in pixels."}]}]},"post /accounts/{}/teamnet/routes":{"operationId":"tunnel-route-create-a-tunnel-route","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared_route","stainlessResource":"zero_trust.networks.routes","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared_route\" \"example_zero_trust_tunnel_cloudflared_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n network = \"172.16.0.0/16\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n comment = \"Example comment for this route.\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range connected by the route, in CIDR notation."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"optional":[{"name":"comment","type":"String","description":"Optional remark describing the route."},{"name":"virtual_network_id","type":"String","description":"UUID of the virtual network."}],"computed":[{"name":"id","type":"String","description":"UUID of the route."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."}]}]},"post /accounts/{}/teamnet/virtual_networks":{"operationId":"tunnel-virtual-network-create-a-virtual-network","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared_virtual_network","stainlessResource":"zero_trust.networks.virtual_networks","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared_virtual_network\" \"example_zero_trust_tunnel_cloudflared_virtual_network\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"us-east-1-vpc\"\n comment = \"Staging VPC for data science\"\n is_default = true\n is_default_network = false\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for the virtual network."}],"optional":[{"name":"is_default","type":"Bool","description":"If `true`, this virtual network is the default for the account.","deprecated":"Use the is_default_network property instead.","requiresReplace":true},{"name":"comment","type":"String","description":"Optional remark describing the virtual network."},{"name":"is_default_network","type":"Bool","description":"If `true`, this virtual network is the default for the account."}],"computed":[{"name":"id","type":"String","description":"UUID of the virtual network."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."}]}]},"post /accounts/{}/tokens":{"operationId":"account-api-tokens-create-token","declarations":[{"kind":"resource","name":"cloudflare_account_token","stainlessResource":"accounts.tokens","methodName":"create","snippet":"resource \"cloudflare_account_token\" \"example_account_token\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"readonly token\"\n policies = [{\n effect = \"allow\"\n permission_groups = [{\n id = \"c8fed203ed3043cba015a93ad1616f1f\"\n meta = {\n category = \"category\"\n deprecated = \"deprecated\"\n description = \"description\"\n editable = \"editable\"\n eol_at = \"2019-12-27T18:11:19.117Z\"\n label = \"load_balancer_admin\"\n scopes = \"com.cloudflare.api.account\"\n visibility = \"visibility\"\n }\n }, {\n id = \"82e64a83756745bbbb1c9c2701bf816b\"\n meta = {\n category = \"category\"\n deprecated = \"deprecated\"\n description = \"description\"\n editable = \"editable\"\n eol_at = \"2019-12-27T18:11:19.117Z\"\n label = \"fbm_user\"\n scopes = \"com.cloudflare.api.account\"\n visibility = \"visibility\"\n }\n }]\n resources = {\n \"com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43\" = \"*\"\n }\n }]\n condition = {\n request_ip = {\n in = [\"123.123.123.0/24\", \"2606:4700::/32\"]\n not_in = [\"123.123.123.100/24\", \"2606:4700:4700::/48\"]\n }\n }\n expires_on = \"2020-01-01T00:00:00Z\"\n not_before = \"2018-07-01T05:20:00Z\"\n}\n","required":[{"name":"account_id","type":"String","description":"Account identifier tag.","requiresReplace":true},{"name":"name","type":"String","description":"Token name."},{"name":"policies","type":"List[Attributes]","description":"List of access policies assigned to the token.","children":[{"name":"id","type":"String","description":"Policy identifier."},{"name":"effect","type":"String","description":"Allow or deny operations against the resources."},{"name":"permission_groups","type":"List[Attributes]","description":"A set of permission groups that are specified to the policy.","children":[{"name":"id","type":"String","description":"Identifier of the permission group."},{"name":"meta","type":"Attributes","description":"Attributes associated to the permission group.","children":[{"name":"category","type":"String","description":"A category used to group permission groups."},{"name":"deprecated","type":"String","description":"Indicates whether the permission group is deprecated."},{"name":"description","type":"String","description":"Additional information about the permission group."},{"name":"editable","type":"String","description":"Indicates whether the permission group can be edited."},{"name":"eol_at","type":"Time","description":"The planned end-of-life date and time, when provided."},{"name":"label","type":"String","description":"A label identifying the permission group."},{"name":"scopes","type":"String","description":"The scope associated with the permission group."},{"name":"visibility","type":"String","description":"Indicates the permission group's availability or visibility."}]},{"name":"name","type":"String","description":"Name of the permission group."}]},{"name":"resources","type":"Map[String]","description":"A list of resource names that the policy applies to."}]}],"optional":[{"name":"expires_on","type":"Time","description":"The expiration time on or after which the JWT MUST NOT be accepted for processing."},{"name":"not_before","type":"Time","description":"The time before which the token MUST NOT be accepted for processing."},{"name":"condition","type":"Attributes","children":[{"name":"request_ip","type":"Attributes","description":"Client IP restrictions.","children":[{"name":"in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."},{"name":"not_in","type":"List[String]","description":"List of IPv4/IPv6 CIDR addresses."}]}]},{"name":"status","type":"String","description":"Status of the token."}],"computed":[{"name":"id","type":"String","description":"Token identifier tag."},{"name":"creator_email_at_creation","type":"String","description":"The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available."},{"name":"issued_on","type":"Time","description":"The time on which the token was created."},{"name":"last_used_on","type":"Time","description":"Last time the token was used."},{"name":"modified_on","type":"Time","description":"Last time the token was modified."},{"name":"provisioner_id","type":"String","description":"The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable."},{"name":"provisioner_type","type":"String","description":"The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens."},{"name":"value","type":"String","description":"The token value.","sensitive":true}]}]},"post /accounts/{}/vuln_scanner/credential_sets":{"operationId":"create-credential-set","declarations":[{"kind":"resource","name":"cloudflare_vulnerability_scanner_credential_set","stainlessResource":"vulnerability_scanner.credential_sets","methodName":"create","snippet":"resource \"cloudflare_vulnerability_scanner_credential_set\" \"example_vulnerability_scanner_credential_set\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production API credentials\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Human-readable name."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Credential set identifier."}]}]},"post /accounts/{}/vuln_scanner/credential_sets/{}/credentials":{"operationId":"create-credential","declarations":[{"kind":"resource","name":"cloudflare_vulnerability_scanner_credential","stainlessResource":"vulnerability_scanner.credential_sets.credentials","methodName":"create","snippet":"resource \"cloudflare_vulnerability_scanner_credential\" \"example_vulnerability_scanner_credential\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n location = \"header\"\n location_name = \"Authorization\"\n name = \"Admin API key\"\n value = \"Bearer EXAMPLE_TOKEN\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"credential_set_id","type":"String","requiresReplace":true},{"name":"location","type":"String","description":"Where the credential is attached in outgoing requests."},{"name":"location_name","type":"String","description":"Name of the header or cookie where the credential is attached.\n"},{"name":"name","type":"String","description":"Human-readable name."},{"name":"value","type":"String","description":"The credential value (e.g. API key, session token). Write-only.\nNever returned in responses.\n","sensitive":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"Credential identifier."}]}]},"post /accounts/{}/vuln_scanner/target_environments":{"operationId":"create-target-environment","declarations":[{"kind":"resource","name":"cloudflare_vulnerability_scanner_target_environment","stainlessResource":"vulnerability_scanner.target_environments","methodName":"create","snippet":"resource \"cloudflare_vulnerability_scanner_target_environment\" \"example_vulnerability_scanner_target_environment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production Zone\"\n target = {\n type = \"zone\"\n zone_tag = \"d8e8fca2dc0f896fd7cb4cb0031ba249\"\n }\n description = \"Main production environment\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Human-readable name."},{"name":"target","type":"Attributes","description":"Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.\n","children":[{"name":"type","type":"String"},{"name":"zone_tag","type":"String","description":"Cloudflare zone tag. The zone must belong to the account.\n"}]}],"optional":[{"name":"description","type":"String","description":"Optional description."}],"computed":[{"name":"id","type":"String","description":"Target environment identifier."}]}]},"post /accounts/{}/warp_connector":{"operationId":"cloudflare-tunnel-create-a-warp-connector-tunnel","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_warp_connector","stainlessResource":"zero_trust.tunnels.warp_connector","methodName":"create","snippet":"resource \"cloudflare_zero_trust_tunnel_warp_connector\" \"example_zero_trust_tunnel_warp_connector\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"blog\"\n ha = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for a tunnel."}],"optional":[{"name":"ha","type":"Bool","description":"Indicates that the tunnel will be created to be highly available. If omitted, defaults to false.","requiresReplace":true},{"name":"tunnel_secret","type":"String","description":"Sets the password required to run a locally-managed tunnel. Must be at least 32 bytes and encoded as a base64 string.","sensitive":true}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel."},{"name":"account_tag","type":"String","description":"Cloudflare account ID"},{"name":"conns_active_at","type":"Time","description":"Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive."},{"name":"conns_inactive_at","type":"Time","description":"Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"status","type":"String","description":"The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge)."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"connections","type":"List[Attributes]","description":"The Cloudflare Tunnel connections between your origin and Cloudflare's edge.","deprecated":"This field will start returning an empty array. To fetch the connections of a given tunnel, please use the dedicated endpoint `/accounts/{account_id}/{tunnel_type}/{tunnel_id}/connections`","children":[{"name":"id","type":"String","description":"UUID of the Cloudflare Tunnel connection."},{"name":"client_id","type":"String","description":"UUID of the Cloudflare Tunnel connector."},{"name":"client_version","type":"String","description":"The cloudflared version used to establish this connection."},{"name":"colo_name","type":"String","description":"The Cloudflare data center used for this connection."},{"name":"is_pending_reconnect","type":"Bool","description":"Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.","deprecated":"This functionality has been removed. The is_pending_reconnect field will now always report false."},{"name":"opened_at","type":"Time","description":"Timestamp of when the connection was established."},{"name":"origin_ip","type":"String","description":"The public IP address of the host running cloudflared."},{"name":"uuid","type":"String","description":"UUID of the Cloudflare Tunnel connection."}]},{"name":"metadata","type":"unknown","description":"Metadata associated with the tunnel."}]}]},"post /accounts/{}/workers/dispatch/namespaces":{"operationId":"namespace-worker-create","declarations":[{"kind":"resource","name":"cloudflare_workers_for_platforms_dispatch_namespace","stainlessResource":"workers_for_platforms.dispatch.namespaces","methodName":"create","snippet":"resource \"cloudflare_workers_for_platforms_dispatch_namespace\" \"example_workers_for_platforms_dispatch_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-dispatch-namespace\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"name","type":"String","description":"The name of the dispatch namespace.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Name of the Workers for Platforms dispatch namespace.","requiresReplace":true},{"name":"namespace_name","type":"String","description":"Name of the Workers for Platforms dispatch namespace.","requiresReplace":true},{"name":"created_by","type":"String","description":"Identifier."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"modified_by","type":"String","description":"Identifier."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"namespace_id","type":"String","description":"API Resource UUID tag."},{"name":"script_count","type":"Int64","description":"The current number of scripts in this Dispatch Namespace."},{"name":"trusted_workers","type":"Bool","description":"Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"."}]}]},"post /accounts/{}/workers/scripts/{}/deployments":{"operationId":"worker-deployments-create-deployment","declarations":[{"kind":"resource","name":"cloudflare_workers_deployment","stainlessResource":"workers.scripts.deployments","methodName":"create","snippet":"resource \"cloudflare_workers_deployment\" \"example_workers_deployment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n strategy = \"percentage\"\n versions = [{\n percentage = 100\n version_id = \"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\"\n }]\n annotations = {\n workers_message = \"Deploy bug fix.\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"script_name","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"strategy","type":"String","requiresReplace":true},{"name":"versions","type":"List[Attributes]","description":"Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.","requiresReplace":true,"children":[{"name":"percentage","type":"Float64","description":"Percentage of traffic served by this version."},{"name":"version_id","type":"String","description":"Identifier of the Worker Version."}]}],"optional":[{"name":"annotations","type":"Attributes","requiresReplace":true,"children":[{"name":"workers_message","type":"String","description":"Human-readable message about the deployment. Truncated to 1000 bytes if longer."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the deployment."}]}],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"author_email","type":"String"},{"name":"created_on","type":"Time"},{"name":"source","type":"String"}]}]},"post /accounts/{}/workers/scripts/{}/subdomain":{"operationId":"worker-script-post-subdomain","declarations":[{"kind":"resource","name":"cloudflare_workers_script_subdomain","stainlessResource":"workers.scripts.subdomain","methodName":"create","snippet":"resource \"cloudflare_workers_script_subdomain\" \"example_workers_script_subdomain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n enabled = true\n previews_enabled = false\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"script_name","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether the Worker should be available on the workers.dev subdomain."}],"optional":[{"name":"previews_enabled","type":"Bool","description":"Whether the Worker's Preview URLs should be available on the workers.dev subdomain."}],"computed":[]}]},"post /accounts/{}/workers/workers":{"operationId":"createWorker","declarations":[{"kind":"resource","name":"cloudflare_worker","stainlessResource":"workers.beta.workers","methodName":"create","snippet":"resource \"cloudflare_worker\" \"example_worker\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-worker\"\n logpush = true\n observability = {\n enabled = true\n head_sampling_rate = 1\n issues = {\n enabled = true\n }\n logs = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n invocation_logs = true\n persist = true\n }\n redact_query_string = true\n traces = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n persist = true\n propagation_policy = \"authenticated\"\n }\n }\n previews_base_config = {\n cache_options = {\n enabled = true\n cross_version_cache = true\n }\n env = {\n MY_ENV_VAR = {\n type = \"plain_text\"\n }\n }\n limits = {\n cpu_ms = 50\n subrequests = 1000\n }\n logpush = true\n observability = {\n enabled = true\n head_sampling_rate = 1\n issues = {\n enabled = true\n }\n logs = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n invocation_logs = true\n persist = true\n }\n redact_query_string = true\n traces = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n persist = true\n propagation_policy = \"authenticated\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n tail_consumers = [{\n name = \"my-tail-consumer\"\n }]\n }\n subdomain = {\n enabled = true\n previews_enabled = true\n }\n tags = [\"my-team\", \"my-public-api\"]\n tail_consumers = [{\n name = \"my-tail-consumer\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"name","type":"String","description":"Name of the Worker."}],"optional":[{"name":"logpush","type":"Bool","description":"Whether logpush is enabled for the Worker."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"previews_base_config","type":"Attributes","description":"Template configuration used when creating new Previews for this Worker.","children":[{"name":"cache_options","type":"Attributes","description":"Cache options used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"env","type":"Map[Attributes]","description":"Bindings used when creating new Previews, keyed by binding name.","children":[{"name":"type","type":"String","description":"The kind of resource that the binding provides."}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime for newly created Previews.","children":[{"name":"cpu_ms","type":"Int64","description":"The amount of CPU time this Worker can use in milliseconds."},{"name":"subrequests","type":"Int64","description":"The number of subrequests this Worker can make per request."}]},{"name":"logpush","type":"Bool","description":"Whether logpush is enabled when creating new Previews."},{"name":"observability","type":"Attributes","description":"Observability settings used when creating new Previews.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Placement configuration used when creating new Previews.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from newly created Previews.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}]},{"name":"subdomain","type":"Attributes","description":"Subdomain settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether the *.workers.dev subdomain is enabled for the Worker."},{"name":"preview_url_suffix","type":"String","description":"Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain."},{"name":"previews_enabled","type":"Bool","description":"Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker."},{"name":"url","type":"String","description":"The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain."}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"Other Workers that should consume logs from the Worker.","children":[{"name":"name","type":"String","description":"Name of the consumer Worker."}]}],"computed":[{"name":"id","type":"String","description":"Immutable ID of the Worker."},{"name":"created_on","type":"Time","description":"When the Worker was created."},{"name":"deployed_on","type":"Time","description":"When the Worker's most recent deployment was created. `null` if the Worker has never been deployed."},{"name":"updated_on","type":"Time","description":"When the Worker was most recently updated."},{"name":"references","type":"Attributes","description":"Other resources that reference the Worker and depend on it existing.","children":[{"name":"dispatch_namespace_outbounds","type":"List[Attributes]","description":"Other Workers that reference the Worker as an outbound for a dispatch namespace.","children":[{"name":"namespace_id","type":"String","description":"ID of the dispatch namespace."},{"name":"namespace_name","type":"String","description":"Name of the dispatch namespace."},{"name":"worker_id","type":"String","description":"ID of the Worker using the dispatch namespace."},{"name":"worker_name","type":"String","description":"Name of the Worker using the dispatch namespace."}]},{"name":"domains","type":"List[Attributes]","description":"Custom domains connected to the Worker.","children":[{"name":"id","type":"String","description":"ID of the custom domain."},{"name":"certificate_id","type":"String","description":"ID of the TLS certificate issued for the custom domain."},{"name":"hostname","type":"String","description":"Full hostname of the custom domain, including the zone name."},{"name":"zone_id","type":"String","description":"ID of the zone."},{"name":"zone_name","type":"String","description":"Name of the zone."}]},{"name":"durable_objects","type":"List[Attributes]","description":"Other Workers that reference Durable Object classes implemented by the Worker.","children":[{"name":"namespace_id","type":"String","description":"ID of the Durable Object namespace being used."},{"name":"namespace_name","type":"String","description":"Name of the Durable Object namespace being used."},{"name":"worker_id","type":"String","description":"ID of the Worker using the Durable Object implementation."},{"name":"worker_name","type":"String","description":"Name of the Worker using the Durable Object implementation."}]},{"name":"queues","type":"List[Attributes]","description":"Queues that send messages to the Worker.","children":[{"name":"queue_consumer_id","type":"String","description":"ID of the queue consumer configuration."},{"name":"queue_id","type":"String","description":"ID of the queue."},{"name":"queue_name","type":"String","description":"Name of the queue."}]},{"name":"workers","type":"List[Attributes]","description":"Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).","children":[{"name":"id","type":"String","description":"ID of the referencing Worker."},{"name":"name","type":"String","description":"Name of the referencing Worker."}]}]}]}]},"post /accounts/{}/workers/workers/{}/versions":{"operationId":"createWorkerVersion","declarations":[{"kind":"resource","name":"cloudflare_worker_version","stainlessResource":"workers.beta.workers.versions","methodName":"create","snippet":"resource \"cloudflare_worker_version\" \"example_worker_version\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n annotations = {\n workers_message = \"Fixed bug.\"\n workers_tag = \"v1.0.1\"\n }\n assets = {\n config = {\n base_path = \"/docs/\"\n html_handling = \"auto-trailing-slash\"\n not_found_handling = \"404-page\"\n run_worker_first = []\n }\n jwt = \"jwt\"\n }\n bindings = [{\n name = \"MY_ENV_VAR\"\n text = \"my_data\"\n type = \"plain_text\"\n }]\n cache_options = {\n enabled = true\n cross_version_cache = true\n }\n compatibility_date = \"2021-01-01T00:00:00Z\"\n compatibility_flags = [\"nodejs_compat\"]\n containers = [{\n class_name = \"MyDurableObject\"\n }]\n exports = {\n Admin = {\n type = \"worker\"\n cache = {\n enabled = true\n }\n state = \"created\"\n }\n Counter = {\n storage = \"sqlite\"\n type = \"durable-object\"\n container = \"my-container\"\n state = \"created\"\n }\n OldCounter = {\n renamed_to = \"Counter\"\n state = \"renamed\"\n type = \"durable-object\"\n }\n default = {\n type = \"worker\"\n cache = {\n enabled = false\n }\n state = \"created\"\n }\n }\n limits = {\n cpu_ms = 50\n subrequests = 1000\n }\n main_module = \"index.js\"\n migrations = {\n deleted_classes = [\"string\"]\n new_classes = [\"string\"]\n new_sqlite_classes = [\"string\"]\n new_tag = \"v2\"\n old_tag = \"v1\"\n renamed_classes = [{\n from = \"from\"\n to = \"to\"\n }]\n transferred_classes = [{\n from = \"from\"\n from_script = \"from_script\"\n to = \"to\"\n }]\n }\n modules = [{\n content_base64 = \"ZXhwb3J0IGRlZmF1bHQgewogIGFzeW5jIGZldGNoKHJlcXVlc3QsIGVudiwgY3R4KSB7CiAgICByZXR1cm4gbmV3IFJlc3BvbnNlKCdIZWxsbyBXb3JsZCEnKQogIH0KfQ==\"\n content_type = \"application/javascript+module\"\n name = \"index.js\"\n }]\n package_dependencies = [{\n installed_version = \"4.17.22\"\n name = \"lodash\"\n package_json_version = \"^4.17.21\"\n }]\n placement = {\n mode = \"smart\"\n }\n usage_model = \"standard\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"worker_id","type":"String","description":"Identifier for the Worker, which can be ID or name.","requiresReplace":true}],"optional":[{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker.","requiresReplace":true},{"name":"main_module","type":"String","description":"The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler).","requiresReplace":true},{"name":"containers","type":"Set[Attributes]","description":"List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.","requiresReplace":true,"children":[{"name":"class_name","type":"String","description":"Select which Durable Object class should get this container attached."}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.\n","requiresReplace":true,"children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"migrations","type":"Attributes","description":"Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.","requiresReplace":true,"children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"new_tag","type":"String","description":"Tag to set as the latest migration tag."},{"name":"old_tag","type":"String","description":"Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]},{"name":"steps","type":"List[Attributes]","description":"Migrations to apply in order.","children":[{"name":"deleted_classes","type":"List[String]","description":"A list of classes to delete Durable Object namespaces from."},{"name":"new_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces from."},{"name":"new_sqlite_classes","type":"List[String]","description":"A list of classes to create Durable Object namespaces with SQLite from."},{"name":"renamed_classes","type":"List[Attributes]","description":"A list of classes with Durable Object namespaces that were renamed.","children":[{"name":"from","type":"String"},{"name":"to","type":"String"}]},{"name":"transferred_classes","type":"List[Attributes]","description":"A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.","children":[{"name":"from","type":"String"},{"name":"from_script","type":"String"},{"name":"to","type":"String"}]}]}]},{"name":"modules","type":"Set[Attributes]","description":"Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","requiresReplace":true,"children":[{"name":"content_base64","type":"String","description":"The base64-encoded module content."},{"name":"content_type","type":"String","description":"The content type of the module."},{"name":"name","type":"String","description":"The name of the module."}]},{"name":"package_dependencies","type":"List[Attributes]","description":"The list of npm packages that were installed and used when this Worker\nversion was built.\n","requiresReplace":true,"children":[{"name":"installed_version","type":"String","description":"The exact version that was resolved and installed by the package manager."},{"name":"name","type":"String","description":"The npm package name."},{"name":"package_json_version","type":"String","description":"The version constraint as written in package.json."}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","requiresReplace":true,"children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"usage_model","type":"String","description":"Usage model for the version.","deprecated":"Deprecated.","requiresReplace":true},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`.","requiresReplace":true},{"name":"annotations","type":"Attributes","description":"Metadata about the version.","requiresReplace":true,"children":[{"name":"workers_message","type":"String","description":"Human-readable message about the version. Truncated to 1000 bytes if longer."},{"name":"workers_tag","type":"String","description":"User-provided identifier for the version. Maximum 100 bytes."},{"name":"workers_triggered_by","type":"String","description":"Operation that triggered the creation of the version."}]},{"name":"assets","type":"Attributes","description":"Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.\n","requiresReplace":true,"children":[{"name":"config","type":"Attributes","description":"Configuration for assets within a Worker.","children":[{"name":"base_path","type":"String","description":"The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%."},{"name":"html_handling","type":"String","description":"Determines the redirects and rewrites of requests for HTML content."},{"name":"not_found_handling","type":"String","description":"Determines the response when a request does not match a static asset, and there is no Worker script."},{"name":"run_worker_first","type":"List[String]","description":"Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules."}]},{"name":"jwt","type":"String","description":"Token provided upon successful upload of all files from a registered manifest.","sensitive":true}]},{"name":"bindings","type":"List[Attributes]","description":"List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.","requiresReplace":true,"children":[{"name":"name","type":"String","description":"A JavaScript variable name for the binding."},{"name":"type","type":"String","description":"The kind of resource that the binding provides."},{"name":"instance_name","type":"String","description":"The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance."},{"name":"namespace","type":"String","description":"The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field."},{"name":"dataset","type":"String","description":"The name of the dataset to bind to."},{"name":"database_id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"id","type":"String","description":"Identifier of the D1 database to bind to."},{"name":"part","type":"String","description":"The name of the file containing the data content. Only accepted for `service worker syntax` Workers."},{"name":"outbound","type":"Attributes","description":"Outbound worker.","children":[{"name":"params","type":"List[Attributes]","description":"Pass information from the Dispatch Worker to the Outbound Worker through the parameters.","children":[{"name":"name","type":"String","description":"Name of the parameter."}]},{"name":"worker","type":"Attributes","description":"Outbound worker.","children":[{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the outbound worker."},{"name":"environment","type":"String","description":"Environment of the outbound worker."},{"name":"service","type":"String","description":"Name of the outbound worker."}]}]},{"name":"class_name","type":"String","description":"The exported class name of the Durable Object."},{"name":"dispatch_namespace","type":"String","description":"The dispatch namespace the Durable Object script belongs to."},{"name":"environment","type":"String","description":"The environment of the script_name to bind to."},{"name":"namespace_id","type":"String","description":"Namespace identifier tag."},{"name":"script_name","type":"String","description":"The script where the Durable Object is defined, if it is external to this Worker."},{"name":"old_name","type":"String","description":"The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions."},{"name":"version_id","type":"String","description":"Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version."},{"name":"json","type":"unknown","description":"JSON data to use."},{"name":"certificate_id","type":"String","description":"Identifier of the certificate to bind to."},{"name":"text","type":"String","description":"The text value to use.","sensitive":true},{"name":"pipeline","type":"String","description":"Name of the Pipeline to bind to."},{"name":"stream","type":"String","description":"ID of a K2 stream owned by the account deploying the Worker."},{"name":"queue_name","type":"String","description":"Name of the Queue to bind to."},{"name":"simple","type":"Attributes","description":"The rate limit configuration.","children":[{"name":"limit","type":"Float64","description":"The limit (requests per period)."},{"name":"period","type":"Int64","description":"The period in seconds."},{"name":"mitigation_timeout","type":"Int64","description":"Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero.\n"}]},{"name":"bucket_name","type":"String","description":"R2 bucket to bind to."},{"name":"jurisdiction","type":"String","description":"The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket."},{"name":"allowed_destination_addresses","type":"List[String]","description":"List of allowed destination addresses."},{"name":"allowed_sender_addresses","type":"List[String]","description":"List of allowed sender addresses."},{"name":"destination_address","type":"String","description":"Destination address for the email."},{"name":"service","type":"String","description":"Name of Worker to bind to."},{"name":"entrypoint","type":"String","description":"Entrypoint to invoke on the target Worker."},{"name":"index_name","type":"String","description":"Name of the Vectorize index to bind to."},{"name":"secret_name","type":"String","description":"Name of the secret in the store."},{"name":"store_id","type":"String","description":"ID of the store containing the secret."},{"name":"app_id","type":"String","description":"ID of the Flagship app to bind to for feature flag evaluation."},{"name":"algorithm","type":"unknown","description":"Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)."},{"name":"format","type":"String","description":"Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format)."},{"name":"usages","type":"Set[String]","description":"Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)."},{"name":"key_base64","type":"String","description":"Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".","sensitive":true},{"name":"key_jwk","type":"unknown","description":"Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".","sensitive":true},{"name":"workflow_name","type":"String","description":"Name of the Workflow to bind to."},{"name":"service_id","type":"String","description":"Identifier of the VPC service to bind to."},{"name":"identity","type":"String","description":"Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\n"},{"name":"network_id","type":"String","description":"Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id.\n"},{"name":"tunnel_id","type":"String","description":"UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id.\n"}]},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","requiresReplace":true,"children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"limits","type":"Attributes","description":"Resource limits enforced at runtime.","requiresReplace":true,"children":[{"name":"cpu_ms","type":"Int64","description":"CPU time limit in milliseconds."},{"name":"subrequests","type":"Int64","description":"Subrequest limit per request."}]}],"computed":[{"name":"id","type":"String","description":"Version identifier.","requiresReplace":true},{"name":"author_email","type":"String","description":"Email of the user who created the version."},{"name":"author_id","type":"String","description":"Identifier of the user who created the version."},{"name":"created_on","type":"Time","description":"When the version was created."},{"name":"migration_tag","type":"String","description":"Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects."},{"name":"number","type":"Int64","description":"The integer version number, starting from one."},{"name":"source","type":"String","description":"The client used to create the version."},{"name":"startup_time_ms","type":"Int64","description":"Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)."},{"name":"urls","type":"List[String]","description":"All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version."},{"name":"exports_reconciliation","type":"Attributes","description":"Summary of the declarative exports reconciliation that ran on\nthis upload. Populated only when the uploaded metadata included\nan `exports` block. Durable Object entries drive reconciliation;\n`type: worker` entries do not contribute to this summary.\n","children":[{"name":"created","type":"List[String]","description":"Class names for which a new namespace was provisioned."},{"name":"deleted","type":"List[String]","description":"Class names whose namespace was deleted by a `deleted` tombstone."},{"name":"info","type":"List[Attributes]","description":"Non-blocking info entries (stale tombstones, tombstone applied\nwith class still in code). See `exports_reconciliation_info`.\n","children":[{"name":"class","type":"String","description":"The class name the info entry is about."},{"name":"message","type":"String","description":"Human-readable explanation."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the entry relates to, when applicable."},{"name":"referencing_scripts","type":"List[String]","description":"Other Workers in the account that still bind to the affected\nclass. Advisory: while non-empty the tombstone is not yet safe\nto remove — redeploy these Workers with bindings re-pointed\nfirst.\n"}]},{"name":"removable_entries","type":"List[String]","description":"Source class names whose tombstone entry is now stale and safe\nto delete from `exports` (no remaining referencing scripts).\n"},{"name":"renamed","type":"List[Attributes]","description":"Applied `renamed` tombstones.","children":[{"name":"from","type":"String","description":"The original (source) class name."},{"name":"to","type":"String","description":"The new class name (`renamed_to`)."}]},{"name":"transfer_pending","type":"List[Attributes]","description":"Phase-1 transfer hints recorded on the target side.","children":[{"name":"class","type":"String","description":"The target-side class name awaiting transfer."},{"name":"from","type":"String","description":"The source script the namespace will be transferred from."}]},{"name":"transferred","type":"List[Attributes]","description":"Committed `transferred` tombstones (phase-2).","children":[{"name":"class","type":"String","description":"The source class name that was transferred."},{"name":"phase","type":"String","description":"The transfer phase. Currently always `committed`."},{"name":"to","type":"String","description":"The destination script that now owns the namespace."}]},{"name":"updated","type":"List[String]","description":"Class names whose provisioned namespace was mutated in place."},{"name":"warnings","type":"List[Attributes]","description":"Non-blocking warnings. See `exports_reconciliation_warning`.","children":[{"name":"class","type":"String","description":"The class name the warning is about."},{"name":"message","type":"String","description":"Human-readable explanation of the warning."},{"name":"scenario","type":"String","description":"Stable, machine-readable tag identifying which reconciliation\nscenario produced an error, warning, or info entry. Clients may\nbranch on this value instead of parsing `message`.\n"},{"name":"namespace_id","type":"String","description":"The provisioned namespace the warning relates to, when applicable."}]}]}]}]},"post /accounts/{}/zerotrust/routes/hostname":{"operationId":"zero-trust-networks-route-hostname-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_network_hostname_route","stainlessResource":"zero_trust.networks.hostname_routes","methodName":"create","snippet":"resource \"cloudflare_zero_trust_network_hostname_route\" \"example_zero_trust_network_hostname_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n comment = \"example comment\"\n hostname = \"office-1.local\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true}],"optional":[{"name":"comment","type":"String","description":"An optional description of the hostname route."},{"name":"hostname","type":"String","description":"The hostname of the route."},{"name":"tunnel_id","type":"String","description":"UUID of the tunnel."}],"computed":[{"name":"id","type":"String","description":"The hostname route ID."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"tun_type","type":"String","description":"The type of tunnel."},{"name":"tunnel_name","type":"String","description":"A user-friendly name for a tunnel."}]}]},"post /accounts/{}/zerotrust/subnets/warp":{"operationId":"zero-trust-networks-subnet-create-warp","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_subnet","stainlessResource":"zero_trust.networks.subnets.warp","methodName":"create","snippet":"resource \"cloudflare_zero_trust_device_subnet\" \"example_zero_trust_device_subnet\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"IPv4 Cloudflare Source IPs\"\n network = \"100.64.0.0/12\"\n comment = \"example comment\"\n is_default_network = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID","requiresReplace":true},{"name":"name","type":"String","description":"A user-friendly name for the subnet."},{"name":"network","type":"String","description":"The private IPv4 or IPv6 range defining the subnet, in CIDR notation."}],"optional":[{"name":"comment","type":"String","description":"An optional description of the subnet."},{"name":"is_default_network","type":"Bool","description":"If `true`, this is the default subnet for the account. There can only be one default subnet per account."}],"computed":[{"name":"id","type":"String","description":"The UUID of the subnet."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"deleted_at","type":"Time","description":"Timestamp of when the resource was deleted. If `null`, the resource has not been deleted."},{"name":"subnet_type","type":"String","description":"The type of subnet."},{"name":"capacity","type":"Attributes","description":"IP capacity information for the subnet.","children":[{"name":"total","type":"Int64","description":"Total number of assignable IPs in the subnet."},{"name":"used","type":"Int64","description":"Number of assigned IPs in the subnet."}]}]}]},"post /accounts/{}/zt_risk_scoring/integrations":{"operationId":"dlp-zt-risk-score-integration-create","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_risk_scoring_integration","stainlessResource":"zero_trust.risk_scoring.integrations","methodName":"create","snippet":"resource \"cloudflare_zero_trust_risk_scoring_integration\" \"example_zero_trust_risk_scoring_integration\" {\n account_id = \"account_id\"\n integration_type = \"Okta\"\n tenant_url = \"https://example.com\"\n reference_id = \"reference_id\"\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"integration_type","type":"String","requiresReplace":true},{"name":"tenant_url","type":"String","description":"The base url of the tenant, e.g. \"https://tenant.okta.com\"."}],"optional":[{"name":"active","type":"Bool","description":"Whether this integration is enabled. If disabled, no risk changes will be exported to the third-party."},{"name":"reference_id","type":"String","description":"A reference id that can be supplied by the client. Currently this should be set to the Access-Okta IDP ID (a UUIDv4).\nhttps://developers.cloudflare.com/api/operations/access-identity-providers-get-an-access-identity-provider"}],"computed":[{"name":"id","type":"String","description":"The id of the integration, a UUIDv4."},{"name":"account_tag","type":"String","description":"The Cloudflare account tag."},{"name":"created_at","type":"Time","description":"When the integration was created in RFC3339 format."},{"name":"well_known_url","type":"String","description":"The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1."}]}]},"post /certificates":{"operationId":"origin-ca-create-certificate","declarations":[{"kind":"resource","name":"cloudflare_origin_ca_certificate","stainlessResource":"origin_ca_certificates","methodName":"create","snippet":"resource \"cloudflare_origin_ca_certificate\" \"example_origin_ca_certificate\" {\n csr = <`."},{"name":"enabled","type":"Bool","description":"Whether Email Sending is enabled on this subdomain."},{"name":"modified","type":"Time","description":"The date and time the destination address was last modified."},{"name":"return_path_domain","type":"String","description":"The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`."}]}]},"post /zones/{}/filters":{"operationId":"filters-create-filters","declarations":[{"kind":"resource","name":"cloudflare_filter","stainlessResource":"filters","methodName":"create","snippet":"resource \"cloudflare_filter\" \"example_filter\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n body = [{\n description = \"Restrict access from these browsers on this address range.\"\n expression = \"(http.request.uri.path ~ \\\".*wp-login.php\\\" or http.request.uri.path ~ \\\".*xmlrpc.php\\\") and ip.addr ne 172.16.22.155\"\n paused = false\n ref = \"FIL-100\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"body","type":"List[Attributes]","requiresReplace":true,"children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}],"optional":[{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the filter."}]}]},"post /zones/{}/firewall/lockdowns":{"operationId":"zone-lockdown-create-a-zone-lockdown-rule","declarations":[{"kind":"resource","name":"cloudflare_zone_lockdown","stainlessResource":"firewall.lockdowns","methodName":"create","snippet":"resource \"cloudflare_zone_lockdown\" \"example_zone_lockdown\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n configurations = [{\n target = \"ip\"\n value = \"198.51.100.4\"\n }]\n urls = [\"shop.example.com/*\"]\n description = \"Prevent multiple login failures to mitigate brute force attacks\"\n paused = false\n priority = 5\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"urls","type":"Set[String]","description":"The URLs to include in the current WAF override. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns."},{"name":"configurations","type":"List[Attributes]","description":"A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule."},{"name":"value","type":"String","description":"The IP address to match. This address will be compared to the IP address of incoming requests."}]}],"optional":[{"name":"description","type":"String","description":"An informative summary of the rule. This value is sanitized and any tags will be removed.","requiresReplace":true},{"name":"priority","type":"Float64","description":"The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority.","requiresReplace":true},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the Zone Lockdown rule."},{"name":"created_on","type":"Time","description":"The timestamp of when the rule was created."},{"name":"modified_on","type":"Time","description":"The timestamp of when the rule was last modified."}]}]},"post /zones/{}/firewall/rules":{"operationId":"firewall-rules-create-firewall-rules","declarations":[{"kind":"resource","name":"cloudflare_firewall_rule","stainlessResource":"firewall.rules","methodName":"create","snippet":"resource \"cloudflare_firewall_rule\" \"example_firewall_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = {\n mode = \"challenge\"\n response = {\n body = \"This request has been rate-limited.\"\n content_type = \"text/xml\"\n }\n timeout = 86400\n }\n filter = {\n description = \"Restrict access from these browsers on this address range.\"\n expression = \"(http.request.uri.path ~ \\\".*wp-login.php\\\" or http.request.uri.path ~ \\\".*xmlrpc.php\\\") and ip.addr ne 172.16.22.155\"\n paused = false\n ref = \"FIL-100\"\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"action","type":"Attributes","description":"The action to perform when the threshold of matched traffic within the configured period is exceeded.","children":[{"name":"mode","type":"String","description":"The action to perform."},{"name":"response","type":"Attributes","description":"A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional.\nNotes: If you omit this object, Cloudflare will use the default HTML error page. If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone challenge pages and you should not provide the \"response\" object.","children":[{"name":"body","type":"String","description":"The response body to return. The value must conform to the configured content type."},{"name":"content_type","type":"String","description":"The content type of the body. Must be one of the following: `text/plain`, `text/xml`, or `application/json`."}]},{"name":"timeout","type":"Float64","description":"The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period.\nNotes: If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone's Challenge Passage time and you should not provide this value."}]},{"name":"filter","type":"Attributes","children":[{"name":"id","type":"String","description":"The unique identifier of the filter."},{"name":"description","type":"String","description":"An informative summary of the filter."},{"name":"expression","type":"String","description":"The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)."},{"name":"paused","type":"Bool","description":"When true, indicates that the filter is currently paused."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related filters."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique identifier of the firewall rule."},{"name":"description","type":"String","description":"An informative summary of the firewall rule."},{"name":"paused","type":"Bool","description":"When true, indicates that the firewall rule is currently paused."},{"name":"priority","type":"Float64","description":"The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority."},{"name":"ref","type":"String","description":"A short reference tag. Allows you to select related firewall rules."},{"name":"products","type":"List[String]"}]}]},"post /zones/{}/firewall/ua_rules":{"operationId":"user-agent-blocking-rules-create-a-user-agent-blocking-rule","declarations":[{"kind":"resource","name":"cloudflare_user_agent_blocking_rule","stainlessResource":"firewall.ua_rules","methodName":"create","snippet":"resource \"cloudflare_user_agent_blocking_rule\" \"example_user_agent_blocking_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n configuration = {\n target = \"ua\"\n value = \"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)\"\n }\n mode = \"challenge\"\n description = \"Prevent multiple login failures to mitigate brute force attacks\"\n paused = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"mode","type":"String","description":"The action to apply to a matched request."},{"name":"configuration","type":"Attributes","children":[{"name":"target","type":"String","description":"The configuration target. You must set the target to `ua` when specifying a user agent in the rule."},{"name":"value","type":"String","description":"the user agent to exactly match"}]}],"optional":[{"name":"description","type":"String","description":"An informative summary of the rule. This value is sanitized and any tags will be removed."},{"name":"paused","type":"Bool","description":"When true, indicates that the rule is currently paused."}],"computed":[{"name":"id","type":"String","description":"The unique identifier of the User Agent Blocking rule."}]}]},"post /zones/{}/healthchecks":{"operationId":"health-checks-create-health-check","declarations":[{"kind":"resource","name":"cloudflare_healthcheck","stainlessResource":"healthchecks","methodName":"create","snippet":"resource \"cloudflare_healthcheck\" \"example_healthcheck\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n address = \"www.example.com\"\n name = \"server-1\"\n check_regions = [\"WEU\", \"ENAM\"]\n consecutive_fails = 0\n consecutive_successes = 0\n description = \"Health check for www.example.com\"\n http_config = {\n allow_insecure = true\n expected_body = \"success\"\n expected_codes = [\"2xx\", \"302\"]\n follow_redirects = true\n header = {\n Host = [\"example.com\"]\n X-App-ID = [\"abc123\"]\n }\n method = \"GET\"\n path = \"/health\"\n port = 0\n }\n interval = 0\n retries = 0\n suspended = true\n tcp_config = {\n method = \"connection_established\"\n port = 0\n }\n timeout = 0\n type = \"HTTPS\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier","requiresReplace":true},{"name":"address","type":"String","description":"The hostname or IP address of the origin server to run health checks on."},{"name":"name","type":"String","description":"A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed."}],"optional":[{"name":"description","type":"String","description":"A human-readable description of the health check."},{"name":"check_regions","type":"List[String]","description":"A list of regions from which to run health checks. Null means Cloudflare will pick a default region."},{"name":"consecutive_fails","type":"Int64","description":"The number of consecutive fails required from a health check before changing the health to unhealthy."},{"name":"consecutive_successes","type":"Int64","description":"The number of consecutive successes required from a health check before changing the health to healthy."},{"name":"interval","type":"Int64","description":"The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations."},{"name":"retries","type":"Int64","description":"The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately."},{"name":"suspended","type":"Bool","description":"If suspended, no health checks are sent to the origin."},{"name":"timeout","type":"Int64","description":"The timeout (in seconds) before marking the health check as failed."},{"name":"type","type":"String","description":"The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'."},{"name":"http_config","type":"Attributes","description":"Parameters specific to an HTTP or HTTPS health check.","children":[{"name":"allow_insecure","type":"Bool","description":"Do not validate the certificate when the health check uses HTTPS."},{"name":"expected_body","type":"String","description":"A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy."},{"name":"expected_codes","type":"List[String]","description":"The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check."},{"name":"follow_redirects","type":"Bool","description":"Follow redirects if the origin returns a 3xx status code."},{"name":"header","type":"Map[List[String]]","description":"The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden."},{"name":"method","type":"String","description":"The HTTP method to use for the health check."},{"name":"path","type":"String","description":"The endpoint path to health check against."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS."}]},{"name":"tcp_config","type":"Attributes","description":"Parameters specific to TCP health check.","children":[{"name":"method","type":"String","description":"The TCP connection method to use for the health check."},{"name":"port","type":"Int64","description":"Port number to connect to for the health check. Defaults to 80."}]}],"computed":[{"name":"id","type":"String","description":"Identifier"},{"name":"created_on","type":"Time"},{"name":"failure_reason","type":"String","description":"The current failure reason if status is unhealthy."},{"name":"modified_on","type":"Time"},{"name":"status","type":"String","description":"The current status of the origin server according to the health check."}]}]},"post /zones/{}/hold":{"operationId":"zones-0-hold-post","declarations":[{"kind":"resource","name":"cloudflare_zone_hold","stainlessResource":"zones.holds","methodName":"create","snippet":"resource \"cloudflare_zone_hold\" \"example_zone_hold\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"hold_after","type":"String","description":"If `hold_after` is provided and future-dated, the hold will be temporarily disabled,\nthen automatically re-enabled by the system at the time specified\nin this RFC3339-formatted timestamp. A past-dated `hold_after` value will have\nno effect on an existing, enabled hold. Providing an empty string will set its value\nto the current time. Providing `null` will disable the hold indefinitely."},{"name":"include_subdomains","type":"Bool","description":"If `true`, the zone hold will extend to block any subdomain of the given zone, as well\nas SSL4SaaS Custom Hostnames. For example, a zone hold on a zone with the hostname\n'example.com' and include_subdomains=true will block 'example.com',\n'staging.example.com', 'api.staging.example.com', etc."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"hold","type":"Bool"}]}]},"post /zones/{}/keyless_certificates":{"operationId":"keyless-ssl-for-a-zone-create-keyless-ssl-configuration","declarations":[{"kind":"resource","name":"cloudflare_keyless_certificate","stainlessResource":"keyless_certificates","methodName":"create","snippet":"resource \"cloudflare_keyless_certificate\" \"example_keyless_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate = <This request has been rate-limited.\"\n content_type = \"text/xml\"\n }\n timeout = 86400\n }\n match = {\n headers = [{\n name = \"Cf-Cache-Status\"\n op = \"ne\"\n value = \"HIT\"\n }]\n request = {\n methods = [\"GET\", \"POST\"]\n schemes = [\"HTTP\", \"HTTPS\"]\n url = \"*.example.org/path*\"\n }\n response = {\n origin_traffic = true\n }\n }\n period = 900\n threshold = 60\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"period","type":"Float64","description":"The time in seconds (an integer value) to count matching traffic. If the count exceeds the configured threshold within this period, Cloudflare will perform the configured action."},{"name":"threshold","type":"Float64","description":"The threshold that will trigger the configured mitigation action. Configure this value along with the `period` property to establish a threshold per period."},{"name":"action","type":"Attributes","description":"The action to perform when the threshold of matched traffic within the configured period is exceeded.","children":[{"name":"mode","type":"String","description":"The action to perform."},{"name":"response","type":"Attributes","description":"A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional.\nNotes: If you omit this object, Cloudflare will use the default HTML error page. If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone challenge pages and you should not provide the \"response\" object.","children":[{"name":"body","type":"String","description":"The response body to return. The value must conform to the configured content type."},{"name":"content_type","type":"String","description":"The content type of the body. Must be one of the following: `text/plain`, `text/xml`, or `application/json`."}]},{"name":"timeout","type":"Float64","description":"The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period.\nNotes: If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone's Challenge Passage time and you should not provide this value."}]},{"name":"match","type":"Attributes","description":"Determines which traffic the rate limit counts towards the threshold.","children":[{"name":"headers","type":"List[Attributes]","children":[{"name":"name","type":"String","description":"The name of the response header to match."},{"name":"op","type":"String","description":"The operator used when matching: `eq` means \"equal\" and `ne` means \"not equal\"."},{"name":"value","type":"String","description":"The value of the response header, which must match exactly."}]},{"name":"request","type":"Attributes","children":[{"name":"methods","type":"List[String]","description":"The HTTP methods to match. You can specify a subset (for example, `['POST','PUT']`) or all methods (`['_ALL_']`). This field is optional when creating a rate limit."},{"name":"schemes","type":"List[String]","description":"The HTTP schemes to match. You can specify one scheme (`['HTTPS']`), both schemes (`['HTTP','HTTPS']`), or all schemes (`['_ALL_']`). This field is optional."},{"name":"url","type":"String","description":"The URL pattern to match, composed of a host and a path such as `example.org/path*`. Normalization is applied before the pattern is matched. `*` wildcards are expanded to match applicable traffic. Query strings are not matched. Set the value to `*` to match all traffic to your zone."}]},{"name":"response","type":"Attributes","children":[{"name":"origin_traffic","type":"Bool","description":"When true, only the uncached traffic served from your origin servers will count towards rate limiting. In this case, any cached traffic served by Cloudflare will not count towards rate limiting. This field is optional.\nNotes: This field is deprecated. Instead, use response headers and set \"origin_traffic\" to \"false\" to avoid legacy behaviour interacting with the \"response_headers\" property."}]}]}],"optional":[{"name":"rate_limit_id","type":"String","description":"Defines the unique identifier of the rate limit.","requiresReplace":true}],"computed":[]}]},"post /zones/{}/schema_validation/schemas":{"operationId":"schema-validation-create-schema","declarations":[{"kind":"resource","name":"cloudflare_schema_validation_schemas","stainlessResource":"schema_validation.schemas","methodName":"create","snippet":"resource \"cloudflare_schema_validation_schemas\" \"example_schema_validation_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"openapi_v3\"\n name = \"petstore schema\"\n source = \"\"\n validation_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"kind","type":"String","description":"The kind of the schema","requiresReplace":true},{"name":"name","type":"String","description":"A human-readable name for the schema","requiresReplace":true},{"name":"source","type":"String","description":"The raw schema, e.g., the OpenAPI schema, either as JSON or YAML","requiresReplace":true},{"name":"validation_enabled","type":"Bool","description":"An indicator if this schema is enabled"}],"optional":[],"computed":[{"name":"id","type":"String","description":"A unique identifier of this schema"},{"name":"schema_id","type":"String","description":"A unique identifier of this schema"},{"name":"created_at","type":"Time"}]}]},"post /zones/{}/secondary_dns/incoming":{"operationId":"secondary-dns-(-secondary-zone)-create-secondary-zone-configuration","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_incoming","stainlessResource":"dns.zone_transfers.incoming","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_incoming\" \"example_dns_zone_transfers_incoming\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n auto_refresh_seconds = 86400\n name = \"www.example.com.\"\n peers = [\"23ff594956f20c2a721606e94745a8aa\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"Zone name."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}],"optional":[{"name":"auto_refresh_seconds","type":"Float64","description":"How often should a secondary zone auto refresh regardless of DNS NOTIFY.\nNot applicable for primary zones."}],"computed":[{"name":"id","type":"String"},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"modified_time","type":"String","description":"The time for a specific event."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."}]}]},"post /zones/{}/secondary_dns/outgoing":{"operationId":"secondary-dns-(-primary-zone)-create-primary-zone-configuration","declarations":[{"kind":"resource","name":"cloudflare_dns_zone_transfers_outgoing","stainlessResource":"dns.zone_transfers.outgoing","methodName":"create","snippet":"resource \"cloudflare_dns_zone_transfers_outgoing\" \"example_dns_zone_transfers_outgoing\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n name = \"www.example.com.\"\n peers = [\"23ff594956f20c2a721606e94745a8aa\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n}\n","required":[{"name":"zone_id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"Zone name."},{"name":"peers","type":"Set[String]","description":"A list of peer tags."}],"optional":[],"computed":[{"name":"id","type":"String"},{"name":"checked_time","type":"String","description":"The time for a specific event."},{"name":"created_time","type":"String","description":"The time for a specific event."},{"name":"last_transferred_time","type":"String","description":"The time for a specific event."},{"name":"soa_serial","type":"Float64","description":"The serial number of the SOA for the given zone."}]}]},"post /zones/{}/spectrum/apps":{"operationId":"spectrum-applications-create-spectrum-application-using-a-name-for-the-origin","declarations":[{"kind":"resource","name":"cloudflare_spectrum_application","stainlessResource":"spectrum.apps","methodName":"create","snippet":"resource \"cloudflare_spectrum_application\" \"example_spectrum_application\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns = {\n name = \"ssh.example.com\"\n type = \"CNAME\"\n }\n protocol = \"tcp/22\"\n traffic_type = \"direct\"\n argo_smart_routing = true\n edge_ips = {\n connectivity = \"all\"\n type = \"dynamic\"\n }\n ip_firewall = false\n origin_direct = [\"tcp://127.0.0.1:8080\"]\n origin_dns = {\n name = \"origin.example.com\"\n ttl = 600\n type = \"\"\n }\n origin_port = 22\n origin_worker_id = \"277b7815c871434b960b60729659000a\"\n proxy_protocol = \"off\"\n tls = \"off\"\n virtual_network_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Zone identifier.","requiresReplace":true},{"name":"protocol","type":"String","description":"The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`."},{"name":"dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the application."},{"name":"type","type":"String","description":"The type of DNS record associated with the application."}]}],"optional":[{"name":"origin_worker_id","type":"String","description":"Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"."},{"name":"virtual_network_id","type":"String","description":"Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks."},{"name":"origin_direct","type":"List[String]","description":"List of origin IP addresses. Array may contain multiple IP addresses for load balancing."},{"name":"origin_dns","type":"Attributes","description":"The name and type of DNS record for the Spectrum application.","children":[{"name":"name","type":"String","description":"The name of the DNS record associated with the origin."},{"name":"ttl","type":"Int64","description":"The TTL of our resolution of your DNS record in seconds."},{"name":"type","type":"String","description":"The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records."}]},{"name":"origin_port","type":"Dynamic Int64 | String","description":"The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field."},{"name":"argo_smart_routing","type":"Bool","description":"Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"."},{"name":"ip_firewall","type":"Bool","description":"Enables IP Access Rules for this application.\nNotes: Only available for TCP applications."},{"name":"proxy_protocol","type":"String","description":"Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol."},{"name":"tls","type":"String","description":"The type of TLS termination associated with the application."},{"name":"traffic_type","type":"String","description":"Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`."},{"name":"edge_ips","type":"Attributes","description":"The anycast edge IP configuration for the hostname of this application.","children":[{"name":"connectivity","type":"String","description":"The IP versions supported for inbound connections on Spectrum anycast IPs."},{"name":"type","type":"String","description":"The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names."},{"name":"ips","type":"List[String]","description":"The array of customer owned IPs we broadcast via anycast for this hostname and application."}]}],"computed":[{"name":"id","type":"String","description":"App identifier."},{"name":"created_on","type":"Time","description":"When the Application was created."},{"name":"modified_on","type":"Time","description":"When the Application was last modified."}]}]},"post /zones/{}/speed_api/schedule/{}":{"operationId":"speed-create-scheduled-test","declarations":[{"kind":"resource","name":"cloudflare_observatory_scheduled_test","stainlessResource":"speed.schedule","methodName":"create","snippet":"resource \"cloudflare_observatory_scheduled_test\" \"example_observatory_scheduled_test\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n url = \"example.com\"\n}\n","required":[{"name":"url","type":"String","description":"A URL.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[],"computed":[{"name":"id","type":"String","description":"A URL.","requiresReplace":true},{"name":"frequency","type":"String","description":"The frequency of the test."},{"name":"region","type":"String","description":"A test region."},{"name":"schedule","type":"Attributes","description":"The test schedule.","children":[{"name":"frequency","type":"String","description":"The frequency of the test."},{"name":"region","type":"String","description":"A test region."},{"name":"url","type":"String","description":"A URL."}]},{"name":"test","type":"Attributes","children":[{"name":"id","type":"String","description":"UUID."},{"name":"date","type":"Time"},{"name":"desktop_report","type":"Attributes","description":"The Lighthouse report.","children":[{"name":"cls","type":"Float64","description":"Cumulative Layout Shift."},{"name":"device_type","type":"String","description":"The type of device."},{"name":"error","type":"Attributes","children":[{"name":"code","type":"String","description":"The error code of the Lighthouse result."},{"name":"detail","type":"String","description":"Detailed error message."},{"name":"final_displayed_url","type":"String","description":"The final URL displayed to the user."}]},{"name":"fcp","type":"Float64","description":"First Contentful Paint."},{"name":"json_report_url","type":"String","description":"The URL to the full Lighthouse JSON report."},{"name":"lcp","type":"Float64","description":"Largest Contentful Paint."},{"name":"performance_score","type":"Float64","description":"The Lighthouse performance score."},{"name":"si","type":"Float64","description":"Speed Index."},{"name":"state","type":"String","description":"The state of the Lighthouse report."},{"name":"tbt","type":"Float64","description":"Total Blocking Time."},{"name":"ttfb","type":"Float64","description":"Time To First Byte."},{"name":"tti","type":"Float64","description":"Time To Interactive."}]},{"name":"mobile_report","type":"Attributes","description":"The Lighthouse report.","children":[{"name":"cls","type":"Float64","description":"Cumulative Layout Shift."},{"name":"device_type","type":"String","description":"The type of device."},{"name":"error","type":"Attributes","children":[{"name":"code","type":"String","description":"The error code of the Lighthouse result."},{"name":"detail","type":"String","description":"Detailed error message."},{"name":"final_displayed_url","type":"String","description":"The final URL displayed to the user."}]},{"name":"fcp","type":"Float64","description":"First Contentful Paint."},{"name":"json_report_url","type":"String","description":"The URL to the full Lighthouse JSON report."},{"name":"lcp","type":"Float64","description":"Largest Contentful Paint."},{"name":"performance_score","type":"Float64","description":"The Lighthouse performance score."},{"name":"si","type":"Float64","description":"Speed Index."},{"name":"state","type":"String","description":"The state of the Lighthouse report."},{"name":"tbt","type":"Float64","description":"Total Blocking Time."},{"name":"ttfb","type":"Float64","description":"Time To First Byte."},{"name":"tti","type":"Float64","description":"Time To Interactive."}]},{"name":"region","type":"Attributes","description":"A test region with a label.","children":[{"name":"label","type":"String"},{"name":"value","type":"String","description":"A test region."}]},{"name":"schedule_frequency","type":"String","description":"The frequency of the test."},{"name":"url","type":"String","description":"A URL."}]}]}]},"post /zones/{}/ssl/certificate_packs/order":{"operationId":"certificate-packs-order-advanced-certificate-manager-certificate-pack","declarations":[{"kind":"resource","name":"cloudflare_certificate_pack","stainlessResource":"ssl.certificate_packs","methodName":"create","snippet":"resource \"cloudflare_certificate_pack\" \"example_certificate_pack\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_authority = \"lets_encrypt\"\n hosts = [\"example.com\", \"*.example.com\", \"www.example.com\"]\n type = \"advanced\"\n validation_method = \"txt\"\n validity_days = 14\n cloudflare_branding = false\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"certificate_authority","type":"String","description":"Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities).","requiresReplace":true},{"name":"type","type":"String","description":"Type of certificate pack.","requiresReplace":true},{"name":"validation_method","type":"String","description":"Validation Method selected for the order.","requiresReplace":true},{"name":"validity_days","type":"Int64","description":"Validity Days selected for the order.","requiresReplace":true}],"optional":[{"name":"cloudflare_branding","type":"Bool","description":"Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true.","requiresReplace":true},{"name":"hosts","type":"Set[String]","description":"Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"The unique identifier for a certificate_pack.","requiresReplace":true},{"name":"primary_certificate","type":"String","description":"Identifier of the primary certificate in a pack."},{"name":"status","type":"String","description":"Status of certificate pack."},{"name":"certificates","type":"List[Attributes]","description":"Array of certificates in this pack.","children":[{"name":"id","type":"String","description":"Certificate identifier."},{"name":"hosts","type":"List[String]","description":"Hostnames covered by this certificate."},{"name":"status","type":"String","description":"Certificate status."},{"name":"bundle_method","type":"String","description":"Certificate bundle method."},{"name":"expires_on","type":"Time","description":"When the certificate from the authority expires."},{"name":"geo_restrictions","type":"Attributes","description":"Specify the region where your private key can be held locally.","children":[{"name":"label","type":"String"}]},{"name":"issuer","type":"String","description":"The certificate authority that issued the certificate."},{"name":"modified_on","type":"Time","description":"When the certificate was last modified."},{"name":"priority","type":"Float64","description":"The order/priority in which the certificate will be used."},{"name":"signature","type":"String","description":"The type of hash used for the certificate."},{"name":"uploaded_on","type":"Time","description":"When the certificate was uploaded to Cloudflare."},{"name":"zone_id","type":"String","description":"Identifier."}]},{"name":"dcv_delegation_records","type":"List[Attributes]","description":"DCV Delegation records for domain validation.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]},{"name":"validation_errors","type":"List[Attributes]","description":"Domain validation errors that have been received by the certificate authority (CA).","children":[{"name":"message","type":"String","description":"A domain validation error."}]},{"name":"validation_records","type":"List[Attributes]","description":"Certificates' validation records.","children":[{"name":"cname","type":"String","description":"The CNAME record hostname for DCV delegation."},{"name":"cname_target","type":"String","description":"The CNAME record target value for DCV delegation."},{"name":"emails","type":"List[String]","description":"The set of email addresses that the certificate authority (CA) will use to complete domain validation."},{"name":"http_body","type":"String","description":"The content that the certificate authority (CA) will expect to find at the http_url during the domain validation."},{"name":"http_url","type":"String","description":"The url that will be checked during domain validation."},{"name":"status","type":"String","description":"Status of the validation record."},{"name":"txt_name","type":"String","description":"The hostname that the certificate authority (CA) will check for a TXT record during domain validation ."},{"name":"txt_value","type":"String","description":"The TXT record that the certificate authority (CA) will check during domain validation."}]}]}]},"post /zones/{}/subscription":{"operationId":"zone-subscription-create-zone-subscription","declarations":[{"kind":"resource","name":"cloudflare_zone_subscription","stainlessResource":"zones.subscriptions","methodName":"create","snippet":"resource \"cloudflare_zone_subscription\" \"example_zone_subscription\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n frequency = \"monthly\"\n rate_plan = {\n id = \"free\"\n currency = \"USD\"\n externally_managed = false\n is_contract = false\n public_name = \"Business Plan\"\n scope = \"zone\"\n sets = [\"string\"]\n }\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier","requiresReplace":true}],"optional":[{"name":"frequency","type":"String","description":"How often the subscription is renewed automatically."},{"name":"rate_plan","type":"Attributes","description":"The rate plan applied to the subscription.","children":[{"name":"id","type":"String","description":"The ID of the rate plan."},{"name":"currency","type":"String","description":"The currency applied to the rate plan subscription."},{"name":"externally_managed","type":"Bool","description":"Whether this rate plan is managed externally from Cloudflare."},{"name":"is_contract","type":"Bool","description":"Whether a rate plan is enterprise-based (or newly adopted term contract)."},{"name":"public_name","type":"String","description":"The full name of the rate plan."},{"name":"scope","type":"String","description":"The scope that this rate plan applies to."},{"name":"sets","type":"List[String]","description":"The list of sets this rate plan applies to. Returns array of strings."}]}],"computed":[{"name":"id","type":"String","description":"Identifier","requiresReplace":true},{"name":"currency","type":"String","description":"The monetary unit in which pricing information is displayed."},{"name":"current_period_end","type":"Time","description":"The end of the current period and also when the next billing is due."},{"name":"current_period_start","type":"Time","description":"When the current billing period started. May match initial_period_start if this is the first period."},{"name":"price","type":"Float64","description":"The price of the subscription that will be billed, in US dollars."},{"name":"state","type":"String","description":"The state that the subscription is in."}]}]},"post /zones/{}/token_validation/config":{"operationId":"token-validation-config-create","declarations":[{"kind":"resource","name":"cloudflare_token_validation_config","stainlessResource":"token_validation.configuration","methodName":"create","snippet":"resource \"cloudflare_token_validation_config\" \"example_token_validation_config\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credentials = {\n keys = [{\n alg = \"RS256\"\n e = \"e\"\n kid = \"kid\"\n kty = \"RSA\"\n n = \"n\"\n }]\n }\n description = \"Long description for Token Validation Configuration\"\n title = \"Example Token Validation Configuration\"\n token_sources = [\"http.request.headers[\\\"x-auth\\\"][0]\", \"http.request.cookies[\\\"Authorization\\\"][0]\"]\n token_type = \"JWT\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"token_type","type":"String","requiresReplace":true},{"name":"credentials","type":"Attributes","description":"Request payload for create and PUT credentials operations. Provided keys define the complete stored key set. Key identities (`{alg,kid}`) must be unique.","requiresReplace":true,"children":[{"name":"keys","type":"List[Attributes]","children":[{"name":"alg","type":"String","description":"Algorithm"},{"name":"e","type":"String","description":"RSA exponent"},{"name":"kid","type":"String","description":"Key ID"},{"name":"kty","type":"String","description":"Key Type"},{"name":"n","type":"String","description":"RSA modulus"},{"name":"crv","type":"String","description":"Curve"},{"name":"x","type":"String","description":"X EC coordinate"},{"name":"y","type":"String","description":"Y EC coordinate"},{"name":"k","type":"String","description":"Symmetric key material. Required for create and PUT update requests."}]}]},{"name":"description","type":"String"},{"name":"title","type":"String"},{"name":"token_sources","type":"List[String]"}],"optional":[],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"last_updated","type":"Time"}]}]},"post /zones/{}/token_validation/rules":{"operationId":"token-validation-rules-create","declarations":[{"kind":"resource","name":"cloudflare_token_validation_rules","stainlessResource":"token_validation.rules","methodName":"create","snippet":"resource \"cloudflare_token_validation_rules\" \"example_token_validation_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = \"log\"\n description = \"Long description for Token Validation Rule\"\n enabled = true\n expression = \"is_jwt_valid(\\\"52973293-cb04-4a97-8f55-e7d2ad1107dd\\\") or is_jwt_valid(\\\"46eab8d1-6376-45e3-968f-2c649d77d423\\\")\"\n selector = {\n exclude = [{\n operation_ids = [\"f9c5615e-fe15-48ce-bec6-cfc1946f1bec\", \"56828eae-035a-4396-ba07-51c66d680a04\"]\n }]\n include = [{\n host = [\"v1.example.com\", \"v2.example.com\"]\n }]\n }\n title = \"Example Token Validation Rule\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"action","type":"String","description":"Action to take on requests that match operations included in `selector` and fail `expression`."},{"name":"description","type":"String","description":"A human-readable description that gives more details than `title`."},{"name":"enabled","type":"Bool","description":"Toggle rule on or off."},{"name":"expression","type":"String","description":"Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n"},{"name":"title","type":"String","description":"A human-readable name for the rule."},{"name":"selector","type":"Attributes","description":"Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).\n","children":[{"name":"exclude","type":"List[Attributes]","description":"Ignore operations that were otherwise included by `include`.","children":[{"name":"operation_ids","type":"List[String]","description":"Excluded operation IDs."}]},{"name":"include","type":"List[Attributes]","description":"Select all matching operations.","children":[{"name":"host","type":"List[String]","description":"Included hostnames."}]}]}],"optional":[{"name":"position","type":"Attributes","description":"Update rule order among zone rules.","children":[{"name":"index","type":"Int64","description":"Move rule to this position"},{"name":"before","type":"String","description":"Move rule to before rule with this ID."},{"name":"after","type":"String","description":"Move rule to after rule with this ID."}]}],"computed":[{"name":"id","type":"String","description":"UUID."},{"name":"created_at","type":"Time"},{"name":"last_updated","type":"Time"}]}]},"post /zones/{}/waiting_rooms":{"operationId":"waiting-room-create-waiting-room","declarations":[{"kind":"resource","name":"cloudflare_waiting_room","stainlessResource":"waiting_rooms","methodName":"create","snippet":"resource \"cloudflare_waiting_room\" \"example_waiting_room\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n host = \"shop.example.com\"\n name = \"production_webinar\"\n new_users_per_minute = 200\n total_active_users = 200\n additional_routes = [{\n host = \"shop2.example.com\"\n path = \"/shop2/checkout\"\n }]\n cookie_attributes = {\n samesite = \"auto\"\n secure = \"auto\"\n }\n cookie_suffix = \"abcd\"\n custom_page_html = \"{{#waitTimeKnown}} {{waitTime}} mins {{/waitTimeKnown}} {{^waitTimeKnown}} Queue all enabled {{/waitTimeKnown}}\"\n default_template_language = \"es-ES\"\n description = \"Production - DO NOT MODIFY\"\n disable_session_renewal = false\n enabled_origin_commands = [\"revoke\"]\n json_response_enabled = false\n path = \"/shop/checkout\"\n queue_all = true\n queueing_method = \"fifo\"\n queueing_status_code = 202\n session_duration = 1\n suspended = true\n turnstile_action = \"log\"\n turnstile_mode = \"off\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"host","type":"String","description":"The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination must be unique."},{"name":"name","type":"String","description":"A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed."},{"name":"new_users_per_minute","type":"Int64","description":"Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. So it is possible that there is a little more or little less traffic coming to the route based on the traffic patterns at that time around the world."},{"name":"total_active_users","type":"Int64","description":"Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available. This value is used as a baseline for the total number of active user sessions on the route. It is possible to have a situation where there are more or less active users sessions on the route based on the traffic patterns at that time around the world."}],"optional":[{"name":"cookie_suffix","type":"String","description":"Appends a '_' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(__cf_waitingroom). If `cookie_suffix` is \"abcd\", the cookie name will be `__cf_waitingroom_abcd`. This field is required if using `additional_routes`."},{"name":"custom_page_html","type":"String","description":"Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custom_page_html is provided, the default waiting room will be used. The template is based on mustache ( https://mustache.github.io/ ). There are several variables that are evaluated by the Cloudflare edge:\n1. {{`waitTimeKnown`}} Acts like a boolean value that indicates the behavior to take when wait time is not available, for instance when queue_all is **true**.\n2. {{`waitTimeFormatted`}} Estimated wait time for the user. For example, five minutes. Alternatively, you can use:\n3. {{`waitTime`}} Number of minutes of estimated wait for a user.\n4. {{`waitTimeHours`}} Number of hours of estimated wait for a user (`Math.floor(waitTime/60)`).\n5. {{`waitTimeHourMinutes`}} Number of minutes above the `waitTimeHours` value (`waitTime%60`).\n6. {{`queueIsFull`}} Changes to **true** when no more people can be added to the queue.\n\nTo view the full list of variables, look at the `cfWaitingRoom` object described under the `json_response_enabled` property in other Waiting Room API calls."},{"name":"default_template_language","type":"String","description":"The language of the default page template. If no default_template_language is provided, then `en-US` (English) will be used."},{"name":"description","type":"String","description":"A note that you can use to add more details about the waiting room."},{"name":"disable_session_renewal","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If `true`, an accepted user will have session_duration minutes to browse the site. After that, they will have to go through the waiting room again. If `false`, a user's session cookie will be automatically renewed on every request."},{"name":"json_response_enabled","type":"Bool","description":"Only available for the Waiting Room Advanced subscription. If `true`, requests to the waiting room with the header `Accept: application/json` will receive a JSON response object with information on the user's status in the waiting room as opposed to the configured static HTML page. This JSON response object has one property `cfWaitingRoom` which is an object containing the following fields:\n1. `inWaitingRoom`: Boolean indicating if the user is in the waiting room (always **true**).\n2. `waitTimeKnown`: Boolean indicating if the current estimated wait times are accurate. If **false**, they are not available.\n3. `waitTime`: Valid only when `waitTimeKnown` is **true**. Integer indicating the current estimated time in minutes the user will wait in the waiting room. When `queueingMethod` is **random**, this is set to `waitTime50Percentile`.\n4. `waitTime25Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 25% of users that gain entry the fastest (25th percentile).\n5. `waitTime50Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 50% of users that gain entry the fastest (50th percentile). In other words, half of the queued users are expected to let into the origin website before `waitTime50Percentile` and half are expected to be let in after it.\n6. `waitTime75Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 75% of users that gain entry the fastest (75th percentile).\n7. `waitTimeFormatted`: String displaying the `waitTime` formatted in English for users. If `waitTimeKnown` is **false**, `waitTimeFormatted` will display **unavailable**.\n8. `queueIsFull`: Boolean indicating if the waiting room's queue is currently full and not accepting new users at the moment.\n9. `queueAll`: Boolean indicating if all users will be queued in the waiting room and no one will be let into the origin website.\n10. `lastUpdated`: String displaying the timestamp as an ISO 8601 string of the user's last attempt to leave the waiting room and be let into the origin website. The user is able to make another attempt after `refreshIntervalSeconds` past this time. If the user makes a request too soon, it will be ignored and `lastUpdated` will not change.\n11. `refreshIntervalSeconds`: Integer indicating the number of seconds after `lastUpdated` until the user is able to make another attempt to leave the waiting room and be let into the origin website. When the `queueingMethod` is `reject`, there is no specified refresh time —\\_it will always be **zero**.\n12. `queueingMethod`: The queueing method currently used by the waiting room. It is either **fifo**, **random**, **passthrough**, or **reject**.\n13. `isFIFOQueue`: Boolean indicating if the waiting room uses a FIFO (First-In-First-Out) queue.\n14. `isRandomQueue`: Boolean indicating if the waiting room uses a Random queue where users gain access randomly.\n15. `isPassthroughQueue`: Boolean indicating if the waiting room uses a passthrough queue. Keep in mind that when passthrough is enabled, this JSON response will only exist when `queueAll` is **true** or `isEventPrequeueing` is **true** because in all other cases requests will go directly to the origin.\n16. `isRejectQueue`: Boolean indicating if the waiting room uses a reject queue.\n17. `isEventActive`: Boolean indicating if an event is currently occurring. Events are able to change a waiting room's behavior during a specified period of time. For additional information, look at the event properties `prequeue_start_time`, `event_start_time`, and `event_end_time` in the documentation for creating waiting room events. Events are considered active between these start and end times, as well as during the prequeueing period if it exists.\n18. `isEventPrequeueing`: Valid only when `isEventActive` is **true**. Boolean indicating if an event is currently prequeueing users before it starts.\n19. `timeUntilEventStart`: Valid only when `isEventPrequeueing` is **true**. Integer indicating the number of minutes until the event starts.\n20. `timeUntilEventStartFormatted`: String displaying the `timeUntilEventStart` formatted in English for users. If `isEventPrequeueing` is **false**, `timeUntilEventStartFormatted` will display **unavailable**.\n21. `timeUntilEventEnd`: Valid only when `isEventActive` is **true**. Integer indicating the number of minutes until the event ends.\n22. `timeUntilEventEndFormatted`: String displaying the `timeUntilEventEnd` formatted in English for users. If `isEventActive` is **false**, `timeUntilEventEndFormatted` will display **unavailable**.\n23. `shuffleAtEventStart`: Valid only when `isEventActive` is **true**. Boolean indicating if the users in the prequeue are shuffled randomly when the event starts.\n24. `turnstile`: Empty when turnstile isn't enabled. String displaying an html tag to display the Turnstile widget. Please add the `{{{turnstile}}}` tag to the `custom_html` template to ensure the Turnstile widget appears.\n25. `infiniteQueue`: Boolean indicating whether the response is for a user in the infinite queue.\n\nAn example cURL to a waiting room could be:\n\n\tcurl -X GET \"https://example.com/waitingroom\" \\\n\t\t-H \"Accept: application/json\"\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **fifo** and no event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 0,\n\t\t\t\"waitTime50Percentile\": 0,\n\t\t\t\"waitTime75Percentile\": 0,\n\t\t\t\"waitTimeFormatted\": \"10 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"fifo\",\n\t\t\t\"isFIFOQueue\": true,\n\t\t\t\"isRandomQueue\": false,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": false,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 0,\n\t\t\t\"timeUntilEventEndFormatted\": \"unavailable\",\n\t\t\t\"shuffleAtEventStart\": false\n\t\t}\n\t}\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **random** and an event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 5,\n\t\t\t\"waitTime50Percentile\": 10,\n\t\t\t\"waitTime75Percentile\": 15,\n\t\t\t\"waitTimeFormatted\": \"5 minutes to 15 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"random\",\n\t\t\t\"isFIFOQueue\": false,\n\t\t\t\"isRandomQueue\": true,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": true,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 15,\n\t\t\t\"timeUntilEventEndFormatted\": \"15 minutes\",\n\t\t\t\"shuffleAtEventStart\": true\n\t\t}\n\t}"},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."},{"name":"queue_all","type":"Bool","description":"If queue_all is `true`, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and estimated time will become unavailable."},{"name":"queueing_method","type":"String","description":"Sets the queueing method used by the waiting room. Changing this parameter from the **default** queueing method is only available for the Waiting Room Advanced subscription. Regardless of the queueing method, if `queue_all` is enabled or an event is prequeueing, users in the waiting room will not be accepted to the origin. These users will always see a waiting room page that refreshes automatically. The valid queueing methods are:\n1. `fifo` **(default)**: First-In-First-Out queue where customers gain access in the order they arrived.\n2. `random`: Random queue where customers gain access randomly, regardless of arrival time.\n3. `passthrough`: Users will pass directly through the waiting room and into the origin website. As a result, any configured limits will not be respected while this is enabled. This method can be used as an alternative to disabling a waiting room (with `suspended`) so that analytics are still reported. This can be used if you wish to allow all traffic normally, but want to restrict traffic during a waiting room event, or vice versa.\n4. `reject`: Users will be immediately rejected from the waiting room. As a result, no users will reach the origin website while this is enabled. This can be used if you wish to reject all traffic while performing maintenance, block traffic during a specified period of time (an event), or block traffic while events are not occurring. Consider a waiting room used for vaccine distribution that only allows traffic during sign-up events, and otherwise blocks all traffic. For this case, the waiting room uses `reject`, and its events override this with `fifo`, `random`, or `passthrough`. When this queueing method is enabled and neither `queueAll` is enabled nor an event is prequeueing, the waiting room page **will not refresh automatically**."},{"name":"queueing_status_code","type":"Int64","description":"HTTP status code returned to a user while in the queue."},{"name":"session_duration","type":"Int64","description":"Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they will be treated as a new user that visits the route."},{"name":"suspended","type":"Bool","description":"Suspends or allows traffic going to the waiting room. If set to `true`, the traffic will not go to the waiting room."},{"name":"turnstile_action","type":"String","description":"Which action to take when a bot is detected using Turnstile. `log` will\nhave no impact on queueing behavior, simply keeping track of how many\nbots are detected in Waiting Room Analytics. `infinite_queue` will send\nbots to a false queueing state, where they will never reach your\norigin. `infinite_queue` requires Advanced Waiting Room.\n"},{"name":"turnstile_mode","type":"String","description":"Which Turnstile widget type to use for detecting bot traffic. See\n[the Turnstile documentation](https://developers.cloudflare.com/turnstile/concepts/widget/#widget-types)\nfor the definitions of these widget types. Set to `off` to disable the\nTurnstile integration entirely. Setting this to anything other than\n`off` or `invisible` requires Advanced Waiting Room.\n"},{"name":"enabled_origin_commands","type":"List[String]","description":"A list of enabled origin commands."},{"name":"additional_routes","type":"List[Attributes]","description":"Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an implied wildcard at the end of the path. The hostname and path combination must be unique to this and all other waiting rooms.","children":[{"name":"host","type":"String","description":"The hostname to which this waiting room will be applied (no wildcards). The hostname must be the primary domain, subdomain, or custom hostname (if using SSL for SaaS) of this zone. Please do not include the scheme (http:// or https://)."},{"name":"path","type":"String","description":"Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported."}]},{"name":"cookie_attributes","type":"Attributes","description":"Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.","children":[{"name":"samesite","type":"String","description":"Configures the SameSite attribute on the waiting room cookie. Value `auto` will be translated to `lax` or `none` depending if **Always Use HTTPS** is enabled. Note that when using value `none`, the secure attribute cannot be set to `never`."},{"name":"secure","type":"String","description":"Configures the Secure attribute on the waiting room cookie. Value `always` indicates that the Secure attribute will be set in the Set-Cookie header, `never` indicates that the Secure attribute will not be set, and `auto` will set the Secure attribute depending if **Always Use HTTPS** is enabled."}]}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"},{"name":"next_event_prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will begin queueing."},{"name":"next_event_start_time","type":"String","description":"An ISO 8601 timestamp that marks when the next event will start."}]}]},"post /zones/{}/waiting_rooms/{}/events":{"operationId":"waiting-room-create-event","declarations":[{"kind":"resource","name":"cloudflare_waiting_room_event","stainlessResource":"waiting_rooms.events","methodName":"create","snippet":"resource \"cloudflare_waiting_room_event\" \"example_waiting_room_event\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n event_end_time = \"2021-09-28T17:00:00Z\"\n event_start_time = \"2021-09-28T15:30:00Z\"\n name = \"production_webinar_event\"\n custom_page_html = \"{{#waitTimeKnown}} {{waitTime}} mins {{/waitTimeKnown}} {{^waitTimeKnown}} Event is prequeueing / Queue all enabled {{/waitTimeKnown}}\"\n description = \"Production event - DO NOT MODIFY\"\n disable_session_renewal = true\n new_users_per_minute = 200\n prequeue_start_time = \"2021-09-28T15:00:00Z\"\n queueing_method = \"random\"\n session_duration = 1\n shuffle_at_event_start = true\n suspended = true\n total_active_users = 200\n turnstile_action = \"log\"\n turnstile_mode = \"off\"\n}\n","required":[{"name":"waiting_room_id","type":"String","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"event_end_time","type":"String","description":"An ISO 8601 timestamp that marks the end of the event."},{"name":"event_start_time","type":"String","description":"An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`."},{"name":"name","type":"String","description":"A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed."}],"optional":[{"name":"custom_page_html","type":"String","description":"If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it."},{"name":"disable_session_renewal","type":"Bool","description":"If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it."},{"name":"new_users_per_minute","type":"Int64","description":"If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set."},{"name":"prequeue_start_time","type":"String","description":"An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`."},{"name":"queueing_method","type":"String","description":"If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it."},{"name":"session_duration","type":"Int64","description":"If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it."},{"name":"total_active_users","type":"Int64","description":"If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set."},{"name":"turnstile_action","type":"String","description":"If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it."},{"name":"turnstile_mode","type":"String","description":"If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it."},{"name":"description","type":"String","description":"A note that you can use to add more details about the event."},{"name":"shuffle_at_event_start","type":"Bool","description":"If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary."},{"name":"suspended","type":"Bool","description":"Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration."}],"computed":[{"name":"id","type":"String"},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"}]}]},"post /zones/{}/web3/hostnames":{"operationId":"web3-hostname-create-web3-hostname","declarations":[{"kind":"resource","name":"cloudflare_web3_hostname","stainlessResource":"web3.hostnames","methodName":"create","snippet":"resource \"cloudflare_web3_hostname\" \"example_web3_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"gateway.example.com\"\n target = \"ipfs\"\n description = \"This is my IPFS gateway.\"\n dnslink = \"/ipns/onboarding.ipfs.cloudflare.com\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the identifier of the hostname.","requiresReplace":true},{"name":"name","type":"String","description":"Specify the hostname that points to the target gateway via CNAME.","requiresReplace":true},{"name":"target","type":"String","description":"Specify the target gateway of the hostname.","requiresReplace":true}],"optional":[{"name":"description","type":"String","description":"Specify an optional description of the hostname."},{"name":"dnslink","type":"String","description":"Specify the DNSLink value used if the target is ipfs."}],"computed":[{"name":"id","type":"String","description":"Specify the identifier of the hostname."},{"name":"created_on","type":"Time"},{"name":"modified_on","type":"Time"},{"name":"status","type":"String","description":"Specifies the status of the hostname's activation."}]}]},"post /zones/{}/workers/routes":{"operationId":"worker-routes-create-route","declarations":[{"kind":"resource","name":"cloudflare_workers_route","stainlessResource":"workers.routes","methodName":"create","snippet":"resource \"cloudflare_workers_route\" \"example_workers_route\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pattern = \"example.com/*\"\n script = \"my-workers-script\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"pattern","type":"String","description":"Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)."}],"optional":[{"name":"script","type":"String","description":"Name of the script to run if the route matches."}],"computed":[{"name":"id","type":"String","description":"Identifier."}]}]},"put /accounts/{}/access/keys":{"operationId":"access-key-configuration-update-the-access-key-configuration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_access_key_configuration","stainlessResource":"zero_trust.access.keys","methodName":"update","snippet":"resource \"cloudflare_zero_trust_access_key_configuration\" \"example_zero_trust_access_key_configuration\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n key_rotation_interval_days = 30\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"key_rotation_interval_days","type":"Float64","description":"The number of days between key rotations."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"days_until_next_rotation","type":"Float64","description":"The number of days until the next key rotation."},{"name":"last_key_rotation_at","type":"Time","description":"The timestamp of the previous key rotation."}]}]},"put /accounts/{}/cfd_tunnel/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-put-configuration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_cloudflared_config","stainlessResource":"zero_trust.tunnels.cloudflared.configurations","methodName":"update","snippet":"resource \"cloudflare_zero_trust_tunnel_cloudflared_config\" \"example_zero_trust_tunnel_cloudflared_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n config = {\n ingress = [{\n hostname = \"tunnel.example.com\"\n service = \"https://localhost:8001\"\n origin_request = {\n access = {\n aud_tag = [\"string\"]\n team_name = \"zero-trust-organization-name\"\n required = false\n }\n ca_pool = \"caPool\"\n connect_timeout = 10\n disable_chunked_encoding = true\n http2_origin = true\n http_host_header = \"httpHostHeader\"\n keep_alive_connections = 100\n keep_alive_timeout = 90\n match_sn_ito_host = false\n no_happy_eyeballs = false\n no_tls_verify = false\n origin_server_name = \"originServerName\"\n proxy_type = \"proxyType\"\n tcp_keep_alive = 30\n tls_timeout = 10\n }\n path = \"subpath\"\n }]\n origin_request = {\n access = {\n aud_tag = [\"string\"]\n team_name = \"zero-trust-organization-name\"\n required = false\n }\n ca_pool = \"caPool\"\n connect_timeout = 10\n disable_chunked_encoding = true\n http2_origin = true\n http_host_header = \"httpHostHeader\"\n keep_alive_connections = 100\n keep_alive_timeout = 90\n match_sn_ito_host = false\n no_happy_eyeballs = false\n no_tls_verify = false\n origin_server_name = \"originServerName\"\n proxy_type = \"proxyType\"\n tcp_keep_alive = 30\n tls_timeout = 10\n }\n }\n}\n","required":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"config","type":"Attributes","description":"The tunnel configuration and ingress rules.","children":[{"name":"ingress","type":"List[Attributes]","description":"List of public hostname definitions. At least one ingress rule needs to be defined for the tunnel.","children":[{"name":"hostname","type":"String","description":"Public hostname for this service."},{"name":"service","type":"String","description":"Protocol and address of destination server. Supported protocols: http://, https://, unix://, tcp://, ssh://, rdp://, unix+tls://, smb://. Alternatively can return a HTTP status code http_status:[code] e.g. 'http_status:404'.\n"},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"path","type":"String","description":"Requests with this path route to this public hostname."}]},{"name":"origin_request","type":"Attributes","description":"Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.","children":[{"name":"access","type":"Attributes","description":"For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.","children":[{"name":"aud_tag","type":"List[String]","description":"Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API."},{"name":"team_name","type":"String"},{"name":"required","type":"Bool","description":"Deny traffic that has not fulfilled Access authorization."}]},{"name":"ca_pool","type":"String","description":"Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare."},{"name":"connect_timeout","type":"Int64","description":"Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout."},{"name":"disable_chunked_encoding","type":"Bool","description":"Disables chunked transfer encoding. Useful if you are running a WSGI server."},{"name":"http2_origin","type":"Bool","description":"Attempt to connect to origin using HTTP2. Origin must be configured as https."},{"name":"http_host_header","type":"String","description":"Sets the HTTP Host header on requests sent to the local service."},{"name":"keep_alive_connections","type":"Int64","description":"Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections."},{"name":"keep_alive_timeout","type":"Int64","description":"Timeout after which an idle keepalive connection can be discarded."},{"name":"match_sn_ito_host","type":"Bool","description":"Auto configure the Hostname on the origin server certificate."},{"name":"no_happy_eyeballs","type":"Bool","description":"Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols."},{"name":"no_tls_verify","type":"Bool","description":"Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted."},{"name":"origin_server_name","type":"String","description":"Hostname that cloudflared should expect from your origin server certificate."},{"name":"proxy_type","type":"String","description":"cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy.\n"},{"name":"tcp_keep_alive","type":"Int64","description":"The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server."},{"name":"tls_timeout","type":"Int64","description":"Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server."}]},{"name":"warp_routing","type":"Attributes","description":"Enable private network access from WARP users to private network routes. This is enabled if the tunnel has an assigned route.","deprecated":"This field is ignored by cloudflared since version 2023.10.0.","children":[{"name":"enabled","type":"Bool"}]}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"created_at","type":"Time"},{"name":"source","type":"String","description":"Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel's configuration on the Zero Trust dashboard."},{"name":"version","type":"Int64","description":"The version of the Tunnel Configuration."}]}]},"put /accounts/{}/devices/policy/{}/fallback_domains":{"operationId":"devices-set-local-domain-fallback-list-for-a-device-settings-policy","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_custom_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.custom.fallback_domains","methodName":"update","snippet":"resource \"cloudflare_zero_trust_device_custom_profile_local_domain_fallback\" \"example_zero_trust_device_custom_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n domains = [{\n suffix = \"example.com\"\n description = \"Domain bypass for local development\"\n dns_server = [\"1.1.1.1\"]\n }]\n}\n","required":[{"name":"policy_id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/devices/policy/fallback_domains":{"operationId":"devices-set-local-domain-fallback-list","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_default_profile_local_domain_fallback","stainlessResource":"zero_trust.devices.policies.default.fallback_domains","methodName":"update","snippet":"resource \"cloudflare_zero_trust_device_default_profile_local_domain_fallback\" \"example_zero_trust_device_default_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n domains = [{\n suffix = \"example.com\"\n description = \"Domain bypass for local development\"\n dns_server = [\"1.1.1.1\"]\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"domains","type":"List[Attributes]","children":[{"name":"suffix","type":"String","description":"The domain suffix to match when resolving locally."},{"name":"description","type":"String","description":"A description of the fallback domain, displayed in the client UI."},{"name":"dns_server","type":"List[String]","description":"A list of IP addresses to handle domain resolution."}]}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/devices/settings":{"operationId":"zero-trust-accounts-update-device-settings-for-the-zero-trust-account","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_device_settings","stainlessResource":"zero_trust.devices.settings","methodName":"update","snippet":"resource \"cloudflare_zero_trust_device_settings\" \"example_zero_trust_device_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n disable_for_time = 0\n external_emergency_signal_enabled = true\n external_emergency_signal_fingerprint = \"abcd1234567890abcd1234567890abcd1234567890abcd1234567890abcd1234\"\n external_emergency_signal_interval = \"5m\"\n external_emergency_signal_url = \"https://192.0.2.1/signal\"\n gateway_proxy_enabled = true\n gateway_udp_proxy_enabled = true\n root_certificate_installation_enabled = true\n use_zt_virtual_ip = true\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"disable_for_time","type":"Float64","description":"Sets the time limit, in seconds, that a user can use an override code to bypass WARP."},{"name":"external_emergency_signal_enabled","type":"Bool","description":"Controls whether the external emergency disconnect feature is enabled."},{"name":"external_emergency_signal_fingerprint","type":"String","description":"The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external_emergency_signal_url. If provided, the WARP client will use this value to verify the server's identity. The device will ignore any response if the server's certificate fingerprint does not exactly match this value."},{"name":"external_emergency_signal_interval","type":"String","description":"The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., \"5m\", \"2m30s\", \"1h\"). Minimum 30 seconds."},{"name":"external_emergency_signal_url","type":"String","description":"The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host."},{"name":"gateway_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on TCP."},{"name":"gateway_udp_proxy_enabled","type":"Bool","description":"Enable gateway proxy filtering on UDP."},{"name":"root_certificate_installation_enabled","type":"Bool","description":"Enable installation of cloudflare managed root certificate."},{"name":"use_zt_virtual_ip","type":"Bool","description":"Enable using CGNAT virtual IPv4."}],"computed":[]}]},"put /accounts/{}/dlp/profiles/predefined/{}/config":{"operationId":"dlp-profiles-update-predefined-profile-config","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_predefined_profile","stainlessResource":"zero_trust.dlp.profiles.predefined","methodName":"update","snippet":"resource \"cloudflare_zero_trust_dlp_predefined_profile\" \"example_zero_trust_dlp_predefined_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n ai_context_enabled = true\n allowed_match_count = 5\n confidence_threshold = \"confidence_threshold\"\n enabled_entries = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n entries = [{\n id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n enabled = true\n }]\n ocr_enabled = true\n}\n","required":[{"name":"profile_id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"enabled_entries","type":"List[String]"},{"name":"ai_context_enabled","type":"Bool"},{"name":"allowed_match_count","type":"Int64"},{"name":"confidence_threshold","type":"String"},{"name":"ocr_enabled","type":"Bool"},{"name":"entries","type":"List[Attributes]","deprecated":"Deprecated.","children":[{"name":"id","type":"String"},{"name":"enabled","type":"Bool"}]}],"computed":[{"name":"id","type":"String","requiresReplace":true},{"name":"name","type":"String","description":"The name of the predefined profile."},{"name":"open_access","type":"Bool","description":"Whether this profile can be accessed by anyone."}]}]},"put /accounts/{}/dlp/sensitivity_groups/{}/level_order":{"operationId":"dlp-sensitivity-groups-put-level-order","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_sensitivity_level_order","stainlessResource":"zero_trust.dlp.sensitivity_groups.levels.order","methodName":"update","snippet":"resource \"cloudflare_zero_trust_dlp_sensitivity_level_order\" \"example_zero_trust_dlp_sensitivity_level_order\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_ids = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n}\n","required":[{"name":"sensitivity_group_id","type":"String","requiresReplace":true},{"name":"account_id","type":"String","requiresReplace":true},{"name":"level_ids","type":"List[String]"}],"optional":[],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/dlp/settings":{"operationId":"dlp-settings-update","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_dlp_settings","stainlessResource":"zero_trust.dlp.settings","methodName":"update","snippet":"resource \"cloudflare_zero_trust_dlp_settings\" \"example_zero_trust_dlp_settings\" {\n account_id = \"account_id\"\n ai_context_analysis = true\n ocr = true\n payload_logging = {\n masking_level = \"full\"\n public_key = \"public_key\"\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true}],"optional":[{"name":"ai_context_analysis","type":"Bool","description":"Whether AI context analysis is enabled at the account level."},{"name":"ocr","type":"Bool","description":"Whether OCR is enabled at the account level."},{"name":"payload_logging","type":"Attributes","description":"Request model for payload log settings within the DLP settings endpoint.\nUnlike the legacy endpoint, null and missing are treated identically here\n(both mean \"not provided\" for PATCH, \"reset to default\" for PUT).","children":[{"name":"masking_level","type":"String","description":"Masking level for payload logs.\n\n- `full`: The entire payload is masked.\n- `partial`: Only partial payload content is masked.\n- `clear`: No masking is applied to the payload content.\n- `default`: DLP uses its default masking behavior."},{"name":"public_key","type":"String","description":"Base64-encoded public key for encrypting payload logs.\n\n- Set to a non-empty base64 string to enable payload logging with the given key.\n- Set to an empty string to disable payload logging.\n- Omit or set to null to leave unchanged (PATCH) or reset to disabled (PUT)."}]}],"computed":[{"name":"id","type":"String","requiresReplace":true}]}]},"put /accounts/{}/event_notifications/r2/{}/configuration/queues/{}":{"operationId":"r2-put-event-notification-config","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_event_notification","stainlessResource":"r2.buckets.event_notifications","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_event_notification\" \"example_r2_bucket_event_notification\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n queue_id = \"queue_id\"\n rules = [{\n actions = [\"PutObject\", \"CopyObject\"]\n description = \"Notifications from source bucket to queue\"\n prefix = \"img/\"\n suffix = \".jpeg\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"queue_id","type":"String","description":"ID of the Cloudflare Queue that receives notifications for matching R2 object events.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","description":"Array of rules to drive notifications.","children":[{"name":"actions","type":"List[String]","description":"Array of R2 object actions that will trigger notifications."},{"name":"description","type":"String","description":"A description that can be used to identify the event notification rule after creation."},{"name":"prefix","type":"String","description":"Notifications will be sent only for objects with this prefix."},{"name":"suffix","type":"String","description":"Notifications will be sent only for objects with this suffix."}]}],"optional":[],"computed":[{"name":"queue_name","type":"String","description":"Name of the queue."}]}]},"put /accounts/{}/field_extractors/{}":{"operationId":"updateFieldExtractor","declarations":[{"kind":"resource","name":"cloudflare_field_extractor","stainlessResource":"field_extractors","methodName":"update","snippet":"resource \"cloudflare_field_extractor\" \"example_field_extractor\" {\n account_id = \"123456\"\n extractor = \"llm_prompts\"\n rules = [{\n fields = [{\n expression = \"x\"\n name = \"x\"\n }]\n ref = \"x\"\n description = \"description\"\n }]\n}\n","required":[{"name":"extractor","type":"String","description":"Extractor type.","requiresReplace":true},{"name":"account_id","type":"String","description":"Cloudflare account ID.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","children":[{"name":"fields","type":"List[Attributes]","children":[{"name":"expression","type":"String"},{"name":"name","type":"String"}]},{"name":"ref","type":"String"},{"name":"description","type":"String"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Extractor type.","requiresReplace":true}]}]},"put /accounts/{}/gateway/configuration":{"operationId":"zero-trust-accounts-update-zero-trust-account-configuration.","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_settings","stainlessResource":"zero_trust.gateway.configurations","methodName":"update","snippet":"resource \"cloudflare_zero_trust_gateway_settings\" \"example_zero_trust_gateway_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n settings = {\n activity_log = {\n enabled = true\n }\n antivirus = {\n enabled_download_phase = false\n enabled_upload_phase = false\n fail_closed = false\n notification_settings = {\n enabled = true\n include_context = true\n msg = \"msg\"\n support_url = \"support_url\"\n }\n }\n block_page = {\n background_color = \"background_color\"\n enabled = true\n footer_text = \"--footer--\"\n header_text = \"--header--\"\n include_context = true\n logo_path = \"https://logos.com/a.png\"\n mailto_address = \"admin@example.com\"\n mailto_subject = \"Blocked User Inquiry\"\n mode = \"\"\n name = \"Cloudflare\"\n suppress_footer = false\n target_uri = \"https://example.com\"\n }\n body_scanning = {\n inspection_mode = \"deep\"\n }\n browser_isolation = {\n non_identity_enabled = true\n url_browser_isolation_enabled = true\n }\n certificate = {\n id = \"d1b364c5-1311-466e-a194-f0e943e0799f\"\n }\n custom_certificate = {\n enabled = true\n id = \"d1b364c5-1311-466e-a194-f0e943e0799f\"\n }\n extended_email_matching = {\n enabled = true\n }\n fips = {\n tls = true\n }\n host_selector = {\n enabled = false\n }\n inspection = {\n mode = \"static\"\n }\n max_ttl_secs = 3600\n protocol_detection = {\n enabled = true\n }\n sandbox = {\n enabled = true\n fallback_action = \"allow\"\n }\n tls_decrypt = {\n enabled = true\n }\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}],"optional":[{"name":"settings","type":"Attributes","description":"Specify account settings.","children":[{"name":"activity_log","type":"Attributes","description":"Specify activity log settings.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to log activity."}]},{"name":"antivirus","type":"Attributes","description":"Specify anti-virus settings.","children":[{"name":"enabled_download_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on downloads."},{"name":"enabled_upload_phase","type":"Bool","description":"Specify whether to enable anti-virus scanning on uploads."},{"name":"fail_closed","type":"Bool","description":"Specify whether to block requests for unscannable files."},{"name":"notification_settings","type":"Attributes","description":"Configure the message the user's device shows during an antivirus scan.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable notifications."},{"name":"include_context","type":"Bool","description":"Specify whether to include context information as query parameters."},{"name":"msg","type":"String","description":"Specify the message to show in the notification."},{"name":"support_url","type":"String","description":"Specify a URL that directs users to more information. If unset, the notification opens a block page."}]}]},{"name":"block_page","type":"Attributes","description":"Specify block page layout settings.","children":[{"name":"background_color","type":"String","description":"Specify the block page background color in `#rrggbb` format when the mode is customized_block_page."},{"name":"enabled","type":"Bool","description":"Specify whether to enable the custom block page."},{"name":"footer_text","type":"String","description":"Specify the block page footer text when the mode is customized_block_page."},{"name":"header_text","type":"String","description":"Specify the block page header text when the mode is customized_block_page."},{"name":"include_context","type":"Bool","description":"Specify whether to append context to target_uri as query parameters. This applies only when the mode is redirect_uri."},{"name":"logo_path","type":"String","description":"Specify the full URL to the logo file when the mode is customized_block_page."},{"name":"mailto_address","type":"String","description":"Specify the admin email for users to contact when the mode is customized_block_page."},{"name":"mailto_subject","type":"String","description":"Specify the subject line for emails created from the block page when the mode is customized_block_page."},{"name":"mode","type":"String","description":"Specify whether to redirect users to a Cloudflare-hosted block page or a customer-provided URI."},{"name":"name","type":"String","description":"Specify the block page title when the mode is customized_block_page."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"suppress_footer","type":"Bool","description":"Specify whether to suppress detailed information at the bottom of the block page when the mode is customized_block_page."},{"name":"target_uri","type":"String","description":"Specify the URI to redirect users to when the mode is redirect_uri."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"body_scanning","type":"Attributes","description":"Specify the DLP inspection mode.","children":[{"name":"inspection_mode","type":"String","description":"Specify the inspection mode as either `deep` or `shallow`."}]},{"name":"browser_isolation","type":"Attributes","description":"Specify Clientless Browser Isolation settings.","children":[{"name":"non_identity_enabled","type":"Bool","description":"Specify whether to enable non-identity onramp support for Browser Isolation."},{"name":"url_browser_isolation_enabled","type":"Bool","description":"Specify whether to enable Clientless Browser Isolation."}]},{"name":"certificate","type":"Attributes","description":"Specify certificate settings for Gateway TLS interception. If unset, the Cloudflare Root CA handles interception.","children":[{"name":"id","type":"String","description":"Specify the UUID of the certificate used for interception. Ensure the certificate is available at the edge(previously called 'active'). A nil UUID directs Cloudflare to use the Root CA."}]},{"name":"custom_certificate","type":"Attributes","description":"Specify custom certificate settings for BYO-PKI. This field is deprecated; use `certificate` instead.","deprecated":"Deprecated.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable a custom certificate authority for signing Gateway traffic."},{"name":"id","type":"String","description":"Specify the UUID of the certificate (ID from MTLS certificate store)."},{"name":"binding_status","type":"String","description":"Indicate the internal certificate status."},{"name":"updated_at","type":"Time"}]},{"name":"extended_email_matching","type":"Attributes","description":"Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses `.` or `+` modifiers.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to match all variants of user emails (with + or . modifiers) used as criteria in Firewall policies."},{"name":"read_only","type":"Bool","description":"Indicate that this setting was shared via the Orgs API and read only for the current account."},{"name":"source_account","type":"String","description":"Indicate the account tag of the account that shared this setting."},{"name":"version","type":"Int64","description":"Indicate the version number of the setting."}]},{"name":"fips","type":"Attributes","description":"Specify FIPS settings.","children":[{"name":"tls","type":"Bool","description":"Enforce cipher suites and TLS versions compliant with FIPS 140-2."}]},{"name":"host_selector","type":"Attributes","description":"Enable host selection in egress policies.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable filtering via hosts for egress policies."}]},{"name":"inspection","type":"Attributes","description":"Define the proxy inspection mode.","children":[{"name":"mode","type":"String","description":"Define the proxy inspection mode. 1. static: Gateway applies static inspection to HTTP on TCP(80). With TLS decryption on, Gateway inspects HTTPS traffic on TCP(443) and UDP(443). 2. dynamic: Gateway applies protocol detection to inspect HTTP and HTTPS traffic on any port. TLS decryption must remain on to inspect HTTPS traffic."}]},{"name":"max_ttl_secs","type":"Int64","description":"Account-level cap on DNS response TTLs, in seconds. Gateway rewrites DNS responses so returned record TTLs do not exceed this value. Null means no cap. Each DNS location can inherit, override, or disable it through the location `max_ttl` setting."},{"name":"protocol_detection","type":"Attributes","description":"Specify whether to detect protocols from the initial bytes of client traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to detect protocols from the initial bytes of client traffic."}]},{"name":"sandbox","type":"Attributes","description":"Specify whether to enable the sandbox.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to enable the sandbox."},{"name":"fallback_action","type":"String","description":"Specify the action to take when the system cannot scan the file."}]},{"name":"tls_decrypt","type":"Attributes","description":"Specify whether to inspect encrypted HTTP traffic.","children":[{"name":"enabled","type":"Bool","description":"Specify whether to inspect encrypted HTTP traffic."}]}]}],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true},{"name":"created_at","type":"Time"},{"name":"updated_at","type":"Time"}]}]},"put /accounts/{}/gateway/logging":{"operationId":"zero-trust-accounts-update-logging-settings-for-the-zero-trust-account","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_gateway_logging","stainlessResource":"zero_trust.gateway.logging","methodName":"update","snippet":"resource \"cloudflare_zero_trust_gateway_logging\" \"example_zero_trust_gateway_logging\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n redact_pii = true\n settings_by_rule_type = {\n dns = {\n log_all = false\n log_blocks = true\n }\n http = {\n log_all = false\n log_blocks = true\n }\n l4 = {\n log_all = false\n log_blocks = true\n }\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}],"optional":[{"name":"redact_pii","type":"Bool","description":"Indicate whether to redact personally identifiable information from activity logging (PII fields include source IP, user email, user ID, device ID, URL, referrer, and user agent)."},{"name":"settings_by_rule_type","type":"Attributes","description":"Configure logging settings for each rule type.","children":[{"name":"dns","type":"Attributes","description":"Configure logging settings for DNS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"http","type":"Attributes","description":"Configure logging settings for HTTP/HTTPS firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]},{"name":"l4","type":"Attributes","description":"Configure logging settings for Network firewall.","children":[{"name":"log_all","type":"Bool","description":"Specify whether to log all requests to this service."},{"name":"log_blocks","type":"Bool","description":"Specify whether to log only blocking requests to this service."}]}]}],"computed":[{"name":"id","type":"String","description":"Specify the Cloudflare account identifier.","requiresReplace":true}]}]},"put /accounts/{}/r2/buckets/{}/cors":{"operationId":"r2-put-bucket-cors-policy","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_cors","stainlessResource":"r2.buckets.cors","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_cors\" \"example_r2_bucket_cors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n allowed = {\n methods = [\"GET\"]\n origins = [\"http://localhost:3000\"]\n headers = [\"x-requested-by\"]\n }\n id = \"Allow Local Development\"\n expose_headers = [\"Content-Encoding\"]\n max_age_seconds = 3600\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"rules","type":"List[Attributes]","children":[{"name":"allowed","type":"Attributes","description":"Object specifying allowed origins, methods and headers for this CORS rule.","children":[{"name":"methods","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Methods header R2 sets when requesting objects in a bucket from a browser."},{"name":"origins","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Origin header R2 sets when requesting objects in a bucket from a browser."},{"name":"headers","type":"List[String]","description":"Specifies the value for the Access-Control-Allow-Headers header R2 sets when requesting objects in this bucket from a browser. Cross-origin requests that include custom headers (e.g. x-user-id) should specify these headers as AllowedHeaders."}]},{"name":"id","type":"String","description":"Identifier for this rule."},{"name":"expose_headers","type":"List[String]","description":"Specifies the headers that can be exposed back, and accessed by, the JavaScript making the cross-origin request. If you need to access headers beyond the safelisted response headers, such as Content-Encoding or cf-cache-status, you must specify it here."},{"name":"max_age_seconds","type":"Float64","description":"Specifies the amount of time (in seconds) browsers are allowed to cache CORS preflight responses. Browsers may limit this to 2 hours or less, even if the maximum value (86400) is specified."}]}],"computed":[]}]},"put /accounts/{}/r2/buckets/{}/domains/managed":{"operationId":"r2-put-bucket-public-policy","declarations":[{"kind":"resource","name":"cloudflare_r2_managed_domain","stainlessResource":"r2.buckets.domains.managed","methodName":"update","snippet":"resource \"cloudflare_r2_managed_domain\" \"example_r2_managed_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n enabled = true\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Whether to enable public bucket access at the r2.dev domain."}],"optional":[],"computed":[{"name":"bucket_id","type":"String","description":"Bucket ID."},{"name":"domain","type":"String","description":"Domain name of the bucket's r2.dev domain."}]}]},"put /accounts/{}/r2/buckets/{}/lifecycle":{"operationId":"r2-put-bucket-lifecycle-configuration","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_lifecycle","stainlessResource":"r2.buckets.lifecycle","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_lifecycle\" \"example_r2_bucket_lifecycle\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n id = \"Expire all objects older than 24 hours\"\n conditions = {\n prefix = \"prefix\"\n }\n enabled = true\n abort_multipart_uploads_transition = {\n condition = {\n max_age = 0\n type = \"Age\"\n }\n }\n delete_objects_transition = {\n condition = {\n max_age = 0\n type = \"Age\"\n }\n }\n storage_class_transitions = [{\n condition = {\n max_age = 0\n type = \"Age\"\n }\n storage_class = \"InfrequentAccess\"\n }]\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"conditions","type":"Attributes","description":"Conditions that apply to all transitions of this rule.","children":[{"name":"prefix","type":"String","description":"Transitions will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"abort_multipart_uploads_transition","type":"Attributes","description":"Transition to abort ongoing multipart uploads.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"}]}]},{"name":"delete_objects_transition","type":"Attributes","description":"Transition to delete objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]}]},{"name":"storage_class_transitions","type":"List[Attributes]","description":"Transitions to change the storage class of objects.","children":[{"name":"condition","type":"Attributes","description":"Condition for lifecycle transitions to apply after an object reaches an age in seconds.","children":[{"name":"max_age","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"storage_class","type":"String"}]}]}],"computed":[]}]},"put /accounts/{}/r2/buckets/{}/lock":{"operationId":"r2-put-bucket-lock-configuration","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_lock","stainlessResource":"r2.buckets.locks","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_lock\" \"example_r2_bucket_lock\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n id = \"Lock all objects for 24 hours\"\n condition = {\n max_age_seconds = 100\n type = \"Age\"\n }\n enabled = true\n prefix = \"prefix\"\n }]\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String","description":"Unique identifier for this rule."},{"name":"condition","type":"Attributes","description":"Condition to apply a lock rule to an object for how long in seconds.","children":[{"name":"max_age_seconds","type":"Int64"},{"name":"type","type":"String"},{"name":"date","type":"Time"}]},{"name":"enabled","type":"Bool","description":"Whether or not this rule is in effect."},{"name":"prefix","type":"String","description":"Rule will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads."}]}],"computed":[]}]},"put /accounts/{}/r2/buckets/{}/sippy":{"operationId":"r2-put-bucket-sippy-config","declarations":[{"kind":"resource","name":"cloudflare_r2_bucket_sippy","stainlessResource":"r2.buckets.sippy","methodName":"update","snippet":"resource \"cloudflare_r2_bucket_sippy\" \"example_r2_bucket_sippy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n destination = {\n access_key_id = \"accessKeyId\"\n r2_bucket_sippy_provider = \"r2\"\n secret_access_key = \"secretAccessKey\"\n }\n source = {\n access_key_id = \"accessKeyId\"\n bucket = \"bucket\"\n r2_bucket_sippy_provider = \"aws\"\n region = \"region\"\n secret_access_key = \"secretAccessKey\"\n }\n}\n","required":[{"name":"account_id","type":"String","description":"Cloudflare account ID that owns the R2 resource.","requiresReplace":true},{"name":"bucket_name","type":"String","description":"Name of the bucket.","requiresReplace":true}],"optional":[{"name":"destination","type":"Attributes","description":"R2 bucket to copy objects to.","children":[{"name":"access_key_id","type":"String","description":"ID of a Cloudflare API token.\nThis is the value labelled \"Access Key ID\" when creating an API.\ntoken from the [R2 dashboard](https://dash.cloudflare.com/?to=/:account/r2/api-tokens).\n\nSippy will use this token when writing objects to R2, so it is\nbest to scope this token to the bucket you're enabling Sippy for.\n"},{"name":"r2_bucket_sippy_provider","type":"String"},{"name":"secret_access_key","type":"String","description":"Value of a Cloudflare API token.\nThis is the value labelled \"Secret Access Key\" when creating an API.\ntoken from the [R2 dashboard](https://dash.cloudflare.com/?to=/:account/r2/api-tokens).\n\nSippy will use this token when writing objects to R2, so it is\nbest to scope this token to the bucket you're enabling Sippy for.\n","sensitive":true}]},{"name":"source","type":"Attributes","description":"AWS S3 bucket to copy objects from.","children":[{"name":"access_key_id","type":"String","description":"Access Key ID of an IAM credential (ideally scoped to a single S3 bucket)."},{"name":"bucket","type":"String","description":"Name of the AWS S3 bucket."},{"name":"r2_bucket_sippy_provider","type":"String"},{"name":"region","type":"String","description":"AWS region containing the source S3 bucket."},{"name":"secret_access_key","type":"String","description":"Secret Access Key of an IAM credential (ideally scoped to a single S3 bucket).","sensitive":true},{"name":"client_email","type":"String","description":"Client email of an IAM credential (ideally scoped to a single GCS bucket)."},{"name":"private_key","type":"String","description":"Private Key of an IAM credential (ideally scoped to a single GCS bucket).","sensitive":true},{"name":"bucket_url","type":"String","description":"URL to the S3-compatible API of the bucket."},{"name":"account_key","type":"String","description":"Access key for the Azure Storage account. Mutually exclusive with sasToken.","sensitive":true},{"name":"account_name","type":"String","description":"Name of the Azure Storage account."},{"name":"container","type":"String","description":"Name of the Azure Blob Storage container."},{"name":"sas_token","type":"String","description":"Shared Access Signature token for the Azure Storage account. Mutually exclusive with accountKey.","sensitive":true}]}],"computed":[{"name":"enabled","type":"Bool","description":"State of Sippy for this bucket."}]}]},"put /accounts/{}/registrar/domains/{}":{"operationId":"registrar-domains-update-domain","declarations":[{"kind":"resource","name":"cloudflare_registrar_domain","stainlessResource":"registrar.domains","methodName":"update","snippet":"resource \"cloudflare_registrar_domain\" \"example_registrar_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_name = \"example.com\"\n auto_renew = true\n locked = false\n privacy = true\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"domain_name","type":"String","description":"Provides a fully qualified domain name (FQDN), including the extension\n(e.g., `example.com`, `mybrand.app`). The domain name uniquely identifies\na registration. Cloudflare permits only one registration per domain, making\nthe domain name a natural idempotency key for registration requests.\n","requiresReplace":true}],"optional":[{"name":"auto_renew","type":"Bool","description":"Auto-renew controls whether subscription is automatically renewed upon domain expiration."},{"name":"locked","type":"Bool","description":"Shows whether a registrar lock is in place for a domain."},{"name":"privacy","type":"Bool","description":"Privacy option controls redacting WHOIS information."}],"computed":[]}]},"put /accounts/{}/storage/kv/namespaces/{}/values/{}":{"operationId":"workers-kv-namespace-write-key-value-pair-with-metadata","declarations":[{"kind":"resource","name":"cloudflare_workers_kv","stainlessResource":"kv.namespaces.values","methodName":"update","snippet":"resource \"cloudflare_workers_kv\" \"example_workers_kv\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n key_name = \"My-Key\"\n value = \"Some Value\"\n metadata = {\n\n }\n}\n","required":[{"name":"key_name","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL.","requiresReplace":true},{"name":"account_id","type":"String","description":"ID of the Cloudflare account that owns the Workers KV namespaces.","requiresReplace":true},{"name":"namespace_id","type":"String","description":"ID of the Workers KV namespace.","requiresReplace":true},{"name":"value","type":"String","description":"A byte sequence to be stored, up to 25 MiB in length."}],"optional":[{"name":"metadata","type":"unknown","description":"Associates arbitrary JSON data with a key/value pair."}],"computed":[{"name":"id","type":"String","description":"A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL.","requiresReplace":true}]}]},"put /accounts/{}/stream/webhook":{"operationId":"stream-webhook-create-webhooks","declarations":[{"kind":"resource","name":"cloudflare_stream_webhook","stainlessResource":"stream.webhooks","methodName":"update","snippet":"resource \"cloudflare_stream_webhook\" \"example_stream_webhook\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n notification_url = \"https://example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"The account identifier tag.","requiresReplace":true}],"optional":[{"name":"notification_url","type":"String","description":"The URL where webhooks will be sent."}],"computed":[{"name":"modified","type":"Time","description":"The date and time the webhook was last modified."},{"name":"secret","type":"String","description":"The secret used to verify webhook signatures.","sensitive":true}]}]},"put /accounts/{}/warp_connector/{}/configurations":{"operationId":"cloudflare-tunnel-configuration-update-warp-connector-configuration","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_tunnel_warp_connector_config","stainlessResource":"zero_trust.tunnels.warp_connector.configurations","methodName":"update","snippet":"resource \"cloudflare_zero_trust_tunnel_warp_connector_config\" \"example_zero_trust_tunnel_warp_connector_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n ha_mode = \"aws\"\n config = {\n fnr_id = \"eni-0123456789abcdef0\"\n }\n}\n","required":[{"name":"tunnel_id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"ha_mode","type":"String","description":"High-availability mode for the Mesh node. `none` means HA is enabled but no provider is configured yet (newly created nodes default to this). `disabled` means HA is explicitly turned off. `aws` uses AWS ENI move for failover. `local` uses virtual IPs (VIPs) on the local interface."}],"optional":[{"name":"config","type":"Attributes","description":"Provider-specific configuration. Required shape depends on ha_mode. For `aws`, must contain `fnr_id`. For `local`, must contain `vips`. For `none` and `disabled`, must be empty or omitted.","children":[{"name":"fnr_id","type":"String","description":"Floating Network Resource ID — the secondary ENI that is moved between nodes on failover."},{"name":"vips","type":"List[Attributes]","description":"VIPs to assign on the CloudflareWARP interface.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]},{"name":"vips_previous","type":"List[Attributes]","description":"VIPs to clean up on demotion or version drift.","children":[{"name":"address","type":"String","description":"Virtual IP address (IPv4 or IPv6)."}]}]}],"computed":[{"name":"id","type":"String","description":"UUID of the tunnel.","requiresReplace":true},{"name":"configuration_version","type":"Int64","description":"Monotonically increasing configuration version, incremented on each PUT."},{"name":"created_at","type":"Time","description":"Timestamp of when the resource was created."},{"name":"updated_at","type":"Time","description":"Timestamp of the last update. Null if never updated."}]}]},"put /accounts/{}/workers/domains":{"operationId":"workers.domains.update","declarations":[{"kind":"resource","name":"cloudflare_workers_custom_domain","stainlessResource":"workers.domains","methodName":"update","snippet":"resource \"cloudflare_workers_custom_domain\" \"example_workers_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"app.example.com\"\n service = \"my-worker\"\n zone_id = \"593c9c94de529bbbfaac7c53ced0447d\"\n zone_name = \"example.com\"\n}\n","required":[{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"hostname","type":"String","description":"Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker.","requiresReplace":true},{"name":"service","type":"String","description":"Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker.","requiresReplace":true}],"optional":[{"name":"zone_id","type":"String","description":"ID of the zone containing the domain hostname.","requiresReplace":true},{"name":"zone_name","type":"String","description":"Name of the zone containing the domain hostname.","requiresReplace":true}],"computed":[{"name":"id","type":"String","description":"Immutable ID of the domain.","requiresReplace":true},{"name":"cert_id","type":"String","description":"ID of the TLS certificate issued for the domain."},{"name":"environment","type":"String","description":"Worker environment associated with the domain.","deprecated":"Deprecated."}]}]},"put /accounts/{}/workers/scripts/{}":{"operationId":"worker-script-upload-worker-module","declarations":[{"kind":"resource","name":"cloudflare_workers_script","stainlessResource":"workers.scripts","methodName":"update","snippet":"resource \"cloudflare_workers_script\" \"example_workers_script\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n metadata = {\n annotations = {\n workers_message = \"Fixed bug.\"\n workers_tag = \"v1.0.1\"\n }\n assets = {\n config = {\n headers = <Possible Content-Type(s) are: `application/javascript+module`, `text/javascript+module`, `application/javascript`, `text/javascript`, `text/x-python`, `text/x-python-requirement`, `application/wasm`, `text/plain`, `application/octet-stream`, `application/source-map`."}],"computed":[{"name":"id","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"compatibility_date","type":"String","description":"Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker."},{"name":"created_on","type":"Time","description":"When the script was created."},{"name":"entry_point","type":"String","description":"The entry point for the script."},{"name":"etag","type":"String","description":"Hashed script content, can be used in a If-None-Match header when updating."},{"name":"has_assets","type":"Bool","description":"Whether a Worker contains assets."},{"name":"has_modules","type":"Bool","description":"Whether a Worker contains modules."},{"name":"last_deployed_from","type":"String","description":"The client most recently used to deploy this Worker."},{"name":"logpush","type":"Bool","description":"Whether Logpush is turned on for the Worker."},{"name":"migration_tag","type":"String","description":"The tag of the Durable Object migration that was most recently applied for this Worker."},{"name":"modified_on","type":"Time","description":"When the script was last modified."},{"name":"placement_mode","type":"String","deprecated":"Deprecated."},{"name":"placement_status","type":"String","deprecated":"Deprecated."},{"name":"startup_time_ms","type":"Int64"},{"name":"tag","type":"String","description":"The immutable ID of the script."},{"name":"usage_model","type":"String","description":"Usage model for the Worker invocations."},{"name":"compatibility_flags","type":"Set[String]","description":"Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`."},{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the default export."},{"name":"tags","type":"Set[String]","description":"Tags associated with the Worker."},{"name":"cache_options","type":"Attributes","description":"Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this Worker."},{"name":"cross_version_cache","type":"Bool","description":"Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on.\n"}]},{"name":"exports","type":"Map[Attributes]","description":"Declarative exports for the Worker's most recent version,\nincluding Durable Object classes (with their `storage`\nbackend) and named Worker entrypoints. Tombstoned lifecycle\nentries are omitted, so only live exports (`created` and\n`expecting-transfer`) are returned.\n","children":[{"name":"type","type":"String","description":"Marks this entry as a Worker entrypoint export."},{"name":"cache","type":"Attributes","description":"Cache override for this entrypoint. Overrides the Worker's\nglobal `cache_options.enabled` for this entrypoint only.\n","children":[{"name":"enabled","type":"Bool","description":"Whether caching is enabled for this entrypoint."}]},{"name":"state","type":"String","description":"Live export. May be omitted; defaults to `created`."},{"name":"storage","type":"String","description":"Durable Object storage backend. `sqlite` is the recommended (and\nonly) backend for new namespaces. `legacy-kv` is accepted only for\na class whose namespace already exists as KV-backed; the `exports`\nflow never provisions a new `legacy-kv` namespace.\n"},{"name":"container","type":"String","description":"Name of the container (declared in the upload's\n`metadata.containers`) that backs this Durable Object. When\nset, the namespace is container-enabled. Valid only on live\nentries.\n"},{"name":"renamed_to","type":"String","description":"The destination class name. Must differ from the source class\n(the map key) and must be declared as a live (`created`) entry\nin the same `exports` map. Write-only: never present in GET\nresponses.\n"},{"name":"transferred_to","type":"String","description":"The destination script name. Must be in the same account and\nthe same dispatch-namespace context (or both non-dispatch).\nCross-dispatch-namespace transfers are rejected. Write-only:\nnever present in GET responses.\n"},{"name":"transfer_from","type":"String","description":"The source script name to receive the namespace from. Must be\nin the same account and dispatch-namespace context. Present on\nreads for `expecting-transfer` entries.\n"}]},{"name":"named_handlers","type":"List[Attributes]","description":"Named exports, such as Durable Object class implementations and named entrypoints.","children":[{"name":"handlers","type":"List[String]","description":"The names of handlers exported as part of the named export."},{"name":"name","type":"String","description":"The name of the export."}]},{"name":"observability","type":"Attributes","description":"Observability settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether observability is enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for incoming requests. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"issues","type":"Attributes","description":"Real-time Issues settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether real-time Issues are enabled for the Worker."}]},{"name":"logs","type":"Attributes","description":"Log settings for the Worker.","children":[{"name":"enabled","type":"Bool","description":"Whether logs are enabled for the Worker."},{"name":"invocation_logs","type":"Bool","description":"Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker."},{"name":"destinations","type":"List[String]","description":"A list of destinations where logs will be exported to."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether log persistence is enabled for the Worker."}]},{"name":"redact_query_string","type":"Bool","description":"Whether query strings are removed from request URLs in logs and traces."},{"name":"traces","type":"Attributes","description":"Trace settings for the Worker.","children":[{"name":"destinations","type":"List[String]","description":"A list of destinations where traces will be exported to."},{"name":"enabled","type":"Bool","description":"Whether traces are enabled for the Worker."},{"name":"head_sampling_rate","type":"Float64","description":"The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1."},{"name":"persist","type":"Bool","description":"Whether trace persistence is enabled for the Worker."},{"name":"propagation_policy","type":"String","description":"Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account."}]}]},{"name":"placement","type":"Attributes","description":"Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.","children":[{"name":"mode","type":"String","description":"Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"last_analyzed_at","type":"Time","description":"The last time the script was analyzed for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"status","type":"String","description":"Status of [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)."},{"name":"region","type":"String","description":"Cloud region for targeted placement in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host and port for targeted placement."},{"name":"target","type":"List[Attributes]","description":"Array of placement targets (currently limited to single target).","children":[{"name":"region","type":"String","description":"Cloud region in format 'provider:region'."},{"name":"hostname","type":"String","description":"HTTP hostname for targeted placement."},{"name":"host","type":"String","description":"TCP host:port for targeted placement."}]}]},{"name":"tail_consumers","type":"Set[Attributes]","description":"List of Workers that will consume logs from the attached Worker.","children":[{"name":"service","type":"String","description":"Name of Worker that is to be the consumer."},{"name":"environment","type":"String","description":"Optional environment if the Worker utilizes one."},{"name":"namespace","type":"String","description":"Optional dispatch namespace the script belongs to."}]}]}]},"put /accounts/{}/workers/scripts/{}/schedules":{"operationId":"worker-cron-trigger-update-cron-triggers","declarations":[{"kind":"resource","name":"cloudflare_workers_cron_trigger","stainlessResource":"workers.scripts.schedules","methodName":"update","snippet":"resource \"cloudflare_workers_cron_trigger\" \"example_workers_cron_trigger\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n body = [{\n cron = \"*/30 * * * *\"\n }]\n}\n","required":[{"name":"script_name","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"account_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"body","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Name of the script.","requiresReplace":true},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"},{"name":"created_on","type":"String"},{"name":"modified_on","type":"String"}]}]}]},"put /accounts/{}/workflows/{}":{"operationId":"wor-create-or-modify-workflow","declarations":[{"kind":"resource","name":"cloudflare_workflow","stainlessResource":"workflows","methodName":"update","snippet":"resource \"cloudflare_workflow\" \"example_workflow\" {\n account_id = \"account_id\"\n workflow_name = \"x\"\n class_name = \"x\"\n script_name = \"x\"\n concurrency = {\n limit = 1\n }\n default_retention = {\n error_retention = \"5 minutes\"\n success_retention = \"5 minutes\"\n }\n limits = {\n steps = 1\n }\n schedules = [{\n cron = \"x\"\n }]\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"workflow_name","type":"String","requiresReplace":true},{"name":"class_name","type":"String"},{"name":"script_name","type":"String"}],"optional":[{"name":"concurrency","type":"Attributes","children":[{"name":"limit","type":"Int64","description":"Maximum number of instances of this workflow that can run concurrently. Additional instances are queued and started as running instances complete. Must not exceed the account concurrency limit."}]},{"name":"default_retention","type":"Attributes","description":"Default retention applied to instances of this version when they do not set their own retention.","children":[{"name":"error_retention","type":"Dynamic Int64 | String","description":"Specifies the duration in milliseconds or as a string like '5 minutes'."},{"name":"success_retention","type":"Dynamic Int64 | String","description":"Specifies the duration in milliseconds or as a string like '5 minutes'."}]},{"name":"limits","type":"Attributes","children":[{"name":"steps","type":"Int64"}]},{"name":"schedules","type":"List[Attributes]","children":[{"name":"cron","type":"String"}]}],"computed":[{"name":"id","type":"String"},{"name":"name","type":"String"},{"name":"created_on","type":"Time"},{"name":"is_deleted","type":"Float64"},{"name":"modified_on","type":"Time"},{"name":"script_deleted","type":"Bool","description":"Whether the bound Worker was deleted, leaving this Workflow inactive."},{"name":"terminator_running","type":"Float64"},{"name":"triggered_on","type":"Time"},{"name":"version_id","type":"String"},{"name":"instances","type":"Map[Float64]"}]}]},"put /accounts/{}/zt_risk_scoring/behaviors":{"operationId":"dlp-risk-score-behaviors-put","declarations":[{"kind":"resource","name":"cloudflare_zero_trust_risk_behavior","stainlessResource":"zero_trust.risk_scoring.behaviours","methodName":"update","snippet":"resource \"cloudflare_zero_trust_risk_behavior\" \"example_zero_trust_risk_behavior\" {\n account_id = \"account_id\"\n behaviors = {\n foo = {\n enabled = true\n risk_level = \"low\"\n }\n }\n}\n","required":[{"name":"account_id","type":"String","requiresReplace":true},{"name":"behaviors","type":"Map[Attributes]","children":[{"name":"enabled","type":"Bool"},{"name":"risk_level","type":"String"}]}],"optional":[],"computed":[]}]},"put /organizations/{}/profile":{"operationId":"Organizations_modifyProfile","declarations":[{"kind":"resource","name":"cloudflare_organization_profile","stainlessResource":"organizations.organization_profile","methodName":"update","snippet":"resource \"cloudflare_organization_profile\" \"example_organization_profile\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n business_address = \"business_address\"\n business_email = \"business_email\"\n business_name = \"business_name\"\n business_phone = \"business_phone\"\n external_metadata = \"external_metadata\"\n}\n","required":[{"name":"organization_id","type":"String","requiresReplace":true},{"name":"business_address","type":"String"},{"name":"business_email","type":"String"},{"name":"business_name","type":"String"},{"name":"business_phone","type":"String"},{"name":"external_metadata","type":"String"}],"optional":[],"computed":[]}]},"put /zones/{}/api_gateway/configuration":{"operationId":"api-shield-settings-set-configuration-properties","declarations":[{"kind":"resource","name":"cloudflare_api_shield","stainlessResource":"api_gateway.configurations","methodName":"update","snippet":"resource \"cloudflare_api_shield\" \"example_api_shield\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n auth_id_characteristics = [{\n name = \"authorization\"\n type = \"header\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"auth_id_characteristics","type":"List[Attributes]","children":[{"name":"name","type":"String","description":"The name of the characteristic field, i.e., the header or cookie name."},{"name":"type","type":"String","description":"The type of characteristic."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/api_gateway/operations/{}/schema_validation":{"operationId":"api-shield-schema-validation-update-operation-level-settings","declarations":[{"kind":"resource","name":"cloudflare_api_shield_operation_schema_validation_settings","stainlessResource":"api_gateway.operations.schema_validation","methodName":"update","snippet":"resource \"cloudflare_api_shield_operation_schema_validation_settings\" \"example_api_shield_operation_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n mitigation_action = \"block\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation\n\n - `log` log request when request does not conform to schema for this operation\n - `block` deny access to the site when request does not conform to schema for this operation\n - `none` will skip mitigation for this operation\n - `null` indicates that no operation level mitigation is in place, see Zone Level Schema Validation Settings for mitigation action that will be applied\n"}],"computed":[{"name":"id","type":"String","description":"UUID.","requiresReplace":true}]}]},"put /zones/{}/api_gateway/settings/schema_validation":{"operationId":"api-shield-schema-validation-update-zone-level-settings","declarations":[{"kind":"resource","name":"cloudflare_api_shield_schema_validation_settings","stainlessResource":"api_gateway.settings.schema_validation","methodName":"update","snippet":"resource \"cloudflare_api_shield_schema_validation_settings\" \"example_api_shield_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_default_mitigation_action = \"block\"\n validation_override_mitigation_action = \"none\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used when there is no mitigation action defined on the operation\n\nMitigation actions are as follows:\n\n * `log` - log request when request does not conform to schema\n * `block` - deny access to the site when request does not conform to schema\n\nA special value of of `none` will skip running schema validation entirely for the request when there is no mitigation action defined on the operation\n"}],"optional":[{"name":"validation_override_mitigation_action","type":"String","description":"When set, this overrides both zone level and operation level mitigation actions.\n\n - `none` will skip running schema validation entirely for the request\n - `null` indicates that no override is in place\n\nTo clear any override, use the special value `disable_override` or `null`\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/bot_management":{"operationId":"bot-management-for-a-zone-update-config","declarations":[{"kind":"resource","name":"cloudflare_bot_management","stainlessResource":"bot_management","methodName":"update","snippet":"resource \"cloudflare_bot_management\" \"example_bot_management\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ai_bots_migration_opt_out = false\n ai_bots_protection = \"block\"\n aisearch = \"block\"\n ai_training = \"disallow\"\n ai_user = \"only_on_ad_pages\"\n bot_preference_sync_enabled = true\n cf_robots_variant = \"policy_only\"\n content_bots_protection = \"disabled\"\n crawler_protection = \"enabled\"\n enable_js = true\n fight_mode = true\n is_robots_txt_managed = false\n jsd_api_results_enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"ai_bots_migration_opt_out","type":"Bool","description":"Temporary migration flag tracking zones opted out of AI bots managed-rule updates."},{"name":"ai_bots_protection","type":"String","description":"Enable rule to block AI Scrapers and Crawlers."},{"name":"ai_training","type":"String","description":"Configure robots.txt policy for AI model training bots."},{"name":"ai_user","type":"String","description":"Configure robots.txt policy for AI assistant and agent bots."},{"name":"aisearch","type":"String","description":"Configure robots.txt policy for AI search bots."},{"name":"auto_update_model","type":"Bool","description":"Automatically update to the newest bot detection models created by Cloudflare as they are released. [Learn more.](https://developers.cloudflare.com/bots/reference/machine-learning-models#model-versions-and-release-notes)"},{"name":"bm_cookie_enabled","type":"Bool","description":"Indicates that the bot management cookie can be placed on end user devices accessing the site. Defaults to true"},{"name":"bot_preference_sync_enabled","type":"Bool","description":"Enable Bot Preference Sync for this zone. When enabled, Cloudflare can serve robots.txt content derived from the zone's AI Search, AI User, and AI Training preferences."},{"name":"cf_robots_variant","type":"String","description":"Specifies the Robots Access Control License variant to use."},{"name":"content_bots_protection","type":"String","description":"Enable rule to block content bots. When enabled, blocks automated traffic with low bot scores, excluding safe verified bot categories. Exceptions should be managed via skip rules."},{"name":"crawler_protection","type":"String","description":"Enable rule to punish AI Scrapers and Crawlers via a link maze."},{"name":"enable_js","type":"Bool","description":"Use lightweight, invisible JavaScript detections to improve Bot Management. [Learn more about JavaScript Detections](https://developers.cloudflare.com/bots/reference/javascript-detections/)."},{"name":"fight_mode","type":"Bool","description":"Whether to enable Bot Fight Mode."},{"name":"is_robots_txt_managed","type":"Bool","description":"Enable cloudflare managed robots.txt. If an existing robots.txt is detected, then managed robots.txt will be prepended to the existing robots.txt."},{"name":"jsd_api_results_enabled","type":"Bool","description":"Whether to use JavaScript Detection results submitted through the API for this zone."},{"name":"optimize_wordpress","type":"Bool","description":"Whether to optimize Super Bot Fight Mode protections for Wordpress."},{"name":"sbfm_definitely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on definitely automated requests."},{"name":"sbfm_likely_automated","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on likely automated requests."},{"name":"sbfm_static_resource_protection","type":"Bool","description":"Super Bot Fight Mode (SBFM) to enable static resource protection.\nEnable if static resources on your application need bot protection.\nNote: Static resource protection can also result in legitimate traffic being blocked.\n"},{"name":"sbfm_verified_bots","type":"String","description":"Super Bot Fight Mode (SBFM) action to take on verified bots requests."},{"name":"suppress_session_score","type":"Bool","description":"Whether to disable tracking the highest bot score for a session in the Bot Management cookie."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"using_latest_model","type":"Bool","description":"A read-only field that indicates whether the zone currently is running the latest ML model.\n"},{"name":"stale_zone_configuration","type":"Attributes","description":"A read-only field that shows which unauthorized settings are currently active on the zone. These settings typically result from upgrades or downgrades.","children":[{"name":"optimize_wordpress","type":"Bool","description":"Indicates that the zone's wordpress optimization for SBFM is turned on."},{"name":"sbfm_definitely_automated","type":"String","description":"Indicates that the zone's definitely automated requests are being blocked or challenged."},{"name":"sbfm_likely_automated","type":"String","description":"Indicates that the zone's likely automated requests are being blocked or challenged."},{"name":"sbfm_static_resource_protection","type":"String","description":"Indicates that the zone's static resource protection is turned on."},{"name":"sbfm_verified_bots","type":"String","description":"Indicates that the zone's verified bot requests are being blocked."},{"name":"suppress_session_score","type":"Bool","description":"Indicates that the zone's session score tracking is disabled."},{"name":"fight_mode","type":"Bool","description":"Indicates that the zone's Bot Fight Mode is turned on."}]}]}]},"put /zones/{}/certificate_authorities/hostname_associations":{"operationId":"client-certificate-for-a-zone-put-hostname-associations","declarations":[{"kind":"resource","name":"cloudflare_certificate_authorities_hostname_associations","stainlessResource":"certificate_authorities.hostname_associations","methodName":"update","snippet":"resource \"cloudflare_certificate_authorities_hostname_associations\" \"example_certificate_authorities_hostname_associations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostnames = [\"api.example.com\"]\n mtls_certificate_id = \"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"mtls_certificate_id","type":"String","description":"The UUID for a certificate that was uploaded to the mTLS Certificate Management endpoint. If no mtls_certificate_id is given, the hostnames will be associated to your active Cloudflare Managed CA."},{"name":"hostnames","type":"List[String]"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/cloud_connector/rules":{"operationId":"zone-cloud-conenctor-rules-put","declarations":[{"kind":"resource","name":"cloudflare_cloud_connector_rules","stainlessResource":"cloud_connector.rules","methodName":"update","snippet":"resource \"cloudflare_cloud_connector_rules\" \"example_cloud_connector_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rules = [{\n id = \"95c365e17e1b46599cd99e5b231fac4e\"\n description = \"Rule description\"\n enabled = true\n expression = \"http.cookie eq \\\"a=b\\\"\"\n parameters = {\n host = \"examplebucket.s3.eu-north-1.amazonaws.com\"\n }\n cloud_connector_rules_provider = \"aws_s3\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","children":[{"name":"id","type":"String"},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String"},{"name":"parameters","type":"Attributes","description":"Parameters of Cloud Connector Rule","children":[{"name":"host","type":"String","description":"Host to perform Cloud Connection to"}]},{"name":"cloud_connector_rules_provider","type":"String","description":"Cloud Provider type"}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/content-upload-scan/settings":{"operationId":"waf-content-scanning-update-settings","declarations":[{"kind":"resource","name":"cloudflare_content_scanning","stainlessResource":"content_scanning","methodName":"create","snippet":"resource \"cloudflare_content_scanning\" \"example_content_scanning\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"enabled\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Defines an identifier.","requiresReplace":true},{"name":"value","type":"String","description":"The status value for Content Scanning."}],"optional":[],"computed":[{"name":"modified","type":"String","description":"Defines the last modification date (ISO 8601) of the Content Scanning status."}]}]},"put /zones/{}/custom_hostnames/fallback_origin":{"operationId":"custom-hostname-fallback-origin-for-a-zone-update-fallback-origin-for-custom-hostnames","declarations":[{"kind":"resource","name":"cloudflare_custom_hostname_fallback_origin","stainlessResource":"custom_hostnames.fallback_origin","methodName":"update","snippet":"resource \"cloudflare_custom_hostname_fallback_origin\" \"example_custom_hostname_fallback_origin\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin = \"fallback.example.com\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"origin","type":"String","description":"Your origin hostname that requests to your custom hostnames will be sent to."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"created_at","type":"Time","description":"This is the time the fallback origin was created."},{"name":"status","type":"String","description":"Status of the fallback origin's activation."},{"name":"updated_at","type":"Time","description":"This is the time the fallback origin was updated."},{"name":"errors","type":"List[String]","description":"These are errors that were encountered while trying to activate a fallback origin."}]}]},"put /zones/{}/email/routing/rules/catch_all":{"operationId":"email-routing-routing-rules-update-catch-all-rule","declarations":[{"kind":"resource","name":"cloudflare_email_routing_catch_all","stainlessResource":"email_routing.rules.catch_alls","methodName":"update","snippet":"resource \"cloudflare_email_routing_catch_all\" \"example_email_routing_catch_all\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n actions = [{\n type = \"forward\"\n value = [\"destinationaddress@example.net\"]\n }]\n matchers = [{\n type = \"all\"\n }]\n enabled = true\n name = \"Send to user@example.net rule.\"\n owner_worker_tag = \"a7e6fb77503c41d8a7f3113c6918f10c\"\n source = \"api\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"actions","type":"List[Attributes]","description":"List actions for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of action for catch-all rule."},{"name":"value","type":"List[String]","description":"List of values for the action. Currently limited to a single value."}]},{"name":"matchers","type":"List[Attributes]","description":"List of matchers for the catch-all routing rule.","children":[{"name":"type","type":"String","description":"Type of matcher. Default is 'all'."}]}],"optional":[{"name":"name","type":"String","description":"Routing rule name."},{"name":"owner_worker_tag","type":"String","description":"Public tag (script_tag) of the Worker that owns this rule. Required when\n`source` is `wrangler`.\n"},{"name":"enabled","type":"Bool","description":"Routing rule status."},{"name":"source","type":"String","description":"Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"tag","type":"String","description":"Routing rule tag. (Deprecated, replaced by routing rule identifier)","deprecated":"Deprecated."}]}]},"put /zones/{}/hostnames/settings/{}/{}":{"operationId":"per-hostname-tls-settings-put","declarations":[{"kind":"resource","name":"cloudflare_hostname_tls_setting","stainlessResource":"hostnames.settings.tls","methodName":"update","snippet":"resource \"cloudflare_hostname_tls_setting\" \"example_hostname_tls_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n hostname = \"app.example.com\"\n value = [\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]\n}\n","required":[{"name":"setting_id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.","requiresReplace":true},{"name":"hostname","type":"String","description":"The hostname for which the tls settings are set.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"String","description":"The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`)."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.","requiresReplace":true},{"name":"created_at","type":"Time","description":"This is the time the tls setting was originally created for this hostname."},{"name":"status","type":"String","description":"Deployment status for the given tls setting."},{"name":"updated_at","type":"Time","description":"This is the time the tls setting was updated."}]}]},"put /zones/{}/observability/tracing/rules":{"operationId":"zone.observability.tracing.rules.update","declarations":[{"kind":"resource","name":"cloudflare_zone_tracing_rules","stainlessResource":"zones.observability.tracing.rules","methodName":"update","snippet":"resource \"cloudflare_zone_tracing_rules\" \"example_zone_tracing_rules\" {\n zone_id = \"zone_id\"\n rules = [{\n action = \"set_trace_settings\"\n action_parameters = {\n sampling_ratio = 0\n }\n description = \"description\"\n enabled = true\n expression = \"x\"\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Specify the zone ID.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","description":"Trace rules in evaluation order.","children":[{"name":"action","type":"String"},{"name":"action_parameters","type":"Attributes","children":[{"name":"sampling_ratio","type":"Float64","description":"The ratio of requests sampled for tracing, from 0 to 1."}]},{"name":"description","type":"String"},{"name":"enabled","type":"Bool"},{"name":"expression","type":"String","description":"A Rules language expression that selects requests."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Specify the zone ID.","requiresReplace":true}]}]},"put /zones/{}/origin_tls_client_auth/settings":{"operationId":"zone-level-authenticated-origin-pulls-set-enablement-for-zone","declarations":[{"kind":"resource","name":"cloudflare_authenticated_origin_pulls_settings","stainlessResource":"origin_tls_client_auth.settings","methodName":"update","snippet":"resource \"cloudflare_authenticated_origin_pulls_settings\" \"example_authenticated_origin_pulls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Indicates whether zone-level authenticated origin pulls is enabled."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/origin/cloud_regions/{}":{"operationId":"origin-cloud-regions-v2-upsert","declarations":[{"kind":"resource","name":"cloudflare_origin_cloud_region","stainlessResource":"cache.origin_cloud_regions","methodName":"update","snippet":"resource \"cloudflare_origin_cloud_region\" \"example_origin_cloud_region\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin_ip = \"192.0.2.1\"\n region = \"us-east-1\"\n vendor = \"aws\"\n}\n","required":[{"name":"origin_ip","type":"String","description":"Origin IP address (IPv4 or IPv6). For the single PUT endpoint (`PUT /origin/cloud_regions/{origin_ip}`), this field must match the path parameter or the request will be rejected with a 400 error. For the batch PUT endpoint, this field identifies which mapping to upsert.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"region","type":"String","description":"Cloud vendor region identifier. Must be a valid region for the specified vendor as returned by the supported_regions endpoint."},{"name":"vendor","type":"String","description":"Cloud vendor hosting the origin. Must be one of the supported vendors."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Origin IP address (IPv4 or IPv6). For the single PUT endpoint (`PUT /origin/cloud_regions/{origin_ip}`), this field must match the path parameter or the request will be rejected with a 400 error. For the batch PUT endpoint, this field identifies which mapping to upsert.","requiresReplace":true},{"name":"modified_on","type":"Time","description":"Time this mapping was last modified."}]}]},"put /zones/{}/precursor":{"operationId":"precursor-for-a-zone-update-config","declarations":[{"kind":"resource","name":"cloudflare_precursor","stainlessResource":"precursor","methodName":"update","snippet":"resource \"cloudflare_precursor\" \"example_precursor\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n default_mode = \"min-friction\"\n enforcement_rules = [{\n expression = \"http.request.uri.path eq \\\"/login\\\"\"\n mode = \"max-security\"\n description = \"Ease friction on the login path\"\n enabled = true\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"default_mode","type":"String","description":"The zone-level Precursor enforcement mode applied to requests that do\nnot match a more specific enforcement rule.\n","deprecated":"Deprecated."},{"name":"enforcement_rules","type":"List[Attributes]","description":"The ordered list of enforcement rules for the zone.","deprecated":"Deprecated.","children":[{"name":"expression","type":"String","description":"The filter expression that determines which requests the rule matches."},{"name":"mode","type":"String","description":"The override mode Precursor applies to requests matching an enforcement\nrule. Unlike `default_mode`, this cannot be `off`.\n"},{"name":"id","type":"String","description":"The read-only identifier that Cloudflare assigns to the rule."},{"name":"description","type":"String","description":"An informative description of the rule."},{"name":"enabled","type":"Bool","description":"Whether the rule is active."}]}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/schema_validation/settings":{"operationId":"schema-validation-update-settings","declarations":[{"kind":"resource","name":"cloudflare_schema_validation_settings","stainlessResource":"schema_validation.settings","methodName":"update","snippet":"resource \"cloudflare_schema_validation_settings\" \"example_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_default_mitigation_action = \"block\"\n validation_override_mitigation_action = \"none\"\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"validation_default_mitigation_action","type":"String","description":"The default mitigation action used\nMitigation actions are as follows:\n\n - `\"log\"` - log request when request does not conform to schema\n - `\"block\"` - deny access to the site when request does not conform to schema\n - `\"none\"` - skip running schema validation\n"}],"optional":[{"name":"validation_override_mitigation_action","type":"String","description":"When set, this overrides both zone level and operation level mitigation actions.\n\n - `\"none\"` - skip running schema validation entirely for the request\n - `null` - clears any existing override\n"}],"computed":[]}]},"put /zones/{}/schema_validation/settings/operations/{}":{"operationId":"schema-validation-update-per-operation-setting","declarations":[{"kind":"resource","name":"cloudflare_schema_validation_operation_settings","stainlessResource":"schema_validation.settings.operations","methodName":"update","snippet":"resource \"cloudflare_schema_validation_operation_settings\" \"example_schema_validation_operation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n mitigation_action = \"block\"\n}\n","required":[{"name":"operation_id","type":"String","description":"UUID.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"mitigation_action","type":"String","description":"When set, this applies a mitigation action to this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\n - `null` - clears any mitigation action\n"}],"optional":[],"computed":[]}]},"put /zones/{}/settings/google-tag-gateway/config":{"operationId":"zone-settings-change-google-tag-gateway-config","declarations":[{"kind":"resource","name":"cloudflare_google_tag_gateway","stainlessResource":"google_tag_gateway.config","methodName":"update","snippet":"resource \"cloudflare_google_tag_gateway\" \"example_google_tag_gateway\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n endpoint = \"/metrics\"\n hide_original_ip = true\n measurement_id = \"GTM-P2F3N47Q\"\n set_up_tag = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"enabled","type":"Bool","description":"Enables or disables Google Tag Gateway for this zone."},{"name":"endpoint","type":"String","description":"Specifies the endpoint path for proxying Google Tag Manager requests. Use an absolute path starting with '/', with no nested paths and alphanumeric characters only (e.g. /metrics)."},{"name":"hide_original_ip","type":"Bool","description":"Hides the original client IP address from Google when enabled."},{"name":"measurement_id","type":"String","description":"Specify the Google Tag Manager container or measurement ID (e.g. GTM-XXXXXXX or G-XXXXXXXXXX)."}],"optional":[{"name":"set_up_tag","type":"Bool","description":"Set up the associated Google Tag on the zone automatically when enabled."}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]},"put /zones/{}/settings/origin_tls_compliance_modes":{"operationId":"zone-cache-settings-replace-origin-tls-compliance-modes-setting","declarations":[{"kind":"resource","name":"cloudflare_origin_tls_compliance_modes","stainlessResource":"origin_tls_compliance_modes","methodName":"update","snippet":"resource \"cloudflare_origin_tls_compliance_modes\" \"example_origin_tls_compliance_modes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = [\"fips\", \"pqh\"]\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"value","type":"List[String]","description":"List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone's origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint."}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"editable","type":"Bool","description":"Whether the setting is editable."},{"name":"modified_on","type":"Time","description":"Last time this setting was modified."}]}]},"put /zones/{}/snippets/{}":{"operationId":"updateZoneSnippet","declarations":[{"kind":"resource","name":"cloudflare_snippet","stainlessResource":"snippets","methodName":"update","snippet":"resource \"cloudflare_snippet\" \"example_snippet\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n snippet_name = \"my_snippet\"\n metadata = {\n main_module = \"main.js\"\n }\n}\n","required":[{"name":"snippet_name","type":"String","description":"Identify the snippet.","requiresReplace":true},{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone.","requiresReplace":true},{"name":"metadata","type":"Attributes","description":"Provide metadata about the snippet.","children":[{"name":"main_module","type":"String","description":"Specify the name of the file that contains the main module of the snippet."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Identify the snippet.","requiresReplace":true},{"name":"created_on","type":"Time","description":"Indicates when the snippet was created."},{"name":"modified_on","type":"Time","description":"Indicates when the snippet was last modified."}]}]},"put /zones/{}/snippets/snippet_rules":{"operationId":"updateZoneSnippetRules","declarations":[{"kind":"resource","name":"cloudflare_snippet_rules","stainlessResource":"snippets.rules","methodName":"update","snippet":"resource \"cloudflare_snippet_rules\" \"example_snippet_rules\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n rules = [{\n expression = \"ip.src eq 1.1.1.1\"\n snippet_name = \"my_snippet\"\n description = \"Execute my_snippet when IP address is 1.1.1.1.\"\n enabled = true\n }]\n}\n","required":[{"name":"zone_id","type":"String","description":"Use this field to specify the unique ID of the zone.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","description":"Lists snippet rules.","children":[{"name":"id","type":"String","description":"Specify the unique ID of the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"Use this field to specify the unique ID of the zone.","requiresReplace":true},{"name":"description","type":"String","description":"Provide an informative description of the rule."},{"name":"enabled","type":"Bool","description":"Indicate whether to execute the rule."},{"name":"expression","type":"String","description":"Define the expression that determines which traffic matches the rule."},{"name":"last_updated","type":"Time","description":"Specify the timestamp of when the rule was last modified."},{"name":"snippet_name","type":"String","description":"Identify the snippet."}]}]},"put /zones/{}/url_normalization":{"operationId":"updateUrlNormalization","declarations":[{"kind":"resource","name":"cloudflare_url_normalization_settings","stainlessResource":"url_normalization","methodName":"update","snippet":"resource \"cloudflare_url_normalization_settings\" \"example_url_normalization_settings\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n scope = \"incoming\"\n type = \"cloudflare\"\n}\n","required":[{"name":"zone_id","type":"String","description":"The unique ID of the zone.","requiresReplace":true},{"name":"scope","type":"String","description":"The scope of the URL normalization."},{"name":"type","type":"String","description":"The type of URL normalization performed by Cloudflare."}],"optional":[],"computed":[{"name":"id","type":"String","description":"The unique ID of the zone.","requiresReplace":true}]}]},"put /zones/{}/waiting_rooms/{}/rules":{"operationId":"waiting-room-replace-waiting-room-rules","declarations":[{"kind":"resource","name":"cloudflare_waiting_room_rules","stainlessResource":"waiting_rooms.rules","methodName":"update","snippet":"resource \"cloudflare_waiting_room_rules\" \"example_waiting_room_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n rules = [{\n action = \"bypass_waiting_room\"\n expression = \"ip.src in {10.20.30.40}\"\n description = \"allow all traffic from 10.20.30.40\"\n enabled = true\n }]\n}\n","required":[{"name":"waiting_room_id","type":"String","requiresReplace":true},{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true},{"name":"rules","type":"List[Attributes]","children":[{"name":"action","type":"String","description":"The action to take when the expression matches."},{"name":"expression","type":"String","description":"Criteria defining when there is a match for the current rule."},{"name":"description","type":"String","description":"The description of the rule."},{"name":"enabled","type":"Bool","description":"When set to true, the rule is enabled."}]}],"optional":[],"computed":[{"name":"id","type":"String","description":"The ID of the rule."}]}]},"put /zones/{}/waiting_rooms/settings":{"operationId":"waiting-room-update-zone-settings","declarations":[{"kind":"resource","name":"cloudflare_waiting_room_settings","stainlessResource":"waiting_rooms.settings","methodName":"update","snippet":"resource \"cloudflare_waiting_room_settings\" \"example_waiting_room_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n search_engine_crawler_bypass = true\n}\n","required":[{"name":"zone_id","type":"String","description":"Identifier.","requiresReplace":true}],"optional":[{"name":"search_engine_crawler_bypass","type":"Bool","description":"Whether to allow verified search engine crawlers to bypass all waiting rooms on this zone.\nVerified search engine crawlers will not be tracked or counted by the waiting room system,\nand will not appear in waiting room analytics.\n"}],"computed":[{"name":"id","type":"String","description":"Identifier.","requiresReplace":true}]}]}}} +{ + "format": 2, + "source": { + "provider": { + "repository": "https://github.com/cloudflare/terraform-provider-cloudflare", + "version": "5.27.0", + "commit": "46e69b7239fce198d66bdfa84083367e14156aff" + }, + "sdks": [ + { + "module": "github.com/cloudflare/cloudflare-go/v6", + "version": "v6.10.0", + "commit": "44e6fd4ef22cede57bd544286781530d6e7c8765" + }, + { + "module": "github.com/cloudflare/cloudflare-go/v7", + "version": "v7.12.0", + "commit": "05ca1e4fc7c7f02ffd8257ea199c985e1ec618e8" + } + ] + }, + "stats": { + "declarations": 741, + "linkedDeclarations": 740, + "endpoints": 1116, + "unresolvedCalls": 0 + }, + "unlinked": [ + "resource:cloudflare_snippets" + ], + "undocumented": [ + "list-data-source:cloudflare_rate_limits" + ], + "unresolvedCalls": [], + "declarations": { + "data-source:cloudflare_access_rule": { + "kind": "data-source", + "name": "cloudflare_access_rule", + "description": "Accepted Permissions\n\n- `Account Firewall Access Rules Read`\n- `Account Firewall Access Rules Write`", + "example": "data \"cloudflare_access_rule\" \"example_access_rule\" {\n rule_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "configuration", + "type": "Attributes", + "children": [ + { + "name": "target", + "type": "String", + "description": "Defines the target to search in existing rules.\nAvailable values: \"ip\", \"ip_range\", \"asn\", \"country\"." + }, + { + "name": "value", + "type": "String", + "description": "Defines the target value to search for in existing rules: an IP address, an IP address range, or a country code, depending on the provided `configuration.target`.\nNotes: You can search for a single IPv4 address, an IP address range with a subnet of '/16' or '/24', or a two-letter ISO-3166-1 alpha-2 country code." + } + ] + }, + { + "name": "direction", + "type": "String", + "description": "Defines the direction used to sort returned rules.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "match", + "type": "String", + "description": "Defines the search requirements. When set to `all`, all the search requirements must match. When set to `any`, only one of the search requirements has to match.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"whitelist\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "notes", + "type": "String", + "description": "Defines the string to search for in the notes of existing IP Access rules.\nNotes: For example, the string 'attack' would match IP Access rules with notes 'Attack 26/02' and 'Attack 27/02'. The search is case insensitive." + }, + { + "name": "order", + "type": "String", + "description": "Defines the field used to sort returned rules.\nAvailable values: \"configuration.target\", \"configuration.value\", \"mode\"." + } + ] + }, + { + "name": "rule_id", + "type": "String", + "description": "Unique identifier for a rule." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "allowed_modes", + "type": "List of String", + "description": "The available actions that a rule can apply to a matched request." + }, + { + "name": "configuration", + "type": "Attributes", + "description": "The rule configuration.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target. You must set the target to `ip` when specifying an IP address in the rule.\nAvailable values: \"ip\", \"ip6\", \"ip_range\", \"asn\", \"country\"." + }, + { + "name": "value", + "type": "String", + "description": "The IP address to match. This address will be compared to the IP address of incoming requests." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for a rule." + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"whitelist\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + }, + { + "name": "notes", + "type": "String", + "description": "An informative summary of the rule, typically used as a reminder or explanation." + }, + { + "name": "scope", + "type": "Attributes", + "description": "All zones owned by the user will have the rule applied.", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Defines an identifier." + }, + { + "name": "type", + "type": "String", + "description": "Defines the scope of the rule.\nAvailable values: \"user\", \"organization\"." + } + ] + } + ] + }, + "resource:cloudflare_access_rule": { + "kind": "resource", + "name": "cloudflare_access_rule", + "description": "Accepted Permissions\n\n- `Account Firewall Access Rules Read`\n- `Account Firewall Access Rules Write`", + "example": "resource \"cloudflare_access_rule\" \"example_access_rule\" {\n configuration = {\n target = \"ip\"\n value = \"198.51.100.4\"\n }\n mode = \"challenge\"\n zone_id = \"zone_id\"\n notes = \"This rule is enabled because of an event that occurred on date X.\"\n}", + "importExample": "$ terraform import cloudflare_access_rule.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "configuration", + "type": "Attributes", + "description": "The rule configuration.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target. You must set the target to `ip` when specifying an IP address in the rule.\nAvailable values: \"ip\", \"ip6\", \"ip_range\", \"asn\", \"country\"." + }, + { + "name": "value", + "type": "String", + "description": "The IP address to match. This address will be compared to the IP address of incoming requests." + } + ] + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"whitelist\", \"js_challenge\", \"managed_challenge\"." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "notes", + "type": "String", + "description": "An informative summary of the rule, typically used as a reminder or explanation." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "allowed_modes", + "type": "List of String", + "description": "The available actions that a rule can apply to a matched request." + }, + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the IP Access rule." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + }, + { + "name": "scope", + "type": "Attributes", + "description": "All zones owned by the user will have the rule applied.", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Defines an identifier." + }, + { + "name": "type", + "type": "String", + "description": "Defines the scope of the rule.\nAvailable values: \"user\", \"organization\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_access_rules": { + "kind": "list-data-source", + "name": "cloudflare_access_rules", + "description": "Accepted Permissions\n\n- `Account Firewall Access Rules Read`\n- `Account Firewall Access Rules Write`", + "example": "data \"cloudflare_access_rules\" \"example_access_rules\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n configuration = {\n target = \"ip\"\n value = \"198.51.100.4\"\n }\n direction = \"desc\"\n mode = \"challenge\"\n notes = \"my note\"\n order = \"mode\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "configuration", + "type": "Attributes", + "children": [ + { + "name": "target", + "type": "String", + "description": "Defines the target to search in existing rules.\nAvailable values: \"ip\", \"ip_range\", \"asn\", \"country\"." + }, + { + "name": "value", + "type": "String", + "description": "Defines the target value to search for in existing rules: an IP address, an IP address range, or a country code, depending on the provided `configuration.target`.\nNotes: You can search for a single IPv4 address, an IP address range with a subnet of '/16' or '/24', or a two-letter ISO-3166-1 alpha-2 country code." + } + ] + }, + { + "name": "direction", + "type": "String", + "description": "Defines the direction used to sort returned rules.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "match", + "type": "String", + "description": "Defines the search requirements. When set to `all`, all the search requirements must match. When set to `any`, only one of the search requirements has to match.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"whitelist\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "notes", + "type": "String", + "description": "Defines the string to search for in the notes of existing IP Access rules.\nNotes: For example, the string 'attack' would match IP Access rules with notes 'Attack 26/02' and 'Attack 27/02'. The search is case insensitive." + }, + { + "name": "order", + "type": "String", + "description": "Defines the field used to sort returned rules.\nAvailable values: \"configuration.target\", \"configuration.value\", \"mode\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allowed_modes", + "type": "List of String", + "description": "The available actions that a rule can apply to a matched request." + }, + { + "name": "configuration", + "type": "Attributes", + "description": "The rule configuration.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target. You must set the target to `ip` when specifying an IP address in the rule.\nAvailable values: \"ip\", \"ip6\", \"ip_range\", \"asn\", \"country\"." + }, + { + "name": "value", + "type": "String", + "description": "The IP address to match. This address will be compared to the IP address of incoming requests." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the IP Access rule." + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"whitelist\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + }, + { + "name": "notes", + "type": "String", + "description": "An informative summary of the rule, typically used as a reminder or explanation." + }, + { + "name": "scope", + "type": "Attributes", + "description": "All zones owned by the user will have the rule applied.", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Defines an identifier." + }, + { + "name": "type", + "type": "String", + "description": "Defines the scope of the rule.\nAvailable values: \"user\", \"organization\"." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_account": { + "kind": "data-source", + "name": "cloudflare_account", + "description": "Accepted Permissions\n\n- `Account Firewall Access Rules Read`\n- `Account Firewall Access Rules Write`\n- `Account Settings Read`\n- `Account Settings Write`\n- `Billing Read`\n- `Billing Write`\n- `DDoS Botnet Feed Read`\n- `DDoS Botnet Feed Write`\n- `DDoS Protection Read`\n- `DDoS Protection Write`\n- `DNS Firewall Read`\n- `DNS Firewall Write`\n- `DNS View Read`\n- `DNS View Write`\n- `Load Balancers Account Read`\n- `Load Balancers Account Write`\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`\n- `SCIM Provisioning`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_account\" \"example_account\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "name", + "type": "String", + "description": "Name of the account." + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the account" + }, + { + "name": "id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "managed_by", + "type": "Attributes", + "description": "Parent container details", + "children": [ + { + "name": "parent_org_id", + "type": "String", + "description": "ID of the parent Organization, if one exists" + }, + { + "name": "parent_org_name", + "type": "String", + "description": "Name of the parent Organization, if one exists" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Account name" + }, + { + "name": "settings", + "type": "Attributes", + "description": "Account settings", + "children": [ + { + "name": "abuse_contact_email", + "type": "String", + "description": "Sets an abuse contact email to notify for abuse reports." + }, + { + "name": "enforce_twofactor", + "type": "Boolean", + "description": "Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"standard\", \"enterprise\"." + } + ] + }, + "resource:cloudflare_account": { + "kind": "resource", + "name": "cloudflare_account", + "description": "Accepted Permissions\n\n- `Account Firewall Access Rules Read`\n- `Account Firewall Access Rules Write`\n- `Account Settings Read`\n- `Account Settings Write`\n- `Billing Read`\n- `Billing Write`\n- `DDoS Botnet Feed Read`\n- `DDoS Botnet Feed Write`\n- `DDoS Protection Read`\n- `DDoS Protection Write`\n- `DNS Firewall Read`\n- `DNS Firewall Write`\n- `DNS View Read`\n- `DNS View Write`\n- `Load Balancers Account Read`\n- `Load Balancers Account Write`\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`\n- `SCIM Provisioning`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`\n- `Zero Trust: PII Read`", + "example": "resource \"cloudflare_account\" \"example_account\" {\n name = \"name\"\n standalone = true\n type = \"standard\"\n unit = {\n id = \"f267e341f3dd4697bd3b9f71dd96247f\"\n }\n}", + "importExample": "$ terraform import cloudflare_account.example ''", + "required": [ + { + "name": "name", + "type": "String", + "description": "Account name" + } + ], + "optional": [ + { + "name": "managed_by", + "type": "Attributes", + "description": "Parent container details", + "children": [ + { + "name": "parent_org_id", + "type": "String", + "description": "ID of the parent Organization, if one exists" + }, + { + "name": "parent_org_name", + "type": "String", + "description": "Name of the parent Organization, if one exists" + } + ] + }, + { + "name": "settings", + "type": "Attributes", + "description": "Account settings", + "children": [ + { + "name": "abuse_contact_email", + "type": "String", + "description": "Sets an abuse contact email to notify for abuse reports." + }, + { + "name": "enforce_twofactor", + "type": "Boolean", + "description": "Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled" + } + ] + }, + { + "name": "standalone", + "type": "Boolean", + "description": "Set to `true` and omit `unit` to create a standalone Free Account. If provided, this field must be `true`." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"standard\", \"enterprise\".", + "deprecated": "Deprecated." + }, + { + "name": "unit", + "type": "Attributes", + "description": "Information related to the tenant unit. Provide its ID and omit `standalone` to create the Account within an Organization. See https://developers.cloudflare.com/tenant/how-to/manage-accounts/.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Tenant unit ID" + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the account" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + "data-source:cloudflare_account_api_token_permission_groups": { + "kind": "data-source", + "name": "cloudflare_account_api_token_permission_groups", + "description": "Accepted Permissions\n\n- `Account API Tokens Read`\n- `Account API Tokens Write`", + "example": "data \"cloudflare_account_api_token_permission_groups\" \"example_account_api_token_permission_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "Filter by the name of the permission group.\nThe value must be URL-encoded." + }, + { + "name": "scope", + "type": "String", + "description": "Filter by the scope of the permission group.\nThe value must be URL-encoded." + } + ], + "computed": [ + { + "name": "permission_groups", + "type": "Attributes List", + "children": [ + { + "name": "category", + "type": "String", + "description": "Product category that this permission group belongs to.\nAvailable values: \"developer_platform\", \"ai_and_machine_learning\", \"dns_and_zones\", \"app_security\", \"rules_and_configuration\", \"cloudflare_one_and_zero_trust\", \"analytics_and_logs\", \"network_services\", \"media\", \"email_and_messaging\", \"cache_and_performance\", \"account_and_billing\", \"other\"." + }, + { + "name": "id", + "type": "String", + "description": "Public ID." + }, + { + "name": "is_selectable", + "type": "Boolean", + "description": "Whether the caller can select this permission group when creating a token." + }, + { + "name": "name", + "type": "String", + "description": "Permission Group Name" + }, + { + "name": "scopes", + "type": "List of String", + "description": "Resources to which the Permission Group is scoped" + } + ] + } + ] + }, + "list-data-source:cloudflare_account_api_token_permission_groups_list": { + "kind": "list-data-source", + "name": "cloudflare_account_api_token_permission_groups_list", + "description": "Accepted Permissions\n\n- `Account API Tokens Read`\n- `Account API Tokens Write`", + "example": "data \"cloudflare_account_api_token_permission_groups_list\" \"example_account_api_token_permission_groups_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Filter by the name of the permission group.\nThe value must be URL-encoded." + }, + { + "name": "scope", + "type": "String", + "description": "Filter by the scope of the permission group.\nThe value must be URL-encoded." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "category", + "type": "String", + "description": "Product category that this permission group belongs to.\nAvailable values: \"developer_platform\", \"ai_and_machine_learning\", \"dns_and_zones\", \"app_security\", \"rules_and_configuration\", \"cloudflare_one_and_zero_trust\", \"analytics_and_logs\", \"network_services\", \"media\", \"email_and_messaging\", \"cache_and_performance\", \"account_and_billing\", \"other\"." + }, + { + "name": "id", + "type": "String", + "description": "Public ID." + }, + { + "name": "is_selectable", + "type": "Boolean", + "description": "Whether the caller can select this permission group when creating a token." + }, + { + "name": "name", + "type": "String", + "description": "Permission Group Name" + }, + { + "name": "scopes", + "type": "List of String", + "description": "Resources to which the Permission Group is scoped" + } + ] + } + ] + }, + "data-source:cloudflare_account_dns_settings": { + "kind": "data-source", + "name": "cloudflare_account_dns_settings", + "description": "Accepted Permissions\n\n- `Account DNS Settings Read`\n- `Account DNS Settings Write`", + "example": "data \"cloudflare_account_dns_settings\" \"example_account_dns_settings\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "enforce_dns_only", + "type": "Boolean", + "description": "When enabled, forces all proxied DNS records in the account to behave as DNS-only at the edge, regardless of each record's individual proxy setting. Note that this account-level override does not modify the records themselves; it only affects how they are served at the edge. See more on [Enforce DNS-only](https://developers.cloudflare.com/dns/proxy-status/enforce-dns-only)." + }, + { + "name": "zone_defaults", + "type": "Attributes", + "description": "Default settings for new zones created in this account.", + "children": [ + { + "name": "flatten_all_cnames", + "type": "Boolean", + "description": "Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened." + }, + { + "name": "foundation_dns", + "type": "Boolean", + "description": "Whether to enable Foundation DNS Advanced Nameservers on the zone." + }, + { + "name": "internal_dns", + "type": "Attributes", + "description": "Settings for this internal zone.", + "children": [ + { + "name": "reference_zone_id", + "type": "String", + "description": "The ID of the zone to fallback to." + } + ] + }, + { + "name": "multi_provider", + "type": "Boolean", + "description": "Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers." + }, + { + "name": "nameservers", + "type": "Attributes", + "description": "Settings determining the nameservers through which the zone should be available.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Nameserver type\nAvailable values: \"cloudflare.standard\", \"cloudflare.standard.random\", \"custom.account\", \"custom.tenant\"." + } + ] + }, + { + "name": "ns_ttl", + "type": "Number", + "description": "The time to live (TTL) of the zone's nameserver (NS) records." + }, + { + "name": "secondary_overrides", + "type": "Boolean", + "description": "Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex." + }, + { + "name": "soa", + "type": "Attributes", + "description": "Components of the zone's SOA record.", + "children": [ + { + "name": "expire", + "type": "Number", + "description": "Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone." + }, + { + "name": "min_ttl", + "type": "Number", + "description": "The time to live (TTL) for negative caching of records within the zone." + }, + { + "name": "mname", + "type": "String", + "description": "The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used." + }, + { + "name": "refresh", + "type": "Number", + "description": "Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated." + }, + { + "name": "retry", + "type": "Number", + "description": "Time in seconds after which secondary servers should retry queries after the primary server was unresponsive." + }, + { + "name": "rname", + "type": "String", + "description": "The email address of the zone administrator, with the first label representing the local part of the email address." + }, + { + "name": "ttl", + "type": "Number", + "description": "The time to live (TTL) of the SOA record itself." + } + ] + }, + { + "name": "zone_mode", + "type": "String", + "description": "Whether the zone mode is a regular or CDN/DNS only zone.\nAvailable values: \"standard\", \"cdn_only\", \"dns_only\"." + } + ] + } + ] + }, + "resource:cloudflare_account_dns_settings": { + "kind": "resource", + "name": "cloudflare_account_dns_settings", + "description": "Accepted Permissions\n\n- `Account DNS Settings Read`\n- `Account DNS Settings Write`", + "example": "resource \"cloudflare_account_dns_settings\" \"example_account_dns_settings\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enforce_dns_only = false\n zone_defaults = {\n flatten_all_cnames = false\n foundation_dns = false\n internal_dns = {\n reference_zone_id = \"reference_zone_id\"\n }\n multi_provider = false\n nameservers = {\n type = \"cloudflare.standard\"\n }\n ns_ttl = 86400\n secondary_overrides = false\n soa = {\n expire = 604800\n min_ttl = 1800\n mname = \"kristina.ns.cloudflare.com\"\n refresh = 10000\n retry = 2400\n rname = \"admin.example.com\"\n ttl = 3600\n }\n zone_mode = \"dns_only\"\n }\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "enforce_dns_only", + "type": "Boolean", + "description": "When enabled, forces all proxied DNS records in the account to behave as DNS-only at the edge, regardless of each record's individual proxy setting. Note that this account-level override does not modify the records themselves; it only affects how they are served at the edge. See more on [Enforce DNS-only](https://developers.cloudflare.com/dns/proxy-status/enforce-dns-only)." + }, + { + "name": "zone_defaults", + "type": "Attributes", + "description": "Default settings for new zones created in this account.", + "children": [ + { + "name": "flatten_all_cnames", + "type": "Boolean", + "description": "Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened." + }, + { + "name": "foundation_dns", + "type": "Boolean", + "description": "Whether to enable Foundation DNS Advanced Nameservers on the zone." + }, + { + "name": "internal_dns", + "type": "Attributes", + "description": "Settings for this internal zone.", + "children": [ + { + "name": "reference_zone_id", + "type": "String", + "description": "The ID of the zone to fallback to." + } + ] + }, + { + "name": "multi_provider", + "type": "Boolean", + "description": "Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers." + }, + { + "name": "nameservers", + "type": "Attributes", + "description": "Settings determining the nameservers through which the zone should be available.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Nameserver type\nAvailable values: \"cloudflare.standard\", \"cloudflare.standard.random\", \"custom.account\", \"custom.tenant\"." + } + ] + }, + { + "name": "ns_ttl", + "type": "Number", + "description": "The time to live (TTL) of the zone's nameserver (NS) records." + }, + { + "name": "secondary_overrides", + "type": "Boolean", + "description": "Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex." + }, + { + "name": "soa", + "type": "Attributes", + "description": "Components of the zone's SOA record.", + "children": [ + { + "name": "expire", + "type": "Number", + "description": "Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone." + }, + { + "name": "min_ttl", + "type": "Number", + "description": "The time to live (TTL) for negative caching of records within the zone." + }, + { + "name": "mname", + "type": "String", + "description": "The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used." + }, + { + "name": "refresh", + "type": "Number", + "description": "Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated." + }, + { + "name": "retry", + "type": "Number", + "description": "Time in seconds after which secondary servers should retry queries after the primary server was unresponsive." + }, + { + "name": "rname", + "type": "String", + "description": "The email address of the zone administrator, with the first label representing the local part of the email address." + }, + { + "name": "ttl", + "type": "Number", + "description": "The time to live (TTL) of the SOA record itself." + } + ] + }, + { + "name": "zone_mode", + "type": "String", + "description": "Whether the zone mode is a regular or CDN/DNS only zone.\nAvailable values: \"standard\", \"cdn_only\", \"dns_only\"." + } + ] + } + ], + "computed": [] + }, + "data-source:cloudflare_account_dns_settings_internal_view": { + "kind": "data-source", + "name": "cloudflare_account_dns_settings_internal_view", + "description": "Accepted Permissions\n\n- `DNS View Read`\n- `DNS View Write`", + "example": "data \"cloudflare_account_dns_settings_internal_view\" \"example_account_dns_settings_internal_view\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n view_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order DNS views in.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "name", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS view name." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS view name." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS view name." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS view name." + } + ] + }, + { + "name": "order", + "type": "String", + "description": "Field to order DNS views by.\nAvailable values: \"name\", \"created_on\", \"modified_on\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "A zone ID that exists in the zones list for the view." + }, + { + "name": "zone_name", + "type": "String", + "description": "A zone name that exists in the zones list for the view." + } + ] + }, + { + "name": "view_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_time", + "type": "String", + "description": "When the view was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_time", + "type": "String", + "description": "When the view was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the view." + }, + { + "name": "zones", + "type": "Set of String", + "description": "The list of zones linked to this view." + } + ] + }, + "resource:cloudflare_account_dns_settings_internal_view": { + "kind": "resource", + "name": "cloudflare_account_dns_settings_internal_view", + "description": "Accepted Permissions\n\n- `DNS View Read`\n- `DNS View Write`", + "example": "resource \"cloudflare_account_dns_settings_internal_view\" \"example_account_dns_settings_internal_view\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my view\"\n zones = [\"372e67954025e0ba6aaa6d586b9e0b59\"]\n}", + "importExample": "$ terraform import cloudflare_account_dns_settings_internal_view.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "The name of the view." + }, + { + "name": "zones", + "type": "Set of String", + "description": "The list of zones linked to this view." + } + ], + "optional": [], + "computed": [ + { + "name": "created_time", + "type": "String", + "description": "When the view was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_time", + "type": "String", + "description": "When the view was last modified." + } + ] + }, + "list-data-source:cloudflare_account_dns_settings_internal_views": { + "kind": "list-data-source", + "name": "cloudflare_account_dns_settings_internal_views", + "description": "Accepted Permissions\n\n- `DNS View Read`\n- `DNS View Write`", + "example": "data \"cloudflare_account_dns_settings_internal_views\" \"example_account_dns_settings_internal_views\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = {\n contains = \"view\"\n endswith = \"ew\"\n exact = \"my view\"\n startswith = \"my\"\n }\n order = \"name\"\n zone_id = \"ae29bea30e2e427ba9cd8d78b628177b\"\n zone_name = \"www.example.com\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order DNS views in.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS view name." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS view name." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS view name." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS view name." + } + ] + }, + { + "name": "order", + "type": "String", + "description": "Field to order DNS views by.\nAvailable values: \"name\", \"created_on\", \"modified_on\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "A zone ID that exists in the zones list for the view." + }, + { + "name": "zone_name", + "type": "String", + "description": "A zone name that exists in the zones list for the view." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_time", + "type": "String", + "description": "When the view was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_time", + "type": "String", + "description": "When the view was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the view." + }, + { + "name": "zones", + "type": "Set of String", + "description": "The list of zones linked to this view." + } + ] + } + ] + }, + "data-source:cloudflare_account_member": { + "kind": "data-source", + "name": "cloudflare_account_member", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_account_member\" \"example_account_member\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n member_id = \"4536bcfad5faccb111b47003c79917fa\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order", + "type": "String", + "description": "Field to order results by.\nAvailable values: \"user.first_name\", \"user.last_name\", \"user.email\", \"status\"." + }, + { + "name": "status", + "type": "String", + "description": "A member's status in the account.\nAvailable values: \"accepted\", \"pending\", \"rejected\"." + } + ] + }, + { + "name": "member_id", + "type": "String", + "description": "Membership identifier tag." + } + ], + "computed": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Membership identifier tag." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "Access policy for the membership", + "children": [ + { + "name": "access", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resource_groups", + "type": "Attributes List", + "description": "A list of resource groups that the policy applies to.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the resource group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the resource group.", + "children": [ + { + "name": "key", + "type": "String" + }, + { + "name": "value", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the resource group." + }, + { + "name": "scope", + "type": "Attributes List", + "description": "The scope associated to the resource group", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Account ID etc.)" + }, + { + "name": "objects", + "type": "Attributes List", + "description": "A list of scope objects for additional context.", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Zone ID etc.)" + } + ] + } + ] + } + ] + } + ] + }, + { + "name": "roles", + "type": "Attributes List", + "description": "Roles assigned to this Member.", + "children": [ + { + "name": "description", + "type": "String", + "description": "Description of role's permissions." + }, + { + "name": "id", + "type": "String", + "description": "Role identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "Role name." + }, + { + "name": "permissions", + "type": "Attributes", + "children": [ + { + "name": "analytics", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "billing", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "cache_purge", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns_records", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "lb", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "organization", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "ssl", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "waf", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zone_settings", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zones", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + } + ] + } + ] + }, + { + "name": "status", + "type": "String", + "description": "A member's status in the account.\nAvailable values: \"accepted\", \"pending\"." + }, + { + "name": "user", + "type": "Attributes", + "description": "Details of the user associated to the membership.", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "first_name", + "type": "String", + "description": "User's first name" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "last_name", + "type": "String", + "description": "User's last name" + }, + { + "name": "two_factor_authentication_enabled", + "type": "Boolean", + "description": "Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication." + } + ] + } + ] + }, + "resource:cloudflare_account_member": { + "kind": "resource", + "name": "cloudflare_account_member", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "resource \"cloudflare_account_member\" \"example_account_member\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"user@example.com\"\n roles = [\"3536bcfad5faccb999b47003c79917fb\"]\n status = \"accepted\"\n}", + "importExample": "$ terraform import cloudflare_account_member.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + } + ], + "optional": [ + { + "name": "policies", + "type": "Attributes Set", + "description": "Array of policies associated with this member.", + "children": [ + { + "name": "access", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "permission_groups", + "type": "Attributes Set", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the group." + } + ] + }, + { + "name": "resource_groups", + "type": "Attributes Set", + "description": "A list of resource groups that the policy applies to.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the group." + } + ] + } + ] + }, + { + "name": "roles", + "type": "Set of String", + "description": "Set of roles associated with this member." + }, + { + "name": "status", + "type": "String", + "description": "Status of the member invitation. If not provided during creation, defaults to 'pending'.\nChanging from 'accepted' back to 'pending' will trigger a replacement of the member resource in Terraform.\nAvailable values: \"accepted\", \"pending\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Membership identifier tag." + }, + { + "name": "user", + "type": "Attributes", + "description": "Details of the user associated to the membership.", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "first_name", + "type": "String", + "description": "User's first name" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "last_name", + "type": "String", + "description": "User's last name" + }, + { + "name": "two_factor_authentication_enabled", + "type": "Boolean", + "description": "Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication." + } + ] + } + ] + }, + "list-data-source:cloudflare_account_members": { + "kind": "list-data-source", + "name": "cloudflare_account_members", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_account_members\" \"example_account_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n order = \"status\"\n status = \"accepted\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to order results by.\nAvailable values: \"user.first_name\", \"user.last_name\", \"user.email\", \"status\"." + }, + { + "name": "status", + "type": "String", + "description": "A member's status in the account.\nAvailable values: \"accepted\", \"pending\", \"rejected\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Membership identifier tag." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "Access policy for the membership", + "children": [ + { + "name": "access", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resource_groups", + "type": "Attributes List", + "description": "A list of resource groups that the policy applies to.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the resource group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the resource group.", + "children": [ + { + "name": "key", + "type": "String" + }, + { + "name": "value", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the resource group." + }, + { + "name": "scope", + "type": "Attributes List", + "description": "The scope associated to the resource group", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Account ID etc.)" + }, + { + "name": "objects", + "type": "Attributes List", + "description": "A list of scope objects for additional context.", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Zone ID etc.)" + } + ] + } + ] + } + ] + } + ] + }, + { + "name": "roles", + "type": "Attributes List", + "description": "Roles assigned to this Member.", + "children": [ + { + "name": "description", + "type": "String", + "description": "Description of role's permissions." + }, + { + "name": "id", + "type": "String", + "description": "Role identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "Role name." + }, + { + "name": "permissions", + "type": "Attributes", + "children": [ + { + "name": "analytics", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "billing", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "cache_purge", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns_records", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "lb", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "organization", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "ssl", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "waf", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zone_settings", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zones", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + } + ] + } + ] + }, + { + "name": "status", + "type": "String", + "description": "A member's status in the account.\nAvailable values: \"accepted\", \"pending\"." + }, + { + "name": "user", + "type": "Attributes", + "description": "Details of the user associated to the membership.", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "first_name", + "type": "String", + "description": "User's first name" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "last_name", + "type": "String", + "description": "User's last name" + }, + { + "name": "two_factor_authentication_enabled", + "type": "Boolean", + "description": "Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_account_permission_group": { + "kind": "data-source", + "name": "cloudflare_account_permission_group", + "description": "Accepted Permissions\n\n- `Account Firewall Access Rules Read`\n- `Account Firewall Access Rules Write`\n- `Account Settings Read`\n- `Account Settings Write`\n- `Billing Read`\n- `Billing Write`\n- `DDoS Botnet Feed Read`\n- `DDoS Botnet Feed Write`\n- `DDoS Protection Read`\n- `DDoS Protection Write`\n- `DNS Firewall Read`\n- `DNS Firewall Write`\n- `DNS View Read`\n- `DNS View Write`\n- `Load Balancers Account Read`\n- `Load Balancers Account Write`\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`\n- `SCIM Provisioning`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_account_permission_group\" \"example_account_permission_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n permission_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "permission_group_id", + "type": "String", + "description": "Permission Group identifier tag." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + "list-data-source:cloudflare_account_permission_groups": { + "kind": "list-data-source", + "name": "cloudflare_account_permission_groups", + "description": "Accepted Permissions\n\n- `Account Firewall Access Rules Read`\n- `Account Firewall Access Rules Write`\n- `Account Settings Read`\n- `Account Settings Write`\n- `Billing Read`\n- `Billing Write`\n- `DDoS Botnet Feed Read`\n- `DDoS Botnet Feed Write`\n- `DDoS Protection Read`\n- `DDoS Protection Write`\n- `DNS Firewall Read`\n- `DNS Firewall Write`\n- `DNS View Read`\n- `DNS View Write`\n- `Load Balancers Account Read`\n- `Load Balancers Account Write`\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`\n- `SCIM Provisioning`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_account_permission_groups\" \"example_account_permission_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"6d7f2f5f5b1d4a0e9081fdc98d432fd1\"\n label = \"labelOfThePermissionGroup\"\n name = \"NameOfThePermissionGroup\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "id", + "type": "String", + "description": "ID of the permission group to be fetched." + }, + { + "name": "label", + "type": "String", + "description": "Label of the permission group to be fetched." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group to be fetched." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + } + ] + }, + "data-source:cloudflare_account_role": { + "kind": "data-source", + "name": "cloudflare_account_role", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_account_role\" \"example_account_role\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n role_id = \"3536bcfad5faccb999b47003c79917fb\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "role_id", + "type": "String", + "description": "Role identifier tag." + } + ], + "optional": [], + "computed": [ + { + "name": "description", + "type": "String", + "description": "Description of role's permissions." + }, + { + "name": "id", + "type": "String", + "description": "Role identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "Role name." + }, + { + "name": "permissions", + "type": "Attributes", + "children": [ + { + "name": "analytics", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "billing", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "cache_purge", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns_records", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "lb", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "organization", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "ssl", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "waf", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zone_settings", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zones", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + } + ] + } + ] + }, + "list-data-source:cloudflare_account_roles": { + "kind": "list-data-source", + "name": "cloudflare_account_roles", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_account_roles\" \"example_account_roles\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "Description of role's permissions." + }, + { + "name": "id", + "type": "String", + "description": "Role identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "Role name." + }, + { + "name": "permissions", + "type": "Attributes", + "children": [ + { + "name": "analytics", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "billing", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "cache_purge", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "dns_records", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "lb", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "organization", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "ssl", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "waf", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zone_settings", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + }, + { + "name": "zones", + "type": "Attributes", + "children": [ + { + "name": "read", + "type": "Boolean" + }, + { + "name": "write", + "type": "Boolean" + } + ] + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_account_subscription": { + "kind": "data-source", + "name": "cloudflare_account_subscription", + "description": "Accepted Permissions\n\n- `Billing Read`\n- `Billing Write`", + "example": "data \"cloudflare_account_subscription\" \"example_account_subscription\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "currency", + "type": "String", + "description": "The monetary unit in which pricing information is displayed." + }, + { + "name": "current_period_end", + "type": "String", + "description": "The end of the current period and also when the next billing is due." + }, + { + "name": "current_period_start", + "type": "String", + "description": "When the current billing period started. May match initial_period_start if this is the first period." + }, + { + "name": "frequency", + "type": "String", + "description": "How often the subscription is renewed automatically.\nAvailable values: \"weekly\", \"monthly\", \"quarterly\", \"yearly\"." + }, + { + "name": "id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + }, + { + "name": "price", + "type": "Number", + "description": "The price of the subscription that will be billed, in US dollars." + }, + { + "name": "rate_plan", + "type": "Attributes", + "description": "The rate plan applied to the subscription.", + "children": [ + { + "name": "currency", + "type": "String", + "description": "The currency applied to the rate plan subscription." + }, + { + "name": "externally_managed", + "type": "Boolean", + "description": "Whether this rate plan is managed externally from Cloudflare." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the rate plan.\nAvailable values: \"free\", \"lite\", \"pro\", \"pro_plus\", \"business\", \"enterprise\", \"partners_free\", \"partners_pro\", \"partners_business\", \"partners_ent\"." + }, + { + "name": "is_contract", + "type": "Boolean", + "description": "Whether a rate plan is enterprise-based (or newly adopted term contract)." + }, + { + "name": "public_name", + "type": "String", + "description": "The full name of the rate plan." + }, + { + "name": "scope", + "type": "String", + "description": "The scope that this rate plan applies to." + }, + { + "name": "sets", + "type": "List of String", + "description": "The list of sets this rate plan applies to. Returns array of strings." + } + ] + }, + { + "name": "state", + "type": "String", + "description": "The state that the subscription is in.\nAvailable values: \"Trial\", \"Provisioned\", \"Paid\", \"AwaitingPayment\", \"Cancelled\", \"Failed\", \"Expired\"." + } + ] + }, + "resource:cloudflare_account_subscription": { + "kind": "resource", + "name": "cloudflare_account_subscription", + "description": "Accepted Permissions\n\n- `Billing Read`\n- `Billing Write`", + "example": "resource \"cloudflare_account_subscription\" \"example_account_subscription\" {\n account_id = \"account_id\"\n frequency = \"monthly\"\n rate_plan = {\n id = \"free\"\n currency = \"USD\"\n externally_managed = false\n is_contract = false\n public_name = \"Business Plan\"\n scope = \"zone\"\n sets = [\"string\"]\n }\n}", + "importExample": "$ terraform import cloudflare_account_subscription.example '/'", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "frequency", + "type": "String", + "description": "How often the subscription is renewed automatically.\nAvailable values: \"weekly\", \"monthly\", \"quarterly\", \"yearly\"." + }, + { + "name": "rate_plan", + "type": "Attributes", + "description": "The rate plan applied to the subscription.", + "children": [ + { + "name": "currency", + "type": "String", + "description": "The currency applied to the rate plan subscription." + }, + { + "name": "externally_managed", + "type": "Boolean", + "description": "Whether this rate plan is managed externally from Cloudflare." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the rate plan." + }, + { + "name": "is_contract", + "type": "Boolean", + "description": "Whether a rate plan is enterprise-based (or newly adopted term contract)." + }, + { + "name": "public_name", + "type": "String", + "description": "The full name of the rate plan." + }, + { + "name": "scope", + "type": "String", + "description": "The scope that this rate plan applies to." + }, + { + "name": "sets", + "type": "List of String", + "description": "The list of sets this rate plan applies to. Returns array of strings." + } + ] + } + ], + "computed": [ + { + "name": "currency", + "type": "String", + "description": "The monetary unit in which pricing information is displayed." + }, + { + "name": "current_period_end", + "type": "String", + "description": "The end of the current period and also when the next billing is due." + }, + { + "name": "current_period_start", + "type": "String", + "description": "When the current billing period started. May match initial_period_start if this is the first period." + }, + { + "name": "id", + "type": "String", + "description": "Subscription identifier tag." + }, + { + "name": "price", + "type": "Number", + "description": "The price of the subscription that will be billed, in US dollars." + }, + { + "name": "state", + "type": "String", + "description": "The state that the subscription is in.\nAvailable values: \"Trial\", \"Provisioned\", \"Paid\", \"AwaitingPayment\", \"Cancelled\", \"Failed\", \"Expired\"." + } + ] + }, + "data-source:cloudflare_account_token": { + "kind": "data-source", + "name": "cloudflare_account_token", + "description": "Accepted Permissions\n\n- `Account API Tokens Read`\n- `Account API Tokens Write`", + "example": "data \"cloudflare_account_token\" \"example_account_token\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n token_id = \"ed17574386854bf78a67040be0a770b0\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "include_expired", + "type": "Boolean", + "description": "When true, includes recently-expired tokens in the response." + } + ] + }, + { + "name": "token_id", + "type": "String", + "description": "Token identifier tag." + } + ], + "computed": [ + { + "name": "condition", + "type": "Attributes", + "children": [ + { + "name": "request_ip", + "type": "Attributes", + "description": "Client IP restrictions.", + "children": [ + { + "name": "in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + }, + { + "name": "not_in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + } + ] + } + ] + }, + { + "name": "creator_email_at_creation", + "type": "String", + "description": "The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available." + }, + { + "name": "expires_on", + "type": "String", + "description": "The expiration time on or after which the JWT MUST NOT be accepted for processing." + }, + { + "name": "id", + "type": "String", + "description": "Token identifier tag." + }, + { + "name": "issued_on", + "type": "String", + "description": "The time on which the token was created." + }, + { + "name": "last_used_on", + "type": "String", + "description": "Last time the token was used." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the token was modified." + }, + { + "name": "name", + "type": "String", + "description": "Token name." + }, + { + "name": "not_before", + "type": "String", + "description": "The time before which the token MUST NOT be accepted for processing." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "List of access policies assigned to the token.", + "children": [ + { + "name": "effect", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resources", + "type": "Map of String", + "description": "A list of resource names that the policy applies to." + } + ] + }, + { + "name": "provisioner_id", + "type": "String", + "description": "The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable." + }, + { + "name": "provisioner_type", + "type": "String", + "description": "The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens." + }, + { + "name": "status", + "type": "String", + "description": "Status of the token.\nAvailable values: \"active\", \"disabled\", \"expired\"." + } + ] + }, + "resource:cloudflare_account_token": { + "kind": "resource", + "name": "cloudflare_account_token", + "description": "Accepted Permissions\n\n- `Account API Tokens Read`\n- `Account API Tokens Write`", + "example": "resource \"cloudflare_account_token\" \"example_account_token\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"readonly token\"\n policies = [{\n effect = \"allow\"\n permission_groups = [{\n id = \"c8fed203ed3043cba015a93ad1616f1f\"\n }, {\n id = \"82e64a83756745bbbb1c9c2701bf816b\"\n }]\n resources = jsonencode({\n \"com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43\" = \"*\"\n })\n }]\n condition = {\n request_ip = {\n in = [\"123.123.123.0/24\", \"2606:4700::/32\"]\n not_in = [\"123.123.123.100/24\", \"2606:4700:4700::/48\"]\n }\n }\n expires_on = \"2020-01-01T00:00:00Z\"\n not_before = \"2018-07-01T05:20:00Z\"\n}", + "importExample": "$ terraform import cloudflare_account_token.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "Token name." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "List of access policies assigned to the token.", + "children": [ + { + "name": "effect", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + } + ] + }, + { + "name": "resources", + "type": "String", + "description": "A json object representing the resources that are specified to the policy." + } + ] + } + ], + "optional": [ + { + "name": "condition", + "type": "Attributes", + "children": [ + { + "name": "request_ip", + "type": "Attributes", + "description": "Client IP restrictions.", + "children": [ + { + "name": "in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + }, + { + "name": "not_in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + } + ] + } + ] + }, + { + "name": "expires_on", + "type": "String", + "description": "The expiration time on or after which the JWT MUST NOT be accepted for processing." + }, + { + "name": "not_before", + "type": "String", + "description": "The time before which the token MUST NOT be accepted for processing." + }, + { + "name": "status", + "type": "String", + "description": "Status of the token.\nAvailable values: \"active\", \"disabled\", \"expired\"." + } + ], + "computed": [ + { + "name": "creator_email_at_creation", + "type": "String", + "description": "The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available." + }, + { + "name": "id", + "type": "String", + "description": "Token identifier tag." + }, + { + "name": "issued_on", + "type": "String", + "description": "The time on which the token was created." + }, + { + "name": "last_used_on", + "type": "String", + "description": "Last time the token was used." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the token was modified." + }, + { + "name": "provisioner_id", + "type": "String", + "description": "The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable." + }, + { + "name": "provisioner_type", + "type": "String", + "description": "The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens." + }, + { + "name": "value", + "type": "String", + "description": "The token value.", + "sensitive": true + } + ] + }, + "list-data-source:cloudflare_account_tokens": { + "kind": "list-data-source", + "name": "cloudflare_account_tokens", + "description": "Accepted Permissions\n\n- `Account API Tokens Read`\n- `Account API Tokens Write`", + "example": "data \"cloudflare_account_tokens\" \"example_account_tokens\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "include_expired", + "type": "Boolean", + "description": "When true, includes recently-expired tokens in the response." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "condition", + "type": "Attributes", + "children": [ + { + "name": "request_ip", + "type": "Attributes", + "description": "Client IP restrictions.", + "children": [ + { + "name": "in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + }, + { + "name": "not_in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + } + ] + } + ] + }, + { + "name": "creator_email_at_creation", + "type": "String", + "description": "The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available." + }, + { + "name": "expires_on", + "type": "String", + "description": "The expiration time on or after which the JWT MUST NOT be accepted for processing." + }, + { + "name": "id", + "type": "String", + "description": "Token identifier tag." + }, + { + "name": "issued_on", + "type": "String", + "description": "The time on which the token was created." + }, + { + "name": "last_used_on", + "type": "String", + "description": "Last time the token was used." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the token was modified." + }, + { + "name": "name", + "type": "String", + "description": "Token name." + }, + { + "name": "not_before", + "type": "String", + "description": "The time before which the token MUST NOT be accepted for processing." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "List of access policies assigned to the token.", + "children": [ + { + "name": "effect", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resources", + "type": "Map of String", + "description": "A list of resource names that the policy applies to." + } + ] + }, + { + "name": "provisioner_id", + "type": "String", + "description": "The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable." + }, + { + "name": "provisioner_type", + "type": "String", + "description": "The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens." + }, + { + "name": "status", + "type": "String", + "description": "Status of the token.\nAvailable values: \"active\", \"disabled\", \"expired\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_accounts": { + "kind": "list-data-source", + "name": "cloudflare_accounts", + "example": "data \"cloudflare_accounts\" \"example_accounts\" {\n direction = \"desc\"\n name = \"example.com\"\n}", + "required": [], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Name of the account." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the account" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "managed_by", + "type": "Attributes", + "description": "Parent container details", + "children": [ + { + "name": "parent_org_id", + "type": "String", + "description": "ID of the parent Organization, if one exists" + }, + { + "name": "parent_org_name", + "type": "String", + "description": "Name of the parent Organization, if one exists" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Account name" + }, + { + "name": "settings", + "type": "Attributes", + "description": "Account settings", + "children": [ + { + "name": "abuse_contact_email", + "type": "String", + "description": "Sets an abuse contact email to notify for abuse reports." + }, + { + "name": "enforce_twofactor", + "type": "Boolean", + "description": "Indicates whether membership in this account requires that\nTwo-Factor Authentication is enabled" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"standard\", \"enterprise\"." + } + ] + } + ] + }, + "data-source:cloudflare_address_map": { + "kind": "data-source", + "name": "cloudflare_address_map", + "description": "Accepted Permissions\n\n- `Address Maps Read`\n- `Address Maps Write`", + "example": "data \"cloudflare_address_map\" \"example_address_map\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n address_map_id = \"055817b111884e0227e1be16a0be6ee0\"\n}", + "required": [ + { + "name": "address_map_id", + "type": "String", + "description": "Identifier of an Address Map." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + } + ], + "computed": [ + { + "name": "can_delete", + "type": "Boolean", + "description": "If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps." + }, + { + "name": "can_modify_ips", + "type": "Boolean", + "description": "If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "default_sni", + "type": "String", + "description": "If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account." + }, + { + "name": "description", + "type": "String", + "description": "An optional description field which may be used to describe the types of IPs or zones on the map." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of an Address Map." + }, + { + "name": "ips", + "type": "Attributes List", + "description": "The set of IPs on the Address Map.", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 address." + } + ] + }, + { + "name": "memberships", + "type": "Attributes List", + "description": "Zones and Accounts which will be assigned IPs on this Address Map. A zone membership will take priority over an account membership.", + "children": [ + { + "name": "can_delete", + "type": "Boolean", + "description": "Controls whether the membership can be deleted via the API or not." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "identifier", + "type": "String", + "description": "The identifier for the membership (eg. a zone or account tag)." + }, + { + "name": "kind", + "type": "String", + "description": "The type of the membership.\nAvailable values: \"zone\", \"account\"." + } + ] + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "resource:cloudflare_address_map": { + "kind": "resource", + "name": "cloudflare_address_map", + "description": "Accepted Permissions\n\n- `Address Maps Read`\n- `Address Maps Write`", + "example": "resource \"cloudflare_address_map\" \"example_address_map\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n description = \"My Ecommerce zones\"\n enabled = true\n ips = [\"192.0.2.1\"]\n memberships = [{\n identifier = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"zone\"\n }]\n}", + "importExample": "$ terraform import cloudflare_address_map.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + } + ], + "optional": [ + { + "name": "default_sni", + "type": "String", + "description": "If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account." + }, + { + "name": "description", + "type": "String", + "description": "An optional description field which may be used to describe the types of IPs or zones on the map." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled." + }, + { + "name": "ips", + "type": "List of String" + }, + { + "name": "memberships", + "type": "Attributes List", + "description": "Zones and Accounts which will be assigned IPs on this Address Map. A zone membership will take priority over an account membership.", + "children": [ + { + "name": "identifier", + "type": "String", + "description": "The identifier for the membership (eg. a zone or account tag)." + }, + { + "name": "kind", + "type": "String", + "description": "The type of the membership.\nAvailable values: \"zone\", \"account\"." + } + ] + } + ], + "computed": [ + { + "name": "can_delete", + "type": "Boolean", + "description": "If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps." + }, + { + "name": "can_modify_ips", + "type": "Boolean", + "description": "If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier of an Address Map." + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_address_maps": { + "kind": "list-data-source", + "name": "cloudflare_address_maps", + "description": "Accepted Permissions\n\n- `Address Maps Read`\n- `Address Maps Write`", + "example": "data \"cloudflare_address_maps\" \"example_address_maps\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "can_delete", + "type": "Boolean", + "description": "If set to false, then the Address Map cannot be deleted via API. This is true for Cloudflare-managed maps." + }, + { + "name": "can_modify_ips", + "type": "Boolean", + "description": "If set to false, then the IPs on the Address Map cannot be modified via the API. This is true for Cloudflare-managed maps." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "default_sni", + "type": "String", + "description": "If you have legacy TLS clients which do not send the TLS server name indicator, then you can specify one default SNI on the map. If Cloudflare receives a TLS handshake from a client without an SNI, it will respond with the default SNI on those IPs. The default SNI can be any valid zone or subdomain owned by the account." + }, + { + "name": "description", + "type": "String", + "description": "An optional description field which may be used to describe the types of IPs or zones on the map." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Address Map is enabled or not. Cloudflare's DNS will not respond with IP addresses on an Address Map until the map is enabled." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of an Address Map." + }, + { + "name": "modified_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_ai_gateway": { + "kind": "data-source", + "name": "cloudflare_ai_gateway", + "description": "Accepted Permissions\n\n- `AI Gateway Read`\n- `AI Gateway Write`", + "example": "data \"cloudflare_ai_gateway\" \"example_ai_gateway\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n id = \"my-gateway\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "search", + "type": "String", + "description": "Search by id" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier of the AI Gateway within the account." + } + ], + "computed": [ + { + "name": "authentication", + "type": "Boolean" + }, + { + "name": "byok_only", + "type": "Boolean", + "description": "Requires customer-provided provider credentials and prevents fallback to Unified Billing." + }, + { + "name": "cache_invalidate_on_update", + "type": "Boolean" + }, + { + "name": "cache_ttl", + "type": "Number" + }, + { + "name": "collect_logs", + "type": "Boolean" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dlp", + "type": "Attributes", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"BLOCK\", \"FLAG\"." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "policies", + "type": "Attributes List", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "check", + "type": "List of String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "profiles", + "type": "List of String" + } + ] + }, + { + "name": "profiles", + "type": "List of String" + } + ] + }, + { + "name": "guardrails", + "type": "Attributes", + "children": [ + { + "name": "prompt", + "type": "Attributes", + "children": [ + { + "name": "p1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s10", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s11", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s12", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s13", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s2", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s3", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s4", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s5", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s6", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s7", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s8", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s9", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + } + ] + }, + { + "name": "response", + "type": "Attributes", + "children": [ + { + "name": "p1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s10", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s11", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s12", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s13", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s2", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s3", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s4", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s5", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s6", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s7", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s8", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s9", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + } + ] + } + ] + }, + { + "name": "is_default", + "type": "Boolean" + }, + { + "name": "log_classification", + "type": "Boolean" + }, + { + "name": "log_management", + "type": "Number" + }, + { + "name": "log_management_strategy", + "type": "String", + "description": "Available values: \"STOP_INSERTING\", \"DELETE_OLDEST\"." + }, + { + "name": "logpush", + "type": "Boolean" + }, + { + "name": "logpush_public_key", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "otel", + "type": "Attributes List", + "children": [ + { + "name": "authorization", + "type": "String" + }, + { + "name": "content_type", + "type": "String", + "description": "Available values: \"json\", \"protobuf\"." + }, + { + "name": "headers", + "type": "Map of String" + }, + { + "name": "url", + "type": "String" + } + ] + }, + { + "name": "rate_limiting_interval", + "type": "Number" + }, + { + "name": "rate_limiting_limit", + "type": "Number" + }, + { + "name": "rate_limiting_technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + }, + { + "name": "retry_backoff", + "type": "String", + "description": "Backoff strategy for retry delays\nAvailable values: \"constant\", \"linear\", \"exponential\"." + }, + { + "name": "retry_delay", + "type": "Number", + "description": "Delay between retry attempts in milliseconds (0-60000)" + }, + { + "name": "retry_max_attempts", + "type": "Number", + "description": "Maximum number of retry attempts for failed requests (1-5)" + }, + { + "name": "spend_limits", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "ai_gateway_provider", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "limit", + "type": "Number" + }, + { + "name": "limit_type", + "type": "String", + "description": "Available values: \"cost\"." + }, + { + "name": "metadata", + "type": "Attributes Map", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"partition\", \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "model", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + }, + { + "name": "window", + "type": "Number" + } + ] + } + ] + }, + { + "name": "store_id", + "type": "String" + }, + { + "name": "stripe", + "type": "Attributes", + "children": [ + { + "name": "authorization", + "type": "String" + }, + { + "name": "usage_events", + "type": "Attributes List", + "children": [ + { + "name": "payload", + "type": "String" + } + ] + } + ] + }, + { + "name": "workers_ai_billing_mode", + "type": "String", + "description": "Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway.\nAvailable values: \"postpaid\", \"unified\"." + }, + { + "name": "zdr", + "type": "Boolean" + } + ] + }, + "resource:cloudflare_ai_gateway": { + "kind": "resource", + "name": "cloudflare_ai_gateway", + "description": "Accepted Permissions\n\n- `AI Gateway Read`\n- `AI Gateway Write`", + "example": "resource \"cloudflare_ai_gateway\" \"example_ai_gateway\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n id = \"my-gateway\"\n cache_invalidate_on_update = true\n cache_ttl = 0\n collect_logs = true\n rate_limiting_interval = 0\n rate_limiting_limit = 0\n authentication = true\n byok_only = true\n dlp = {\n action = \"BLOCK\"\n enabled = true\n profiles = [\"string\"]\n }\n guardrails = {\n prompt = {\n p1 = \"FLAG\"\n s1 = \"FLAG\"\n s10 = \"FLAG\"\n s11 = \"FLAG\"\n s12 = \"FLAG\"\n s13 = \"FLAG\"\n s2 = \"FLAG\"\n s3 = \"FLAG\"\n s4 = \"FLAG\"\n s5 = \"FLAG\"\n s6 = \"FLAG\"\n s7 = \"FLAG\"\n s8 = \"FLAG\"\n s9 = \"FLAG\"\n }\n response = {\n p1 = \"FLAG\"\n s1 = \"FLAG\"\n s10 = \"FLAG\"\n s11 = \"FLAG\"\n s12 = \"FLAG\"\n s13 = \"FLAG\"\n s2 = \"FLAG\"\n s3 = \"FLAG\"\n s4 = \"FLAG\"\n s5 = \"FLAG\"\n s6 = \"FLAG\"\n s7 = \"FLAG\"\n s8 = \"FLAG\"\n s9 = \"FLAG\"\n }\n }\n log_classification = true\n log_management = 10000\n log_management_strategy = \"STOP_INSERTING\"\n logpush = true\n logpush_public_key = \"xxxxxxxxxxxxxxxx\"\n otel = [{\n headers = {\n foo = \"string\"\n }\n url = \"https://example.com\"\n authorization = \"authorization\"\n content_type = \"json\"\n }]\n rate_limiting_technique = \"fixed\"\n retry_backoff = \"constant\"\n retry_delay = 0\n retry_max_attempts = 1\n spend_limits = {\n enabled = true\n rules = [{\n limit = 1\n limit_type = \"cost\"\n window = 1\n id = \"x\"\n enabled = true\n metadata = {\n foo = {\n mode = \"partition\"\n }\n }\n model = {\n mode = \"filter\"\n values = [\"string\"]\n }\n ai_gateway_provider = {\n mode = \"filter\"\n values = [\"string\"]\n }\n technique = \"fixed\"\n }]\n }\n store_id = \"store_id\"\n stripe = {\n authorization = \"authorization\"\n usage_events = [{\n payload = \"payload\"\n }]\n }\n workers_ai_billing_mode = \"postpaid\"\n zdr = true\n}", + "importExample": "$ terraform import cloudflare_ai_gateway.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "cache_invalidate_on_update", + "type": "Boolean" + }, + { + "name": "cache_ttl", + "type": "Number" + }, + { + "name": "collect_logs", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier of the AI Gateway within the account." + }, + { + "name": "rate_limiting_interval", + "type": "Number" + }, + { + "name": "rate_limiting_limit", + "type": "Number" + } + ], + "optional": [ + { + "name": "authentication", + "type": "Boolean" + }, + { + "name": "byok_only", + "type": "Boolean", + "description": "Requires customer-provided provider credentials and prevents fallback to Unified Billing." + }, + { + "name": "dlp", + "type": "Attributes", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"BLOCK\", \"FLAG\"." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "policies", + "type": "Attributes List", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "check", + "type": "List of String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "profiles", + "type": "List of String" + } + ] + }, + { + "name": "profiles", + "type": "List of String" + } + ] + }, + { + "name": "guardrails", + "type": "Attributes", + "children": [ + { + "name": "prompt", + "type": "Attributes", + "children": [ + { + "name": "p1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s10", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s11", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s12", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s13", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s2", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s3", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s4", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s5", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s6", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s7", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s8", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s9", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + } + ] + }, + { + "name": "response", + "type": "Attributes", + "children": [ + { + "name": "p1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s10", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s11", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s12", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s13", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s2", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s3", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s4", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s5", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s6", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s7", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s8", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s9", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + } + ] + } + ] + }, + { + "name": "log_classification", + "type": "Boolean" + }, + { + "name": "log_management", + "type": "Number" + }, + { + "name": "log_management_strategy", + "type": "String", + "description": "Available values: \"STOP_INSERTING\", \"DELETE_OLDEST\"." + }, + { + "name": "logpush", + "type": "Boolean" + }, + { + "name": "logpush_public_key", + "type": "String" + }, + { + "name": "otel", + "type": "Attributes List", + "children": [ + { + "name": "authorization", + "type": "String" + }, + { + "name": "content_type", + "type": "String", + "description": "Available values: \"json\", \"protobuf\"." + }, + { + "name": "headers", + "type": "Map of String" + }, + { + "name": "url", + "type": "String" + } + ] + }, + { + "name": "rate_limiting_technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + }, + { + "name": "retry_backoff", + "type": "String", + "description": "Backoff strategy for retry delays\nAvailable values: \"constant\", \"linear\", \"exponential\"." + }, + { + "name": "retry_delay", + "type": "Number", + "description": "Delay between retry attempts in milliseconds (0-60000)" + }, + { + "name": "retry_max_attempts", + "type": "Number", + "description": "Maximum number of retry attempts for failed requests (1-5)" + }, + { + "name": "spend_limits", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "ai_gateway_provider", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "limit", + "type": "Number" + }, + { + "name": "limit_type", + "type": "String", + "description": "Available values: \"cost\"." + }, + { + "name": "metadata", + "type": "Attributes Map", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"partition\", \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "model", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + }, + { + "name": "window", + "type": "Number" + } + ] + } + ] + }, + { + "name": "store_id", + "type": "String" + }, + { + "name": "stripe", + "type": "Attributes", + "children": [ + { + "name": "authorization", + "type": "String" + }, + { + "name": "usage_events", + "type": "Attributes List", + "children": [ + { + "name": "payload", + "type": "String" + } + ] + } + ] + }, + { + "name": "workers_ai_billing_mode", + "type": "String", + "description": "Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway.\nAvailable values: \"postpaid\", \"unified\"." + }, + { + "name": "zdr", + "type": "Boolean" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "is_default", + "type": "Boolean" + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "data-source:cloudflare_ai_gateway_dynamic_routing": { + "kind": "data-source", + "name": "cloudflare_ai_gateway_dynamic_routing", + "description": "Accepted Permissions\n\n- `AI Gateway Read`\n- `AI Gateway Write`", + "example": "data \"cloudflare_ai_gateway_dynamic_routing\" \"example_ai_gateway_dynamic_routing\" {\n account_id = \"0d37909e38d3e99c29fa2cd343ac421a\"\n gateway_id = \"54442216\"\n id = \"54442216\"\n}", + "required": [ + { + "name": "gateway_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "deployment", + "type": "Attributes", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "deployment_id", + "type": "String" + }, + { + "name": "version_id", + "type": "String" + } + ] + }, + { + "name": "elements", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "outputs", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + }, + { + "name": "fallback", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "false", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "next", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "success", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "true", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + } + ] + }, + { + "name": "properties", + "type": "Attributes", + "children": [ + { + "name": "ai_gateway_dynamic_routing_provider", + "type": "String" + }, + { + "name": "conditions", + "type": "String" + }, + { + "name": "key", + "type": "String" + }, + { + "name": "limit", + "type": "Number" + }, + { + "name": "limit_type", + "type": "String", + "description": "Available values: \"count\", \"cost\"." + }, + { + "name": "model", + "type": "String" + }, + { + "name": "retries", + "type": "Number" + }, + { + "name": "timeout", + "type": "Number" + }, + { + "name": "window", + "type": "Number" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"start\", \"conditional\", \"percentage\", \"rate\", \"model\", \"end\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "version", + "type": "Attributes", + "children": [ + { + "name": "active", + "type": "String", + "description": "Available values: \"true\", \"false\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "data", + "type": "String" + }, + { + "name": "is_valid", + "type": "Boolean" + }, + { + "name": "version_id", + "type": "String" + } + ] + } + ] + }, + "resource:cloudflare_ai_gateway_dynamic_routing": { + "kind": "resource", + "name": "cloudflare_ai_gateway_dynamic_routing", + "description": "Accepted Permissions\n\n- `AI Gateway Read`\n- `AI Gateway Write`", + "example": "resource \"cloudflare_ai_gateway_dynamic_routing\" \"example_ai_gateway_dynamic_routing\" {\n account_id = \"0d37909e38d3e99c29fa2cd343ac421a\"\n gateway_id = \"54442216\"\n elements = [{\n id = \"id\"\n outputs = {\n next = {\n element_id = \"elementId\"\n }\n }\n type = \"start\"\n }]\n name = \"x\"\n}", + "importExample": "$ terraform import cloudflare_ai_gateway_dynamic_routing.example '//'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "elements", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "outputs", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + }, + { + "name": "fallback", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "false", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "next", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "success", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "true", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + } + ] + }, + { + "name": "properties", + "type": "Attributes", + "children": [ + { + "name": "ai_gateway_dynamic_routing_provider", + "type": "String" + }, + { + "name": "conditions", + "type": "String" + }, + { + "name": "key", + "type": "String" + }, + { + "name": "limit", + "type": "Number" + }, + { + "name": "limit_type", + "type": "String", + "description": "Available values: \"count\", \"cost\"." + }, + { + "name": "model", + "type": "String" + }, + { + "name": "retries", + "type": "Number" + }, + { + "name": "timeout", + "type": "Number" + }, + { + "name": "window", + "type": "Number" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"start\", \"conditional\", \"percentage\", \"rate\", \"model\", \"end\"." + } + ] + }, + { + "name": "gateway_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "deployment", + "type": "Attributes", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "deployment_id", + "type": "String" + }, + { + "name": "version_id", + "type": "String" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "route", + "type": "Attributes", + "children": [ + { + "name": "account_tag", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deployment", + "type": "Attributes", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "deployment_id", + "type": "String" + }, + { + "name": "version_id", + "type": "String" + } + ] + }, + { + "name": "elements", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "outputs", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + }, + { + "name": "fallback", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "false", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "next", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "success", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + }, + { + "name": "true", + "type": "Attributes", + "children": [ + { + "name": "element_id", + "type": "String" + } + ] + } + ] + }, + { + "name": "properties", + "type": "Attributes", + "children": [ + { + "name": "ai_gateway_dynamic_routing_provider", + "type": "String" + }, + { + "name": "conditions", + "type": "String" + }, + { + "name": "key", + "type": "String" + }, + { + "name": "limit", + "type": "Number" + }, + { + "name": "limit_type", + "type": "String", + "description": "Available values: \"count\", \"cost\"." + }, + { + "name": "model", + "type": "String" + }, + { + "name": "retries", + "type": "Number" + }, + { + "name": "timeout", + "type": "Number" + }, + { + "name": "window", + "type": "Number" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"start\", \"conditional\", \"percentage\", \"rate\", \"model\", \"end\"." + } + ] + }, + { + "name": "gateway_id", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "version", + "type": "Attributes", + "children": [ + { + "name": "active", + "type": "String", + "description": "Available values: \"true\", \"false\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "data", + "type": "String" + }, + { + "name": "is_valid", + "type": "Boolean" + }, + { + "name": "version_id", + "type": "String" + } + ] + } + ] + }, + { + "name": "success", + "type": "Boolean" + }, + { + "name": "version", + "type": "Attributes", + "children": [ + { + "name": "active", + "type": "String", + "description": "Available values: \"true\", \"false\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "data", + "type": "String" + }, + { + "name": "is_valid", + "type": "Boolean" + }, + { + "name": "version_id", + "type": "String" + } + ] + } + ] + }, + "list-data-source:cloudflare_ai_gateways": { + "kind": "list-data-source", + "name": "cloudflare_ai_gateways", + "description": "Accepted Permissions\n\n- `AI Gateway Read`\n- `AI Gateway Write`", + "example": "data \"cloudflare_ai_gateways\" \"example_ai_gateways\" {\n account_id = \"3ebbcb006d4d46d7bb6a8c7f14676cb0\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "search", + "type": "String", + "description": "Search by id" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "authentication", + "type": "Boolean" + }, + { + "name": "byok_only", + "type": "Boolean", + "description": "Requires customer-provided provider credentials and prevents fallback to Unified Billing." + }, + { + "name": "cache_invalidate_on_update", + "type": "Boolean" + }, + { + "name": "cache_ttl", + "type": "Number" + }, + { + "name": "collect_logs", + "type": "Boolean" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dlp", + "type": "Attributes", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"BLOCK\", \"FLAG\"." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "policies", + "type": "Attributes List", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "check", + "type": "List of String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "profiles", + "type": "List of String" + } + ] + }, + { + "name": "profiles", + "type": "List of String" + } + ] + }, + { + "name": "guardrails", + "type": "Attributes", + "children": [ + { + "name": "prompt", + "type": "Attributes", + "children": [ + { + "name": "p1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s10", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s11", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s12", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s13", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s2", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s3", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s4", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s5", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s6", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s7", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s8", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s9", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + } + ] + }, + { + "name": "response", + "type": "Attributes", + "children": [ + { + "name": "p1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s1", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s10", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s11", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s12", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s13", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s2", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s3", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s4", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s5", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s6", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s7", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s8", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + }, + { + "name": "s9", + "type": "String", + "description": "Available values: \"FLAG\", \"BLOCK\"." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier of the AI Gateway within the account." + }, + { + "name": "is_default", + "type": "Boolean" + }, + { + "name": "log_classification", + "type": "Boolean" + }, + { + "name": "log_management", + "type": "Number" + }, + { + "name": "log_management_strategy", + "type": "String", + "description": "Available values: \"STOP_INSERTING\", \"DELETE_OLDEST\"." + }, + { + "name": "logpush", + "type": "Boolean" + }, + { + "name": "logpush_public_key", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "otel", + "type": "Attributes List", + "children": [ + { + "name": "authorization", + "type": "String" + }, + { + "name": "content_type", + "type": "String", + "description": "Available values: \"json\", \"protobuf\"." + }, + { + "name": "headers", + "type": "Map of String" + }, + { + "name": "url", + "type": "String" + } + ] + }, + { + "name": "rate_limiting_interval", + "type": "Number" + }, + { + "name": "rate_limiting_limit", + "type": "Number" + }, + { + "name": "rate_limiting_technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + }, + { + "name": "retry_backoff", + "type": "String", + "description": "Backoff strategy for retry delays\nAvailable values: \"constant\", \"linear\", \"exponential\"." + }, + { + "name": "retry_delay", + "type": "Number", + "description": "Delay between retry attempts in milliseconds (0-60000)" + }, + { + "name": "retry_max_attempts", + "type": "Number", + "description": "Maximum number of retry attempts for failed requests (1-5)" + }, + { + "name": "spend_limits", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "ai_gateway_provider", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "limit", + "type": "Number" + }, + { + "name": "limit_type", + "type": "String", + "description": "Available values: \"cost\"." + }, + { + "name": "metadata", + "type": "Attributes Map", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"partition\", \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "model", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Available values: \"filter\"." + }, + { + "name": "values", + "type": "List of String" + } + ] + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + }, + { + "name": "window", + "type": "Number" + } + ] + } + ] + }, + { + "name": "store_id", + "type": "String" + }, + { + "name": "stripe", + "type": "Attributes", + "children": [ + { + "name": "authorization", + "type": "String" + }, + { + "name": "usage_events", + "type": "Attributes List", + "children": [ + { + "name": "payload", + "type": "String" + } + ] + } + ] + }, + { + "name": "workers_ai_billing_mode", + "type": "String", + "description": "Controls how Workers AI inference calls routed through this gateway are billed. 'postpaid' bills the account directly through Workers AI; 'unified' deducts credits via AI Gateway using neuron-based pricing and delegates billing to AI Gateway.\nAvailable values: \"postpaid\", \"unified\"." + }, + { + "name": "zdr", + "type": "Boolean" + } + ] + } + ] + }, + "data-source:cloudflare_ai_search_instance": { + "kind": "data-source", + "name": "cloudflare_ai_search_instance", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "hostname", + "type": "String", + "description": "Filter by exact Search for Agents hostname (case-insensitive)." + }, + { + "name": "namespace", + "type": "String", + "description": "Filter by namespace." + }, + { + "name": "order_by", + "type": "String", + "description": "Field to order results by.\nAvailable values: \"created_at\"." + }, + { + "name": "order_by_direction", + "type": "String", + "description": "Order direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "search", + "type": "String", + "description": "Filter instances whose id contains this string (case-insensitive)." + } + ] + } + ], + "computed": [ + { + "name": "ai_gateway_id", + "type": "String" + }, + { + "name": "aisearch_model", + "type": "String", + "description": "A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model." + }, + { + "name": "cache", + "type": "Boolean" + }, + { + "name": "cache_threshold", + "type": "String", + "description": "Available values: \"super_strict_match\", \"close_enough\", \"flexible_friend\", \"anything_goes\"." + }, + { + "name": "cache_ttl", + "type": "Number", + "description": "Cache entry TTL in seconds. Allowed values: 600 (10min), 1800 (30min), 3600 (1h), 7200 (2h), 21600 (6h), 43200 (12h), 86400 (24h), 172800 (48h), 259200 (72h), 518400 (6d).\nAvailable values: 600, 1800, 3600, 7200, 21600, 43200, 86400, 172800, 259200, 518400." + }, + { + "name": "chunk_overlap", + "type": "Number" + }, + { + "name": "chunk_size", + "type": "Number" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "custom_metadata", + "type": "Attributes List", + "children": [ + { + "name": "data_type", + "type": "String", + "description": "Available values: \"text\", \"number\", \"boolean\", \"datetime\"." + }, + { + "name": "field_name", + "type": "String" + } + ] + }, + { + "name": "embedding_model", + "type": "String" + }, + { + "name": "enable", + "type": "Boolean" + }, + { + "name": "engine_version", + "type": "Number" + }, + { + "name": "fusion_method", + "type": "String", + "description": "Available values: \"max\", \"rrf\"." + }, + { + "name": "hybrid_search_enabled", + "type": "Boolean", + "description": "Deprecated — use index_method instead. Defaults to true for new instances; set false to create a vector-only instance.", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "index_method", + "type": "Attributes", + "description": "Controls which storage backends are used during indexing. Defaults to vector and keyword indexing for new instances.", + "children": [ + { + "name": "keyword", + "type": "Boolean", + "description": "Enable keyword (BM25) storage backend." + }, + { + "name": "vector", + "type": "Boolean", + "description": "Enable vector (embedding) storage backend." + } + ] + }, + { + "name": "indexing_options", + "type": "Attributes", + "children": [ + { + "name": "keyword_tokenizer", + "type": "String", + "description": "Tokenizer used for keyword search indexing. porter provides word-level tokenization with Porter stemming (good for natural language queries). trigram enables character-level substring matching (good for partial matches, code, identifiers). Changing this triggers a full re-index. Defaults to porter.\nAvailable values: \"porter\", \"trigram\"." + }, + { + "name": "use_ocr", + "type": "Boolean", + "description": "Enables OCR ingestion for PDFs and images. Changing this triggers a full re-index. Defaults to false." + } + ] + }, + { + "name": "last_activity", + "type": "String" + }, + { + "name": "max_num_results", + "type": "Number" + }, + { + "name": "metadata", + "type": "Attributes", + "children": [ + { + "name": "created_from_aisearch_wizard", + "type": "Boolean" + }, + { + "name": "worker_domain", + "type": "String" + } + ] + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "namespace", + "type": "String" + }, + { + "name": "paused", + "type": "Boolean" + }, + { + "name": "public_endpoint_id", + "type": "String" + }, + { + "name": "public_endpoint_params", + "type": "Attributes", + "children": [ + { + "name": "authorized_hosts", + "type": "List of String" + }, + { + "name": "chat_completions_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable chat completions endpoint for this public endpoint" + } + ] + }, + { + "name": "custom_domains", + "type": "List of String", + "description": "Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)." + }, + { + "name": "default_domain_enabled", + "type": "Boolean", + "description": "When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "mcp", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable MCP endpoint for this public endpoint" + } + ] + }, + { + "name": "rate_limit", + "type": "Attributes", + "children": [ + { + "name": "period_ms", + "type": "Number" + }, + { + "name": "requests", + "type": "Number" + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + } + ] + }, + { + "name": "search_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable search endpoint for this public endpoint" + } + ] + } + ] + }, + { + "name": "reranking", + "type": "Boolean" + }, + { + "name": "reranking_model", + "type": "String" + }, + { + "name": "retrieval_options", + "type": "Attributes", + "children": [ + { + "name": "boost_by", + "type": "Attributes List", + "description": "Metadata fields to boost search results by. Each entry specifies a metadata field and an optional direction. Direction defaults to 'asc' for numeric/datetime fields and 'exists' for text/boolean fields. Fields must match 'timestamp' or a defined custom_metadata field.", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Boost direction. 'desc' = higher values rank higher (e.g. newer timestamps). 'asc' = lower values rank higher. 'exists' = boost chunks that have the field. 'not_exists' = boost chunks that lack the field. Optional — defaults to 'asc' for numeric/datetime fields, 'exists' for text/boolean fields.\nAvailable values: \"asc\", \"desc\", \"exists\", \"not_exists\"." + }, + { + "name": "field", + "type": "String", + "description": "Metadata field name to boost by. Use 'timestamp' for document freshness, or any custom_metadata field. Numeric and datetime fields support all four directions (asc, desc, exists, not_exists); text/boolean fields only support exists/not_exists." + } + ] + }, + { + "name": "keyword_match_mode", + "type": "String", + "description": "Controls which documents are candidates for BM25 scoring. 'and' restricts candidates to documents containing all query terms; 'or' includes any document containing at least one term, ranked by BM25 relevance. Defaults to 'and'.\nAvailable values: \"and\", \"or\"." + } + ] + }, + { + "name": "rewrite_model", + "type": "String", + "description": "A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model." + }, + { + "name": "rewrite_query", + "type": "Boolean" + }, + { + "name": "score_threshold", + "type": "Number" + }, + { + "name": "source", + "type": "String" + }, + { + "name": "source_params", + "type": "Attributes", + "children": [ + { + "name": "exclude_items", + "type": "List of String", + "description": "List of path patterns to exclude. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /admin/** matches /admin/users and /admin/settings/advanced). Most accounts are limited to 10 rules; contact support to raise it." + }, + { + "name": "include_items", + "type": "List of String", + "description": "List of path patterns to include. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /blog/** matches /blog/post and /blog/2024/post). Most accounts are limited to 10 rules; contact support to raise it." + }, + { + "name": "prefix", + "type": "String" + }, + { + "name": "r2_jurisdiction", + "type": "String" + }, + { + "name": "web_crawler", + "type": "Attributes", + "children": [ + { + "name": "discover_options", + "type": "Attributes", + "description": "Options for parse_type 'discover', where Browser Run discovers URLs by link following and sitemaps. Ignored for 'sitemap'.", + "children": [ + { + "name": "depth", + "type": "Number", + "description": "Maximum link-follow depth from the seed URL." + }, + { + "name": "include_external_links", + "type": "Boolean", + "description": "Follow links that point outside the source domain. Must stay `false` — discover crawls are restricted to the zone you own." + }, + { + "name": "include_subdomains", + "type": "Boolean", + "description": "Follow links to subdomains of the source host." + }, + { + "name": "limit", + "type": "Number", + "description": "Maximum number of pages to crawl (1-100000)." + }, + { + "name": "max_age", + "type": "Number", + "description": "Maximum content age in seconds to accept (0–604800)." + }, + { + "name": "source", + "type": "String", + "description": "Where the crawler looks for URLs: 'sitemaps' reads sitemap XML only, 'links' follows page links only, 'all' does both.\nAvailable values: \"all\", \"sitemaps\", \"links\"." + } + ] + }, + { + "name": "parse_options", + "type": "Attributes", + "children": [ + { + "name": "content_selector", + "type": "Attributes List", + "description": "List of path-to-selector mappings for extracting specific content from crawled pages. Each entry pairs a URL glob pattern with a CSS selector. The first matching path wins. Only the matched HTML fragment is stored and indexed. Omit the field to disable content selection — empty arrays are rejected.", + "children": [ + { + "name": "path", + "type": "String", + "description": "Glob pattern to match against the page URL path. Uses standard glob syntax: * matches within a segment, ** crosses directories." + }, + { + "name": "selector", + "type": "String", + "description": "CSS selector to extract content from pages matching the path pattern. Must not contain disallowed characters (;, `, $, {, }, \\). Must target a single element; if multiple elements match, the selector is ignored and the full page is used." + } + ] + }, + { + "name": "include_headers", + "type": "Map of String", + "description": "Up to 5 custom HTTP headers sent with each crawl request. Names must be RFC-7230 token characters (no spaces, colons, or control characters); values must be HTAB + printable ASCII (no CR/LF)." + }, + { + "name": "include_images", + "type": "Boolean" + }, + { + "name": "specific_sitemaps", + "type": "List of String", + "description": "List of specific sitemap URLs to use for crawling. Only valid when parse_type is 'sitemap'." + }, + { + "name": "use_browser_rendering", + "type": "Boolean" + } + ] + }, + { + "name": "parse_type", + "type": "String", + "description": "How URLs are discovered. 'sitemap' reads XML sitemaps; 'discover' follows links recursively and requires the source to be a Verified zone on this account.\nAvailable values: \"sitemap\", \"discover\"." + }, + { + "name": "store_options", + "type": "Attributes", + "children": [ + { + "name": "r2_jurisdiction", + "type": "String" + }, + { + "name": "storage_id", + "type": "String" + }, + { + "name": "storage_type", + "type": "String", + "description": "Available values: \"r2\"." + } + ] + } + ] + } + ] + }, + { + "name": "status", + "type": "String" + }, + { + "name": "sync_interval", + "type": "Number", + "description": "Interval between automatic syncs, in seconds. Allowed values: 900 (15min), 1800 (30min), 3600 (1h), 7200 (2h), 14400 (4h), 21600 (6h), 43200 (12h), 86400 (24h).\nAvailable values: 900, 1800, 3600, 7200, 14400, 21600, 43200, 86400." + }, + { + "name": "token_id", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Source type. When omitted or null with a non-blank source, HTTP(S) URLs infer web-crawler and existing R2 bucket names infer r2. A missing or blank source without a type uses managed upload-only storage.\nAvailable values: \"r2\", \"web-crawler\"." + } + ] + }, + "resource:cloudflare_ai_search_instance": { + "kind": "resource", + "name": "cloudflare_ai_search_instance", + "importExample": "$ terraform import cloudflare_ai_search_instance.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "AI Search instance ID. Lowercase alphanumeric, hyphens, and underscores." + } + ], + "optional": [ + { + "name": "ai_gateway_id", + "type": "String" + }, + { + "name": "aisearch_model", + "type": "String", + "description": "A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model." + }, + { + "name": "cache", + "type": "Boolean" + }, + { + "name": "cache_threshold", + "type": "String", + "description": "Available values: \"super_strict_match\", \"close_enough\", \"flexible_friend\", \"anything_goes\"." + }, + { + "name": "cache_ttl", + "type": "Number", + "description": "Cache entry TTL in seconds. Allowed values: 600 (10min), 1800 (30min), 3600 (1h), 7200 (2h), 21600 (6h), 43200 (12h), 86400 (24h), 172800 (48h), 259200 (72h), 518400 (6d).\nAvailable values: 600, 1800, 3600, 7200, 21600, 43200, 86400, 172800, 259200, 518400." + }, + { + "name": "chunk", + "type": "Boolean" + }, + { + "name": "chunk_overlap", + "type": "Number" + }, + { + "name": "chunk_size", + "type": "Number" + }, + { + "name": "custom_metadata", + "type": "Attributes List", + "children": [ + { + "name": "data_type", + "type": "String", + "description": "Available values: \"text\", \"number\", \"boolean\", \"datetime\"." + }, + { + "name": "field_name", + "type": "String" + } + ] + }, + { + "name": "embedding_model", + "type": "String" + }, + { + "name": "fusion_method", + "type": "String", + "description": "Available values: \"max\", \"rrf\"." + }, + { + "name": "hybrid_search_enabled", + "type": "Boolean", + "description": "Deprecated — use index_method instead. Defaults to true for new instances; set false to create a vector-only instance.", + "deprecated": "Deprecated." + }, + { + "name": "index_method", + "type": "Attributes", + "description": "Controls which storage backends are used during indexing. Defaults to vector and keyword indexing for new instances.", + "children": [ + { + "name": "keyword", + "type": "Boolean", + "description": "Enable keyword (BM25) storage backend." + }, + { + "name": "vector", + "type": "Boolean", + "description": "Enable vector (embedding) storage backend." + } + ] + }, + { + "name": "indexing_options", + "type": "Attributes", + "children": [ + { + "name": "keyword_tokenizer", + "type": "String", + "description": "Tokenizer used for keyword search indexing. porter provides word-level tokenization with Porter stemming (good for natural language queries). trigram enables character-level substring matching (good for partial matches, code, identifiers). Changing this triggers a full re-index. Defaults to porter.\nAvailable values: \"porter\", \"trigram\"." + }, + { + "name": "use_ocr", + "type": "Boolean", + "description": "Enables OCR ingestion for PDFs and images. Changing this triggers a full re-index. Defaults to false." + } + ] + }, + { + "name": "max_num_results", + "type": "Number" + }, + { + "name": "metadata", + "type": "Attributes", + "children": [ + { + "name": "created_from_aisearch_wizard", + "type": "Boolean" + }, + { + "name": "worker_domain", + "type": "String" + } + ] + }, + { + "name": "paused", + "type": "Boolean" + }, + { + "name": "public_endpoint_params", + "type": "Attributes", + "children": [ + { + "name": "authorized_hosts", + "type": "List of String" + }, + { + "name": "chat_completions_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable chat completions endpoint for this public endpoint" + } + ] + }, + { + "name": "custom_domains", + "type": "List of String", + "description": "Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)." + }, + { + "name": "default_domain_enabled", + "type": "Boolean", + "description": "When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "mcp", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable MCP endpoint for this public endpoint" + } + ] + }, + { + "name": "rate_limit", + "type": "Attributes", + "children": [ + { + "name": "period_ms", + "type": "Number" + }, + { + "name": "requests", + "type": "Number" + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + } + ] + }, + { + "name": "search_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable search endpoint for this public endpoint" + } + ] + } + ] + }, + { + "name": "reranking", + "type": "Boolean" + }, + { + "name": "reranking_model", + "type": "String" + }, + { + "name": "retrieval_options", + "type": "Attributes", + "children": [ + { + "name": "boost_by", + "type": "Attributes List", + "description": "Metadata fields to boost search results by. Each entry specifies a metadata field and an optional direction. Direction defaults to 'asc' for numeric/datetime fields and 'exists' for text/boolean fields. Fields must match 'timestamp' or a defined custom_metadata field.", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Boost direction. 'desc' = higher values rank higher (e.g. newer timestamps). 'asc' = lower values rank higher. 'exists' = boost chunks that have the field. 'not_exists' = boost chunks that lack the field. Optional — defaults to 'asc' for numeric/datetime fields, 'exists' for text/boolean fields.\nAvailable values: \"asc\", \"desc\", \"exists\", \"not_exists\"." + }, + { + "name": "field", + "type": "String", + "description": "Metadata field name to boost by. Use 'timestamp' for document freshness, or any custom_metadata field. Numeric and datetime fields support all four directions (asc, desc, exists, not_exists); text/boolean fields only support exists/not_exists." + } + ] + }, + { + "name": "keyword_match_mode", + "type": "String", + "description": "Controls which documents are candidates for BM25 scoring. 'and' restricts candidates to documents containing all query terms; 'or' includes any document containing at least one term, ranked by BM25 relevance. When omitted on an update, the existing stored value is preserved; when never set, search falls back to 'and'.\nAvailable values: \"and\", \"or\"." + } + ] + }, + { + "name": "rewrite_model", + "type": "String", + "description": "A Workers AI model ID or an AI Gateway model ID compatible with the OpenAI Chat Completions API. An empty string uses the configured or default model." + }, + { + "name": "rewrite_query", + "type": "Boolean" + }, + { + "name": "score_threshold", + "type": "Number" + }, + { + "name": "source", + "type": "String" + }, + { + "name": "source_params", + "type": "Attributes", + "children": [ + { + "name": "exclude_items", + "type": "List of String", + "description": "List of path patterns to exclude. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /admin/** matches /admin/users and /admin/settings/advanced). Most accounts are limited to 10 rules; contact support to raise it." + }, + { + "name": "include_items", + "type": "List of String", + "description": "List of path patterns to include. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /blog/** matches /blog/post and /blog/2024/post). Most accounts are limited to 10 rules; contact support to raise it." + }, + { + "name": "prefix", + "type": "String" + }, + { + "name": "r2_jurisdiction", + "type": "String" + }, + { + "name": "web_crawler", + "type": "Attributes", + "children": [ + { + "name": "discover_options", + "type": "Attributes", + "description": "Options for parse_type 'discover', where Browser Run discovers URLs by link following and sitemaps. Ignored for 'sitemap'.", + "children": [ + { + "name": "depth", + "type": "Number", + "description": "Maximum link-follow depth from the seed URL." + }, + { + "name": "include_external_links", + "type": "Boolean", + "description": "Follow links that point outside the source domain. Must stay `false` — discover crawls are restricted to the zone you own." + }, + { + "name": "include_subdomains", + "type": "Boolean", + "description": "Follow links to subdomains of the source host." + }, + { + "name": "limit", + "type": "Number", + "description": "Maximum number of pages to crawl (1-100000)." + }, + { + "name": "max_age", + "type": "Number", + "description": "Maximum content age in seconds to accept (0–604800)." + }, + { + "name": "source", + "type": "String", + "description": "Where the crawler looks for URLs: 'sitemaps' reads sitemap XML only, 'links' follows page links only, 'all' does both.\nAvailable values: \"all\", \"sitemaps\", \"links\"." + } + ] + }, + { + "name": "parse_options", + "type": "Attributes", + "children": [ + { + "name": "content_selector", + "type": "Attributes List", + "description": "List of path-to-selector mappings for extracting specific content from crawled pages. Each entry pairs a URL glob pattern with a CSS selector. The first matching path wins. Only the matched HTML fragment is stored and indexed. Omit the field to disable content selection — empty arrays are rejected.", + "children": [ + { + "name": "path", + "type": "String", + "description": "Glob pattern to match against the page URL path. Uses standard glob syntax: * matches within a segment, ** crosses directories." + }, + { + "name": "selector", + "type": "String", + "description": "CSS selector to extract content from pages matching the path pattern. Must not contain disallowed characters (;, `, $, {, }, \\). Must target a single element; if multiple elements match, the selector is ignored and the full page is used." + } + ] + }, + { + "name": "include_headers", + "type": "Map of String", + "description": "Up to 5 custom HTTP headers sent with each crawl request. Names must be RFC-7230 token characters (no spaces, colons, or control characters); values must be HTAB + printable ASCII (no CR/LF)." + }, + { + "name": "include_images", + "type": "Boolean" + }, + { + "name": "specific_sitemaps", + "type": "List of String", + "description": "List of specific sitemap URLs to use for crawling. Only valid when parse_type is 'sitemap'." + }, + { + "name": "use_browser_rendering", + "type": "Boolean" + } + ] + }, + { + "name": "parse_type", + "type": "String", + "description": "How URLs are discovered. 'sitemap' reads XML sitemaps; 'discover' follows links recursively and requires the source to be a Verified zone on this account.\nAvailable values: \"sitemap\", \"discover\"." + } + ] + } + ] + }, + { + "name": "summarization", + "type": "Boolean" + }, + { + "name": "summarization_model", + "type": "String" + }, + { + "name": "sync_interval", + "type": "Number", + "description": "Interval between automatic syncs, in seconds. Allowed values: 900 (15min), 1800 (30min), 3600 (1h), 7200 (2h), 14400 (4h), 21600 (6h), 43200 (12h), 86400 (24h).\nAvailable values: 900, 1800, 3600, 7200, 14400, 21600, 43200, 86400." + }, + { + "name": "system_prompt_aisearch", + "type": "String" + }, + { + "name": "system_prompt_index_summarization", + "type": "String" + }, + { + "name": "system_prompt_rewrite_query", + "type": "String" + }, + { + "name": "token_id", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Source type. When omitted or null with a non-blank source, HTTP(S) URLs infer web-crawler and existing R2 bucket names infer r2. A missing or blank source without a type uses managed upload-only storage.\nAvailable values: \"r2\", \"web-crawler\"." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "enable", + "type": "Boolean" + }, + { + "name": "engine_version", + "type": "Number" + }, + { + "name": "last_activity", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "namespace", + "type": "String" + }, + { + "name": "public_endpoint_id", + "type": "String" + }, + { + "name": "status", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_ai_search_instances": { + "kind": "list-data-source", + "name": "cloudflare_ai_search_instances", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "hostname", + "type": "String", + "description": "Filter by exact Search for Agents hostname (case-insensitive)." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "namespace", + "type": "String", + "description": "Filter by namespace." + }, + { + "name": "order_by", + "type": "String", + "description": "Field to order results by.\nAvailable values: \"created_at\"." + }, + { + "name": "order_by_direction", + "type": "String", + "description": "Order direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "search", + "type": "String", + "description": "Filter instances whose id contains this string (case-insensitive)." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "ai_gateway_id", + "type": "String" + }, + { + "name": "aisearch_model", + "type": "String", + "description": "Available values: \"@cf/meta/llama-3.3-70b-instruct-fp8-fast\", \"@cf/zai-org/glm-4.7-flash\", \"@cf/meta/llama-3.1-8b-instruct-fast\", \"@cf/meta/llama-3.1-8b-instruct-fp8\", \"@cf/meta/llama-4-scout-17b-16e-instruct\", \"@cf/qwen/qwen3-30b-a3b-fp8\", \"@cf/deepseek-ai/deepseek-r1-distill-qwen-32b\", \"@cf/moonshotai/kimi-k2-instruct\", \"@cf/google/gemma-3-12b-it\", \"@cf/google/gemma-4-26b-a4b-it\", \"@cf/moonshotai/kimi-k2.5\", \"anthropic/claude-3-7-sonnet\", \"anthropic/claude-sonnet-4\", \"anthropic/claude-opus-4\", \"anthropic/claude-3-5-haiku\", \"cerebras/qwen-3-235b-a22b-instruct\", \"cerebras/qwen-3-235b-a22b-thinking\", \"cerebras/llama-3.3-70b\", \"cerebras/llama-4-maverick-17b-128e-instruct\", \"cerebras/llama-4-scout-17b-16e-instruct\", \"cerebras/gpt-oss-120b\", \"google-ai-studio/gemini-2.5-flash\", \"google-ai-studio/gemini-2.5-pro\", \"grok/grok-4\", \"groq/llama-3.3-70b-versatile\", \"groq/llama-3.1-8b-instant\", \"openai/gpt-5\", \"openai/gpt-5-mini\", \"openai/gpt-5-nano\", \"\"." + }, + { + "name": "cache", + "type": "Boolean" + }, + { + "name": "cache_threshold", + "type": "String", + "description": "Available values: \"super_strict_match\", \"close_enough\", \"flexible_friend\", \"anything_goes\"." + }, + { + "name": "cache_ttl", + "type": "Number", + "description": "Cache entry TTL in seconds. Allowed values: 600 (10min), 1800 (30min), 3600 (1h), 7200 (2h), 21600 (6h), 43200 (12h), 86400 (24h), 172800 (48h), 259200 (72h), 518400 (6d).\nAvailable values: 600, 1800, 3600, 7200, 21600, 43200, 86400, 172800, 259200, 518400." + }, + { + "name": "chunk_overlap", + "type": "Number" + }, + { + "name": "chunk_size", + "type": "Number" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "custom_metadata", + "type": "Attributes List", + "children": [ + { + "name": "data_type", + "type": "String", + "description": "Available values: \"text\", \"number\", \"boolean\", \"datetime\"." + }, + { + "name": "field_name", + "type": "String" + } + ] + }, + { + "name": "embedding_model", + "type": "String", + "description": "Available values: \"@cf/qwen/qwen3-embedding-0.6b\", \"@cf/baai/bge-m3\", \"@cf/baai/bge-large-en-v1.5\", \"@cf/google/embeddinggemma-300m\", \"google-ai-studio/gemini-embedding-001\", \"google-ai-studio/gemini-embedding-2-preview\", \"google-ai-studio/gemini-embedding-2\", \"openai/text-embedding-3-small\", \"openai/text-embedding-3-large\", \"\"." + }, + { + "name": "enable", + "type": "Boolean" + }, + { + "name": "engine_version", + "type": "Number" + }, + { + "name": "fusion_method", + "type": "String", + "description": "Available values: \"max\", \"rrf\"." + }, + { + "name": "hybrid_search_enabled", + "type": "Boolean", + "description": "Deprecated — use index_method instead.", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "String", + "description": "AI Search instance ID. Lowercase alphanumeric, hyphens, and underscores." + }, + { + "name": "index_method", + "type": "Attributes", + "description": "Controls which storage backends are used during indexing. Defaults to vector-only.", + "children": [ + { + "name": "keyword", + "type": "Boolean", + "description": "Enable keyword (BM25) storage backend." + }, + { + "name": "vector", + "type": "Boolean", + "description": "Enable vector (embedding) storage backend." + } + ] + }, + { + "name": "indexing_options", + "type": "Attributes", + "children": [ + { + "name": "keyword_tokenizer", + "type": "String", + "description": "Tokenizer used for keyword search indexing. porter provides word-level tokenization with Porter stemming (good for natural language queries). trigram enables character-level substring matching (good for partial matches, code, identifiers). Changing this triggers a full re-index. Defaults to porter.\nAvailable values: \"porter\", \"trigram\"." + }, + { + "name": "use_ocr", + "type": "Boolean" + } + ] + }, + { + "name": "last_activity", + "type": "String" + }, + { + "name": "max_num_results", + "type": "Number" + }, + { + "name": "metadata", + "type": "Attributes", + "children": [ + { + "name": "created_from_aisearch_wizard", + "type": "Boolean" + }, + { + "name": "worker_domain", + "type": "String" + } + ] + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "namespace", + "type": "String" + }, + { + "name": "paused", + "type": "Boolean" + }, + { + "name": "public_endpoint_id", + "type": "String" + }, + { + "name": "public_endpoint_params", + "type": "Attributes", + "children": [ + { + "name": "authorized_hosts", + "type": "List of String" + }, + { + "name": "chat_completions_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable chat completions endpoint for this public endpoint" + } + ] + }, + { + "name": "custom_domains", + "type": "List of String", + "description": "Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)." + }, + { + "name": "default_domain_enabled", + "type": "Boolean", + "description": "When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "mcp", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable MCP endpoint for this public endpoint" + } + ] + }, + { + "name": "rate_limit", + "type": "Attributes", + "children": [ + { + "name": "period_ms", + "type": "Number" + }, + { + "name": "requests", + "type": "Number" + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + } + ] + }, + { + "name": "search_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable search endpoint for this public endpoint" + } + ] + } + ] + }, + { + "name": "reranking", + "type": "Boolean" + }, + { + "name": "reranking_model", + "type": "String", + "description": "Available values: \"@cf/baai/bge-reranker-base\", \"\"." + }, + { + "name": "retrieval_options", + "type": "Attributes", + "children": [ + { + "name": "boost_by", + "type": "Attributes List", + "description": "Metadata fields to boost search results by. Each entry specifies a metadata field and an optional direction. Direction defaults to 'asc' for numeric/datetime fields and 'exists' for text/boolean fields. Fields must match 'timestamp' or a defined custom_metadata field.", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Boost direction. 'desc' = higher values rank higher (e.g. newer timestamps). 'asc' = lower values rank higher. 'exists' = boost chunks that have the field. 'not_exists' = boost chunks that lack the field. Optional — defaults to 'asc' for numeric/datetime fields, 'exists' for text/boolean fields.\nAvailable values: \"asc\", \"desc\", \"exists\", \"not_exists\"." + }, + { + "name": "field", + "type": "String", + "description": "Metadata field name to boost by. Use 'timestamp' for document freshness, or any custom_metadata field. Numeric and datetime fields support all four directions (asc, desc, exists, not_exists); text/boolean fields only support exists/not_exists." + } + ] + }, + { + "name": "keyword_match_mode", + "type": "String", + "description": "Controls which documents are candidates for BM25 scoring. 'and' restricts candidates to documents containing all query terms; 'or' includes any document containing at least one term, ranked by BM25 relevance. Defaults to 'and'.\nAvailable values: \"and\", \"or\"." + } + ] + }, + { + "name": "rewrite_model", + "type": "String", + "description": "Available values: \"@cf/meta/llama-3.3-70b-instruct-fp8-fast\", \"@cf/zai-org/glm-4.7-flash\", \"@cf/meta/llama-3.1-8b-instruct-fast\", \"@cf/meta/llama-3.1-8b-instruct-fp8\", \"@cf/meta/llama-4-scout-17b-16e-instruct\", \"@cf/qwen/qwen3-30b-a3b-fp8\", \"@cf/deepseek-ai/deepseek-r1-distill-qwen-32b\", \"@cf/moonshotai/kimi-k2-instruct\", \"@cf/google/gemma-3-12b-it\", \"@cf/google/gemma-4-26b-a4b-it\", \"@cf/moonshotai/kimi-k2.5\", \"anthropic/claude-3-7-sonnet\", \"anthropic/claude-sonnet-4\", \"anthropic/claude-opus-4\", \"anthropic/claude-3-5-haiku\", \"cerebras/qwen-3-235b-a22b-instruct\", \"cerebras/qwen-3-235b-a22b-thinking\", \"cerebras/llama-3.3-70b\", \"cerebras/llama-4-maverick-17b-128e-instruct\", \"cerebras/llama-4-scout-17b-16e-instruct\", \"cerebras/gpt-oss-120b\", \"google-ai-studio/gemini-2.5-flash\", \"google-ai-studio/gemini-2.5-pro\", \"grok/grok-4\", \"groq/llama-3.3-70b-versatile\", \"groq/llama-3.1-8b-instant\", \"openai/gpt-5\", \"openai/gpt-5-mini\", \"openai/gpt-5-nano\", \"\"." + }, + { + "name": "rewrite_query", + "type": "Boolean" + }, + { + "name": "score_threshold", + "type": "Number" + }, + { + "name": "source", + "type": "String" + }, + { + "name": "source_params", + "type": "Attributes", + "children": [ + { + "name": "exclude_items", + "type": "List of String", + "description": "List of path patterns to exclude. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /admin/** matches /admin/users and /admin/settings/advanced)" + }, + { + "name": "include_items", + "type": "List of String", + "description": "List of path patterns to include. Uses micromatch glob syntax: * matches within a path segment, ** matches across path segments (e.g., /blog/** matches /blog/post and /blog/2024/post)" + }, + { + "name": "prefix", + "type": "String" + }, + { + "name": "r2_jurisdiction", + "type": "String" + }, + { + "name": "web_crawler", + "type": "Attributes", + "children": [ + { + "name": "discover_options", + "type": "Attributes", + "children": [ + { + "name": "depth", + "type": "Number" + }, + { + "name": "include_external_links", + "type": "Boolean" + }, + { + "name": "include_subdomains", + "type": "Boolean" + }, + { + "name": "limit", + "type": "Number", + "description": "Maximum number of pages to crawl. New values are capped at 100000; instances configured before that cap may report a higher stored value, which the crawler clamps at run time." + }, + { + "name": "max_age", + "type": "Number" + }, + { + "name": "source", + "type": "String", + "description": "Available values: \"all\", \"sitemaps\", \"links\"." + } + ] + }, + { + "name": "parse_options", + "type": "Attributes", + "children": [ + { + "name": "content_selector", + "type": "Attributes List", + "description": "List of path-to-selector mappings for extracting specific content from crawled pages. Each entry pairs a URL glob pattern with a CSS selector. The first matching path wins. Only the matched HTML fragment is stored and indexed. Omit the field to disable content selection — empty arrays are rejected.", + "children": [ + { + "name": "path", + "type": "String", + "description": "Glob pattern to match against the page URL path. Uses standard glob syntax: * matches within a segment, ** crosses directories." + }, + { + "name": "selector", + "type": "String", + "description": "CSS selector to extract content from pages matching the path pattern. Must not contain disallowed characters (;, `, $, {, }, \\). Must target a single element; if multiple elements match, the selector is ignored and the full page is used." + } + ] + }, + { + "name": "include_headers", + "type": "Map of String", + "description": "Up to 5 custom HTTP headers sent with each crawl request. Names must be RFC-7230 token characters (no spaces, colons, or control characters); values must be HTAB + printable ASCII (no CR/LF)." + }, + { + "name": "include_images", + "type": "Boolean" + }, + { + "name": "specific_sitemaps", + "type": "List of String", + "description": "List of specific sitemap URLs to use for crawling. Only valid when parse_type is 'sitemap'." + }, + { + "name": "use_browser_rendering", + "type": "Boolean" + } + ] + }, + { + "name": "parse_type", + "type": "String", + "description": "Available values: \"sitemap\", \"feed-rss\", \"crawl\"." + }, + { + "name": "store_options", + "type": "Attributes", + "children": [ + { + "name": "r2_jurisdiction", + "type": "String" + }, + { + "name": "storage_id", + "type": "String" + }, + { + "name": "storage_type", + "type": "String", + "description": "Available values: \"r2\"." + } + ] + } + ] + } + ] + }, + { + "name": "status", + "type": "String" + }, + { + "name": "sync_interval", + "type": "Number", + "description": "Interval between automatic syncs, in seconds. Allowed values: 900 (15min), 1800 (30min), 3600 (1h), 7200 (2h), 14400 (4h), 21600 (6h), 43200 (12h), 86400 (24h).\nAvailable values: 900, 1800, 3600, 7200, 14400, 21600, 43200, 86400." + }, + { + "name": "token_id", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"r2\", \"web-crawler\"." + } + ] + } + ] + }, + "data-source:cloudflare_ai_search_namespace": { + "kind": "data-source", + "name": "cloudflare_ai_search_namespace", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the namespace. Max 256 characters." + }, + { + "name": "public_endpoint_id", + "type": "String" + }, + { + "name": "public_endpoint_params", + "type": "Attributes", + "children": [ + { + "name": "authorized_hosts", + "type": "List of String" + }, + { + "name": "chat_completions_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable chat completions endpoint for this public endpoint" + } + ] + }, + { + "name": "custom_domains", + "type": "List of String", + "description": "Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)." + }, + { + "name": "default_domain_enabled", + "type": "Boolean", + "description": "When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "instances_allowed", + "type": "List of String", + "description": "Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit." + }, + { + "name": "mcp", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable MCP endpoint for this public endpoint" + } + ] + }, + { + "name": "rate_limit", + "type": "Attributes", + "children": [ + { + "name": "period_ms", + "type": "Number" + }, + { + "name": "requests", + "type": "Number" + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + } + ] + }, + { + "name": "search_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable search endpoint for this public endpoint" + } + ] + } + ] + } + ] + }, + "resource:cloudflare_ai_search_namespace": { + "kind": "resource", + "name": "cloudflare_ai_search_namespace", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Optional description for the namespace. Max 256 characters." + }, + { + "name": "public_endpoint_params", + "type": "Attributes", + "children": [ + { + "name": "authorized_hosts", + "type": "List of String" + }, + { + "name": "chat_completions_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable chat completions endpoint for this public endpoint" + } + ] + }, + { + "name": "custom_domains", + "type": "List of String", + "description": "Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)." + }, + { + "name": "default_domain_enabled", + "type": "Boolean", + "description": "When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "instances_allowed", + "type": "List of String", + "description": "Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit." + }, + { + "name": "mcp", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable MCP endpoint for this public endpoint" + } + ] + }, + { + "name": "rate_limit", + "type": "Attributes", + "children": [ + { + "name": "period_ms", + "type": "Number" + }, + { + "name": "requests", + "type": "Number" + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + } + ] + }, + { + "name": "search_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable search endpoint for this public endpoint" + } + ] + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "public_endpoint_id", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_ai_search_namespaces": { + "kind": "list-data-source", + "name": "cloudflare_ai_search_namespaces", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "search", + "type": "String", + "description": "Filter namespaces whose name or description contains this string (case-insensitive)." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the namespace. Max 256 characters." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "public_endpoint_id", + "type": "String" + }, + { + "name": "public_endpoint_params", + "type": "Attributes", + "children": [ + { + "name": "authorized_hosts", + "type": "List of String" + }, + { + "name": "chat_completions_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable chat completions endpoint for this public endpoint" + } + ] + }, + { + "name": "custom_domains", + "type": "List of String", + "description": "Custom domain hostnames that alias this public endpoint. GET and create responses return the current set; on update (PUT) this field is only echoed back when supplied in the request body, otherwise it is null (omit it to leave domains unchanged)." + }, + { + "name": "default_domain_enabled", + "type": "Boolean", + "description": "When false, the instance is reachable only via a registered custom domain and the default .search.ai.cloudflare.com host returns 404. Requires at least one custom domain. Defaults to true. public_endpoint_params is replaced wholesale on update, so resend default_domain_enabled on every update to keep the default host off — omitting it resets to true." + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "instances_allowed", + "type": "List of String", + "description": "Instance IDs exposed through the namespace public endpoint. Empty means nothing is searchable. Every ID must be an existing instance in this namespace, and the list cannot exceed the account's multi-instance search limit." + }, + { + "name": "mcp", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable MCP endpoint for this public endpoint" + } + ] + }, + { + "name": "rate_limit", + "type": "Attributes", + "children": [ + { + "name": "period_ms", + "type": "Number" + }, + { + "name": "requests", + "type": "Number" + }, + { + "name": "technique", + "type": "String", + "description": "Available values: \"fixed\", \"sliding\"." + } + ] + }, + { + "name": "search_endpoint", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Disable search endpoint for this public endpoint" + } + ] + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_ai_search_token": { + "kind": "data-source", + "name": "cloudflare_ai_search_token", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "search", + "type": "String", + "description": "Filter tokens whose name contains this string (case-insensitive)." + } + ] + } + ], + "computed": [ + { + "name": "cf_api_id", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "legacy", + "type": "Boolean" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + "resource:cloudflare_ai_search_token": { + "kind": "resource", + "name": "cloudflare_ai_search_token", + "importExample": "$ terraform import cloudflare_ai_search_token.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "cf_api_id", + "type": "String" + }, + { + "name": "cf_api_key", + "type": "String", + "sensitive": true + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "legacy", + "type": "Boolean" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_ai_search_tokens": { + "kind": "list-data-source", + "name": "cloudflare_ai_search_tokens", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "search", + "type": "String", + "description": "Filter tokens whose name contains this string (case-insensitive)." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "cf_api_id", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "legacy", + "type": "Boolean" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_api_shield": { + "kind": "data-source", + "name": "cloudflare_api_shield", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield\" \"example_api_shield\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n normalize = true\n}", + "required": [], + "optional": [ + { + "name": "normalize", + "type": "Boolean", + "description": "Ensures that the configuration is written or retrieved in normalized fashion" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "auth_id_characteristics", + "type": "Attributes List", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the characteristic field, i.e., the header or cookie name." + }, + { + "name": "type", + "type": "String", + "description": "The type of characteristic.\nAvailable values: \"header\", \"cookie\", \"jwt\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_api_shield": { + "kind": "resource", + "name": "cloudflare_api_shield", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`\n\nWhen using `type = \"jwt\"` for auth ID characteristics, the `name` field must be a claim location expressed as `$(token_config_id):$(json_path)`, where:\n- `token_config_id` is the ID of the token configuration used in validating the JWT\n- `json_path` is a [RFC 9535](https://www.rfc-editor.org/rfc/rfc9535.html) [JSONPath](https://goessner.net/articles/JsonPath/) expression that returns a singleton value (interpreted as a string)\n\nThe JSONPath expression may be in dot or bracket notation and may only specify literal keys or array indexes.\n\n### Header Example\n\n```terraform\nresource \"cloudflare_api_shield\" \"header_example\" {\n zone_id = \"0da42c8d2132a9ddaf714f9e7c920711\"\n auth_id_characteristics = [{\n name = \"authorization\"\n type = \"header\"\n }]\n}\n```\n\nThis configuration uses the `Authorization` header as the session identifier.\n\n### Cookie Example\n\n```terraform\nresource \"cloudflare_api_shield\" \"cookie_example\" {\n zone_id = \"0da42c8d2132a9ddaf714f9e7c920711\"\n auth_id_characteristics = [{\n name = \"session_id\"\n type = \"cookie\"\n }]\n}\n```\n\nThis configuration uses a cookie named `session_id` as the session identifier.\n\n### JWT Example\n\n```terraform\nresource \"cloudflare_api_shield\" \"jwt_example\" {\n zone_id = \"0da42c8d2132a9ddaf714f9e7c920711\"\n auth_id_characteristics = [{\n name = \"d5902294-00c3-4aed-b517-57e752e9cd58:$.sub\"\n type = \"jwt\"\n }]\n}\n```\n\nThis configuration extracts the `sub` (subject) claim from a JWT token validated by the token configuration with ID `d5902294-00c3-4aed-b517-57e752e9cd58`. The extracted claim value is then used as the session identifier.\n\n### Multiple Session Identifiers\n\nYou can combine multiple session identifiers to handle different authentication methods:\n\n```terraform\nresource \"cloudflare_api_shield\" \"multiple_identifiers\" {\n zone_id = \"0da42c8d2132a9ddaf714f9e7c920711\"\n auth_id_characteristics = [\n {\n name = \"x-api-key\"\n type = \"header\"\n },\n {\n name = \"session_token\"\n type = \"cookie\"\n }\n ]\n}\n```\n\nThis configuration identifies API consumers using either the `x-api-key` header or a `session_token` cookie.\n\n### Combining Header and JWT\n\n```terraform\nresource \"cloudflare_api_shield\" \"header_and_jwt\" {\n zone_id = \"0da42c8d2132a9ddaf714f9e7c920711\"\n auth_id_characteristics = [\n {\n name = \"x-client-id\"\n type = \"header\"\n },\n {\n name = \"d5902294-00c3-4aed-b517-57e752e9cd58:$.email\"\n type = \"jwt\"\n }\n ]\n}\n```\n\nThis configuration uses a custom `x-client-id` header alongside a JWT `email` claim for session identification.", + "example": "resource \"cloudflare_api_shield\" \"example_api_shield\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n auth_id_characteristics = [{\n name = \"authorization\"\n type = \"header\"\n }]\n}", + "importExample": "$ terraform import cloudflare_api_shield.example ''", + "required": [ + { + "name": "auth_id_characteristics", + "type": "Attributes List", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the characteristic field, i.e., the header or cookie name." + }, + { + "name": "type", + "type": "String", + "description": "The type of characteristic.\nAvailable values: \"header\", \"cookie\", \"jwt\"." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "normalize", + "type": "Boolean", + "description": "Ensures that the configuration is written or retrieved in normalized fashion" + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_api_shield_discovery_operation": { + "kind": "resource", + "name": "cloudflare_api_shield_discovery_operation", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Domain API Gateway`", + "example": "resource \"cloudflare_api_shield_discovery_operation\" \"example_api_shield_discovery_operation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n state = \"review\"\n}", + "required": [ + { + "name": "operation_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "state", + "type": "String", + "description": "Mark state of operation in API Discovery\n * `review` - Mark operation as for review\n * `ignored` - Mark operation as ignored\nAvailable values: \"review\", \"ignored\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "UUID." + } + ] + }, + "list-data-source:cloudflare_api_shield_discovery_operations": { + "kind": "list-data-source", + "name": "cloudflare_api_shield_discovery_operations", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield_discovery_operations\" \"example_api_shield_discovery_operations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n diff = true\n direction = \"desc\"\n endpoint = \"/api/v1\"\n host = [\"api.cloudflare.com\"]\n method = [\"GET\"]\n order = \"method\"\n origin = \"ML\"\n state = \"review\"\n}", + "required": [], + "optional": [ + { + "name": "diff", + "type": "Boolean", + "description": "When `true`, only return API Discovery results that are not saved into API Shield Endpoint Management" + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "endpoint", + "type": "String", + "description": "Filter results to only include endpoints containing this pattern." + }, + { + "name": "host", + "type": "List of String", + "description": "Filter results to only include the specified hosts." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "method", + "type": "List of String", + "description": "Filter results to only include the specified HTTP methods." + }, + { + "name": "order", + "type": "String", + "description": "Field to order by\nAvailable values: \"host\", \"method\", \"endpoint\", \"traffic_stats.requests\", \"traffic_stats.last_updated\"." + }, + { + "name": "origin", + "type": "String", + "description": "Filter results to only include discovery results sourced from a particular discovery engine\n * `ML` - Discovered operations that were sourced using ML API Discovery\n * `SessionIdentifier` - Discovered operations that were sourced using Session Identifier API Discovery\nAvailable values: \"ML\", \"SessionIdentifier\", \"LabelDiscovery\"." + }, + { + "name": "state", + "type": "String", + "description": "Filter results to only include discovery results in a particular state. States are as follows\n * `review` - Discovered operations that are not saved into API Shield Endpoint Management\n * `saved` - Discovered operations that are already saved into API Shield Endpoint Management\n * `ignored` - Discovered operations that have been marked as ignored\nAvailable values: \"review\", \"saved\", \"ignored\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "endpoint", + "type": "String", + "description": "The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/." + }, + { + "name": "features", + "type": "Attributes", + "children": [ + { + "name": "traffic_stats", + "type": "Attributes", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "period_seconds", + "type": "Number", + "description": "The period in seconds these statistics were computed over" + }, + { + "name": "requests", + "type": "Number", + "description": "The average number of requests seen during this period" + } + ] + } + ] + }, + { + "name": "host", + "type": "String", + "description": "RFC3986-compliant host." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "method", + "type": "String", + "description": "The HTTP method used to access the endpoint.\nAvailable values: \"GET\", \"POST\", \"HEAD\", \"OPTIONS\", \"PUT\", \"DELETE\", \"CONNECT\", \"PATCH\", \"TRACE\"." + }, + { + "name": "origin", + "type": "List of String", + "description": "API discovery engine(s) that discovered this operation" + }, + { + "name": "state", + "type": "String", + "description": "State of operation in API Discovery\n * `review` - Operation is not saved into API Shield Endpoint Management\n * `saved` - Operation is saved into API Shield Endpoint Management\n * `ignored` - Operation is marked as ignored\nAvailable values: \"review\", \"saved\", \"ignored\"." + } + ] + } + ] + }, + "data-source:cloudflare_api_shield_operation": { + "kind": "data-source", + "name": "cloudflare_api_shield_operation", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield_operation\" \"example_api_shield_operation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n feature = [\"thresholds\"]\n with_schemas = true\n}", + "required": [], + "optional": [ + { + "name": "feature", + "type": "List of String", + "description": "Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "endpoint", + "type": "String", + "description": "Filter results to only include endpoints containing this pattern." + }, + { + "name": "feature", + "type": "List of String", + "description": "Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning." + }, + { + "name": "host", + "type": "List of String", + "description": "Filter results to only include the specified hosts." + }, + { + "name": "method", + "type": "List of String", + "description": "Filter results to only include the specified HTTP methods." + }, + { + "name": "order", + "type": "String", + "description": "Field to order by. When requesting a feature, the feature keys are available for ordering as well, e.g., `thresholds.suggested_threshold`.\nAvailable values: \"method\", \"host\", \"endpoint\", \"thresholds.$key\"." + } + ] + }, + { + "name": "operation_id", + "type": "String", + "description": "UUID." + }, + { + "name": "with_schemas", + "type": "Boolean", + "description": "When true, includes OpenAPI schemas (both uploaded and learned) for the operation in the response. Due to the conversion overhead, this parameter is only supported on single-operation retrieval." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "endpoint", + "type": "String", + "description": "The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/." + }, + { + "name": "features", + "type": "Attributes", + "children": [ + { + "name": "api_routing", + "type": "Attributes", + "description": "API Routing settings on endpoint.", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "route", + "type": "String", + "description": "Target route." + } + ] + }, + { + "name": "confidence_intervals", + "type": "Attributes", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "suggested_threshold", + "type": "Attributes", + "children": [ + { + "name": "confidence_intervals", + "type": "Attributes", + "children": [ + { + "name": "p90", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + }, + { + "name": "p95", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + }, + { + "name": "p99", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + } + ] + }, + { + "name": "mean", + "type": "Number", + "description": "Suggested threshold." + } + ] + } + ] + }, + { + "name": "parameter_schemas", + "type": "Attributes", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "parameter_schemas", + "type": "Attributes", + "description": "An operation schema object containing a response.", + "children": [ + { + "name": "parameters", + "type": "List of String", + "description": "An array containing the learned parameter schemas." + }, + { + "name": "responses", + "type": "String", + "description": "An empty response object. This field is required to yield a valid operation schema." + } + ] + } + ] + }, + { + "name": "schema_info", + "type": "Attributes", + "children": [ + { + "name": "active_schema", + "type": "Attributes", + "description": "Schema active on endpoint.", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "Schema file name." + } + ] + }, + { + "name": "mitigation_action", + "type": "String", + "description": "Action taken on requests failing validation.\nAvailable values: \"none\", \"log\", \"block\"." + } + ] + }, + { + "name": "thresholds", + "type": "Attributes", + "children": [ + { + "name": "auth_id_tokens", + "type": "Number", + "description": "The total number of auth-ids seen across this calculation." + }, + { + "name": "data_points", + "type": "Number", + "description": "The number of data points used for the threshold suggestion calculation." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "p50", + "type": "Number", + "description": "The p50 quantile of requests (in period_seconds)." + }, + { + "name": "p90", + "type": "Number", + "description": "The p90 quantile of requests (in period_seconds)." + }, + { + "name": "p99", + "type": "Number", + "description": "The p99 quantile of requests (in period_seconds)." + }, + { + "name": "period_seconds", + "type": "Number", + "description": "The period over which this threshold is suggested." + }, + { + "name": "requests", + "type": "Number", + "description": "The estimated number of requests covered by these calculations." + }, + { + "name": "suggested_threshold", + "type": "Number", + "description": "The suggested threshold in requests done by the same auth_id or period_seconds." + } + ] + } + ] + }, + { + "name": "host", + "type": "String", + "description": "RFC3986-compliant host." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "method", + "type": "String", + "description": "The HTTP method used to access the endpoint.\nAvailable values: \"GET\", \"POST\", \"HEAD\", \"OPTIONS\", \"PUT\", \"DELETE\", \"CONNECT\", \"PATCH\", \"TRACE\"." + }, + { + "name": "schemas", + "type": "Attributes", + "description": "OpenAPI JSON schemas for an operation, including both user-uploaded and Cloudflare-learned schemas.", + "children": [ + { + "name": "learned", + "type": "Attributes", + "description": "An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.", + "children": [ + { + "name": "parameters", + "type": "List of Map of String", + "description": "OpenAPI parameter objects describing path, query, header, or cookie parameters." + }, + { + "name": "request_body", + "type": "Map of String", + "description": "OpenAPI request body object describing the expected request payload." + } + ] + }, + { + "name": "uploaded", + "type": "Attributes", + "description": "An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.", + "children": [ + { + "name": "parameters", + "type": "List of Map of String", + "description": "OpenAPI parameter objects describing path, query, header, or cookie parameters." + }, + { + "name": "request_body", + "type": "Map of String", + "description": "OpenAPI request body object describing the expected request payload." + } + ] + } + ] + } + ] + }, + "resource:cloudflare_api_shield_operation": { + "kind": "resource", + "name": "cloudflare_api_shield_operation", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "resource \"cloudflare_api_shield_operation\" \"example_api_shield_operation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n endpoint = \"/api/v1/users/{var1}\"\n host = \"www.example.com\"\n method = \"GET\"\n}", + "importExample": "$ terraform import cloudflare_api_shield_operation.example '/'", + "required": [ + { + "name": "endpoint", + "type": "String", + "description": "The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/." + }, + { + "name": "host", + "type": "String", + "description": "RFC3986-compliant host." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP method used to access the endpoint.\nAvailable values: \"GET\", \"POST\", \"HEAD\", \"OPTIONS\", \"PUT\", \"DELETE\", \"CONNECT\", \"PATCH\", \"TRACE\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "features", + "type": "Attributes", + "children": [ + { + "name": "api_routing", + "type": "Attributes", + "description": "API Routing settings on endpoint.", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "route", + "type": "String", + "description": "Target route." + } + ] + }, + { + "name": "confidence_intervals", + "type": "Attributes", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "suggested_threshold", + "type": "Attributes", + "children": [ + { + "name": "confidence_intervals", + "type": "Attributes", + "children": [ + { + "name": "p90", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + }, + { + "name": "p95", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + }, + { + "name": "p99", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + } + ] + }, + { + "name": "mean", + "type": "Number", + "description": "Suggested threshold." + } + ] + } + ] + }, + { + "name": "parameter_schemas", + "type": "Attributes", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "parameter_schemas", + "type": "Attributes", + "description": "An operation schema object containing a response.", + "children": [ + { + "name": "parameters", + "type": "List of String", + "description": "An array containing the learned parameter schemas." + }, + { + "name": "responses", + "type": "String", + "description": "An empty response object. This field is required to yield a valid operation schema." + } + ] + } + ] + }, + { + "name": "schema_info", + "type": "Attributes", + "children": [ + { + "name": "active_schema", + "type": "Attributes", + "description": "Schema active on endpoint.", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "Schema file name." + } + ] + }, + { + "name": "mitigation_action", + "type": "String", + "description": "Action taken on requests failing validation.\nAvailable values: \"none\", \"log\", \"block\"." + } + ] + }, + { + "name": "thresholds", + "type": "Attributes", + "children": [ + { + "name": "auth_id_tokens", + "type": "Number", + "description": "The total number of auth-ids seen across this calculation." + }, + { + "name": "data_points", + "type": "Number", + "description": "The number of data points used for the threshold suggestion calculation." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "p50", + "type": "Number", + "description": "The p50 quantile of requests (in period_seconds)." + }, + { + "name": "p90", + "type": "Number", + "description": "The p90 quantile of requests (in period_seconds)." + }, + { + "name": "p99", + "type": "Number", + "description": "The p99 quantile of requests (in period_seconds)." + }, + { + "name": "period_seconds", + "type": "Number", + "description": "The period over which this threshold is suggested." + }, + { + "name": "requests", + "type": "Number", + "description": "The estimated number of requests covered by these calculations." + }, + { + "name": "suggested_threshold", + "type": "Number", + "description": "The suggested threshold in requests done by the same auth_id or period_seconds." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "operation_id", + "type": "String", + "description": "UUID." + }, + { + "name": "schemas", + "type": "Attributes", + "description": "OpenAPI JSON schemas for an operation, including both user-uploaded and Cloudflare-learned schemas.", + "children": [ + { + "name": "learned", + "type": "Attributes", + "description": "An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.", + "children": [ + { + "name": "parameters", + "type": "List of Map of String", + "description": "OpenAPI parameter objects describing path, query, header, or cookie parameters." + }, + { + "name": "request_body", + "type": "Map of String", + "description": "OpenAPI request body object describing the expected request payload." + } + ] + }, + { + "name": "uploaded", + "type": "Attributes", + "description": "An OpenAPI operation object fragment containing schema information for an operation. May include parameter definitions, request body specifications, and a component schema extension.", + "children": [ + { + "name": "parameters", + "type": "List of Map of String", + "description": "OpenAPI parameter objects describing path, query, header, or cookie parameters." + }, + { + "name": "request_body", + "type": "Map of String", + "description": "OpenAPI request body object describing the expected request payload." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_api_shield_operation_schema_validation_settings": { + "kind": "data-source", + "name": "cloudflare_api_shield_operation_schema_validation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield_operation_schema_validation_settings\" \"example_api_shield_operation_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "operation_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "mitigation_action", + "type": "String", + "description": "When set, this applies a mitigation action to this operation\n\n - `log` log request when request does not conform to schema for this operation\n - `block` deny access to the site when request does not conform to schema for this operation\n - `none` will skip mitigation for this operation\n - `null` indicates that no operation level mitigation is in place, see Zone Level Schema Validation Settings for mitigation action that will be applied\nAvailable values: \"log\", \"block\", \"none\"." + } + ] + }, + "resource:cloudflare_api_shield_operation_schema_validation_settings": { + "kind": "resource", + "name": "cloudflare_api_shield_operation_schema_validation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`\n\n~> `cloudflare_api_shield_operation_schema_validation_settings` is in a deprecation phase and will be removed in the future.\n Instead, please utilize the [cloudflare_schema_validation_operation_settings](./schema_validation_operation_settings) resource instead.", + "example": "resource \"cloudflare_api_shield_operation_schema_validation_settings\" \"example_api_shield_operation_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n mitigation_action = \"block\"\n}", + "importExample": "$ terraform import cloudflare_api_shield_operation_schema_validation_settings.example '/'", + "required": [ + { + "name": "operation_id", + "type": "String", + "description": "UUID." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "mitigation_action", + "type": "String", + "description": "When set, this applies a mitigation action to this operation\n\n - `log` log request when request does not conform to schema for this operation\n - `block` deny access to the site when request does not conform to schema for this operation\n - `none` will skip mitigation for this operation\n - `null` indicates that no operation level mitigation is in place, see Zone Level Schema Validation Settings for mitigation action that will be applied\nAvailable values: \"log\", \"block\", \"none\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "UUID." + } + ] + }, + "list-data-source:cloudflare_api_shield_operations": { + "kind": "list-data-source", + "name": "cloudflare_api_shield_operations", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield_operations\" \"example_api_shield_operations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"desc\"\n endpoint = \"/api/v1\"\n feature = [\"thresholds\"]\n host = [\"api.cloudflare.com\"]\n method = [\"GET\"]\n order = \"method\"\n}", + "required": [], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "endpoint", + "type": "String", + "description": "Filter results to only include endpoints containing this pattern." + }, + { + "name": "feature", + "type": "List of String", + "description": "Add feature(s) to the results. The feature name that is given here corresponds to the resulting feature object. Have a look at the top-level object description for more details on the specific meaning." + }, + { + "name": "host", + "type": "List of String", + "description": "Filter results to only include the specified hosts." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "method", + "type": "List of String", + "description": "Filter results to only include the specified HTTP methods." + }, + { + "name": "order", + "type": "String", + "description": "Field to order by. When requesting a feature, the feature keys are available for ordering as well, e.g., `thresholds.suggested_threshold`.\nAvailable values: \"method\", \"host\", \"endpoint\", \"thresholds.$key\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "endpoint", + "type": "String", + "description": "The endpoint which can contain path parameter templates in curly braces, each will be replaced from left to right with {varN}, starting with {var1}, during insertion. This will further be Cloudflare-normalized upon insertion. See: https://developers.cloudflare.com/rules/normalization/how-it-works/." + }, + { + "name": "features", + "type": "Attributes", + "children": [ + { + "name": "api_routing", + "type": "Attributes", + "description": "API Routing settings on endpoint.", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "route", + "type": "String", + "description": "Target route." + } + ] + }, + { + "name": "confidence_intervals", + "type": "Attributes", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "suggested_threshold", + "type": "Attributes", + "children": [ + { + "name": "confidence_intervals", + "type": "Attributes", + "children": [ + { + "name": "p90", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + }, + { + "name": "p95", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + }, + { + "name": "p99", + "type": "Attributes", + "description": "Upper and lower bound for percentile estimate", + "children": [ + { + "name": "lower", + "type": "Number", + "description": "Lower bound for percentile estimate" + }, + { + "name": "upper", + "type": "Number", + "description": "Upper bound for percentile estimate" + } + ] + } + ] + }, + { + "name": "mean", + "type": "Number", + "description": "Suggested threshold." + } + ] + } + ] + }, + { + "name": "parameter_schemas", + "type": "Attributes", + "children": [ + { + "name": "last_updated", + "type": "String" + }, + { + "name": "parameter_schemas", + "type": "Attributes", + "description": "An operation schema object containing a response.", + "children": [ + { + "name": "parameters", + "type": "List of String", + "description": "An array containing the learned parameter schemas." + }, + { + "name": "responses", + "type": "String", + "description": "An empty response object. This field is required to yield a valid operation schema." + } + ] + } + ] + }, + { + "name": "schema_info", + "type": "Attributes", + "children": [ + { + "name": "active_schema", + "type": "Attributes", + "description": "Schema active on endpoint.", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "Schema file name." + } + ] + }, + { + "name": "mitigation_action", + "type": "String", + "description": "Action taken on requests failing validation.\nAvailable values: \"none\", \"log\", \"block\"." + } + ] + }, + { + "name": "thresholds", + "type": "Attributes", + "children": [ + { + "name": "auth_id_tokens", + "type": "Number", + "description": "The total number of auth-ids seen across this calculation." + }, + { + "name": "data_points", + "type": "Number", + "description": "The number of data points used for the threshold suggestion calculation." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "p50", + "type": "Number", + "description": "The p50 quantile of requests (in period_seconds)." + }, + { + "name": "p90", + "type": "Number", + "description": "The p90 quantile of requests (in period_seconds)." + }, + { + "name": "p99", + "type": "Number", + "description": "The p99 quantile of requests (in period_seconds)." + }, + { + "name": "period_seconds", + "type": "Number", + "description": "The period over which this threshold is suggested." + }, + { + "name": "requests", + "type": "Number", + "description": "The estimated number of requests covered by these calculations." + }, + { + "name": "suggested_threshold", + "type": "Number", + "description": "The suggested threshold in requests done by the same auth_id or period_seconds." + } + ] + } + ] + }, + { + "name": "host", + "type": "String", + "description": "RFC3986-compliant host." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "method", + "type": "String", + "description": "The HTTP method used to access the endpoint.\nAvailable values: \"GET\", \"POST\", \"HEAD\", \"OPTIONS\", \"PUT\", \"DELETE\", \"CONNECT\", \"PATCH\", \"TRACE\"." + }, + { + "name": "operation_id", + "type": "String", + "description": "UUID." + } + ] + } + ] + }, + "data-source:cloudflare_api_shield_schema": { + "kind": "data-source", + "name": "cloudflare_api_shield_schema", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield_schema\" \"example_api_shield_schema\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n schema_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n omit_source = true\n}", + "required": [ + { + "name": "schema_id", + "type": "String" + } + ], + "optional": [ + { + "name": "omit_source", + "type": "Boolean", + "description": "Omit the source-files of schemas and only retrieve their meta-data." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "kind", + "type": "String", + "description": "Kind of schema\nAvailable values: \"openapi_v3\"." + }, + { + "name": "name", + "type": "String", + "description": "Name of the schema" + }, + { + "name": "source", + "type": "String", + "description": "Source of the schema" + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "Flag whether schema is enabled for validation." + } + ] + }, + "resource:cloudflare_api_shield_schema": { + "kind": "resource", + "name": "cloudflare_api_shield_schema", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`\n\n~> `cloudflare_api_shield_schema` is in a deprecation phase and will be removed in the future.\n Instead, please utilize the [cloudflare_schema_validation_schemas](./schema_validation_schemas) resource instead.", + "example": "resource \"cloudflare_api_shield_schema\" \"example_api_shield_schema\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n file = \"Example data\"\n kind = \"openapi_v3\"\n name = \"petstore schema\"\n validation_enabled = \"true\"\n}", + "required": [ + { + "name": "file", + "type": "String", + "description": "Schema file bytes" + }, + { + "name": "kind", + "type": "String", + "description": "Kind of schema\nAvailable values: \"openapi_v3\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "name", + "type": "String", + "description": "Name of the schema" + }, + { + "name": "omit_source", + "type": "Boolean", + "description": "Omit the source-files of schemas and only retrieve their meta-data." + }, + { + "name": "schema_id", + "type": "String" + }, + { + "name": "validation_enabled", + "type": "String", + "description": "Flag whether schema is enabled for validation.\nAvailable values: \"true\", \"false\"." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "schema", + "type": "Attributes", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "kind", + "type": "String", + "description": "Kind of schema\nAvailable values: \"openapi_v3\"." + }, + { + "name": "name", + "type": "String", + "description": "Name of the schema" + }, + { + "name": "schema_id", + "type": "String", + "description": "UUID." + }, + { + "name": "source", + "type": "String", + "description": "Source of the schema" + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "Flag whether schema is enabled for validation." + } + ] + }, + { + "name": "source", + "type": "String", + "description": "Source of the schema" + }, + { + "name": "upload_details", + "type": "Attributes", + "children": [ + { + "name": "warnings", + "type": "Attributes List", + "description": "Diagnostic warning events that occurred during processing. These events are non-critical errors found within the schema.", + "children": [ + { + "name": "code", + "type": "Number", + "description": "Code that identifies the event that occurred." + }, + { + "name": "locations", + "type": "List of String", + "description": "JSONPath location(s) in the schema where these events were encountered. See [https://goessner.net/articles/JsonPath/](https://goessner.net/articles/JsonPath/) for JSONPath specification." + }, + { + "name": "message", + "type": "String", + "description": "Diagnostic message that describes the event." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_api_shield_schema_validation_settings": { + "kind": "data-source", + "name": "cloudflare_api_shield_schema_validation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield_schema_validation_settings\" \"example_api_shield_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "validation_default_mitigation_action", + "type": "String", + "description": "The default mitigation action used when there is no mitigation action defined on the operation\n\nMitigation actions are as follows:\n\n * `log` - log request when request does not conform to schema\n * `block` - deny access to the site when request does not conform to schema\n\nA special value of of `none` will skip running schema validation entirely for the request when there is no mitigation action defined on the operation\nAvailable values: \"none\", \"log\", \"block\"." + }, + { + "name": "validation_override_mitigation_action", + "type": "String", + "description": "When set, this overrides both zone level and operation level mitigation actions.\n\n - `none` will skip running schema validation entirely for the request\n - `null` indicates that no override is in place\nAvailable values: \"none\"." + } + ] + }, + "resource:cloudflare_api_shield_schema_validation_settings": { + "kind": "resource", + "name": "cloudflare_api_shield_schema_validation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`\n\n~> `cloudflare_api_shield_schema_validation_settings` is in a deprecation phase and will be removed in the future.\n Instead, please utilize the [cloudflare_schema_validation_settings](./schema_validation_settings) resource instead.", + "example": "resource \"cloudflare_api_shield_schema_validation_settings\" \"example_api_shield_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_default_mitigation_action = \"block\"\n validation_override_mitigation_action = \"none\"\n}", + "importExample": "$ terraform import cloudflare_api_shield_schema_validation_settings.example ''", + "required": [ + { + "name": "validation_default_mitigation_action", + "type": "String", + "description": "The default mitigation action used when there is no mitigation action defined on the operation\n\nMitigation actions are as follows:\n\n * `log` - log request when request does not conform to schema\n * `block` - deny access to the site when request does not conform to schema\n\nA special value of of `none` will skip running schema validation entirely for the request when there is no mitigation action defined on the operation\nAvailable values: \"none\", \"log\", \"block\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "validation_override_mitigation_action", + "type": "String", + "description": "When set, this overrides both zone level and operation level mitigation actions.\n\n - `none` will skip running schema validation entirely for the request\n - `null` indicates that no override is in place\n\nTo clear any override, use the special value `disable_override` or `null`\nAvailable values: \"none\", \"disable_override\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "list-data-source:cloudflare_api_shield_schemas": { + "kind": "list-data-source", + "name": "cloudflare_api_shield_schemas", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_api_shield_schemas\" \"example_api_shield_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_enabled = true\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "omit_source", + "type": "Boolean", + "description": "Omit the source-files of schemas and only retrieve their meta-data." + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "Flag whether schema is enabled for validation." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "kind", + "type": "String", + "description": "Kind of schema\nAvailable values: \"openapi_v3\"." + }, + { + "name": "name", + "type": "String", + "description": "Name of the schema" + }, + { + "name": "schema_id", + "type": "String", + "description": "UUID." + }, + { + "name": "source", + "type": "String", + "description": "Source of the schema" + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "Flag whether schema is enabled for validation." + } + ] + } + ] + }, + "data-source:cloudflare_api_token": { + "kind": "data-source", + "name": "cloudflare_api_token", + "description": "Accepted Permissions\n\n- `API Tokens Read`\n- `API Tokens Write`", + "example": "data \"cloudflare_api_token\" \"example_api_token\" {\n token_id = \"ed17574386854bf78a67040be0a770b0\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "include_expired", + "type": "Boolean", + "description": "When true, includes recently-expired tokens in the response." + } + ] + }, + { + "name": "token_id", + "type": "String", + "description": "Token identifier tag." + } + ], + "computed": [ + { + "name": "condition", + "type": "Attributes", + "children": [ + { + "name": "request_ip", + "type": "Attributes", + "description": "Client IP restrictions.", + "children": [ + { + "name": "in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + }, + { + "name": "not_in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + } + ] + } + ] + }, + { + "name": "creator_email_at_creation", + "type": "String", + "description": "The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available." + }, + { + "name": "expires_on", + "type": "String", + "description": "The expiration time on or after which the JWT MUST NOT be accepted for processing." + }, + { + "name": "id", + "type": "String", + "description": "Token identifier tag." + }, + { + "name": "issued_on", + "type": "String", + "description": "The time on which the token was created." + }, + { + "name": "last_used_on", + "type": "String", + "description": "Last time the token was used." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the token was modified." + }, + { + "name": "name", + "type": "String", + "description": "Token name." + }, + { + "name": "not_before", + "type": "String", + "description": "The time before which the token MUST NOT be accepted for processing." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "List of access policies assigned to the token.", + "children": [ + { + "name": "effect", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resources", + "type": "Map of String", + "description": "A list of resource names that the policy applies to." + } + ] + }, + { + "name": "provisioner_id", + "type": "String", + "description": "The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable." + }, + { + "name": "provisioner_type", + "type": "String", + "description": "The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens." + }, + { + "name": "status", + "type": "String", + "description": "Status of the token.\nAvailable values: \"active\", \"disabled\", \"expired\"." + } + ] + }, + "resource:cloudflare_api_token": { + "kind": "resource", + "name": "cloudflare_api_token", + "description": "Accepted Permissions\n\n- `API Tokens Read`\n- `API Tokens Write`", + "example": "resource \"cloudflare_api_token\" \"example_api_token\" {\n name = \"readonly token\"\n policies = [{\n effect = \"allow\"\n permission_groups = [{\n id = \"c8fed203ed3043cba015a93ad1616f1f\"\n }, {\n id = \"82e64a83756745bbbb1c9c2701bf816b\"\n }]\n resources = jsonencode({\n \"com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43\" = \"*\"\n })\n }]\n condition = {\n request_ip = {\n in = [\"123.123.123.0/24\", \"2606:4700::/32\"]\n not_in = [\"123.123.123.100/24\", \"2606:4700:4700::/48\"]\n }\n }\n expires_on = \"2020-01-01T00:00:00Z\"\n not_before = \"2018-07-01T05:20:00Z\"\n}", + "importExample": "$ terraform import cloudflare_api_token.example ''", + "required": [ + { + "name": "name", + "type": "String", + "description": "Token name." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "List of access policies assigned to the token.", + "children": [ + { + "name": "effect", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + } + ] + }, + { + "name": "resources", + "type": "String", + "description": "A json object representing the resources that are specified to the policy." + } + ] + } + ], + "optional": [ + { + "name": "condition", + "type": "Attributes", + "children": [ + { + "name": "request_ip", + "type": "Attributes", + "description": "Client IP restrictions.", + "children": [ + { + "name": "in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + }, + { + "name": "not_in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + } + ] + } + ] + }, + { + "name": "expires_on", + "type": "String", + "description": "The expiration time on or after which the JWT MUST NOT be accepted for processing." + }, + { + "name": "not_before", + "type": "String", + "description": "The time before which the token MUST NOT be accepted for processing." + }, + { + "name": "status", + "type": "String", + "description": "Status of the token.\nAvailable values: \"active\", \"disabled\", \"expired\"." + } + ], + "computed": [ + { + "name": "creator_email_at_creation", + "type": "String", + "description": "The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available." + }, + { + "name": "id", + "type": "String", + "description": "Token identifier tag." + }, + { + "name": "issued_on", + "type": "String", + "description": "The time on which the token was created." + }, + { + "name": "last_used_on", + "type": "String", + "description": "Last time the token was used." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the token was modified." + }, + { + "name": "provisioner_id", + "type": "String", + "description": "The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable." + }, + { + "name": "provisioner_type", + "type": "String", + "description": "The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens." + }, + { + "name": "value", + "type": "String", + "description": "The token value.", + "sensitive": true + } + ] + }, + "list-data-source:cloudflare_api_token_permission_groups_list": { + "kind": "list-data-source", + "name": "cloudflare_api_token_permission_groups_list", + "description": "Accepted Permissions\n\n- `API Tokens Read`\n- `API Tokens Write`", + "example": "data \"cloudflare_api_token_permission_groups_list\" \"example_api_token_permission_groups_list\" {\n name = \"Account%20Settings%20Write\"\n scope = \"com.cloudflare.api.account.zone\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Filter by the name of the permission group.\nThe value must be URL-encoded." + }, + { + "name": "scope", + "type": "String", + "description": "Filter by the scope of the permission group.\nThe value must be URL-encoded." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "category", + "type": "String", + "description": "Product category that this permission group belongs to.\nAvailable values: \"developer_platform\", \"ai_and_machine_learning\", \"dns_and_zones\", \"app_security\", \"rules_and_configuration\", \"cloudflare_one_and_zero_trust\", \"analytics_and_logs\", \"network_services\", \"media\", \"email_and_messaging\", \"cache_and_performance\", \"account_and_billing\", \"other\"." + }, + { + "name": "id", + "type": "String", + "description": "Public ID." + }, + { + "name": "is_selectable", + "type": "Boolean", + "description": "Whether the caller can select this permission group when creating a token." + }, + { + "name": "name", + "type": "String", + "description": "Permission Group Name" + }, + { + "name": "scopes", + "type": "List of String", + "description": "Resources to which the Permission Group is scoped" + } + ] + } + ] + }, + "list-data-source:cloudflare_api_tokens": { + "kind": "list-data-source", + "name": "cloudflare_api_tokens", + "description": "Accepted Permissions\n\n- `API Tokens Read`\n- `API Tokens Write`", + "example": "data \"cloudflare_api_tokens\" \"example_api_tokens\" {\n direction = \"desc\"\n}", + "required": [], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "include_expired", + "type": "Boolean", + "description": "When true, includes recently-expired tokens in the response." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "condition", + "type": "Attributes", + "children": [ + { + "name": "request_ip", + "type": "Attributes", + "description": "Client IP restrictions.", + "children": [ + { + "name": "in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + }, + { + "name": "not_in", + "type": "List of String", + "description": "List of IPv4/IPv6 CIDR addresses." + } + ] + } + ] + }, + { + "name": "creator_email_at_creation", + "type": "String", + "description": "The email address of the user who created the token at the time of\ncreation. Only present for Account Owned API Tokens when a creator email\nwas available." + }, + { + "name": "expires_on", + "type": "String", + "description": "The expiration time on or after which the JWT MUST NOT be accepted for processing." + }, + { + "name": "id", + "type": "String", + "description": "Token identifier tag." + }, + { + "name": "issued_on", + "type": "String", + "description": "The time on which the token was created." + }, + { + "name": "last_used_on", + "type": "String", + "description": "Last time the token was used." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the token was modified." + }, + { + "name": "name", + "type": "String", + "description": "Token name." + }, + { + "name": "not_before", + "type": "String", + "description": "The time before which the token MUST NOT be accepted for processing." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "List of access policies assigned to the token.", + "children": [ + { + "name": "effect", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resources", + "type": "Map of String", + "description": "A list of resource names that the policy applies to." + } + ] + }, + { + "name": "provisioner_id", + "type": "String", + "description": "The identifier of the service that provisioned the token. For an\nOAuth-provisioned token, this is the OAuth client identifier. Present\nwhen `provisioner_type` is present and null when the identifier is\nunavailable." + }, + { + "name": "provisioner_type", + "type": "String", + "description": "The type of service that provisioned the token. Only present for\nprovisioned Account Owned API Tokens." + }, + { + "name": "status", + "type": "String", + "description": "Status of the token.\nAvailable values: \"active\", \"disabled\", \"expired\"." + } + ] + } + ] + }, + "data-source:cloudflare_argo_smart_routing": { + "kind": "data-source", + "name": "cloudflare_argo_smart_routing", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_argo_smart_routing\" \"example_argo_smart_routing\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Specifies the zone associated with the API call." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Specifies if the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Specifies the zone associated with the API call." + }, + { + "name": "modified_on", + "type": "String", + "description": "Specifies the time when the setting was last modified." + }, + { + "name": "value", + "type": "String", + "description": "Specifies the enablement value of Argo Smart Routing.\nAvailable values: \"on\", \"off\"." + } + ] + }, + "resource:cloudflare_argo_smart_routing": { + "kind": "resource", + "name": "cloudflare_argo_smart_routing", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "resource \"cloudflare_argo_smart_routing\" \"example_argo_smart_routing\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}", + "importExample": "$ terraform import cloudflare_argo_smart_routing.example ''", + "required": [ + { + "name": "value", + "type": "String", + "description": "Specifies the enablement value of Argo Smart Routing.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Specifies the zone associated with the API call." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Specifies if the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Specifies the zone associated with the API call." + }, + { + "name": "modified_on", + "type": "String", + "description": "Specifies the time when the setting was last modified." + } + ] + }, + "data-source:cloudflare_argo_tiered_caching": { + "kind": "data-source", + "name": "cloudflare_argo_tiered_caching", + "example": "data \"cloudflare_argo_tiered_caching\" \"example_argo_tiered_caching\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + }, + { + "name": "value", + "type": "String", + "description": "Value of the Tiered Cache zone setting.\nAvailable values: \"on\", \"off\"." + } + ] + }, + "resource:cloudflare_argo_tiered_caching": { + "kind": "resource", + "name": "cloudflare_argo_tiered_caching", + "example": "resource \"cloudflare_argo_tiered_caching\" \"example_argo_tiered_caching\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}", + "importExample": "$ terraform import cloudflare_argo_tiered_caching.example ''", + "required": [ + { + "name": "value", + "type": "String", + "description": "Enables Tiered Caching.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "data-source:cloudflare_authenticated_origin_pulls": { + "kind": "data-source", + "name": "cloudflare_authenticated_origin_pulls", + "example": "data \"cloudflare_authenticated_origin_pulls\" \"example_authenticated_origin_pulls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"app.example.com\"\n}", + "required": [ + { + "name": "hostname", + "type": "String", + "description": "The hostname on the origin for which the client certificate uploaded will be used." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "cert_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "cert_status", + "type": "String", + "description": "Status of the certificate or the association.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "cert_updated_at", + "type": "String", + "description": "The time when the certificate was updated." + }, + { + "name": "cert_uploaded_on", + "type": "String", + "description": "The time when the certificate was uploaded." + }, + { + "name": "certificate", + "type": "String", + "description": "The hostname certificate." + }, + { + "name": "created_at", + "type": "String", + "description": "The time when the certificate was created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether hostname-level authenticated origin pulls is enabled. A null value voids the association." + }, + { + "name": "expires_on", + "type": "String", + "description": "The date when the certificate expires." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate or the association.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "The time when the certificate was updated." + } + ] + }, + "resource:cloudflare_authenticated_origin_pulls": { + "kind": "resource", + "name": "cloudflare_authenticated_origin_pulls", + "example": "resource \"cloudflare_authenticated_origin_pulls\" \"example_authenticated_origin_pulls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n config = [{\n cert_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n enabled = true\n hostname = \"app.example.com\"\n }]\n}", + "importExample": "$ terraform import cloudflare_authenticated_origin_pulls.example '/'", + "required": [ + { + "name": "config", + "type": "Attributes List", + "children": [ + { + "name": "cert_id", + "type": "String", + "description": "Certificate identifier tag." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether hostname-level authenticated origin pulls is enabled. A null value voids the association." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname on the origin for which the client certificate uploaded will be used." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "cert_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "cert_status", + "type": "String", + "description": "Status of the certificate or the association.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "cert_updated_at", + "type": "String", + "description": "The time when the certificate was updated." + }, + { + "name": "cert_uploaded_on", + "type": "String", + "description": "The time when the certificate was uploaded." + }, + { + "name": "certificate", + "type": "String", + "description": "The hostname certificate." + }, + { + "name": "created_at", + "type": "String", + "description": "The time when the certificate was created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether hostname-level authenticated origin pulls is enabled. A null value voids the association." + }, + { + "name": "expires_on", + "type": "String", + "description": "The date when the certificate expires." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname on the origin for which the client certificate uploaded will be used." + }, + { + "name": "id", + "type": "String", + "description": "The hostname on the origin for which the client certificate uploaded will be used." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "private_key", + "type": "String", + "description": "The hostname certificate's private key.", + "sensitive": true + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate or the association.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "The time when the certificate was updated." + } + ] + }, + "data-source:cloudflare_authenticated_origin_pulls_certificate": { + "kind": "data-source", + "name": "cloudflare_authenticated_origin_pulls_certificate", + "example": "data \"cloudflare_authenticated_origin_pulls_certificate\" \"example_authenticated_origin_pulls_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "certificate_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "certificate", + "type": "String", + "description": "The zone's leaf certificate." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate activation.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "This is the time the certificate was uploaded." + } + ] + }, + "resource:cloudflare_authenticated_origin_pulls_certificate": { + "kind": "resource", + "name": "cloudflare_authenticated_origin_pulls_certificate", + "example": "resource \"cloudflare_authenticated_origin_pulls_certificate\" \"example_authenticated_origin_pulls_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate = </'", + "required": [ + { + "name": "certificate", + "type": "String", + "description": "The zone's leaf certificate." + }, + { + "name": "private_key", + "type": "String", + "description": "The zone's private key.", + "sensitive": true + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "certificate_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether zone-level authenticated origin pulls is enabled." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate activation.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "This is the time the certificate was uploaded." + } + ] + }, + "list-data-source:cloudflare_authenticated_origin_pulls_certificates": { + "kind": "list-data-source", + "name": "cloudflare_authenticated_origin_pulls_certificates", + "example": "data \"cloudflare_authenticated_origin_pulls_certificates\" \"example_authenticated_origin_pulls_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "certificate", + "type": "String", + "description": "The zone's leaf certificate." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate activation.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "This is the time the certificate was uploaded." + } + ] + } + ] + }, + "data-source:cloudflare_authenticated_origin_pulls_hostname_certificate": { + "kind": "data-source", + "name": "cloudflare_authenticated_origin_pulls_hostname_certificate", + "example": "data \"cloudflare_authenticated_origin_pulls_hostname_certificate\" \"example_authenticated_origin_pulls_hostname_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "certificate_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "certificate", + "type": "String", + "description": "The hostname certificate." + }, + { + "name": "expires_on", + "type": "String", + "description": "The date when the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate or the association.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "The time when the certificate was uploaded." + } + ] + }, + "resource:cloudflare_authenticated_origin_pulls_hostname_certificate": { + "kind": "resource", + "name": "cloudflare_authenticated_origin_pulls_hostname_certificate", + "example": "resource \"cloudflare_authenticated_origin_pulls_hostname_certificate\" \"example_authenticated_origin_pulls_hostname_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate = </'", + "required": [ + { + "name": "certificate", + "type": "String", + "description": "The hostname certificate." + }, + { + "name": "private_key", + "type": "String", + "description": "The hostname certificate's private key.", + "sensitive": true + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "expires_on", + "type": "String", + "description": "The date when the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate or the association.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "The time when the certificate was uploaded." + } + ] + }, + "list-data-source:cloudflare_authenticated_origin_pulls_hostname_certificates": { + "kind": "list-data-source", + "name": "cloudflare_authenticated_origin_pulls_hostname_certificates", + "example": "data \"cloudflare_authenticated_origin_pulls_hostname_certificates\" \"example_authenticated_origin_pulls_hostname_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "certificate", + "type": "String", + "description": "The hostname certificate." + }, + { + "name": "expires_on", + "type": "String", + "description": "The date when the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the uploaded certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the certificate or the association.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deleted\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "The time when the certificate was uploaded." + } + ] + } + ] + }, + "data-source:cloudflare_authenticated_origin_pulls_settings": { + "kind": "data-source", + "name": "cloudflare_authenticated_origin_pulls_settings", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_authenticated_origin_pulls_settings\" \"example_authenticated_origin_pulls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether zone-level authenticated origin pulls is enabled." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_authenticated_origin_pulls_settings": { + "kind": "resource", + "name": "cloudflare_authenticated_origin_pulls_settings", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_authenticated_origin_pulls_settings\" \"example_authenticated_origin_pulls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}", + "importExample": "$ terraform import cloudflare_authenticated_origin_pulls_settings.example ''", + "required": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether zone-level authenticated origin pulls is enabled." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_bot_management": { + "kind": "data-source", + "name": "cloudflare_bot_management", + "description": "Accepted Permissions\n\n- `Bot Management Read`\n- `Bot Management Write`", + "example": "data \"cloudflare_bot_management\" \"example_bot_management\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "ai_bots_migration_opt_out", + "type": "Boolean", + "description": "Temporary migration flag tracking zones opted out of AI bots managed-rule updates." + }, + { + "name": "ai_bots_protection", + "type": "String", + "description": "Enable rule to block AI Scrapers and Crawlers.\nAvailable values: \"block\", \"disabled\", \"only_on_ad_pages\"." + }, + { + "name": "ai_training", + "type": "String", + "description": "Configure robots.txt policy for AI model training bots.\nAvailable values: \"disabled\", \"disallow\", \"block\", \"only_on_ad_pages\"." + }, + { + "name": "ai_user", + "type": "String", + "description": "Configure robots.txt policy for AI assistant and agent bots.\nAvailable values: \"disabled\", \"block\", \"only_on_ad_pages\"." + }, + { + "name": "aisearch", + "type": "String", + "description": "Configure robots.txt policy for AI search bots.\nAvailable values: \"disabled\", \"block\", \"only_on_ad_pages\"." + }, + { + "name": "auto_update_model", + "type": "Boolean", + "description": "Automatically update to the newest bot detection models created by Cloudflare as they are released. [Learn more.](https://developers.cloudflare.com/bots/reference/machine-learning-models#model-versions-and-release-notes)" + }, + { + "name": "bm_cookie_enabled", + "type": "Boolean", + "description": "Indicates that the bot management cookie can be placed on end user devices accessing the site. Defaults to true" + }, + { + "name": "bot_preference_sync_enabled", + "type": "Boolean", + "description": "Enable Bot Preference Sync for this zone. When enabled, Cloudflare can serve robots.txt content derived from the zone's AI Search, AI User, and AI Training preferences." + }, + { + "name": "cf_robots_variant", + "type": "String", + "description": "Specifies the Robots Access Control License variant to use.\nAvailable values: \"off\", \"policy_only\"." + }, + { + "name": "content_bots_protection", + "type": "String", + "description": "Enable rule to block content bots. When enabled, blocks automated traffic with low bot scores, excluding safe verified bot categories. Exceptions should be managed via skip rules.\nAvailable values: \"block\", \"disabled\"." + }, + { + "name": "crawler_protection", + "type": "String", + "description": "Enable rule to punish AI Scrapers and Crawlers via a link maze.\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "enable_js", + "type": "Boolean", + "description": "Use lightweight, invisible JavaScript detections to improve Bot Management. [Learn more about JavaScript Detections](https://developers.cloudflare.com/bots/reference/javascript-detections/)." + }, + { + "name": "fight_mode", + "type": "Boolean", + "description": "Whether to enable Bot Fight Mode." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "is_robots_txt_managed", + "type": "Boolean", + "description": "Enable cloudflare managed robots.txt. If an existing robots.txt is detected, then managed robots.txt will be prepended to the existing robots.txt." + }, + { + "name": "jsd_api_results_enabled", + "type": "Boolean", + "description": "Whether to use JavaScript Detection results submitted through the API for this zone." + }, + { + "name": "optimize_wordpress", + "type": "Boolean", + "description": "Whether to optimize Super Bot Fight Mode protections for Wordpress." + }, + { + "name": "sbfm_definitely_automated", + "type": "String", + "description": "Super Bot Fight Mode (SBFM) action to take on definitely automated requests.\nAvailable values: \"allow\", \"block\", \"managed_challenge\"." + }, + { + "name": "sbfm_likely_automated", + "type": "String", + "description": "Super Bot Fight Mode (SBFM) action to take on likely automated requests.\nAvailable values: \"allow\", \"block\", \"managed_challenge\"." + }, + { + "name": "sbfm_static_resource_protection", + "type": "Boolean", + "description": "Super Bot Fight Mode (SBFM) to enable static resource protection.\nEnable if static resources on your application need bot protection.\nNote: Static resource protection can also result in legitimate traffic being blocked." + }, + { + "name": "sbfm_verified_bots", + "type": "String", + "description": "Super Bot Fight Mode (SBFM) action to take on verified bots requests.\nAvailable values: \"allow\", \"block\"." + }, + { + "name": "stale_zone_configuration", + "type": "Attributes", + "description": "A read-only field that shows which unauthorized settings are currently active on the zone. These settings typically result from upgrades or downgrades.", + "children": [ + { + "name": "fight_mode", + "type": "Boolean", + "description": "Indicates that the zone's Bot Fight Mode is turned on." + }, + { + "name": "optimize_wordpress", + "type": "Boolean", + "description": "Indicates that the zone's wordpress optimization for SBFM is turned on." + }, + { + "name": "sbfm_definitely_automated", + "type": "String", + "description": "Indicates that the zone's definitely automated requests are being blocked or challenged." + }, + { + "name": "sbfm_likely_automated", + "type": "String", + "description": "Indicates that the zone's likely automated requests are being blocked or challenged." + }, + { + "name": "sbfm_static_resource_protection", + "type": "String", + "description": "Indicates that the zone's static resource protection is turned on." + }, + { + "name": "sbfm_verified_bots", + "type": "String", + "description": "Indicates that the zone's verified bot requests are being blocked." + }, + { + "name": "suppress_session_score", + "type": "Boolean", + "description": "Indicates that the zone's session score tracking is disabled." + } + ] + }, + { + "name": "suppress_session_score", + "type": "Boolean", + "description": "Whether to disable tracking the highest bot score for a session in the Bot Management cookie." + }, + { + "name": "using_latest_model", + "type": "Boolean", + "description": "A read-only field that indicates whether the zone currently is running the latest ML model." + } + ] + }, + "resource:cloudflare_bot_management": { + "kind": "resource", + "name": "cloudflare_bot_management", + "description": "Accepted Permissions\n\n- `Bot Management Read`\n- `Bot Management Write`", + "example": "resource \"cloudflare_bot_management\" \"example_bot_management\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ai_bots_migration_opt_out = false\n ai_bots_protection = \"block\"\n aisearch = \"block\"\n ai_training = \"disallow\"\n ai_user = \"only_on_ad_pages\"\n bot_preference_sync_enabled = true\n cf_robots_variant = \"policy_only\"\n content_bots_protection = \"disabled\"\n crawler_protection = \"enabled\"\n enable_js = true\n fight_mode = true\n is_robots_txt_managed = false\n jsd_api_results_enabled = true\n}", + "importExample": "$ terraform import cloudflare_bot_management.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "ai_bots_migration_opt_out", + "type": "Boolean", + "description": "Temporary migration flag tracking zones opted out of AI bots managed-rule updates." + }, + { + "name": "ai_bots_protection", + "type": "String", + "description": "Enable rule to block AI Scrapers and Crawlers.\nAvailable values: \"block\", \"disabled\", \"only_on_ad_pages\"." + }, + { + "name": "ai_training", + "type": "String", + "description": "Configure robots.txt policy for AI model training bots.\nAvailable values: \"disabled\", \"disallow\", \"block\", \"only_on_ad_pages\"." + }, + { + "name": "ai_user", + "type": "String", + "description": "Configure robots.txt policy for AI assistant and agent bots.\nAvailable values: \"disabled\", \"block\", \"only_on_ad_pages\"." + }, + { + "name": "aisearch", + "type": "String", + "description": "Configure robots.txt policy for AI search bots.\nAvailable values: \"disabled\", \"block\", \"only_on_ad_pages\"." + }, + { + "name": "auto_update_model", + "type": "Boolean", + "description": "Automatically update to the newest bot detection models created by Cloudflare as they are released. [Learn more.](https://developers.cloudflare.com/bots/reference/machine-learning-models#model-versions-and-release-notes)" + }, + { + "name": "bm_cookie_enabled", + "type": "Boolean", + "description": "Indicates that the bot management cookie can be placed on end user devices accessing the site. Defaults to true" + }, + { + "name": "bot_preference_sync_enabled", + "type": "Boolean", + "description": "Enable Bot Preference Sync for this zone. When enabled, Cloudflare can serve robots.txt content derived from the zone's AI Search, AI User, and AI Training preferences." + }, + { + "name": "cf_robots_variant", + "type": "String", + "description": "Specifies the Robots Access Control License variant to use.\nAvailable values: \"off\", \"policy_only\"." + }, + { + "name": "content_bots_protection", + "type": "String", + "description": "Enable rule to block content bots. When enabled, blocks automated traffic with low bot scores, excluding safe verified bot categories. Exceptions should be managed via skip rules.\nAvailable values: \"block\", \"disabled\"." + }, + { + "name": "crawler_protection", + "type": "String", + "description": "Enable rule to punish AI Scrapers and Crawlers via a link maze.\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "enable_js", + "type": "Boolean", + "description": "Use lightweight, invisible JavaScript detections to improve Bot Management. [Learn more about JavaScript Detections](https://developers.cloudflare.com/bots/reference/javascript-detections/)." + }, + { + "name": "fight_mode", + "type": "Boolean", + "description": "Whether to enable Bot Fight Mode." + }, + { + "name": "is_robots_txt_managed", + "type": "Boolean", + "description": "Enable cloudflare managed robots.txt. If an existing robots.txt is detected, then managed robots.txt will be prepended to the existing robots.txt." + }, + { + "name": "jsd_api_results_enabled", + "type": "Boolean", + "description": "Whether to use JavaScript Detection results submitted through the API for this zone." + }, + { + "name": "optimize_wordpress", + "type": "Boolean", + "description": "Whether to optimize Super Bot Fight Mode protections for Wordpress." + }, + { + "name": "sbfm_definitely_automated", + "type": "String", + "description": "Super Bot Fight Mode (SBFM) action to take on definitely automated requests.\nAvailable values: \"allow\", \"block\", \"managed_challenge\"." + }, + { + "name": "sbfm_likely_automated", + "type": "String", + "description": "Super Bot Fight Mode (SBFM) action to take on likely automated requests.\nAvailable values: \"allow\", \"block\", \"managed_challenge\"." + }, + { + "name": "sbfm_static_resource_protection", + "type": "Boolean", + "description": "Super Bot Fight Mode (SBFM) to enable static resource protection.\nEnable if static resources on your application need bot protection.\nNote: Static resource protection can also result in legitimate traffic being blocked." + }, + { + "name": "sbfm_verified_bots", + "type": "String", + "description": "Super Bot Fight Mode (SBFM) action to take on verified bots requests.\nAvailable values: \"allow\", \"block\"." + }, + { + "name": "suppress_session_score", + "type": "Boolean", + "description": "Whether to disable tracking the highest bot score for a session in the Bot Management cookie." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "stale_zone_configuration", + "type": "Attributes", + "description": "A read-only field that shows which unauthorized settings are currently active on the zone. These settings typically result from upgrades or downgrades.", + "children": [ + { + "name": "fight_mode", + "type": "Boolean", + "description": "Indicates that the zone's Bot Fight Mode is turned on." + }, + { + "name": "optimize_wordpress", + "type": "Boolean", + "description": "Indicates that the zone's wordpress optimization for SBFM is turned on." + }, + { + "name": "sbfm_definitely_automated", + "type": "String", + "description": "Indicates that the zone's definitely automated requests are being blocked or challenged." + }, + { + "name": "sbfm_likely_automated", + "type": "String", + "description": "Indicates that the zone's likely automated requests are being blocked or challenged." + }, + { + "name": "sbfm_static_resource_protection", + "type": "String", + "description": "Indicates that the zone's static resource protection is turned on." + }, + { + "name": "sbfm_verified_bots", + "type": "String", + "description": "Indicates that the zone's verified bot requests are being blocked." + }, + { + "name": "suppress_session_score", + "type": "Boolean", + "description": "Indicates that the zone's session score tracking is disabled." + } + ] + }, + { + "name": "using_latest_model", + "type": "Boolean", + "description": "A read-only field that indicates whether the zone currently is running the latest ML model." + } + ] + }, + "data-source:cloudflare_botnet_feed_config_asn": { + "kind": "data-source", + "name": "cloudflare_botnet_feed_config_asn", + "description": "Accepted Permissions\n\n- `DDoS Botnet Feed Read`\n- `DDoS Botnet Feed Write`", + "example": "data \"cloudflare_botnet_feed_config_asn\" \"example_botnet_feed_config_asn\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "asn", + "type": "Number" + } + ] + }, + "data-source:cloudflare_byo_ip_prefix": { + "kind": "data-source", + "name": "cloudflare_byo_ip_prefix", + "description": "Accepted Permissions\n\n- `IP Prefixes: BGP On Demand Read`\n- `IP Prefixes: BGP On Demand Write`\n- `IP Prefixes: Read`\n- `IP Prefixes: Write`\n- `Magic Transit Read`\n- `Magic Transit Write`", + "example": "data \"cloudflare_byo_ip_prefix\" \"example_byo_ip_prefix\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n prefix_id = \"2af39739cc4e3b5910c918468bb89828\"\n}", + "required": [ + { + "name": "prefix_id", + "type": "String", + "description": "Identifier of an IP Prefix." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + } + ], + "computed": [ + { + "name": "advertised", + "type": "Boolean", + "description": "Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.", + "deprecated": "Deprecated." + }, + { + "name": "advertised_modified_at", + "type": "String", + "description": "Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.", + "deprecated": "Deprecated." + }, + { + "name": "approved", + "type": "String", + "description": "Approval state of the prefix (P = pending, V = active)." + }, + { + "name": "asn", + "type": "Number", + "description": "Autonomous System Number (ASN) the prefix will be advertised under." + }, + { + "name": "cidr", + "type": "String", + "description": "IP Prefix in Classless Inter-Domain Routing format." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "delegate_loa_creation", + "type": "Boolean", + "description": "Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner." + }, + { + "name": "description", + "type": "String", + "description": "Description of the prefix." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of an IP Prefix." + }, + { + "name": "irr_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + }, + { + "name": "loa_document_id", + "type": "String", + "description": "Identifier for the uploaded LOA document." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "on_demand_enabled", + "type": "Boolean", + "description": "Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.", + "deprecated": "Deprecated." + }, + { + "name": "on_demand_locked", + "type": "Boolean", + "description": "Whether advertisement status of the prefix is locked, meaning it cannot be changed.", + "deprecated": "Deprecated." + }, + { + "name": "ownership_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + }, + { + "name": "ownership_validation_token", + "type": "String", + "description": "Token provided to demonstrate ownership of the prefix." + }, + { + "name": "rpki_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + } + ] + }, + "resource:cloudflare_byo_ip_prefix": { + "kind": "resource", + "name": "cloudflare_byo_ip_prefix", + "description": "Accepted Permissions\n\n- `IP Prefixes: BGP On Demand Read`\n- `IP Prefixes: BGP On Demand Write`\n- `IP Prefixes: Read`\n- `IP Prefixes: Write`\n- `Magic Transit Read`\n- `Magic Transit Write`", + "example": "resource \"cloudflare_byo_ip_prefix\" \"example_byo_ip_prefix\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n asn = 13335\n cidr = \"192.0.2.0/24\"\n delegate_loa_creation = true\n description = \"Internal test prefix\"\n loa_document_id = \"d933b1530bc56c9953cf8ce166da8004\"\n}", + "importExample": "$ terraform import cloudflare_byo_ip_prefix.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + }, + { + "name": "asn", + "type": "Number", + "description": "Autonomous System Number (ASN) the prefix will be advertised under." + }, + { + "name": "cidr", + "type": "String", + "description": "IP Prefix in Classless Inter-Domain Routing format." + } + ], + "optional": [ + { + "name": "delegate_loa_creation", + "type": "Boolean", + "description": "Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner." + }, + { + "name": "description", + "type": "String", + "description": "Description of the prefix." + }, + { + "name": "loa_document_id", + "type": "String", + "description": "Identifier for the uploaded LOA document." + } + ], + "computed": [ + { + "name": "advertised", + "type": "Boolean", + "description": "Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.", + "deprecated": "Deprecated." + }, + { + "name": "advertised_modified_at", + "type": "String", + "description": "Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.", + "deprecated": "Deprecated." + }, + { + "name": "approved", + "type": "String", + "description": "Approval state of the prefix (P = pending, V = active)." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier of an IP Prefix." + }, + { + "name": "irr_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "on_demand_enabled", + "type": "Boolean", + "description": "Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.", + "deprecated": "Deprecated." + }, + { + "name": "on_demand_locked", + "type": "Boolean", + "description": "Whether advertisement status of the prefix is locked, meaning it cannot be changed.", + "deprecated": "Deprecated." + }, + { + "name": "ownership_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + }, + { + "name": "ownership_validation_token", + "type": "String", + "description": "Token provided to demonstrate ownership of the prefix." + }, + { + "name": "rpki_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + } + ] + }, + "list-data-source:cloudflare_byo_ip_prefixes": { + "kind": "list-data-source", + "name": "cloudflare_byo_ip_prefixes", + "description": "Accepted Permissions\n\n- `IP Prefixes: BGP On Demand Read`\n- `IP Prefixes: BGP On Demand Write`\n- `IP Prefixes: Read`\n- `IP Prefixes: Write`\n- `Magic Transit Read`\n- `Magic Transit Write`", + "example": "data \"cloudflare_byo_ip_prefixes\" \"example_byo_ip_prefixes\" {\n account_id = \"258def64c72dae45f3e4c8516e2111f2\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + }, + { + "name": "advertised", + "type": "Boolean", + "description": "Prefix advertisement status to the Internet. This field is only not 'null' if on demand is enabled.", + "deprecated": "Deprecated." + }, + { + "name": "advertised_modified_at", + "type": "String", + "description": "Last time the advertisement status was changed. This field is only not 'null' if on demand is enabled.", + "deprecated": "Deprecated." + }, + { + "name": "approved", + "type": "String", + "description": "Approval state of the prefix (P = pending, V = active)." + }, + { + "name": "asn", + "type": "Number", + "description": "Autonomous System Number (ASN) the prefix will be advertised under." + }, + { + "name": "cidr", + "type": "String", + "description": "IP Prefix in Classless Inter-Domain Routing format." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "delegate_loa_creation", + "type": "Boolean", + "description": "Whether Cloudflare is allowed to generate the LOA document on behalf of the prefix owner." + }, + { + "name": "description", + "type": "String", + "description": "Description of the prefix." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of an IP Prefix." + }, + { + "name": "irr_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + }, + { + "name": "loa_document_id", + "type": "String", + "description": "Identifier for the uploaded LOA document." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "on_demand_enabled", + "type": "Boolean", + "description": "Whether advertisement of the prefix to the Internet may be dynamically enabled or disabled.", + "deprecated": "Deprecated." + }, + { + "name": "on_demand_locked", + "type": "Boolean", + "description": "Whether advertisement status of the prefix is locked, meaning it cannot be changed.", + "deprecated": "Deprecated." + }, + { + "name": "ownership_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + }, + { + "name": "ownership_validation_token", + "type": "String", + "description": "Token provided to demonstrate ownership of the prefix." + }, + { + "name": "rpki_validation_state", + "type": "String", + "description": "State of one kind of validation for an IP prefix." + } + ] + } + ] + }, + "data-source:cloudflare_calls_sfu_app": { + "kind": "data-source", + "name": "cloudflare_calls_sfu_app", + "description": "Accepted Permissions\n\n- `Calls Read`\n- `Calls Write`", + "example": "data \"cloudflare_calls_sfu_app\" \"example_calls_sfu_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n app_id = \"2a95132c15732412d22c1476fa83f27a\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "app_id", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the item was created." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the item was last modified." + }, + { + "name": "name", + "type": "String", + "description": "A short description of a Realtime SFU app, not shown to end users." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ] + }, + "resource:cloudflare_calls_sfu_app": { + "kind": "resource", + "name": "cloudflare_calls_sfu_app", + "description": "Accepted Permissions\n\n- `Calls Read`\n- `Calls Write`", + "example": "resource \"cloudflare_calls_sfu_app\" \"example_calls_sfu_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"production-realtime-app\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + } + ], + "optional": [ + { + "name": "app_id", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + }, + { + "name": "name", + "type": "String", + "description": "A short description of a Realtime SFU app, not shown to end users." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the item was created." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the item was last modified." + }, + { + "name": "secret", + "type": "String", + "description": "Bearer token", + "sensitive": true + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ] + }, + "list-data-source:cloudflare_calls_sfu_apps": { + "kind": "list-data-source", + "name": "cloudflare_calls_sfu_apps", + "description": "Accepted Permissions\n\n- `Calls Read`\n- `Calls Write`", + "example": "data \"cloudflare_calls_sfu_apps\" \"example_calls_sfu_apps\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and time the item was created." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the item was last modified." + }, + { + "name": "name", + "type": "String", + "description": "A short description of a Realtime SFU app, not shown to end users." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ] + } + ] + }, + "data-source:cloudflare_calls_turn_app": { + "kind": "data-source", + "name": "cloudflare_calls_turn_app", + "description": "Accepted Permissions\n\n- `Calls Read`\n- `Calls Write`", + "example": "data \"cloudflare_calls_turn_app\" \"example_calls_turn_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n key_id = \"2a95132c15732412d22c1476fa83f27a\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "key_id", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the item was created." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the item was last modified." + }, + { + "name": "name", + "type": "String", + "description": "A short description of a Realtime SFU app, not shown to end users." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ] + }, + "resource:cloudflare_calls_turn_app": { + "kind": "resource", + "name": "cloudflare_calls_turn_app", + "description": "Accepted Permissions\n\n- `Calls Read`\n- `Calls Write`", + "example": "resource \"cloudflare_calls_turn_app\" \"example_calls_turn_app\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-turn-key\"\n}", + "importExample": "$ terraform import cloudflare_calls_turn_app.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + } + ], + "optional": [ + { + "name": "key_id", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + }, + { + "name": "name", + "type": "String", + "description": "A short description of a TURN key, not shown to end users." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the item was created." + }, + { + "name": "key", + "type": "String", + "description": "Bearer token", + "sensitive": true + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the item was last modified." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ] + }, + "list-data-source:cloudflare_calls_turn_apps": { + "kind": "list-data-source", + "name": "cloudflare_calls_turn_apps", + "description": "Accepted Permissions\n\n- `Calls Read`\n- `Calls Write`", + "example": "data \"cloudflare_calls_turn_apps\" \"example_calls_turn_apps\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and time the item was created." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the item was last modified." + }, + { + "name": "name", + "type": "String", + "description": "A short description of a Realtime SFU app, not shown to end users." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a item." + } + ] + } + ] + }, + "data-source:cloudflare_certificate_authorities_hostname_associations": { + "kind": "data-source", + "name": "cloudflare_certificate_authorities_hostname_associations", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_certificate_authorities_hostname_associations\" \"example_certificate_authorities_hostname_associations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n mtls_certificate_id = \"b2134436-2555-4acf-be5b-26c48136575e\"\n}", + "required": [], + "optional": [ + { + "name": "mtls_certificate_id", + "type": "String", + "description": "The UUID to match against for a certificate that was uploaded to the mTLS Certificate Management endpoint. If no mtls_certificate_id is given, the results will be the hostnames associated to your active Cloudflare Managed CA." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "hostnames", + "type": "List of String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_certificate_authorities_hostname_associations": { + "kind": "resource", + "name": "cloudflare_certificate_authorities_hostname_associations", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_certificate_authorities_hostname_associations\" \"example_certificate_authorities_hostname_associations\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostnames = [\"api.example.com\"]\n mtls_certificate_id = \"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx\"\n}", + "importExample": "$ terraform import cloudflare_certificate_authorities_hostname_associations.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "hostnames", + "type": "List of String" + }, + { + "name": "mtls_certificate_id", + "type": "String", + "description": "The UUID for a certificate that was uploaded to the mTLS Certificate Management endpoint. If no mtls_certificate_id is given, the hostnames will be associated to your active Cloudflare Managed CA." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_certificate_pack": { + "kind": "data-source", + "name": "cloudflare_certificate_pack", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_certificate_pack\" \"example_certificate_pack\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_pack_id = \"3822ff90-ea29-44df-9e55-21300bb9419b\"\n}", + "required": [], + "optional": [ + { + "name": "certificate_pack_id", + "type": "String", + "description": "The unique identifier for a certificate_pack." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "deploy", + "type": "String", + "description": "Specify the deployment environment for the certificate packs.\nAvailable values: \"staging\", \"production\"." + }, + { + "name": "status", + "type": "String", + "description": "Include Certificate Packs of all statuses, not just active ones.\nAvailable values: \"all\"." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities).\nAvailable values: \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "certificates", + "type": "Attributes List", + "description": "Array of certificates in this pack.", + "children": [ + { + "name": "bundle_method", + "type": "String", + "description": "Certificate bundle method." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "geo_restrictions", + "type": "Attributes", + "description": "Specify the region where your private key can be held locally.", + "children": [ + { + "name": "label", + "type": "String", + "description": "Available values: \"us\", \"eu\", \"highest_security\"." + } + ] + }, + { + "name": "hosts", + "type": "List of String", + "description": "Hostnames covered by this certificate." + }, + { + "name": "id", + "type": "String", + "description": "Certificate identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "priority", + "type": "Number", + "description": "The order/priority in which the certificate will be used." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Certificate status." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "cloudflare_branding", + "type": "Boolean", + "description": "Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true." + }, + { + "name": "dcv_delegation_records", + "type": "Attributes List", + "description": "DCV Delegation records for domain validation.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "hosts", + "type": "Set of String", + "description": "Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier for a certificate_pack." + }, + { + "name": "primary_certificate", + "type": "String", + "description": "Identifier of the primary certificate in a pack." + }, + { + "name": "status", + "type": "String", + "description": "Status of certificate pack.\nAvailable values: \"initializing\", \"pending_validation\", \"deleted\", \"pending_issuance\", \"pending_deployment\", \"pending_deletion\", \"pending_expiration\", \"expired\", \"active\", \"initializing_timed_out\", \"validation_timed_out\", \"issuance_timed_out\", \"deployment_timed_out\", \"deletion_timed_out\", \"pending_cleanup\", \"staging_deployment\", \"staging_active\", \"deactivating\", \"inactive\", \"backup_issued\", \"holding_deployment\"." + }, + { + "name": "type", + "type": "String", + "description": "Type of certificate pack.\nAvailable values: \"mh_custom\", \"managed_hostname\", \"sni_custom\", \"universal\", \"advanced\", \"total_tls\", \"keyless\", \"legacy_custom\"." + }, + { + "name": "validation_errors", + "type": "Attributes List", + "description": "Domain validation errors that have been received by the certificate authority (CA).", + "children": [ + { + "name": "message", + "type": "String", + "description": "A domain validation error." + } + ] + }, + { + "name": "validation_method", + "type": "String", + "description": "Validation Method selected for the order.\nAvailable values: \"txt\", \"http\", \"email\"." + }, + { + "name": "validation_records", + "type": "Attributes List", + "description": "Certificates' validation records.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "validity_days", + "type": "Number", + "description": "Validity Days selected for the order.\nAvailable values: 14, 30, 90, 365." + } + ] + }, + "resource:cloudflare_certificate_pack": { + "kind": "resource", + "name": "cloudflare_certificate_pack", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n\n~> Certificate packs are not able to be updated in place. If\nyou require a zero downtime rotation, you can create multiple\nresources using a 2-phase change where you have both resources\nlive at once and you remove the old one once you've confirmed\nthe certificate is available.", + "example": "resource \"cloudflare_certificate_pack\" \"example_certificate_pack\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate_authority = \"lets_encrypt\"\n hosts = [\"example.com\", \"*.example.com\", \"www.example.com\"]\n type = \"advanced\"\n validation_method = \"txt\"\n validity_days = 14\n cloudflare_branding = false\n}", + "importExample": "$ terraform import cloudflare_certificate_pack.example '/'", + "required": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities).\nAvailable values: \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "type", + "type": "String", + "description": "Type of certificate pack.\nAvailable values: \"advanced\"." + }, + { + "name": "validation_method", + "type": "String", + "description": "Validation Method selected for the order.\nAvailable values: \"txt\", \"http\", \"email\"." + }, + { + "name": "validity_days", + "type": "Number", + "description": "Validity Days selected for the order.\nAvailable values: 14, 30, 90, 365." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "cloudflare_branding", + "type": "Boolean", + "description": "Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true." + }, + { + "name": "hosts", + "type": "Set of String", + "description": "Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty." + } + ], + "computed": [ + { + "name": "certificates", + "type": "Attributes List", + "description": "Array of certificates in this pack.", + "children": [ + { + "name": "bundle_method", + "type": "String", + "description": "Certificate bundle method." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "geo_restrictions", + "type": "Attributes", + "description": "Specify the region where your private key can be held locally.", + "children": [ + { + "name": "label", + "type": "String", + "description": "Available values: \"us\", \"eu\", \"highest_security\"." + } + ] + }, + { + "name": "hosts", + "type": "List of String", + "description": "Hostnames covered by this certificate." + }, + { + "name": "id", + "type": "String", + "description": "Certificate identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "priority", + "type": "Number", + "description": "The order/priority in which the certificate will be used." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Certificate status." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "dcv_delegation_records", + "type": "Attributes List", + "description": "DCV Delegation records for domain validation.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier for a certificate_pack." + }, + { + "name": "primary_certificate", + "type": "String", + "description": "Identifier of the primary certificate in a pack." + }, + { + "name": "status", + "type": "String", + "description": "Status of certificate pack.\nAvailable values: \"initializing\", \"pending_validation\", \"deleted\", \"pending_issuance\", \"pending_deployment\", \"pending_deletion\", \"pending_expiration\", \"expired\", \"active\", \"initializing_timed_out\", \"validation_timed_out\", \"issuance_timed_out\", \"deployment_timed_out\", \"deletion_timed_out\", \"pending_cleanup\", \"staging_deployment\", \"staging_active\", \"deactivating\", \"inactive\", \"backup_issued\", \"holding_deployment\"." + }, + { + "name": "validation_errors", + "type": "Attributes List", + "description": "Domain validation errors that have been received by the certificate authority (CA).", + "children": [ + { + "name": "message", + "type": "String", + "description": "A domain validation error." + } + ] + }, + { + "name": "validation_records", + "type": "Attributes List", + "description": "Certificates' validation records.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + } + ] + }, + "list-data-source:cloudflare_certificate_packs": { + "kind": "list-data-source", + "name": "cloudflare_certificate_packs", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_certificate_packs\" \"example_certificate_packs\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n deploy = \"staging\"\n status = \"all\"\n}", + "required": [], + "optional": [ + { + "name": "deploy", + "type": "String", + "description": "Specify the deployment environment for the certificate packs.\nAvailable values: \"staging\", \"production\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "status", + "type": "String", + "description": "Include Certificate Packs of all statuses, not just active ones.\nAvailable values: \"all\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Certificate Authority selected for the order. For information on any certificate authority specific details or restrictions [see this page for more details](https://developers.cloudflare.com/ssl/reference/certificate-authorities).\nAvailable values: \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "certificates", + "type": "Attributes List", + "description": "Array of certificates in this pack.", + "children": [ + { + "name": "bundle_method", + "type": "String", + "description": "Certificate bundle method." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "geo_restrictions", + "type": "Attributes", + "description": "Specify the region where your private key can be held locally.", + "children": [ + { + "name": "label", + "type": "String", + "description": "Available values: \"us\", \"eu\", \"highest_security\"." + } + ] + }, + { + "name": "hosts", + "type": "List of String", + "description": "Hostnames covered by this certificate." + }, + { + "name": "id", + "type": "String", + "description": "Certificate identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "priority", + "type": "Number", + "description": "The order/priority in which the certificate will be used." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Certificate status." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "cloudflare_branding", + "type": "Boolean", + "description": "Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true." + }, + { + "name": "dcv_delegation_records", + "type": "Attributes List", + "description": "DCV Delegation records for domain validation.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "hosts", + "type": "Set of String", + "description": "Comma separated list of valid host names for the certificate packs. Must contain the zone apex, may not contain more than 50 hosts, and may not be empty." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier for a certificate_pack." + }, + { + "name": "primary_certificate", + "type": "String", + "description": "Identifier of the primary certificate in a pack." + }, + { + "name": "status", + "type": "String", + "description": "Status of certificate pack.\nAvailable values: \"initializing\", \"pending_validation\", \"deleted\", \"pending_issuance\", \"pending_deployment\", \"pending_deletion\", \"pending_expiration\", \"expired\", \"active\", \"initializing_timed_out\", \"validation_timed_out\", \"issuance_timed_out\", \"deployment_timed_out\", \"deletion_timed_out\", \"pending_cleanup\", \"staging_deployment\", \"staging_active\", \"deactivating\", \"inactive\", \"backup_issued\", \"holding_deployment\"." + }, + { + "name": "type", + "type": "String", + "description": "Type of certificate pack.\nAvailable values: \"mh_custom\", \"managed_hostname\", \"sni_custom\", \"universal\", \"advanced\", \"total_tls\", \"keyless\", \"legacy_custom\"." + }, + { + "name": "validation_errors", + "type": "Attributes List", + "description": "Domain validation errors that have been received by the certificate authority (CA).", + "children": [ + { + "name": "message", + "type": "String", + "description": "A domain validation error." + } + ] + }, + { + "name": "validation_method", + "type": "String", + "description": "Validation Method selected for the order.\nAvailable values: \"txt\", \"http\", \"email\"." + }, + { + "name": "validation_records", + "type": "Attributes List", + "description": "Certificates' validation records.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "validity_days", + "type": "Number", + "description": "Validity Days selected for the order.\nAvailable values: 14, 30, 90, 365." + } + ] + } + ] + }, + "data-source:cloudflare_client_certificate": { + "kind": "data-source", + "name": "cloudflare_client_certificate", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_client_certificate\" \"example_client_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n client_certificate_id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n}", + "required": [], + "optional": [ + { + "name": "client_certificate_id", + "type": "String", + "description": "Client Certificate Tag" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "Limit to the number of records returned." + }, + { + "name": "offset", + "type": "Number", + "description": "Offset the results." + }, + { + "name": "status", + "type": "String", + "description": "Client Certitifcate Status to filter results by.\nAvailable values: \"all\", \"active\", \"pending_reactivation\", \"pending_revocation\", \"revoked\"." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "certificate", + "type": "String", + "description": "The Client Certificate PEM." + }, + { + "name": "certificate_authority", + "type": "Attributes", + "description": "Certificate Authority used to issue the Client Certificate.", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "common_name", + "type": "String", + "description": "Common Name of the Client Certificate." + }, + { + "name": "country", + "type": "String", + "description": "Country, provided by the CSR." + }, + { + "name": "csr", + "type": "String", + "description": "The Certificate Signing Request (CSR). Must be newline-encoded." + }, + { + "name": "expires_on", + "type": "String", + "description": "Date that the Client Certificate expires." + }, + { + "name": "fingerprint_sha256", + "type": "String", + "description": "Unique identifier of the Client Certificate." + }, + { + "name": "id", + "type": "String", + "description": "Client Certificate Tag" + }, + { + "name": "issued_on", + "type": "String", + "description": "Date that the Client Certificate was issued by the Certificate Authority." + }, + { + "name": "location", + "type": "String", + "description": "Location, provided by the CSR." + }, + { + "name": "organization", + "type": "String", + "description": "Organization, provided by the CSR." + }, + { + "name": "organizational_unit", + "type": "String", + "description": "Organizational Unit, provided by the CSR." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the created Client Certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the Client Certificate.." + }, + { + "name": "ski", + "type": "String", + "description": "Subject Key Identifier." + }, + { + "name": "state", + "type": "String", + "description": "State, provided by the CSR." + }, + { + "name": "status", + "type": "String", + "description": "Client Certificates may be active or revoked, and the pending_reactivation or pending_revocation represent in-progress asynchronous transitions.\nAvailable values: \"active\", \"pending_reactivation\", \"pending_revocation\", \"revoked\"." + }, + { + "name": "validity_days", + "type": "Number", + "description": "The number of days the Client Certificate will be valid after the issued_on date." + } + ] + }, + "resource:cloudflare_client_certificate": { + "kind": "resource", + "name": "cloudflare_client_certificate", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_client_certificate\" \"example_client_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n csr = </'", + "required": [ + { + "name": "csr", + "type": "String", + "description": "The Certificate Signing Request (CSR). Must be newline-encoded." + }, + { + "name": "validity_days", + "type": "Number", + "description": "The number of days the Client Certificate will be valid after the issued_on date." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "reactivate", + "type": "Boolean" + } + ], + "computed": [ + { + "name": "certificate", + "type": "String", + "description": "The Client Certificate PEM." + }, + { + "name": "certificate_authority", + "type": "Attributes", + "description": "Certificate Authority used to issue the Client Certificate.", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "common_name", + "type": "String", + "description": "Common Name of the Client Certificate." + }, + { + "name": "country", + "type": "String", + "description": "Country, provided by the CSR." + }, + { + "name": "expires_on", + "type": "String", + "description": "Date that the Client Certificate expires." + }, + { + "name": "fingerprint_sha256", + "type": "String", + "description": "Unique identifier of the Client Certificate." + }, + { + "name": "id", + "type": "String", + "description": "Client Certificate Tag" + }, + { + "name": "issued_on", + "type": "String", + "description": "Date that the Client Certificate was issued by the Certificate Authority." + }, + { + "name": "location", + "type": "String", + "description": "Location, provided by the CSR." + }, + { + "name": "organization", + "type": "String", + "description": "Organization, provided by the CSR." + }, + { + "name": "organizational_unit", + "type": "String", + "description": "Organizational Unit, provided by the CSR." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the created Client Certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the Client Certificate.." + }, + { + "name": "ski", + "type": "String", + "description": "Subject Key Identifier." + }, + { + "name": "state", + "type": "String", + "description": "State, provided by the CSR." + }, + { + "name": "status", + "type": "String", + "description": "Client Certificates may be active or revoked, and the pending_reactivation or pending_revocation represent in-progress asynchronous transitions.\nAvailable values: \"active\", \"pending_reactivation\", \"pending_revocation\", \"revoked\"." + } + ] + }, + "list-data-source:cloudflare_client_certificates": { + "kind": "list-data-source", + "name": "cloudflare_client_certificates", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_client_certificates\" \"example_client_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n status = \"all\"\n}", + "required": [], + "optional": [ + { + "name": "limit", + "type": "Number", + "description": "Limit to the number of records returned." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "offset", + "type": "Number", + "description": "Offset the results." + }, + { + "name": "status", + "type": "String", + "description": "Client Certitifcate Status to filter results by.\nAvailable values: \"all\", \"active\", \"pending_reactivation\", \"pending_revocation\", \"revoked\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "certificate", + "type": "String", + "description": "The Client Certificate PEM." + }, + { + "name": "certificate_authority", + "type": "Attributes", + "description": "Certificate Authority used to issue the Client Certificate.", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "common_name", + "type": "String", + "description": "Common Name of the Client Certificate." + }, + { + "name": "country", + "type": "String", + "description": "Country, provided by the CSR." + }, + { + "name": "csr", + "type": "String", + "description": "The Certificate Signing Request (CSR). Must be newline-encoded." + }, + { + "name": "expires_on", + "type": "String", + "description": "Date that the Client Certificate expires." + }, + { + "name": "fingerprint_sha256", + "type": "String", + "description": "Unique identifier of the Client Certificate." + }, + { + "name": "id", + "type": "String", + "description": "Client Certificate Tag" + }, + { + "name": "issued_on", + "type": "String", + "description": "Date that the Client Certificate was issued by the Certificate Authority." + }, + { + "name": "location", + "type": "String", + "description": "Location, provided by the CSR." + }, + { + "name": "organization", + "type": "String", + "description": "Organization, provided by the CSR." + }, + { + "name": "organizational_unit", + "type": "String", + "description": "Organizational Unit, provided by the CSR." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on the created Client Certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the Client Certificate.." + }, + { + "name": "ski", + "type": "String", + "description": "Subject Key Identifier." + }, + { + "name": "state", + "type": "String", + "description": "State, provided by the CSR." + }, + { + "name": "status", + "type": "String", + "description": "Client Certificates may be active or revoked, and the pending_reactivation or pending_revocation represent in-progress asynchronous transitions.\nAvailable values: \"active\", \"pending_reactivation\", \"pending_revocation\", \"revoked\"." + }, + { + "name": "validity_days", + "type": "Number", + "description": "The number of days the Client Certificate will be valid after the issued_on date." + } + ] + } + ] + }, + "data-source:cloudflare_cloud_connector_rules": { + "kind": "data-source", + "name": "cloudflare_cloud_connector_rules", + "description": "Accepted Permissions\n\n- `Cloud Connector Read`\n- `Cloud Connector Write`", + "example": "data \"cloudflare_cloud_connector_rules\" \"example_cloud_connector_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "cloud_connector_rules_provider", + "type": "String", + "description": "Cloud Provider type\nAvailable values: \"aws_s3\", \"cloudflare_r2\", \"gcp_storage\", \"azure_storage\", \"oci_storage\"." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "expression", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "parameters", + "type": "Attributes", + "description": "Parameters of Cloud Connector Rule", + "children": [ + { + "name": "host", + "type": "String", + "description": "Host to perform Cloud Connection to" + } + ] + } + ] + }, + "resource:cloudflare_cloud_connector_rules": { + "kind": "resource", + "name": "cloudflare_cloud_connector_rules", + "description": "Accepted Permissions\n\n- `Cloud Connector Read`\n- `Cloud Connector Write`", + "example": "resource \"cloudflare_cloud_connector_rules\" \"example_cloud_connector_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rules = [{\n id = \"95c365e17e1b46599cd99e5b231fac4e\"\n description = \"Rule description\"\n enabled = true\n expression = \"http.cookie eq \\\"a=b\\\"\"\n parameters = {\n host = \"examplebucket.s3.eu-north-1.amazonaws.com\"\n }\n cloud_connector_rules_provider = \"aws_s3\"\n }]\n}", + "importExample": "$ terraform import cloudflare_cloud_connector_rules.example ''", + "required": [ + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "cloud_connector_rules_provider", + "type": "String", + "description": "Cloud Provider type\nAvailable values: \"aws_s3\", \"cloudflare_r2\", \"gcp_storage\", \"azure_storage\", \"oci_storage\"." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "expression", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "parameters", + "type": "Attributes", + "description": "Parameters of Cloud Connector Rule", + "children": [ + { + "name": "host", + "type": "String", + "description": "Host to perform Cloud Connection to" + } + ] + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_cloudforce_one_request": { + "kind": "data-source", + "name": "cloudflare_cloudforce_one_request", + "description": "Accepted Permissions\n\n- `Cloudforce One Read`\n- `Cloudforce One Write`", + "example": "data \"cloudflare_cloudforce_one_request\" \"example_cloudforce_one_request\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "completed_after", + "type": "String", + "description": "Retrieve requests completed after this time." + }, + { + "name": "completed_before", + "type": "String", + "description": "Retrieve requests completed before this time." + }, + { + "name": "created_after", + "type": "String", + "description": "Retrieve requests created after this time." + }, + { + "name": "created_before", + "type": "String", + "description": "Retrieve requests created before this time." + }, + { + "name": "page", + "type": "Number", + "description": "Page number of results." + }, + { + "name": "per_page", + "type": "Number", + "description": "Number of results per page." + }, + { + "name": "request_type", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "sort_by", + "type": "String", + "description": "Field to sort results by." + }, + { + "name": "sort_order", + "type": "String", + "description": "Sort order (asc or desc).\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "status", + "type": "String", + "description": "Request Status.\nAvailable values: \"open\", \"accepted\", \"reported\", \"approved\", \"completed\", \"declined\"." + } + ] + }, + { + "name": "request_id", + "type": "String", + "description": "UUID." + } + ], + "computed": [ + { + "name": "completed", + "type": "String" + }, + { + "name": "content", + "type": "String", + "description": "Request content." + }, + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "message_tokens", + "type": "Number", + "description": "Tokens for the request messages." + }, + { + "name": "priority", + "type": "String" + }, + { + "name": "readable_id", + "type": "String", + "description": "Readable Request ID." + }, + { + "name": "request", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "status", + "type": "String", + "description": "Request Status.\nAvailable values: \"open\", \"accepted\", \"reported\", \"approved\", \"completed\", \"declined\"." + }, + { + "name": "summary", + "type": "String", + "description": "Brief description of the request." + }, + { + "name": "tlp", + "type": "String", + "description": "The CISA defined Traffic Light Protocol (TLP).\nAvailable values: \"clear\", \"amber\", \"amber-strict\", \"green\", \"red\"." + }, + { + "name": "tokens", + "type": "Number", + "description": "Tokens for the request." + }, + { + "name": "updated", + "type": "String" + } + ] + }, + "resource:cloudflare_cloudforce_one_request": { + "kind": "resource", + "name": "cloudflare_cloudforce_one_request", + "description": "Accepted Permissions\n\n- `Cloudforce One Read`\n- `Cloudforce One Write`", + "example": "resource \"cloudflare_cloudforce_one_request\" \"example_cloudforce_one_request\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n content = \"What regions were most effected by the recent DoS?\"\n priority = \"routine\"\n request_type = \"Victomology\"\n summary = \"DoS attack\"\n tlp = \"clear\"\n}", + "importExample": "$ terraform import cloudflare_cloudforce_one_request.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "content", + "type": "String", + "description": "Request content." + }, + { + "name": "priority", + "type": "String", + "description": "Priority for analyzing the request." + }, + { + "name": "request_type", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "summary", + "type": "String", + "description": "Brief description of the request." + }, + { + "name": "tlp", + "type": "String", + "description": "The CISA defined Traffic Light Protocol (TLP).\nAvailable values: \"clear\", \"amber\", \"amber-strict\", \"green\", \"red\"." + } + ], + "computed": [ + { + "name": "completed", + "type": "String" + }, + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "message_tokens", + "type": "Number", + "description": "Tokens for the request messages." + }, + { + "name": "readable_id", + "type": "String", + "description": "Readable Request ID." + }, + { + "name": "request", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "status", + "type": "String", + "description": "Request Status.\nAvailable values: \"open\", \"accepted\", \"reported\", \"approved\", \"completed\", \"declined\"." + }, + { + "name": "tokens", + "type": "Number", + "description": "Tokens for the request." + }, + { + "name": "updated", + "type": "String" + } + ] + }, + "data-source:cloudflare_cloudforce_one_request_asset": { + "kind": "data-source", + "name": "cloudflare_cloudforce_one_request_asset", + "description": "Accepted Permissions\n\n- `Cloudforce One Read`\n- `Cloudforce One Write`", + "example": "data \"cloudflare_cloudforce_one_request_asset\" \"example_cloudforce_one_request_asset\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n asset_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "asset_id", + "type": "String", + "description": "UUID." + }, + { + "name": "request_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "Defines the asset creation time." + }, + { + "name": "description", + "type": "String", + "description": "Asset description." + }, + { + "name": "file_type", + "type": "String", + "description": "Asset file type." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "Asset name." + } + ] + }, + "resource:cloudflare_cloudforce_one_request_asset": { + "kind": "resource", + "name": "cloudflare_cloudforce_one_request_asset", + "description": "Accepted Permissions\n\n- `Cloudforce One Read`\n- `Cloudforce One Write`", + "example": "resource \"cloudflare_cloudforce_one_request_asset\" \"example_cloudforce_one_request_asset\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n page = 0\n per_page = 10\n}", + "importExample": "$ terraform import cloudflare_cloudforce_one_request_asset.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "page", + "type": "Number", + "description": "Page number of results." + }, + { + "name": "per_page", + "type": "Number", + "description": "Number of results per page." + }, + { + "name": "request_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "source", + "type": "String", + "description": "Asset file to upload." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "Defines the asset creation time." + }, + { + "name": "description", + "type": "String", + "description": "Asset description." + }, + { + "name": "file_type", + "type": "String", + "description": "Asset file type." + }, + { + "name": "id", + "type": "Number", + "description": "Asset ID." + }, + { + "name": "name", + "type": "String", + "description": "Asset name." + } + ] + }, + "data-source:cloudflare_cloudforce_one_request_message": { + "kind": "data-source", + "name": "cloudflare_cloudforce_one_request_message", + "description": "Accepted Permissions\n\n- `Cloudforce One Write`", + "example": "data \"cloudflare_cloudforce_one_request_message\" \"example_cloudforce_one_request_message\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n page = 0\n per_page = 10\n after = \"2019-12-27T18:11:19.117Z\"\n before = \"2024-01-01T00:00:00Z\"\n sort_by = \"created\"\n sort_order = \"asc\"\n}", + "required": [ + { + "name": "page", + "type": "Number", + "description": "Page number of results." + }, + { + "name": "per_page", + "type": "Number", + "description": "Number of results per page." + }, + { + "name": "request_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "after", + "type": "String", + "description": "Retrieve mes ges created after this time." + }, + { + "name": "before", + "type": "String", + "description": "Retrieve messages created before this time." + }, + { + "name": "sort_by", + "type": "String", + "description": "Field to sort results by." + }, + { + "name": "sort_order", + "type": "String", + "description": "Sort order (asc or desc).\nAvailable values: \"asc\", \"desc\"." + } + ], + "computed": [ + { + "name": "author", + "type": "String", + "description": "Author of message." + }, + { + "name": "content", + "type": "String", + "description": "Content of message." + }, + { + "name": "created", + "type": "String", + "description": "Defines the message creation time." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "is_follow_on_request", + "type": "Boolean", + "description": "Whether the message is a follow-on request." + }, + { + "name": "updated", + "type": "String", + "description": "Defines the message last updated time." + } + ] + }, + "resource:cloudflare_cloudforce_one_request_message": { + "kind": "resource", + "name": "cloudflare_cloudforce_one_request_message", + "description": "Accepted Permissions\n\n- `Cloudforce One Write`", + "example": "resource \"cloudflare_cloudforce_one_request_message\" \"example_cloudforce_one_request_message\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n request_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n content = \"Can you elaborate on the type of DoS that occurred?\"\n}", + "importExample": "$ terraform import cloudflare_cloudforce_one_request_message.example '///'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "request_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "content", + "type": "String", + "description": "Content of message." + } + ], + "computed": [ + { + "name": "author", + "type": "String", + "description": "Author of message." + }, + { + "name": "created", + "type": "String", + "description": "Defines the message creation time." + }, + { + "name": "id", + "type": "Number", + "description": "Message ID." + }, + { + "name": "is_follow_on_request", + "type": "Boolean", + "description": "Whether the message is a follow-on request." + }, + { + "name": "updated", + "type": "String", + "description": "Defines the message last updated time." + } + ] + }, + "data-source:cloudflare_cloudforce_one_request_priority": { + "kind": "data-source", + "name": "cloudflare_cloudforce_one_request_priority", + "description": "Accepted Permissions\n\n- `Cloudforce One Read`\n- `Cloudforce One Write`", + "example": "data \"cloudflare_cloudforce_one_request_priority\" \"example_cloudforce_one_request_priority\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n priority_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "priority_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "completed", + "type": "String" + }, + { + "name": "content", + "type": "String", + "description": "Request content." + }, + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "message_tokens", + "type": "Number", + "description": "Tokens for the request messages." + }, + { + "name": "priority", + "type": "String" + }, + { + "name": "readable_id", + "type": "String", + "description": "Readable Request ID." + }, + { + "name": "request", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "status", + "type": "String", + "description": "Request Status.\nAvailable values: \"open\", \"accepted\", \"reported\", \"approved\", \"completed\", \"declined\"." + }, + { + "name": "summary", + "type": "String", + "description": "Brief description of the request." + }, + { + "name": "tlp", + "type": "String", + "description": "The CISA defined Traffic Light Protocol (TLP).\nAvailable values: \"clear\", \"amber\", \"amber-strict\", \"green\", \"red\"." + }, + { + "name": "tokens", + "type": "Number", + "description": "Tokens for the request." + }, + { + "name": "updated", + "type": "String" + } + ] + }, + "resource:cloudflare_cloudforce_one_request_priority": { + "kind": "resource", + "name": "cloudflare_cloudforce_one_request_priority", + "description": "Accepted Permissions\n\n- `Cloudforce One Read`\n- `Cloudforce One Write`", + "example": "resource \"cloudflare_cloudforce_one_request_priority\" \"example_cloudforce_one_request_priority\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n labels = [\"DoS\", \"CVE\"]\n priority = 1\n requirement = \"DoS attacks carried out by CVEs\"\n tlp = \"clear\"\n}", + "importExample": "$ terraform import cloudflare_cloudforce_one_request_priority.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "labels", + "type": "List of String", + "description": "List of labels." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority." + }, + { + "name": "requirement", + "type": "String", + "description": "Requirement." + }, + { + "name": "tlp", + "type": "String", + "description": "The CISA defined Traffic Light Protocol (TLP).\nAvailable values: \"clear\", \"amber\", \"amber-strict\", \"green\", \"red\"." + } + ], + "optional": [], + "computed": [ + { + "name": "completed", + "type": "String" + }, + { + "name": "content", + "type": "String", + "description": "Request content." + }, + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "message_tokens", + "type": "Number", + "description": "Tokens for the request messages." + }, + { + "name": "readable_id", + "type": "String", + "description": "Readable Request ID." + }, + { + "name": "request", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "status", + "type": "String", + "description": "Request Status.\nAvailable values: \"open\", \"accepted\", \"reported\", \"approved\", \"completed\", \"declined\"." + }, + { + "name": "summary", + "type": "String", + "description": "Brief description of the request." + }, + { + "name": "tokens", + "type": "Number", + "description": "Tokens for the request." + }, + { + "name": "updated", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_cloudforce_one_requests": { + "kind": "list-data-source", + "name": "cloudflare_cloudforce_one_requests", + "description": "Accepted Permissions\n\n- `Cloudforce One Write`", + "example": "data \"cloudflare_cloudforce_one_requests\" \"example_cloudforce_one_requests\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n page = 0\n per_page = 10\n completed_after = \"2022-01-01T00:00:00Z\"\n completed_before = \"2024-01-01T00:00:00Z\"\n created_after = \"2022-01-01T00:00:00Z\"\n created_before = \"2024-01-01T00:00:00Z\"\n request_type = \"Victomology\"\n sort_by = \"created\"\n sort_order = \"asc\"\n status = \"open\"\n}", + "required": [ + { + "name": "page", + "type": "Number", + "description": "Page number of results." + }, + { + "name": "per_page", + "type": "Number", + "description": "Number of results per page." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "completed_after", + "type": "String", + "description": "Retrieve requests completed after this time." + }, + { + "name": "completed_before", + "type": "String", + "description": "Retrieve requests completed before this time." + }, + { + "name": "created_after", + "type": "String", + "description": "Retrieve requests created after this time." + }, + { + "name": "created_before", + "type": "String", + "description": "Retrieve requests created before this time." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "request_type", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "sort_by", + "type": "String", + "description": "Field to sort results by." + }, + { + "name": "sort_order", + "type": "String", + "description": "Sort order (asc or desc).\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "status", + "type": "String", + "description": "Request Status.\nAvailable values: \"open\", \"accepted\", \"reported\", \"approved\", \"completed\", \"declined\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "completed", + "type": "String", + "description": "Request completion time." + }, + { + "name": "created", + "type": "String", + "description": "Request creation time." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "message_tokens", + "type": "Number", + "description": "Tokens for the request messages." + }, + { + "name": "priority", + "type": "String", + "description": "Available values: \"routine\", \"high\", \"urgent\"." + }, + { + "name": "readable_id", + "type": "String", + "description": "Readable Request ID." + }, + { + "name": "request", + "type": "String", + "description": "Requested information from request." + }, + { + "name": "status", + "type": "String", + "description": "Request Status.\nAvailable values: \"open\", \"accepted\", \"reported\", \"approved\", \"completed\", \"declined\"." + }, + { + "name": "summary", + "type": "String", + "description": "Brief description of the request." + }, + { + "name": "tlp", + "type": "String", + "description": "The CISA defined Traffic Light Protocol (TLP).\nAvailable values: \"clear\", \"amber\", \"amber-strict\", \"green\", \"red\"." + }, + { + "name": "tokens", + "type": "Number", + "description": "Tokens for the request." + }, + { + "name": "updated", + "type": "String", + "description": "Request last updated time." + } + ] + } + ] + }, + "data-source:cloudflare_connectivity_directory_service": { + "kind": "data-source", + "name": "cloudflare_connectivity_directory_service", + "example": "data \"cloudflare_connectivity_directory_service\" \"example_connectivity_directory_service\" {\n account_id = \"account_id\"\n service_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"tcp\", \"http\"." + } + ] + }, + { + "name": "service_id", + "type": "String" + } + ], + "computed": [ + { + "name": "app_protocol", + "type": "String", + "description": "Available values: \"postgresql\", \"mysql\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "host", + "type": "Attributes", + "children": [ + { + "name": "hostname", + "type": "String" + }, + { + "name": "ipv4", + "type": "String" + }, + { + "name": "ipv6", + "type": "String" + }, + { + "name": "network", + "type": "Attributes", + "children": [ + { + "name": "tunnel_id", + "type": "String" + } + ] + }, + { + "name": "resolver_network", + "type": "Attributes", + "children": [ + { + "name": "resolver_ips", + "type": "List of String" + }, + { + "name": "tunnel_id", + "type": "String" + } + ] + } + ] + }, + { + "name": "http_port", + "type": "Number" + }, + { + "name": "https_port", + "type": "Number" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "tcp_port", + "type": "Number" + }, + { + "name": "tls_settings", + "type": "Attributes", + "description": "TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.", + "children": [ + { + "name": "cert_verification_mode", + "type": "String", + "description": "TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"tcp\", \"http\"." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_connectivity_directory_service": { + "kind": "resource", + "name": "cloudflare_connectivity_directory_service", + "example": "resource \"cloudflare_connectivity_directory_service\" \"example_connectivity_directory_service\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n host = {\n ipv4 = \"10.0.0.1\"\n network = {\n tunnel_id = \"0191dce4-9ab4-7fce-b660-8e5dec5172da\"\n }\n }\n name = \"web-app\"\n type = \"http\"\n http_port = 8080\n https_port = 8443\n tls_settings = {\n cert_verification_mode = \"verify_full\"\n }\n}", + "importExample": "$ terraform import cloudflare_connectivity_directory_service.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier" + }, + { + "name": "host", + "type": "Attributes", + "children": [ + { + "name": "hostname", + "type": "String" + }, + { + "name": "ipv4", + "type": "String" + }, + { + "name": "ipv6", + "type": "String" + }, + { + "name": "network", + "type": "Attributes", + "children": [ + { + "name": "tunnel_id", + "type": "String" + } + ] + }, + { + "name": "resolver_network", + "type": "Attributes", + "children": [ + { + "name": "resolver_ips", + "type": "List of String" + }, + { + "name": "tunnel_id", + "type": "String" + } + ] + } + ] + }, + { + "name": "name", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"tcp\", \"http\"." + } + ], + "optional": [ + { + "name": "app_protocol", + "type": "String", + "description": "Available values: \"postgresql\", \"mysql\"." + }, + { + "name": "http_port", + "type": "Number" + }, + { + "name": "https_port", + "type": "Number" + }, + { + "name": "tcp_port", + "type": "Number" + }, + { + "name": "tls_settings", + "type": "Attributes", + "description": "TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.", + "children": [ + { + "name": "cert_verification_mode", + "type": "String", + "description": "TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all" + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "service_id", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_connectivity_directory_services": { + "kind": "list-data-source", + "name": "cloudflare_connectivity_directory_services", + "example": "data \"cloudflare_connectivity_directory_services\" \"example_connectivity_directory_services\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n type = \"tcp\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"tcp\", \"http\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "app_protocol", + "type": "String", + "description": "Available values: \"postgresql\", \"mysql\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "host", + "type": "Attributes", + "children": [ + { + "name": "hostname", + "type": "String" + }, + { + "name": "ipv4", + "type": "String" + }, + { + "name": "ipv6", + "type": "String" + }, + { + "name": "network", + "type": "Attributes", + "children": [ + { + "name": "tunnel_id", + "type": "String" + } + ] + }, + { + "name": "resolver_network", + "type": "Attributes", + "children": [ + { + "name": "resolver_ips", + "type": "List of String" + }, + { + "name": "tunnel_id", + "type": "String" + } + ] + } + ] + }, + { + "name": "http_port", + "type": "Number" + }, + { + "name": "https_port", + "type": "Number" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "service_id", + "type": "String" + }, + { + "name": "tcp_port", + "type": "Number" + }, + { + "name": "tls_settings", + "type": "Attributes", + "description": "TLS settings for a connectivity service.\n\nIf omitted, the default mode (`verify_full`) is used.", + "children": [ + { + "name": "cert_verification_mode", + "type": "String", + "description": "TLS certificate verification mode for the connection to the origin.\n\n- `\"verify_full\"` — verify certificate chain and hostname (default)\n- `\"verify_ca\"` — verify certificate chain only, skip hostname check\n- `\"disabled\"` — do not verify the server certificate at all" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"tcp\", \"http\"." + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_content_scanning": { + "kind": "data-source", + "name": "cloudflare_content_scanning", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "data \"cloudflare_content_scanning\" \"example_content_scanning\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "modified", + "type": "String", + "description": "Defines the last modification date (ISO 8601) of the Content Scanning status." + }, + { + "name": "value", + "type": "String", + "description": "Defines the status of Content Scanning." + } + ] + }, + "resource:cloudflare_content_scanning": { + "kind": "resource", + "name": "cloudflare_content_scanning", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "resource \"cloudflare_content_scanning\" \"example_content_scanning\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"enabled\"\n}", + "required": [ + { + "name": "value", + "type": "String", + "description": "The status value for Content Scanning.\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "modified", + "type": "String", + "description": "Defines the last modification date (ISO 8601) of the Content Scanning status." + } + ] + }, + "resource:cloudflare_content_scanning_expression": { + "kind": "resource", + "name": "cloudflare_content_scanning_expression", + "description": "Accepted Permissions\n\n- `Account WAF Write`\n- `Zone WAF Write`", + "example": "resource \"cloudflare_content_scanning_expression\" \"example_content_scanning_expression\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n body = [{\n payload = \"lookup_json_string(http.request.body.raw, \\\"file\\\")\"\n }]\n}", + "required": [ + { + "name": "body", + "type": "Attributes List", + "children": [ + { + "name": "payload", + "type": "String", + "description": "Defines the custom content extraction expression used to reach content objects in the request." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [ + { + "name": "payload", + "type": "String", + "description": "Defines the custom content extraction expression used to reach content objects in the request." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Defines the unique ID for this Content Scanning custom expression." + } + ] + }, + "list-data-source:cloudflare_content_scanning_expressions": { + "kind": "list-data-source", + "name": "cloudflare_content_scanning_expressions", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "data \"cloudflare_content_scanning_expressions\" \"example_content_scanning_expressions\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "Defines the unique ID for this Content Scanning custom expression." + }, + { + "name": "payload", + "type": "String", + "description": "Defines the custom content extraction expression used to reach content objects in the request." + } + ] + } + ] + }, + "data-source:cloudflare_ct_alerting": { + "kind": "data-source", + "name": "cloudflare_ct_alerting", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_ct_alerting\" \"example_ct_alerting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "emails", + "type": "List of String", + "description": "Email addresses that receive CT alert notifications for the zone. A maximum of 100 addresses may be configured. Each address must be a valid RFC 5322 email address and must not contain a comma." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether CT alerting is enabled for the zone." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_ct_alerting": { + "kind": "resource", + "name": "cloudflare_ct_alerting", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_ct_alerting\" \"example_ct_alerting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n emails = [\"security@example.com\", \"admin@example.com\"]\n}", + "importExample": "$ terraform import cloudflare_ct_alerting.example ''", + "required": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether CT alerting is enabled for the zone." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "emails", + "type": "List of String", + "description": "Email addresses that receive CT alert notifications for the zone. A maximum of 100 addresses may be configured. Each address must be a valid RFC 5322 email address and must not contain a comma." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_custom_csr": { + "kind": "data-source", + "name": "cloudflare_custom_csr", + "description": "Accepted Permissions\n\n- `Account: SSL and Certificates Read`\n- `Account: SSL and Certificates Write`", + "example": "data \"cloudflare_custom_csr\" \"example_custom_csr\" {\n custom_csr_id = \"7b163417-1d2b-4c84-a38a-2fb7a0cd7752\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "custom_csr_id", + "type": "String", + "description": "Custom CSR identifier tag." + }, + { + "name": "filter", + "type": "Attributes" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "Account identifier associated with this CSR." + }, + { + "name": "common_name", + "type": "String", + "description": "The common name (domain) for the CSR." + }, + { + "name": "country", + "type": "String", + "description": "Two-letter ISO 3166-1 alpha-2 country code." + }, + { + "name": "created_at", + "type": "String", + "description": "When the CSR was created." + }, + { + "name": "csr", + "type": "String", + "description": "The PEM-encoded Certificate Signing Request." + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the CSR." + }, + { + "name": "id", + "type": "String", + "description": "Custom CSR identifier tag." + }, + { + "name": "key_type", + "type": "String", + "description": "The key algorithm used to generate the CSR.\nAvailable values: \"rsa2048\", \"p256v1\"." + }, + { + "name": "locality", + "type": "String", + "description": "City or locality name." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name for the CSR." + }, + { + "name": "organization", + "type": "String", + "description": "Organization name." + }, + { + "name": "organizational_unit", + "type": "String", + "description": "Organizational unit name." + }, + { + "name": "sans", + "type": "List of String", + "description": "Subject Alternative Names included in the CSR." + }, + { + "name": "state", + "type": "String", + "description": "State or province name." + } + ] + }, + "resource:cloudflare_custom_csr": { + "kind": "resource", + "name": "cloudflare_custom_csr", + "description": "Accepted Permissions\n\n- `Account: SSL and Certificates Read`\n- `Account: SSL and Certificates Write`", + "example": "resource \"cloudflare_custom_csr\" \"example_custom_csr\" {\n common_name = \"example.com\"\n country = \"US\"\n locality = \"San Francisco\"\n organization = \"Cloudflare, Inc.\"\n sans = [\"example.com\", \"www.example.com\"]\n state = \"California\"\n zone_id = \"zone_id\"\n description = \"CSR for example.com wildcard\"\n key_type = \"rsa2048\"\n name = \"My Custom CSR\"\n organizational_unit = \"Engineering\"\n}", + "importExample": "$ terraform import cloudflare_custom_csr.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "common_name", + "type": "String", + "description": "The common name (domain) for the CSR. Must be at most 64 characters." + }, + { + "name": "country", + "type": "String", + "description": "Two-letter ISO 3166-1 alpha-2 country code." + }, + { + "name": "locality", + "type": "String", + "description": "City or locality name." + }, + { + "name": "organization", + "type": "String", + "description": "Organization name." + }, + { + "name": "sans", + "type": "List of String", + "description": "Subject Alternative Names for the CSR. At least one SAN is required." + }, + { + "name": "state", + "type": "String", + "description": "State or province name." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the CSR." + }, + { + "name": "key_type", + "type": "String", + "description": "Key algorithm to use for the CSR. Defaults to rsa2048 if not specified.\nAvailable values: \"rsa2048\", \"p256v1\"." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name for the CSR." + }, + { + "name": "organizational_unit", + "type": "String", + "description": "Organizational unit name." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "Account identifier associated with this CSR." + }, + { + "name": "created_at", + "type": "String", + "description": "When the CSR was created." + }, + { + "name": "csr", + "type": "String", + "description": "The PEM-encoded Certificate Signing Request." + }, + { + "name": "id", + "type": "String", + "description": "Custom CSR identifier tag." + } + ] + }, + "list-data-source:cloudflare_custom_csrs": { + "kind": "list-data-source", + "name": "cloudflare_custom_csrs", + "description": "Accepted Permissions\n\n- `Account: SSL and Certificates Read`\n- `Account: SSL and Certificates Write`", + "example": "data \"cloudflare_custom_csrs\" \"example_custom_csrs\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_tag", + "type": "String", + "description": "Account identifier associated with this CSR." + }, + { + "name": "common_name", + "type": "String", + "description": "The common name (domain) for the CSR." + }, + { + "name": "country", + "type": "String", + "description": "Two-letter ISO 3166-1 alpha-2 country code." + }, + { + "name": "created_at", + "type": "String", + "description": "When the CSR was created." + }, + { + "name": "csr", + "type": "String", + "description": "The PEM-encoded Certificate Signing Request." + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the CSR." + }, + { + "name": "id", + "type": "String", + "description": "Custom CSR identifier tag." + }, + { + "name": "key_type", + "type": "String", + "description": "The key algorithm used to generate the CSR.\nAvailable values: \"rsa2048\", \"p256v1\"." + }, + { + "name": "locality", + "type": "String", + "description": "City or locality name." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name for the CSR." + }, + { + "name": "organization", + "type": "String", + "description": "Organization name." + }, + { + "name": "organizational_unit", + "type": "String", + "description": "Organizational unit name." + }, + { + "name": "sans", + "type": "List of String", + "description": "Subject Alternative Names included in the CSR." + }, + { + "name": "state", + "type": "String", + "description": "State or province name." + } + ] + } + ] + }, + "data-source:cloudflare_custom_hostname": { + "kind": "data-source", + "name": "cloudflare_custom_hostname", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_custom_hostname\" \"example_custom_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_hostname_id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n}", + "required": [], + "optional": [ + { + "name": "custom_hostname_id", + "type": "String", + "description": "Custom hostname identifier tag." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Filter by the certificate authority that issued the SSL certificate.\nAvailable values: \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "custom_origin_server", + "type": "String", + "description": "Filter by custom origin server name." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order hostnames.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "hostname", + "type": "Attributes", + "children": [ + { + "name": "contain", + "type": "String", + "description": "Filters hostnames by a substring match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.startsWith' parameters." + }, + { + "name": "exact", + "type": "String", + "description": "Fully qualified domain name to match against. This parameter cannot be used with the 'id', 'hostname', 'hostname.contain', or 'hostname.startsWith' parameters." + }, + { + "name": "starts_with", + "type": "String", + "description": "Filters hostnames by a prefix match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.contain' parameters." + } + ] + }, + { + "name": "hostname_status", + "type": "String", + "description": "Filter by the hostname's activation status.\nAvailable values: \"active\", \"pending\", \"active_redeploying\", \"moved\", \"pending_deletion\", \"deleted\", \"pending_blocked\", \"pending_migration\", \"pending_provisioned\", \"test_pending\", \"test_active\", \"test_active_apex\", \"test_blocked\", \"test_failed\", \"provisioned\", \"blocked\"." + }, + { + "name": "id", + "type": "String", + "description": "Hostname ID to match against. This ID was generated and returned during the initial custom_hostname creation. This parameter cannot be used with the 'hostname', 'hostname.exact', 'hostname.contain', or 'hostname.startsWith' parameters." + }, + { + "name": "order", + "type": "String", + "description": "Field to order hostnames by.\nAvailable values: \"ssl\", \"ssl_status\"." + }, + { + "name": "ssl", + "type": "Number", + "description": "Whether to filter hostnames based on if they have SSL enabled.\nAvailable values: 0, 1." + }, + { + "name": "ssl_status", + "type": "String", + "description": "Filter by SSL certificate status.\nAvailable values: \"initializing\", \"pending_validation\", \"deleted\", \"pending_issuance\", \"pending_deployment\", \"pending_deletion\", \"pending_expiration\", \"expired\", \"active\", \"initializing_timed_out\", \"validation_timed_out\", \"issuance_timed_out\", \"deployment_timed_out\", \"deletion_timed_out\", \"pending_cleanup\", \"staging_deployment\", \"staging_active\", \"deactivating\", \"inactive\", \"backup_issued\", \"holding_deployment\"." + }, + { + "name": "wildcard", + "type": "Boolean", + "description": "Filter by whether the custom hostname is a wildcard hostname." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the hostname was created." + }, + { + "name": "custom_metadata", + "type": "Map of String", + "description": "Unique key/value metadata for this hostname. These are per-hostname (customer) settings." + }, + { + "name": "custom_origin_server", + "type": "String", + "description": "a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record." + }, + { + "name": "custom_origin_sni", + "type": "String", + "description": "A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or the string ':request_host_header:' which will cause the host header in the request to be used as SNI. Not configurable with default/fallback origin server." + }, + { + "name": "hostname", + "type": "String", + "description": "The custom hostname that will point to your hostname via CNAME." + }, + { + "name": "id", + "type": "String", + "description": "Custom hostname identifier tag." + }, + { + "name": "ownership_verification", + "type": "Attributes", + "description": "This is a record which can be placed to activate a hostname.", + "children": [ + { + "name": "name", + "type": "String", + "description": "DNS Name for record." + }, + { + "name": "type", + "type": "String", + "description": "DNS Record type.\nAvailable values: \"txt\"." + }, + { + "name": "value", + "type": "String", + "description": "Content for the record." + } + ] + }, + { + "name": "ownership_verification_http", + "type": "Attributes", + "description": "This presents the token to be served by the given http url to activate a hostname.", + "children": [ + { + "name": "http_body", + "type": "String", + "description": "Token to be served." + }, + { + "name": "http_url", + "type": "String", + "description": "The HTTP URL that will be checked during custom hostname verification and where the customer should host the token." + } + ] + }, + { + "name": "ssl", + "type": "Attributes", + "children": [ + { + "name": "bundle_method", + "type": "String", + "description": "A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.\nAvailable values: \"ubiquitous\", \"optimal\", \"force\"." + }, + { + "name": "certificate_authority", + "type": "String", + "description": "The Certificate Authority that will issue the certificate.\nAvailable values: \"digicert\", \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "custom_certificate", + "type": "String", + "description": "If a custom uploaded certificate is used." + }, + { + "name": "custom_csr_id", + "type": "String", + "description": "The identifier for the Custom CSR that was used." + }, + { + "name": "custom_key", + "type": "String", + "description": "The key for a custom uploaded certificate.", + "sensitive": true + }, + { + "name": "dcv_delegation_records", + "type": "Attributes List", + "description": "DCV Delegation records for domain validation.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "expires_on", + "type": "String", + "description": "The time the custom certificate expires on." + }, + { + "name": "hosts", + "type": "List of String", + "description": "A list of Hostnames on a custom uploaded certificate." + }, + { + "name": "id", + "type": "String", + "description": "Custom hostname SSL identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The issuer on a custom uploaded certificate." + }, + { + "name": "method", + "type": "String", + "description": "Domain control validation (DCV) method used for this hostname.\nAvailable values: \"http\", \"txt\", \"email\"." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on a custom uploaded certificate." + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "ciphers", + "type": "List of String", + "description": "An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format." + }, + { + "name": "early_hints", + "type": "String", + "description": "Whether or not Early Hints is enabled.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "http2", + "type": "String", + "description": "Whether or not HTTP2 is enabled.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "min_tls_version", + "type": "String", + "description": "The minimum TLS version supported.\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\"." + }, + { + "name": "tls_1_3", + "type": "String", + "description": "Whether or not TLS 1.3 is enabled.\nAvailable values: \"on\", \"off\"." + } + ] + }, + { + "name": "signature", + "type": "String", + "description": "The signature on a custom uploaded certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the hostname's SSL certificates.\nAvailable values: \"initializing\", \"pending_validation\", \"deleted\", \"pending_issuance\", \"pending_deployment\", \"pending_deletion\", \"pending_expiration\", \"expired\", \"active\", \"initializing_timed_out\", \"validation_timed_out\", \"issuance_timed_out\", \"deployment_timed_out\", \"deletion_timed_out\", \"pending_cleanup\", \"staging_deployment\", \"staging_active\", \"deactivating\", \"inactive\", \"backup_issued\", \"holding_deployment\"." + }, + { + "name": "type", + "type": "String", + "description": "Level of validation to be used for this hostname. Domain validation (dv) must be used.\nAvailable values: \"dv\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "The time the custom certificate was uploaded." + }, + { + "name": "validation_errors", + "type": "Attributes List", + "description": "Domain validation errors that have been received by the certificate authority (CA).", + "children": [ + { + "name": "message", + "type": "String", + "description": "A domain validation error." + } + ] + }, + { + "name": "validation_records", + "type": "Attributes List", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "wildcard", + "type": "Boolean", + "description": "Indicates whether the certificate covers a wildcard." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "Status of the hostname's activation.\nAvailable values: \"active\", \"pending\", \"active_redeploying\", \"moved\", \"pending_deletion\", \"deleted\", \"pending_blocked\", \"pending_migration\", \"pending_provisioned\", \"test_pending\", \"test_active\", \"test_active_apex\", \"test_blocked\", \"test_failed\", \"provisioned\", \"blocked\"." + }, + { + "name": "verification_errors", + "type": "List of String", + "description": "These are errors that were encountered while trying to activate a hostname." + } + ] + }, + "resource:cloudflare_custom_hostname": { + "kind": "resource", + "name": "cloudflare_custom_hostname", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_custom_hostname\" \"example_custom_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"app.example.com\"\n custom_metadata = {\n foo = \"string\"\n }\n custom_origin_server = \"origin2.example.com\"\n custom_origin_sni = \"sni.example.com\"\n ssl = {\n bundle_method = \"ubiquitous\"\n certificate_authority = \"google\"\n cloudflare_branding = false\n custom_cert_bundle = [{\n custom_certificate = </'", + "required": [ + { + "name": "hostname", + "type": "String", + "description": "The custom hostname that will point to your hostname via CNAME." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "custom_metadata", + "type": "Map of String", + "description": "Unique key/value metadata for this hostname. These are per-hostname (customer) settings." + }, + { + "name": "custom_origin_server", + "type": "String", + "description": "a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record." + }, + { + "name": "custom_origin_sni", + "type": "String", + "description": "A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or the string ':request_host_header:' which will cause the host header in the request to be used as SNI. Not configurable with default/fallback origin server." + }, + { + "name": "ssl", + "type": "Attributes", + "description": "SSL properties used when creating the custom hostname.", + "children": [ + { + "name": "bundle_method", + "type": "String", + "description": "A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.\nAvailable values: \"ubiquitous\", \"optimal\", \"force\"." + }, + { + "name": "certificate_authority", + "type": "String", + "description": "The Certificate Authority that will issue the certificate.\nAvailable values: \"digicert\", \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "cloudflare_branding", + "type": "Boolean", + "description": "Whether or not to add Cloudflare Branding for the order. This will add a subdomain of sni.cloudflaressl.com as the Common Name if set to true." + }, + { + "name": "custom_cert_bundle", + "type": "Attributes List", + "description": "Array of custom certificate and key pairs (1 or 2 pairs allowed).", + "children": [ + { + "name": "custom_certificate", + "type": "String", + "description": "If a custom uploaded certificate is used." + }, + { + "name": "custom_key", + "type": "String", + "description": "The key for a custom uploaded certificate.", + "sensitive": true + } + ] + }, + { + "name": "custom_certificate", + "type": "String", + "description": "If a custom uploaded certificate is used." + }, + { + "name": "custom_csr_id", + "type": "String", + "description": "The identifier for the Custom CSR that was used." + }, + { + "name": "custom_key", + "type": "String", + "description": "The key for a custom uploaded certificate.", + "sensitive": true + }, + { + "name": "method", + "type": "String", + "description": "Domain control validation (DCV) method used for this hostname.\nAvailable values: \"http\", \"txt\", \"email\"." + }, + { + "name": "settings", + "type": "Attributes", + "description": "SSL specific settings.", + "children": [ + { + "name": "ciphers", + "type": "List of String", + "description": "An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format." + }, + { + "name": "early_hints", + "type": "String", + "description": "Whether or not Early Hints is enabled.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "http2", + "type": "String", + "description": "Whether or not HTTP2 is enabled.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "min_tls_version", + "type": "String", + "description": "The minimum TLS version supported.\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\"." + }, + { + "name": "tls_1_3", + "type": "String", + "description": "Whether or not TLS 1.3 is enabled.\nAvailable values: \"on\", \"off\"." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Level of validation to be used for this hostname. Domain validation (dv) must be used.\nAvailable values: \"dv\"." + }, + { + "name": "wildcard", + "type": "Boolean", + "description": "Indicates whether the certificate covers a wildcard." + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the hostname was created." + }, + { + "name": "id", + "type": "String", + "description": "Custom hostname identifier tag." + }, + { + "name": "ownership_verification", + "type": "Attributes", + "description": "This is a record which can be placed to activate a hostname.", + "children": [ + { + "name": "name", + "type": "String", + "description": "DNS Name for record." + }, + { + "name": "type", + "type": "String", + "description": "DNS Record type.\nAvailable values: \"txt\"." + }, + { + "name": "value", + "type": "String", + "description": "Content for the record." + } + ] + }, + { + "name": "ownership_verification_http", + "type": "Attributes", + "description": "This presents the token to be served by the given http url to activate a hostname.", + "children": [ + { + "name": "http_body", + "type": "String", + "description": "Token to be served." + }, + { + "name": "http_url", + "type": "String", + "description": "The HTTP URL that will be checked during custom hostname verification and where the customer should host the token." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "Status of the hostname's activation.\nAvailable values: \"active\", \"pending\", \"active_redeploying\", \"moved\", \"pending_deletion\", \"deleted\", \"pending_blocked\", \"pending_migration\", \"pending_provisioned\", \"test_pending\", \"test_active\", \"test_active_apex\", \"test_blocked\", \"test_failed\", \"provisioned\", \"blocked\"." + }, + { + "name": "verification_errors", + "type": "List of String", + "description": "These are errors that were encountered while trying to activate a hostname." + } + ] + }, + "data-source:cloudflare_custom_hostname_fallback_origin": { + "kind": "data-source", + "name": "cloudflare_custom_hostname_fallback_origin", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_custom_hostname_fallback_origin\" \"example_custom_hostname_fallback_origin\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the fallback origin was created." + }, + { + "name": "errors", + "type": "List of String", + "description": "These are errors that were encountered while trying to activate a fallback origin." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "origin", + "type": "String", + "description": "Your origin hostname that requests to your custom hostnames will be sent to." + }, + { + "name": "status", + "type": "String", + "description": "Status of the fallback origin's activation.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "This is the time the fallback origin was updated." + } + ] + }, + "resource:cloudflare_custom_hostname_fallback_origin": { + "kind": "resource", + "name": "cloudflare_custom_hostname_fallback_origin", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_custom_hostname_fallback_origin\" \"example_custom_hostname_fallback_origin\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin = \"fallback.example.com\"\n}", + "importExample": "$ terraform import cloudflare_custom_hostname_fallback_origin.example ''", + "required": [ + { + "name": "origin", + "type": "String", + "description": "Your origin hostname that requests to your custom hostnames will be sent to." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the fallback origin was created." + }, + { + "name": "errors", + "type": "List of String", + "description": "These are errors that were encountered while trying to activate a fallback origin." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "status", + "type": "String", + "description": "Status of the fallback origin's activation.\nAvailable values: \"initializing\", \"pending_deployment\", \"pending_deletion\", \"active\", \"deployment_timed_out\", \"deletion_timed_out\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "This is the time the fallback origin was updated." + } + ] + }, + "list-data-source:cloudflare_custom_hostnames": { + "kind": "list-data-source", + "name": "cloudflare_custom_hostnames", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_custom_hostnames\" \"example_custom_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"0d89c70d-ad9f-4843-b99f-6cc0252067e9\"\n certificate_authority = \"google\"\n custom_origin_server = \"origin2.example.com\"\n direction = \"desc\"\n hostname = {\n contain = \"example.com\"\n exact = \"app.example.com\"\n starts_with = \"app\"\n }\n hostname_status = \"provisioned\"\n ssl_status = \"active\"\n wildcard = false\n}", + "required": [], + "optional": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Filter by the certificate authority that issued the SSL certificate.\nAvailable values: \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "custom_origin_server", + "type": "String", + "description": "Filter by custom origin server name." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order hostnames.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "hostname", + "type": "Attributes", + "children": [ + { + "name": "contain", + "type": "String", + "description": "Filters hostnames by a substring match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.startsWith' parameters." + }, + { + "name": "exact", + "type": "String", + "description": "Fully qualified domain name to match against. This parameter cannot be used with the 'id', 'hostname', 'hostname.contain', or 'hostname.startsWith' parameters." + }, + { + "name": "starts_with", + "type": "String", + "description": "Filters hostnames by a prefix match on the hostname value. This parameter cannot be used with the 'id', 'hostname', 'hostname.exact', or 'hostname.contain' parameters." + } + ] + }, + { + "name": "hostname_status", + "type": "String", + "description": "Filter by the hostname's activation status.\nAvailable values: \"active\", \"pending\", \"active_redeploying\", \"moved\", \"pending_deletion\", \"deleted\", \"pending_blocked\", \"pending_migration\", \"pending_provisioned\", \"test_pending\", \"test_active\", \"test_active_apex\", \"test_blocked\", \"test_failed\", \"provisioned\", \"blocked\"." + }, + { + "name": "id", + "type": "String", + "description": "Hostname ID to match against. This ID was generated and returned during the initial custom_hostname creation. This parameter cannot be used with the 'hostname', 'hostname.exact', 'hostname.contain', or 'hostname.startsWith' parameters." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to order hostnames by.\nAvailable values: \"ssl\", \"ssl_status\"." + }, + { + "name": "ssl", + "type": "Number", + "description": "Whether to filter hostnames based on if they have SSL enabled.\nAvailable values: 0, 1." + }, + { + "name": "ssl_status", + "type": "String", + "description": "Filter by SSL certificate status.\nAvailable values: \"initializing\", \"pending_validation\", \"deleted\", \"pending_issuance\", \"pending_deployment\", \"pending_deletion\", \"pending_expiration\", \"expired\", \"active\", \"initializing_timed_out\", \"validation_timed_out\", \"issuance_timed_out\", \"deployment_timed_out\", \"deletion_timed_out\", \"pending_cleanup\", \"staging_deployment\", \"staging_active\", \"deactivating\", \"inactive\", \"backup_issued\", \"holding_deployment\"." + }, + { + "name": "wildcard", + "type": "Boolean", + "description": "Filter by whether the custom hostname is a wildcard hostname." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the hostname was created." + }, + { + "name": "custom_metadata", + "type": "Map of String", + "description": "Unique key/value metadata for this hostname. These are per-hostname (customer) settings." + }, + { + "name": "custom_origin_server", + "type": "String", + "description": "a valid hostname that’s been added to your DNS zone as an A, AAAA, or CNAME record." + }, + { + "name": "custom_origin_sni", + "type": "String", + "description": "A hostname that will be sent to your custom origin server as SNI for TLS handshake. This can be a valid subdomain of the zone or custom origin server name or the string ':request_host_header:' which will cause the host header in the request to be used as SNI. Not configurable with default/fallback origin server." + }, + { + "name": "hostname", + "type": "String", + "description": "The custom hostname that will point to your hostname via CNAME." + }, + { + "name": "id", + "type": "String", + "description": "Custom hostname identifier tag." + }, + { + "name": "ownership_verification", + "type": "Attributes", + "description": "This is a record which can be placed to activate a hostname.", + "children": [ + { + "name": "name", + "type": "String", + "description": "DNS Name for record." + }, + { + "name": "type", + "type": "String", + "description": "DNS Record type.\nAvailable values: \"txt\"." + }, + { + "name": "value", + "type": "String", + "description": "Content for the record." + } + ] + }, + { + "name": "ownership_verification_http", + "type": "Attributes", + "description": "This presents the token to be served by the given http url to activate a hostname.", + "children": [ + { + "name": "http_body", + "type": "String", + "description": "Token to be served." + }, + { + "name": "http_url", + "type": "String", + "description": "The HTTP URL that will be checked during custom hostname verification and where the customer should host the token." + } + ] + }, + { + "name": "ssl", + "type": "Attributes", + "children": [ + { + "name": "bundle_method", + "type": "String", + "description": "A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.\nAvailable values: \"ubiquitous\", \"optimal\", \"force\"." + }, + { + "name": "certificate_authority", + "type": "String", + "description": "The Certificate Authority that will issue the certificate.\nAvailable values: \"digicert\", \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "custom_certificate", + "type": "String", + "description": "If a custom uploaded certificate is used." + }, + { + "name": "custom_csr_id", + "type": "String", + "description": "The identifier for the Custom CSR that was used." + }, + { + "name": "custom_key", + "type": "String", + "description": "The key for a custom uploaded certificate.", + "sensitive": true + }, + { + "name": "dcv_delegation_records", + "type": "Attributes List", + "description": "DCV Delegation records for domain validation.", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "expires_on", + "type": "String", + "description": "The time the custom certificate expires on." + }, + { + "name": "hosts", + "type": "List of String", + "description": "A list of Hostnames on a custom uploaded certificate." + }, + { + "name": "id", + "type": "String", + "description": "Custom hostname SSL identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The issuer on a custom uploaded certificate." + }, + { + "name": "method", + "type": "String", + "description": "Domain control validation (DCV) method used for this hostname.\nAvailable values: \"http\", \"txt\", \"email\"." + }, + { + "name": "serial_number", + "type": "String", + "description": "The serial number on a custom uploaded certificate." + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "ciphers", + "type": "List of String", + "description": "An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format." + }, + { + "name": "early_hints", + "type": "String", + "description": "Whether or not Early Hints is enabled.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "http2", + "type": "String", + "description": "Whether or not HTTP2 is enabled.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "min_tls_version", + "type": "String", + "description": "The minimum TLS version supported.\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\"." + }, + { + "name": "tls_1_3", + "type": "String", + "description": "Whether or not TLS 1.3 is enabled.\nAvailable values: \"on\", \"off\"." + } + ] + }, + { + "name": "signature", + "type": "String", + "description": "The signature on a custom uploaded certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the hostname's SSL certificates.\nAvailable values: \"initializing\", \"pending_validation\", \"deleted\", \"pending_issuance\", \"pending_deployment\", \"pending_deletion\", \"pending_expiration\", \"expired\", \"active\", \"initializing_timed_out\", \"validation_timed_out\", \"issuance_timed_out\", \"deployment_timed_out\", \"deletion_timed_out\", \"pending_cleanup\", \"staging_deployment\", \"staging_active\", \"deactivating\", \"inactive\", \"backup_issued\", \"holding_deployment\"." + }, + { + "name": "type", + "type": "String", + "description": "Level of validation to be used for this hostname. Domain validation (dv) must be used.\nAvailable values: \"dv\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "The time the custom certificate was uploaded." + }, + { + "name": "validation_errors", + "type": "Attributes List", + "description": "Domain validation errors that have been received by the certificate authority (CA).", + "children": [ + { + "name": "message", + "type": "String", + "description": "A domain validation error." + } + ] + }, + { + "name": "validation_records", + "type": "Attributes List", + "children": [ + { + "name": "cname", + "type": "String", + "description": "The CNAME record hostname for DCV delegation." + }, + { + "name": "cname_target", + "type": "String", + "description": "The CNAME record target value for DCV delegation." + }, + { + "name": "emails", + "type": "List of String", + "description": "The set of email addresses that the certificate authority (CA) will use to complete domain validation." + }, + { + "name": "http_body", + "type": "String", + "description": "The content that the certificate authority (CA) will expect to find at the http_url during the domain validation." + }, + { + "name": "http_url", + "type": "String", + "description": "The url that will be checked during domain validation." + }, + { + "name": "status", + "type": "String", + "description": "Status of the validation record." + }, + { + "name": "txt_name", + "type": "String", + "description": "The hostname that the certificate authority (CA) will check for a TXT record during domain validation ." + }, + { + "name": "txt_value", + "type": "String", + "description": "The TXT record that the certificate authority (CA) will check during domain validation." + } + ] + }, + { + "name": "wildcard", + "type": "Boolean", + "description": "Indicates whether the certificate covers a wildcard." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "Status of the hostname's activation.\nAvailable values: \"active\", \"pending\", \"active_redeploying\", \"moved\", \"pending_deletion\", \"deleted\", \"pending_blocked\", \"pending_migration\", \"pending_provisioned\", \"test_pending\", \"test_active\", \"test_active_apex\", \"test_blocked\", \"test_failed\", \"provisioned\", \"blocked\"." + }, + { + "name": "verification_errors", + "type": "List of String", + "description": "These are errors that were encountered while trying to activate a hostname." + } + ] + } + ] + }, + "data-source:cloudflare_custom_origin_trust_store": { + "kind": "data-source", + "name": "cloudflare_custom_origin_trust_store", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_custom_origin_trust_store\" \"example_custom_origin_trust_store\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_origin_trust_store_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}", + "required": [], + "optional": [ + { + "name": "custom_origin_trust_store_id", + "type": "String", + "description": "Certificate identifier tag." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "Limit to the number of records returned." + }, + { + "name": "offset", + "type": "Number", + "description": "Offset the results." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "certificate", + "type": "String", + "description": "The root CA certificate in PEM format. Only root CA certificates are accepted; intermediate and leaf certificates are not supported." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Certificate identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"initializing\", \"pending_deployment\", \"active\", \"pending_deletion\", \"deleted\", \"expired\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + } + ] + }, + "resource:cloudflare_custom_origin_trust_store": { + "kind": "resource", + "name": "cloudflare_custom_origin_trust_store", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_custom_origin_trust_store\" \"example_custom_origin_trust_store\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate = </'", + "required": [ + { + "name": "certificate", + "type": "String", + "description": "The root CA certificate in PEM format. Only root CA certificates are accepted; intermediate and leaf certificates are not supported." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "expires_on", + "type": "String", + "description": "When the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Certificate identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"initializing\", \"pending_deployment\", \"active\", \"pending_deletion\", \"deleted\", \"expired\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + } + ] + }, + "list-data-source:cloudflare_custom_origin_trust_stores": { + "kind": "list-data-source", + "name": "cloudflare_custom_origin_trust_stores", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_custom_origin_trust_stores\" \"example_custom_origin_trust_stores\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n}", + "required": [], + "optional": [ + { + "name": "limit", + "type": "Number", + "description": "Limit to the number of records returned." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "offset", + "type": "Number", + "description": "Offset the results." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "certificate", + "type": "String", + "description": "The root CA certificate in PEM format. Only root CA certificates are accepted; intermediate and leaf certificates are not supported." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Certificate identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"initializing\", \"pending_deployment\", \"active\", \"pending_deletion\", \"deleted\", \"expired\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + } + ] + } + ] + }, + "data-source:cloudflare_custom_page_asset": { + "kind": "data-source", + "name": "cloudflare_custom_page_asset", + "example": "data \"cloudflare_custom_page_asset\" \"example_custom_page_asset\" {\n asset_name = \"my_custom_error_page\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "asset_name", + "type": "String", + "description": "The unique name of the custom asset. Can only contain letters (A-Z, a-z), numbers (0-9), and underscores (_)." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "description", + "type": "String", + "description": "A short description of the custom asset." + }, + { + "name": "id", + "type": "String", + "description": "The unique name of the custom asset. Can only contain letters (A-Z, a-z), numbers (0-9), and underscores (_)." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The unique name of the custom asset. Can only contain letters (A-Z, a-z), numbers (0-9), and underscores (_)." + }, + { + "name": "size_bytes", + "type": "Number", + "description": "The size of the asset content in bytes." + }, + { + "name": "url", + "type": "String", + "description": "The URL where the asset content is fetched from." + } + ] + }, + "resource:cloudflare_custom_page_asset": { + "kind": "resource", + "name": "cloudflare_custom_page_asset", + "example": "resource \"cloudflare_custom_page_asset\" \"example_custom_page_asset\" {\n description = \"Custom 500 error page\"\n name = \"my_custom_error_page\"\n url = \"https://example.com/error.html\"\n zone_id = \"zone_id\"\n}", + "importExample": "$ terraform import cloudflare_custom_page_asset.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "description", + "type": "String", + "description": "A short description of the custom asset." + }, + { + "name": "name", + "type": "String", + "description": "The unique name of the custom asset. Can only contain letters (A-Z, a-z), numbers (0-9), and underscores (_)." + }, + { + "name": "url", + "type": "String", + "description": "The URL where the asset content is fetched from." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique name of the custom asset. Can only contain letters (A-Z, a-z), numbers (0-9), and underscores (_)." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "size_bytes", + "type": "Number", + "description": "The size of the asset content in bytes." + } + ] + }, + "list-data-source:cloudflare_custom_page_assets": { + "kind": "list-data-source", + "name": "cloudflare_custom_page_assets", + "example": "data \"cloudflare_custom_page_assets\" \"example_custom_page_assets\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "A short description of the custom asset." + }, + { + "name": "id", + "type": "String", + "description": "The unique name of the custom asset. Can only contain letters (A-Z, a-z), numbers (0-9), and underscores (_)." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The unique name of the custom asset. Can only contain letters (A-Z, a-z), numbers (0-9), and underscores (_)." + }, + { + "name": "size_bytes", + "type": "Number", + "description": "The size of the asset content in bytes." + }, + { + "name": "url", + "type": "String", + "description": "The URL where the asset content is fetched from." + } + ] + } + ] + }, + "data-source:cloudflare_custom_pages": { + "kind": "data-source", + "name": "cloudflare_custom_pages", + "description": "Accepted Permissions\n\n- `Account Custom Pages Read`\n- `Account Custom Pages Write`\n- `Account Settings Read`\n- `Account Settings Write`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_custom_pages\" \"example_custom_pages\" {\n identifier = \"ratelimit_block\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "identifier", + "type": "String", + "description": "Custom page type.\nAvailable values: \"1000_errors\", \"500_errors\", \"basic_challenge\", \"country_challenge\", \"ip_block\", \"managed_challenge\", \"ratelimit_block\", \"under_attack\", \"waf_block\", \"waf_challenge\"." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Custom page type.\nAvailable values: \"1000_errors\", \"500_errors\", \"basic_challenge\", \"country_challenge\", \"ip_block\", \"managed_challenge\", \"ratelimit_block\", \"under_attack\", \"waf_block\", \"waf_challenge\"." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "preview_target", + "type": "String" + }, + { + "name": "required_tokens", + "type": "List of String" + }, + { + "name": "state", + "type": "String", + "description": "The custom page state.\nAvailable values: \"default\", \"customized\"." + }, + { + "name": "url", + "type": "String", + "description": "The URL associated with the custom page." + } + ] + }, + "resource:cloudflare_custom_pages": { + "kind": "resource", + "name": "cloudflare_custom_pages", + "description": "Accepted Permissions\n\n- `Account Custom Pages Read`\n- `Account Custom Pages Write`\n- `Account Settings Read`\n- `Account Settings Write`\n- `Zero Trust: PII Read`", + "example": "resource \"cloudflare_custom_pages\" \"example_custom_pages\" {\n identifier = \"ratelimit_block\"\n state = \"default\"\n url = \"http://www.example.com\"\n zone_id = \"zone_id\"\n}", + "importExample": "$ terraform import cloudflare_custom_pages.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "identifier", + "type": "String", + "description": "Custom page type.\nAvailable values: \"1000_errors\", \"500_errors\", \"basic_challenge\", \"country_challenge\", \"ip_block\", \"managed_challenge\", \"ratelimit_block\", \"under_attack\", \"waf_block\", \"waf_challenge\"." + }, + { + "name": "state", + "type": "String", + "description": "The custom page state.\nAvailable values: \"default\", \"customized\"." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "url", + "type": "String", + "description": "The URL associated with the custom page." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Custom page type.\nAvailable values: \"1000_errors\", \"500_errors\", \"basic_challenge\", \"country_challenge\", \"ip_block\", \"managed_challenge\", \"ratelimit_block\", \"under_attack\", \"waf_block\", \"waf_challenge\"." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "preview_target", + "type": "String" + }, + { + "name": "required_tokens", + "type": "List of String" + } + ] + }, + "list-data-source:cloudflare_custom_pages_list": { + "kind": "list-data-source", + "name": "cloudflare_custom_pages_list", + "description": "Accepted Permissions\n\n- `Account Custom Pages Read`\n- `Account Custom Pages Write`\n- `Account Settings Read`\n- `Account Settings Write`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_custom_pages_list\" \"example_custom_pages_list\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "preview_target", + "type": "String" + }, + { + "name": "required_tokens", + "type": "List of String" + }, + { + "name": "state", + "type": "String", + "description": "The custom page state.\nAvailable values: \"default\", \"customized\"." + }, + { + "name": "url", + "type": "String", + "description": "The URL associated with the custom page." + } + ] + } + ] + }, + "data-source:cloudflare_custom_ssl": { + "kind": "data-source", + "name": "cloudflare_custom_ssl", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_custom_ssl\" \"example_custom_ssl\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_certificate_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}", + "required": [], + "optional": [ + { + "name": "custom_certificate_id", + "type": "String", + "description": "Custom certificate identifier tag." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any).\nAvailable values: \"any\", \"all\"." + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"active\", \"expired\", \"deleted\", \"pending\", \"initializing\"." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "bundle_method", + "type": "String", + "description": "A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.\nAvailable values: \"ubiquitous\", \"optimal\", \"force\"." + }, + { + "name": "custom_csr_id", + "type": "String", + "description": "The identifier for the Custom CSR that was used." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "geo_restrictions", + "type": "Attributes", + "description": "Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.", + "children": [ + { + "name": "label", + "type": "String", + "description": "Available values: \"us\", \"eu\", \"highest_security\"." + } + ] + }, + { + "name": "hosts", + "type": "List of String" + }, + { + "name": "id", + "type": "String", + "description": "Custom certificate identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "keyless_server", + "type": "Attributes", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "When the Keyless SSL was created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Keyless SSL is on or off." + }, + { + "name": "host", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "id", + "type": "String", + "description": "Keyless certificate identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Keyless SSL was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Available permissions for the Keyless SSL for the current user requesting the item." + }, + { + "name": "port", + "type": "Number", + "description": "The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server." + }, + { + "name": "status", + "type": "String", + "description": "Status of the Keyless SSL.\nAvailable values: \"active\", \"deleted\"." + }, + { + "name": "tunnel", + "type": "Attributes", + "description": "Configuration for using Keyless SSL through a Cloudflare Tunnel.", + "children": [ + { + "name": "private_ip", + "type": "String", + "description": "Private IP of the Key Server Host." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Cloudflare Tunnel Virtual Network ID." + } + ] + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "policy_restrictions", + "type": "String", + "description": "The policy restrictions returned by the API. This field is returned in responses\nwhen a policy has been set. The API accepts the \"policy\" field in requests but\nreturns this field as \"policy_restrictions\" in responses.\n\nSpecifies the region(s) where your private key can be held locally for optimal\nTLS performance. Format is a boolean expression, for example:\n\"(country: US) or (region: EU)\"" + }, + { + "name": "priority", + "type": "Number", + "description": "The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacy_custom' certificates, but 'legacy_custom' certificates will always supercede 'sni_custom' certificates." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"active\", \"expired\", \"deleted\", \"pending\", \"initializing\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + } + ] + }, + "resource:cloudflare_custom_ssl": { + "kind": "resource", + "name": "cloudflare_custom_ssl", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_custom_ssl\" \"example_custom_ssl\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate = </'", + "required": [ + { + "name": "certificate", + "type": "String", + "description": "The zone's SSL certificate or certificate and the intermediate(s)." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "bundle_method", + "type": "String", + "description": "A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.\nAvailable values: \"ubiquitous\", \"optimal\", \"force\"." + }, + { + "name": "custom_csr_id", + "type": "String", + "description": "The identifier for the Custom CSR that was used." + }, + { + "name": "deploy", + "type": "String", + "description": "The environment to deploy the certificate to.\nAvailable values: \"staging\", \"production\"." + }, + { + "name": "geo_restrictions", + "type": "Attributes", + "description": "Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.", + "children": [ + { + "name": "label", + "type": "String", + "description": "Available values: \"us\", \"eu\", \"highest_security\"." + } + ] + }, + { + "name": "policy", + "type": "String", + "description": "Specify the policy that determines the region where your private key will be held locally. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Any combination of countries, specified by their two letter country code (https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2#Officially_assigned_code_elements) can be chosen, such as 'country: IN', as well as 'region: EU' which refers to the EU region. If there are too few data centers satisfying the policy, it will be rejected.\nNote: The API accepts this field as either \"policy\" or \"policy_restrictions\" in requests. Responses return this field as \"policy_restrictions\"." + }, + { + "name": "private_key", + "type": "String", + "description": "The zone's private key. Not required if custom_csr_id is provided, in which case the private key is retrieved from the CSR record held by Cloudflare.", + "sensitive": true + }, + { + "name": "type", + "type": "String", + "description": "The type 'legacy_custom' enables support for legacy clients which do not include SNI in the TLS handshake.\nAvailable values: \"legacy_custom\", \"sni_custom\"." + } + ], + "computed": [ + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "hosts", + "type": "List of String" + }, + { + "name": "id", + "type": "String", + "description": "Custom certificate identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "keyless_server", + "type": "Attributes", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "When the Keyless SSL was created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Keyless SSL is on or off." + }, + { + "name": "host", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "id", + "type": "String", + "description": "Keyless certificate identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Keyless SSL was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Available permissions for the Keyless SSL for the current user requesting the item." + }, + { + "name": "port", + "type": "Number", + "description": "The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server." + }, + { + "name": "status", + "type": "String", + "description": "Status of the Keyless SSL.\nAvailable values: \"active\", \"deleted\"." + }, + { + "name": "tunnel", + "type": "Attributes", + "description": "Configuration for using Keyless SSL through a Cloudflare Tunnel.", + "children": [ + { + "name": "private_ip", + "type": "String", + "description": "Private IP of the Key Server Host." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Cloudflare Tunnel Virtual Network ID." + } + ] + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "policy_restrictions", + "type": "String", + "description": "The policy restrictions returned by the API. This field is returned in responses\nwhen a policy has been set. The API accepts the \"policy\" field in requests but\nreturns this field as \"policy_restrictions\" in responses.\n\nSpecifies the region(s) where your private key can be held locally for optimal\nTLS performance. Format is a boolean expression, for example:\n\"(country: US) or (region: EU)\"" + }, + { + "name": "priority", + "type": "Number", + "description": "The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacy_custom' certificates, but 'legacy_custom' certificates will always supercede 'sni_custom' certificates." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"active\", \"expired\", \"deleted\", \"pending\", \"initializing\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + } + ] + }, + "list-data-source:cloudflare_custom_ssls": { + "kind": "list-data-source", + "name": "cloudflare_custom_ssls", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_custom_ssls\" \"example_custom_ssls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n status = \"active\"\n}", + "required": [], + "optional": [ + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any).\nAvailable values: \"any\", \"all\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"active\", \"expired\", \"deleted\", \"pending\", \"initializing\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "bundle_method", + "type": "String", + "description": "A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.\nAvailable values: \"ubiquitous\", \"optimal\", \"force\"." + }, + { + "name": "custom_csr_id", + "type": "String", + "description": "The identifier for the Custom CSR that was used." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate from the authority expires." + }, + { + "name": "geo_restrictions", + "type": "Attributes", + "description": "Specify the region where your private key can be held locally for optimal TLS performance. HTTPS connections to any excluded data center will still be fully encrypted, but will incur some latency while Keyless SSL is used to complete the handshake with the nearest allowed data center. Options allow distribution to only to U.S. data centers, only to E.U. data centers, or only to highest security data centers. Default distribution is to all Cloudflare datacenters, for optimal performance.", + "children": [ + { + "name": "label", + "type": "String", + "description": "Available values: \"us\", \"eu\", \"highest_security\"." + } + ] + }, + { + "name": "hosts", + "type": "List of String" + }, + { + "name": "id", + "type": "String", + "description": "Custom certificate identifier tag." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "keyless_server", + "type": "Attributes", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "When the Keyless SSL was created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Keyless SSL is on or off." + }, + { + "name": "host", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "id", + "type": "String", + "description": "Keyless certificate identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Keyless SSL was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Available permissions for the Keyless SSL for the current user requesting the item." + }, + { + "name": "port", + "type": "Number", + "description": "The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server." + }, + { + "name": "status", + "type": "String", + "description": "Status of the Keyless SSL.\nAvailable values: \"active\", \"deleted\"." + }, + { + "name": "tunnel", + "type": "Attributes", + "description": "Configuration for using Keyless SSL through a Cloudflare Tunnel.", + "children": [ + { + "name": "private_ip", + "type": "String", + "description": "Private IP of the Key Server Host." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Cloudflare Tunnel Virtual Network ID." + } + ] + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the certificate was last modified." + }, + { + "name": "policy_restrictions", + "type": "String", + "description": "The policy restrictions returned by the API. This field is returned in responses\nwhen a policy has been set. The API accepts the \"policy\" field in requests but\nreturns this field as \"policy_restrictions\" in responses.\n\nSpecifies the region(s) where your private key can be held locally for optimal\nTLS performance. Format is a boolean expression, for example:\n\"(country: US) or (region: EU)\"" + }, + { + "name": "priority", + "type": "Number", + "description": "The order/priority in which the certificate will be used in a request. The higher priority will break ties across overlapping 'legacy_custom' certificates, but 'legacy_custom' certificates will always supercede 'sni_custom' certificates." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Status of the zone's custom SSL.\nAvailable values: \"active\", \"expired\", \"deleted\", \"pending\", \"initializing\"." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "When the certificate was uploaded to Cloudflare." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ] + } + ] + }, + "data-source:cloudflare_d1_database": { + "kind": "data-source", + "name": "cloudflare_d1_database", + "description": "Accepted Permissions\n\n- `D1 Read`\n- `D1 Write`", + "example": "data \"cloudflare_d1_database\" \"example_d1_database\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n database_id = \"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx\"\n fields = [\"uuid\"]\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "database_id", + "type": "String", + "description": "D1 database identifier (UUID)." + }, + { + "name": "fields", + "type": "List of String", + "description": "Comma-separated list of fields to include in the response. When omitted,\nall fields are returned." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "a database name to search for." + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Specifies the timestamp the resource was created as an ISO8601 string." + }, + { + "name": "file_size", + "type": "Number", + "description": "The D1 database's size, in bytes." + }, + { + "name": "id", + "type": "String", + "description": "D1 database identifier (UUID)." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored.\nAvailable values: \"eu\", \"fedramp\", \"us\"." + }, + { + "name": "name", + "type": "String", + "description": "D1 database name." + }, + { + "name": "num_tables", + "type": "Number", + "description": "The number of tables in the D1 database. This count is no longer accurate and should not be relied upon.", + "deprecated": "Deprecated." + }, + { + "name": "read_replication", + "type": "Attributes", + "description": "Configuration for D1 read replication.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The read replication mode for the database. Mode 'auto' denotes that D1 creates replicas and automatically places them around the world. Mode 'disabled' denotes that no database replicas are used.\nAvailable values: \"auto\", \"disabled\"." + } + ] + }, + { + "name": "uuid", + "type": "String", + "description": "D1 database identifier (UUID)." + }, + { + "name": "version", + "type": "String" + } + ] + }, + "resource:cloudflare_d1_database": { + "kind": "resource", + "name": "cloudflare_d1_database", + "description": "Accepted Permissions\n\n- `D1 Read`\n- `D1 Write`\n\n!> When a D1 Database is replaced all the data is lost. Please ensure you have a\n backup of your data before replacing a D1 Database.", + "example": "resource \"cloudflare_d1_database\" \"example_d1_database\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-database\"\n jurisdiction = \"eu\"\n primary_location_hint = \"wnam\"\n read_replication = {\n mode = \"auto\"\n }\n}", + "importExample": "$ terraform import cloudflare_d1_database.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "D1 database name." + } + ], + "optional": [ + { + "name": "fields", + "type": "List of String", + "description": "Comma-separated list of fields to include in the response. When omitted,\nall fields are returned." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored.\nAvailable values: \"eu\", \"fedramp\", \"us\"." + }, + { + "name": "primary_location_hint", + "type": "String", + "description": "Specify the region to create the D1 primary, if available. If this option is omitted, the D1 will be created as close as possible to the current user.\nAvailable values: \"wnam\", \"enam\", \"weur\", \"eeur\", \"apac\", \"oc\"." + }, + { + "name": "read_replication", + "type": "Attributes", + "description": "Configuration for D1 read replication.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The read replication mode for the database. Use 'auto' to create replicas and allow D1 automatically place them around the world, or 'disabled' to not use any database replicas (it can take a few hours for all replicas to be deleted).\nAvailable values: \"auto\", \"disabled\"." + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Specifies the timestamp the resource was created as an ISO8601 string." + }, + { + "name": "file_size", + "type": "Number", + "description": "The D1 database's size, in bytes." + }, + { + "name": "id", + "type": "String", + "description": "D1 database identifier (UUID)." + }, + { + "name": "num_tables", + "type": "Number", + "description": "The number of tables in the D1 database. This count is no longer accurate and should not be relied upon.", + "deprecated": "Deprecated." + }, + { + "name": "uuid", + "type": "String", + "description": "D1 database identifier (UUID)." + }, + { + "name": "version", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_d1_databases": { + "kind": "list-data-source", + "name": "cloudflare_d1_databases", + "description": "Accepted Permissions\n\n- `D1 Read`\n- `D1 Write`", + "example": "data \"cloudflare_d1_databases\" \"example_d1_databases\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"name\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "a database name to search for." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "Specifies the timestamp the resource was created as an ISO8601 string." + }, + { + "name": "id", + "type": "String", + "description": "D1 database identifier (UUID)." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Specify the location to restrict the D1 database to run and store data. If this option is present, the location hint is ignored.\nAvailable values: \"eu\", \"fedramp\", \"us\"." + }, + { + "name": "name", + "type": "String", + "description": "D1 database name." + }, + { + "name": "uuid", + "type": "String", + "description": "D1 database identifier (UUID)." + }, + { + "name": "version", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_dcv_delegation": { + "kind": "data-source", + "name": "cloudflare_dcv_delegation", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_dcv_delegation\" \"example_dcv_delegation\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "uuid", + "type": "String", + "description": "The DCV Delegation unique identifier." + } + ] + }, + "data-source:cloudflare_dls_prefix_binding": { + "kind": "data-source", + "name": "cloudflare_dls_prefix_binding", + "example": "data \"cloudflare_dls_prefix_binding\" \"example_dls_prefix_binding\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n binding_id = \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + }, + { + "name": "binding_id", + "type": "String", + "description": "Unique identifier for the prefix binding." + } + ], + "optional": [], + "computed": [ + { + "name": "cidr", + "type": "String", + "description": "The CIDR that is bound." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the prefix binding." + }, + { + "name": "prefix_id", + "type": "String", + "description": "The ID of the parent prefix." + }, + { + "name": "region_key", + "type": "String", + "description": "The region key used for the binding." + } + ] + }, + "resource:cloudflare_dls_prefix_binding": { + "kind": "resource", + "name": "cloudflare_dls_prefix_binding", + "description": "Accepted Permissions\n\n- `DLS: Read`\n- `DLS: Write`\n- `IP Prefixes: Write`", + "example": "resource \"cloudflare_dls_prefix_binding\" \"example_dls_prefix_binding\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cidr = \"10.0.1.0/24\"\n prefix_id = \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\"\n region_key = \"eu\"\n}", + "importExample": "$ terraform import cloudflare_dls_prefix_binding.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + }, + { + "name": "cidr", + "type": "String", + "description": "IP prefix in CIDR notation to bind." + }, + { + "name": "prefix_id", + "type": "String", + "description": "The ID of the parent IP prefix that contains the CIDR." + }, + { + "name": "region_key", + "type": "String", + "description": "Region key from managed regions (e.g., \"us\", \"eu\")." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of the binding." + } + ] + }, + "list-data-source:cloudflare_dls_prefix_bindings": { + "kind": "list-data-source", + "name": "cloudflare_dls_prefix_bindings", + "example": "data \"cloudflare_dls_prefix_bindings\" \"example_dls_prefix_bindings\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier of a Cloudflare account." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "cidr", + "type": "String", + "description": "The CIDR that is bound." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the binding." + }, + { + "name": "prefix_id", + "type": "String", + "description": "The ID of the parent prefix." + }, + { + "name": "region_key", + "type": "String", + "description": "The region key used for the binding." + } + ] + } + ] + }, + "data-source:cloudflare_dns_firewall": { + "kind": "data-source", + "name": "cloudflare_dns_firewall", + "description": "Accepted Permissions\n\n- `DNS Firewall Read`\n- `DNS Firewall Write`", + "example": "data \"cloudflare_dns_firewall\" \"example_dns_firewall\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns_firewall_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "dns_firewall_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "attack_mitigation", + "type": "Attributes", + "description": "Attack mitigation settings", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers" + }, + { + "name": "only_when_upstream_unhealthy", + "type": "Boolean", + "description": "Only mitigate attacks when upstream servers seem unhealthy" + } + ] + }, + { + "name": "deprecate_any_requests", + "type": "Boolean", + "description": "Whether to refuse to answer queries for the ANY type" + }, + { + "name": "dns_firewall_ips", + "type": "Set of String" + }, + { + "name": "ecs_fallback", + "type": "Boolean", + "description": "Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "maximum_cache_ttl", + "type": "Number", + "description": "By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers." + }, + { + "name": "minimum_cache_ttl", + "type": "Number", + "description": "By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last modification of DNS Firewall cluster" + }, + { + "name": "name", + "type": "String", + "description": "DNS Firewall cluster name" + }, + { + "name": "negative_cache_ttl", + "type": "Number", + "description": "This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers." + }, + { + "name": "ratelimit", + "type": "Number", + "description": "Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting." + }, + { + "name": "retries", + "type": "Number", + "description": "Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)" + }, + { + "name": "upstream_ips", + "type": "Set of String" + } + ] + }, + "resource:cloudflare_dns_firewall": { + "kind": "resource", + "name": "cloudflare_dns_firewall", + "description": "Accepted Permissions\n\n- `DNS Firewall Read`\n- `DNS Firewall Write`", + "example": "resource \"cloudflare_dns_firewall\" \"example_dns_firewall\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Awesome DNS Firewall cluster\"\n upstream_ips = [\"192.0.2.1\", \"198.51.100.1\", \"2001:DB8:100::CF\"]\n attack_mitigation = {\n enabled = true\n only_when_upstream_unhealthy = false\n }\n deprecate_any_requests = true\n dns_firewall_ip_count = 2\n ecs_fallback = false\n maximum_cache_ttl = 900\n minimum_cache_ttl = 60\n negative_cache_ttl = 900\n ratelimit = 600\n retries = 2\n}", + "importExample": "$ terraform import cloudflare_dns_firewall.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "DNS Firewall cluster name" + }, + { + "name": "upstream_ips", + "type": "Set of String" + } + ], + "optional": [ + { + "name": "attack_mitigation", + "type": "Attributes", + "description": "Attack mitigation settings", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers" + }, + { + "name": "only_when_upstream_unhealthy", + "type": "Boolean", + "description": "Only mitigate attacks when upstream servers seem unhealthy" + } + ] + }, + { + "name": "deprecate_any_requests", + "type": "Boolean", + "description": "Whether to refuse to answer queries for the ANY type" + }, + { + "name": "dns_firewall_ip_count", + "type": "Number", + "description": "Number of IPv4 addresses to assign to the DNS Firewall cluster. Only used during cluster creation and cannot be changed later." + }, + { + "name": "ecs_fallback", + "type": "Boolean", + "description": "Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent" + }, + { + "name": "maximum_cache_ttl", + "type": "Number", + "description": "By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers." + }, + { + "name": "minimum_cache_ttl", + "type": "Number", + "description": "By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons." + }, + { + "name": "negative_cache_ttl", + "type": "Number", + "description": "This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers." + }, + { + "name": "ratelimit", + "type": "Number", + "description": "Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting." + }, + { + "name": "retries", + "type": "Number", + "description": "Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)" + } + ], + "computed": [ + { + "name": "dns_firewall_ips", + "type": "Set of String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last modification of DNS Firewall cluster" + } + ] + }, + "list-data-source:cloudflare_dns_firewalls": { + "kind": "list-data-source", + "name": "cloudflare_dns_firewalls", + "description": "Accepted Permissions\n\n- `DNS Firewall Read`\n- `DNS Firewall Write`", + "example": "data \"cloudflare_dns_firewalls\" \"example_dns_firewalls\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "attack_mitigation", + "type": "Attributes", + "description": "Attack mitigation settings", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers" + }, + { + "name": "only_when_upstream_unhealthy", + "type": "Boolean", + "description": "Only mitigate attacks when upstream servers seem unhealthy" + } + ] + }, + { + "name": "deprecate_any_requests", + "type": "Boolean", + "description": "Whether to refuse to answer queries for the ANY type" + }, + { + "name": "dns_firewall_ips", + "type": "Set of String" + }, + { + "name": "ecs_fallback", + "type": "Boolean", + "description": "Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "maximum_cache_ttl", + "type": "Number", + "description": "By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets an upper bound on this duration. For caching purposes, higher TTLs\nwill be decreased to the maximum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers." + }, + { + "name": "minimum_cache_ttl", + "type": "Number", + "description": "By default, Cloudflare attempts to cache responses for as long as\nindicated by the TTL received from upstream nameservers. This setting\nsets a lower bound on this duration. For caching purposes, lower TTLs\nwill be increased to the minimum value defined by this setting.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers.\n\nNote that, even with this setting, there is no guarantee that a\nresponse will be cached for at least the specified duration. Cached\nresponses may be removed earlier for capacity or other operational\nreasons." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last modification of DNS Firewall cluster" + }, + { + "name": "name", + "type": "String", + "description": "DNS Firewall cluster name" + }, + { + "name": "negative_cache_ttl", + "type": "Number", + "description": "This setting controls how long DNS Firewall should cache negative\nresponses (e.g., NXDOMAIN) from the upstream servers.\n\nThis setting does not affect the TTL value in the DNS response\nCloudflare returns to clients. Cloudflare will always forward the TTL\nvalue received from upstream nameservers." + }, + { + "name": "ratelimit", + "type": "Number", + "description": "Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting." + }, + { + "name": "retries", + "type": "Number", + "description": "Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)" + }, + { + "name": "upstream_ips", + "type": "Set of String" + } + ] + } + ] + }, + "data-source:cloudflare_dns_record": { + "kind": "data-source", + "name": "cloudflare_dns_record", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "data \"cloudflare_dns_record\" \"example_dns_record\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns_record_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n include_shadow_metadata = true\n}", + "required": [], + "optional": [ + { + "name": "dns_record_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "comment", + "type": "Attributes", + "children": [ + { + "name": "absent", + "type": "String", + "description": "If this parameter is present, only records *without* a comment are returned." + }, + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS record comment. Comment filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS record comment. Comment filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS record comment. Comment filters are case-insensitive." + }, + { + "name": "present", + "type": "String", + "description": "If this parameter is present, only records *with* a comment are returned." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS record comment. Comment filters are case-insensitive." + } + ] + }, + { + "name": "content", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS record content. Content filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS record content. Content filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS record content. Content filters are case-insensitive." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS record content. Content filters are case-insensitive." + } + ] + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order DNS records in.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead. Note that the interaction between tag filters is controlled by the `tag-match` parameter instead.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "name", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS record name. Name filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS record name. Name filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS record name. Name filters are case-insensitive." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS record name. Name filters are case-insensitive." + } + ] + }, + { + "name": "order", + "type": "String", + "description": "Field to order DNS records by.\nAvailable values: \"type\", \"name\", \"content\", \"ttl\", \"proxied\"." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the record is receiving the performance and security benefits of Cloudflare." + }, + { + "name": "search", + "type": "String", + "description": "Allows searching in multiple properties of a DNS record simultaneously. This parameter is intended for human users, not automation. Its exact behavior is intentionally left unspecified and is subject to change in the future. This parameter works independently of the `match` setting. For automated searches, please use the other available parameters." + }, + { + "name": "shadowed_by_name", + "type": "String", + "description": "Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires `include_shadow_metadata=true`. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "shadowing_name", + "type": "String", + "description": "Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "tag", + "type": "Attributes", + "children": [ + { + "name": "absent", + "type": "String", + "description": "Name of a tag which must *not* be present on the DNS record. Tag filters are case-insensitive." + }, + { + "name": "contains", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value contains ``. Tag filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value ends with ``. Tag filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value is ``. Tag filters are case-insensitive." + }, + { + "name": "present", + "type": "String", + "description": "Name of a tag which must be present on the DNS record. Tag filters are case-insensitive." + }, + { + "name": "startswith", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value starts with ``. Tag filters are case-insensitive." + } + ] + }, + { + "name": "tag_match", + "type": "String", + "description": "Whether to match all tag search requirements or at least one (any). If set to `all`, acts like a logical AND between tag filters. If set to `any`, acts like a logical OR instead. Note that the regular `match` parameter is still used to combine the resulting condition with other filters that aren't related to tags.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "type", + "type": "String", + "description": "Record type.\nAvailable values: \"A\", \"AAAA\", \"CAA\", \"CERT\", \"CNAME\", \"DNSKEY\", \"DS\", \"HTTPS\", \"LOC\", \"MX\", \"NAPTR\", \"NS\", \"OPENPGPKEY\", \"PTR\", \"SMIMEA\", \"SRV\", \"SSHFP\", \"SVCB\", \"TLSA\", \"TXT\", \"URI\"." + } + ] + }, + { + "name": "include_shadow_metadata", + "type": "Boolean", + "description": "Whether to include shadow metadata in the `meta` field of each record in the response. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "comment", + "type": "String", + "description": "Comments or notes about the DNS record. This field has no effect on DNS responses." + }, + { + "name": "comment_modified_on", + "type": "String", + "description": "When the record comment was last modified. Omitted if there is no comment." + }, + { + "name": "content", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "created_on", + "type": "String", + "description": "When the record was created." + }, + { + "name": "data", + "type": "Attributes", + "description": "Components of a MX record.", + "children": [ + { + "name": "algorithm", + "type": "Number", + "description": "Algorithm." + }, + { + "name": "altitude", + "type": "Number", + "description": "Altitude of location in meters." + }, + { + "name": "certificate", + "type": "String", + "description": "Certificate." + }, + { + "name": "digest", + "type": "String", + "description": "Digest." + }, + { + "name": "digest_type", + "type": "Number", + "description": "Digest Type." + }, + { + "name": "fingerprint", + "type": "String", + "description": "Fingerprint." + }, + { + "name": "flags", + "type": "Dynamic", + "description": "Flags for the CAA record." + }, + { + "name": "key_tag", + "type": "Number", + "description": "Key Tag." + }, + { + "name": "lat_degrees", + "type": "Number", + "description": "Degrees of latitude." + }, + { + "name": "lat_direction", + "type": "String", + "description": "Latitude direction.\nAvailable values: \"N\", \"S\"." + }, + { + "name": "lat_minutes", + "type": "Number", + "description": "Minutes of latitude." + }, + { + "name": "lat_seconds", + "type": "Number", + "description": "Seconds of latitude." + }, + { + "name": "long_degrees", + "type": "Number", + "description": "Degrees of longitude." + }, + { + "name": "long_direction", + "type": "String", + "description": "Longitude direction.\nAvailable values: \"E\", \"W\"." + }, + { + "name": "long_minutes", + "type": "Number", + "description": "Minutes of longitude." + }, + { + "name": "long_seconds", + "type": "Number", + "description": "Seconds of longitude." + }, + { + "name": "matching_type", + "type": "Number", + "description": "Matching Type." + }, + { + "name": "order", + "type": "Number", + "description": "Order." + }, + { + "name": "port", + "type": "Number", + "description": "The port of the service." + }, + { + "name": "precision_horz", + "type": "Number", + "description": "Horizontal precision of location." + }, + { + "name": "precision_vert", + "type": "Number", + "description": "Vertical precision of location." + }, + { + "name": "preference", + "type": "Number", + "description": "Preference." + }, + { + "name": "priority", + "type": "Number", + "description": "Required for MX and URI records; ignored for other record types (but may still be returned by the API). Records with lower priorities are preferred. This field is to be deprecated in favor of the priority field within the data map." + }, + { + "name": "protocol", + "type": "Number", + "description": "Protocol." + }, + { + "name": "public_key", + "type": "String", + "description": "Public Key." + }, + { + "name": "regex", + "type": "String", + "description": "Regex." + }, + { + "name": "replacement", + "type": "String", + "description": "Replacement." + }, + { + "name": "selector", + "type": "Number", + "description": "Selector." + }, + { + "name": "service", + "type": "String", + "description": "Service." + }, + { + "name": "size", + "type": "Number", + "description": "Size of location in meters." + }, + { + "name": "tag", + "type": "String", + "description": "Name of the property controlled by this record (e.g.: issue, issuewild, iodef)." + }, + { + "name": "target", + "type": "String", + "description": "A valid mail server hostname, or \".\" for a NULL MX record." + }, + { + "name": "type", + "type": "Number", + "description": "Type." + }, + { + "name": "usage", + "type": "Number", + "description": "Usage." + }, + { + "name": "value", + "type": "String", + "description": "Value of the record. This field's semantics depend on the chosen tag." + }, + { + "name": "weight", + "type": "Number", + "description": "The record weight." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Extra Cloudflare-specific metadata about the record.", + "children": [ + { + "name": "dead_glue", + "type": "Boolean", + "description": "Whether this glue record is not served because a shallower NS delegation takes precedence over the deeper delegation that needs it. Present only when true; reachable glue carries only `is_glue`. See [Unreachable glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#unreachable-glue-records)." + }, + { + "name": "is_glue", + "type": "Boolean", + "description": "Whether this A or AAAA record is glue for a subdomain NS delegation. See [Glue records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records#glue-records)." + }, + { + "name": "shadowed_by", + "type": "List of String", + "description": "IDs of the NS records that shadow this record. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "shadowed_records_count", + "type": "Number", + "description": "Number of records shadowed by this NS delegation. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the record was last modified." + }, + { + "name": "name", + "type": "String", + "description": "Complete DNS record name, including the zone name, in Punycode." + }, + { + "name": "priority", + "type": "Number", + "description": "Required for MX and URI records; ignored for other record types (but may still be returned by the API). Records with lower priorities are preferred. This field is to be deprecated in favor of the priority field within the data map." + }, + { + "name": "private_routing", + "type": "Boolean", + "description": "Enables private network routing to the origin." + }, + { + "name": "proxiable", + "type": "Boolean", + "description": "Whether the record can be proxied by Cloudflare or not." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the record is receiving the performance and security benefits of Cloudflare." + }, + { + "name": "settings", + "type": "Attributes", + "description": "Settings for the DNS record.", + "children": [ + { + "name": "flatten_cname", + "type": "Boolean", + "description": "If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened." + }, + { + "name": "ipv4_only", + "type": "Boolean", + "description": "When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6." + }, + { + "name": "ipv6_only", + "type": "Boolean", + "description": "When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6." + } + ] + }, + { + "name": "tags", + "type": "Set of String", + "description": "Custom tags for the DNS record. This field has no effect on DNS responses." + }, + { + "name": "tags_modified_on", + "type": "String", + "description": "When the record tags were last modified. Omitted if there are no tags." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterprise zones." + }, + { + "name": "type", + "type": "String", + "description": "Record type.\nAvailable values: \"A\", \"AAAA\", \"CNAME\", \"MX\", \"NS\", \"OPENPGPKEY\", \"PTR\", \"TXT\", \"CAA\", \"CERT\", \"DNSKEY\", \"DS\", \"HTTPS\", \"LOC\", \"NAPTR\", \"SMIMEA\", \"SRV\", \"SSHFP\", \"SVCB\", \"TLSA\", \"URI\"." + } + ] + }, + "resource:cloudflare_dns_record": { + "kind": "resource", + "name": "cloudflare_dns_record", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "resource \"cloudflare_dns_record\" \"example_dns_record\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example.com\"\n ttl = 3600\n type = \"A\"\n comment = \"Domain verification record\"\n content = \"198.51.100.4\"\n private_routing = true\n proxied = true\n settings = {\n ipv4_only = true\n ipv6_only = true\n }\n tags = [\"owner:dns-team\"]\n}", + "importExample": "$ terraform import cloudflare_dns_record.example '/'", + "required": [ + { + "name": "name", + "type": "String", + "description": "DNS record name (or @ for the zone apex) in Punycode." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterprise zones." + }, + { + "name": "type", + "type": "String", + "description": "Record type.\nAvailable values: \"A\", \"AAAA\", \"CNAME\", \"MX\", \"NS\", \"OPENPGPKEY\", \"PTR\", \"TXT\", \"CAA\", \"CERT\", \"DNSKEY\", \"DS\", \"HTTPS\", \"LOC\", \"NAPTR\", \"SMIMEA\", \"SRV\", \"SSHFP\", \"SVCB\", \"TLSA\", \"URI\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "comment", + "type": "String", + "description": "Comments or notes about the DNS record. This field has no effect on DNS responses." + }, + { + "name": "content", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "data", + "type": "Attributes", + "description": "Components of a MX record.", + "children": [ + { + "name": "algorithm", + "type": "Number", + "description": "Algorithm." + }, + { + "name": "altitude", + "type": "Number", + "description": "Altitude of location in meters." + }, + { + "name": "certificate", + "type": "String", + "description": "Certificate." + }, + { + "name": "digest", + "type": "String", + "description": "Digest." + }, + { + "name": "digest_type", + "type": "Number", + "description": "Digest Type." + }, + { + "name": "fingerprint", + "type": "String", + "description": "Fingerprint." + }, + { + "name": "flags", + "type": "Dynamic", + "description": "Flags for the CAA record." + }, + { + "name": "key_tag", + "type": "Number", + "description": "Key Tag." + }, + { + "name": "lat_degrees", + "type": "Number", + "description": "Degrees of latitude." + }, + { + "name": "lat_direction", + "type": "String", + "description": "Latitude direction.\nAvailable values: \"N\", \"S\"." + }, + { + "name": "lat_minutes", + "type": "Number", + "description": "Minutes of latitude." + }, + { + "name": "lat_seconds", + "type": "Number", + "description": "Seconds of latitude." + }, + { + "name": "long_degrees", + "type": "Number", + "description": "Degrees of longitude." + }, + { + "name": "long_direction", + "type": "String", + "description": "Longitude direction.\nAvailable values: \"E\", \"W\"." + }, + { + "name": "long_minutes", + "type": "Number", + "description": "Minutes of longitude." + }, + { + "name": "long_seconds", + "type": "Number", + "description": "Seconds of longitude." + }, + { + "name": "matching_type", + "type": "Number", + "description": "Matching Type." + }, + { + "name": "order", + "type": "Number", + "description": "Order." + }, + { + "name": "port", + "type": "Number", + "description": "The port of the service." + }, + { + "name": "precision_horz", + "type": "Number", + "description": "Horizontal precision of location." + }, + { + "name": "precision_vert", + "type": "Number", + "description": "Vertical precision of location." + }, + { + "name": "preference", + "type": "Number", + "description": "Preference." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority." + }, + { + "name": "protocol", + "type": "Number", + "description": "Protocol." + }, + { + "name": "public_key", + "type": "String", + "description": "Public Key." + }, + { + "name": "regex", + "type": "String", + "description": "Regex." + }, + { + "name": "replacement", + "type": "String", + "description": "Replacement." + }, + { + "name": "selector", + "type": "Number", + "description": "Selector." + }, + { + "name": "service", + "type": "String", + "description": "Service." + }, + { + "name": "size", + "type": "Number", + "description": "Size of location in meters." + }, + { + "name": "tag", + "type": "String", + "description": "Name of the property controlled by this record (e.g.: issue, issuewild, iodef)." + }, + { + "name": "target", + "type": "String", + "description": "Target." + }, + { + "name": "type", + "type": "Number", + "description": "Type." + }, + { + "name": "usage", + "type": "Number", + "description": "Usage." + }, + { + "name": "value", + "type": "String", + "description": "Value of the record. This field's semantics depend on the chosen tag." + }, + { + "name": "weight", + "type": "Number", + "description": "The record weight." + } + ] + }, + { + "name": "include_shadow_metadata", + "type": "Boolean", + "description": "Whether to include shadow metadata in the `meta` field of each record in the response. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "priority", + "type": "Number", + "description": "Required for MX, SRV and URI records; unused by other record types. Records with lower priorities are preferred." + }, + { + "name": "private_routing", + "type": "Boolean", + "description": "Enables private network routing to the origin." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the record is receiving the performance and security benefits of Cloudflare." + }, + { + "name": "settings", + "type": "Attributes", + "description": "Settings for the DNS record.", + "children": [ + { + "name": "flatten_cname", + "type": "Boolean", + "description": "If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened." + }, + { + "name": "ipv4_only", + "type": "Boolean", + "description": "When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6." + }, + { + "name": "ipv6_only", + "type": "Boolean", + "description": "When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6." + } + ] + }, + { + "name": "tags", + "type": "Set of String", + "description": "Custom tags for the DNS record. This field has no effect on DNS responses." + } + ], + "computed": [ + { + "name": "comment_modified_on", + "type": "String", + "description": "When the record comment was last modified. Omitted if there is no comment." + }, + { + "name": "created_on", + "type": "String", + "description": "When the record was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "meta", + "type": "String", + "description": "Extra Cloudflare-specific information about the record." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the record was last modified." + }, + { + "name": "proxiable", + "type": "Boolean", + "description": "Whether the record can be proxied by Cloudflare or not." + }, + { + "name": "tags_modified_on", + "type": "String", + "description": "When the record tags were last modified. Omitted if there are no tags." + } + ] + }, + "list-data-source:cloudflare_dns_records": { + "kind": "list-data-source", + "name": "cloudflare_dns_records", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "data \"cloudflare_dns_records\" \"example_dns_records\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n comment = {\n absent = \"absent\"\n contains = \"ello, worl\"\n endswith = \"o, world\"\n exact = \"Hello, world\"\n present = \"present\"\n startswith = \"Hello, w\"\n }\n content = {\n contains = \"7.0.0.\"\n endswith = \".0.1\"\n exact = \"127.0.0.1\"\n startswith = \"127.0.\"\n }\n name = {\n contains = \"w.example.\"\n endswith = \".example.com\"\n exact = \"www.example.com\"\n startswith = \"www.example\"\n }\n search = \"www.cloudflare.com\"\n shadowed_by_name = \"sub.example.com\"\n shadowing_name = \"www.sub.example.com\"\n tag = {\n absent = \"important\"\n contains = \"greeting:ello, worl\"\n endswith = \"greeting:o, world\"\n exact = \"greeting:Hello, world\"\n present = \"important\"\n startswith = \"greeting:Hello, w\"\n }\n type = \"A\"\n}", + "required": [], + "optional": [ + { + "name": "comment", + "type": "Attributes", + "children": [ + { + "name": "absent", + "type": "String", + "description": "If this parameter is present, only records *without* a comment are returned." + }, + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS record comment. Comment filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS record comment. Comment filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS record comment. Comment filters are case-insensitive." + }, + { + "name": "present", + "type": "String", + "description": "If this parameter is present, only records *with* a comment are returned." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS record comment. Comment filters are case-insensitive." + } + ] + }, + { + "name": "content", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS record content. Content filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS record content. Content filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS record content. Content filters are case-insensitive." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS record content. Content filters are case-insensitive." + } + ] + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order DNS records in.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "include_shadow_metadata", + "type": "Boolean", + "description": "Whether to include shadow metadata in the `meta` field of each record in the response. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any). If set to `all`, acts like a logical AND between filters. If set to `any`, acts like a logical OR instead. Note that the interaction between tag filters is controlled by the `tag-match` parameter instead.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "Substring of the DNS record name. Name filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "Suffix of the DNS record name. Name filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "Exact value of the DNS record name. Name filters are case-insensitive." + }, + { + "name": "startswith", + "type": "String", + "description": "Prefix of the DNS record name. Name filters are case-insensitive." + } + ] + }, + { + "name": "order", + "type": "String", + "description": "Field to order DNS records by.\nAvailable values: \"type\", \"name\", \"content\", \"ttl\", \"proxied\"." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the record is receiving the performance and security benefits of Cloudflare." + }, + { + "name": "search", + "type": "String", + "description": "Allows searching in multiple properties of a DNS record simultaneously. This parameter is intended for human users, not automation. Its exact behavior is intentionally left unspecified and is subject to change in the future. This parameter works independently of the `match` setting. For automated searches, please use the other available parameters." + }, + { + "name": "shadowed_by_name", + "type": "String", + "description": "Filters the response to records at or below the specified NS delegation name. NS, DS, and NSEC records at the delegation name are excluded because they are not shadowed by that delegation. Those record types are included only when they exist below the delegation. The value must be a non-apex subdomain of the zone. Requires `include_shadow_metadata=true`. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "shadowing_name", + "type": "String", + "description": "Returns NS records that shadow the given name, searching at the name itself and each of its ancestor names within the zone, excluding the zone apex. The value must be a subdomain of the zone; the zone apex is not accepted. See [Shadowed records](https://developers.cloudflare.com/dns/manage-dns-records/reference/shadowed-records)." + }, + { + "name": "tag", + "type": "Attributes", + "children": [ + { + "name": "absent", + "type": "String", + "description": "Name of a tag which must *not* be present on the DNS record. Tag filters are case-insensitive." + }, + { + "name": "contains", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value contains ``. Tag filters are case-insensitive." + }, + { + "name": "endswith", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value ends with ``. Tag filters are case-insensitive." + }, + { + "name": "exact", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value is ``. Tag filters are case-insensitive." + }, + { + "name": "present", + "type": "String", + "description": "Name of a tag which must be present on the DNS record. Tag filters are case-insensitive." + }, + { + "name": "startswith", + "type": "String", + "description": "A tag and value, of the form `:`. The API will only return DNS records that have a tag named `` whose value starts with ``. Tag filters are case-insensitive." + } + ] + }, + { + "name": "tag_match", + "type": "String", + "description": "Whether to match all tag search requirements or at least one (any). If set to `all`, acts like a logical AND between tag filters. If set to `any`, acts like a logical OR instead. Note that the regular `match` parameter is still used to combine the resulting condition with other filters that aren't related to tags.\nAvailable values: \"any\", \"all\"." + }, + { + "name": "type", + "type": "String", + "description": "Record type.\nAvailable values: \"A\", \"AAAA\", \"CAA\", \"CERT\", \"CNAME\", \"DNSKEY\", \"DS\", \"HTTPS\", \"LOC\", \"MX\", \"NAPTR\", \"NS\", \"OPENPGPKEY\", \"PTR\", \"SMIMEA\", \"SRV\", \"SSHFP\", \"SVCB\", \"TLSA\", \"TXT\", \"URI\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comment", + "type": "String", + "description": "Comments or notes about the DNS record. This field has no effect on DNS responses." + }, + { + "name": "comment_modified_on", + "type": "String", + "description": "When the record comment was last modified. Omitted if there is no comment." + }, + { + "name": "content", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "created_on", + "type": "String", + "description": "When the record was created." + }, + { + "name": "data", + "type": "Attributes", + "description": "Components of a CAA record.", + "children": [ + { + "name": "algorithm", + "type": "Number", + "description": "Algorithm." + }, + { + "name": "altitude", + "type": "Number", + "description": "Altitude of location in meters." + }, + { + "name": "certificate", + "type": "String", + "description": "Certificate." + }, + { + "name": "digest", + "type": "String", + "description": "Digest." + }, + { + "name": "digest_type", + "type": "Number", + "description": "Digest Type." + }, + { + "name": "fingerprint", + "type": "String", + "description": "Fingerprint." + }, + { + "name": "flags", + "type": "Dynamic", + "description": "Flags for the CAA record." + }, + { + "name": "key_tag", + "type": "Number", + "description": "Key Tag." + }, + { + "name": "lat_degrees", + "type": "Number", + "description": "Degrees of latitude." + }, + { + "name": "lat_direction", + "type": "String", + "description": "Latitude direction.\nAvailable values: \"N\", \"S\"." + }, + { + "name": "lat_minutes", + "type": "Number", + "description": "Minutes of latitude." + }, + { + "name": "lat_seconds", + "type": "Number", + "description": "Seconds of latitude." + }, + { + "name": "long_degrees", + "type": "Number", + "description": "Degrees of longitude." + }, + { + "name": "long_direction", + "type": "String", + "description": "Longitude direction.\nAvailable values: \"E\", \"W\"." + }, + { + "name": "long_minutes", + "type": "Number", + "description": "Minutes of longitude." + }, + { + "name": "long_seconds", + "type": "Number", + "description": "Seconds of longitude." + }, + { + "name": "matching_type", + "type": "Number", + "description": "Matching Type." + }, + { + "name": "order", + "type": "Number", + "description": "Order." + }, + { + "name": "port", + "type": "Number", + "description": "The port of the service." + }, + { + "name": "precision_horz", + "type": "Number", + "description": "Horizontal precision of location." + }, + { + "name": "precision_vert", + "type": "Number", + "description": "Vertical precision of location." + }, + { + "name": "preference", + "type": "Number", + "description": "Preference." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority." + }, + { + "name": "protocol", + "type": "Number", + "description": "Protocol." + }, + { + "name": "public_key", + "type": "String", + "description": "Public Key." + }, + { + "name": "regex", + "type": "String", + "description": "Regex." + }, + { + "name": "replacement", + "type": "String", + "description": "Replacement." + }, + { + "name": "selector", + "type": "Number", + "description": "Selector." + }, + { + "name": "service", + "type": "String", + "description": "Service." + }, + { + "name": "size", + "type": "Number", + "description": "Size of location in meters." + }, + { + "name": "tag", + "type": "String", + "description": "Name of the property controlled by this record (e.g.: issue, issuewild, iodef)." + }, + { + "name": "target", + "type": "String", + "description": "Target." + }, + { + "name": "type", + "type": "Number", + "description": "Type." + }, + { + "name": "usage", + "type": "Number", + "description": "Usage." + }, + { + "name": "value", + "type": "String", + "description": "Value of the record. This field's semantics depend on the chosen tag." + }, + { + "name": "weight", + "type": "Number", + "description": "The record weight." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "meta", + "type": "String", + "description": "Extra Cloudflare-specific information about the record." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the record was last modified." + }, + { + "name": "name", + "type": "String", + "description": "Complete DNS record name, including the zone name, in Punycode." + }, + { + "name": "priority", + "type": "Number", + "description": "Required for MX and URI records; ignored for other record types (but may still be returned by the API). Records with lower priorities are preferred. This field is to be deprecated in favor of the priority field within the data map." + }, + { + "name": "private_routing", + "type": "Boolean", + "description": "Enables private network routing to the origin." + }, + { + "name": "proxiable", + "type": "Boolean", + "description": "Whether the record can be proxied by Cloudflare or not." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the record is receiving the performance and security benefits of Cloudflare." + }, + { + "name": "settings", + "type": "Attributes", + "description": "Settings for the DNS record.", + "children": [ + { + "name": "flatten_cname", + "type": "Boolean", + "description": "If enabled, causes the CNAME record to be resolved externally and the resulting address records (e.g., A and AAAA) to be returned instead of the CNAME record itself. This setting is unavailable for proxied records, since they are always flattened." + }, + { + "name": "ipv4_only", + "type": "Boolean", + "description": "When enabled, only A records will be generated, and AAAA records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6." + }, + { + "name": "ipv6_only", + "type": "Boolean", + "description": "When enabled, only AAAA records will be generated, and A records will not be created. This setting is intended for exceptional cases. Note that this option only applies to proxied records and it has no effect on whether Cloudflare communicates with the origin using IPv4 or IPv6." + } + ] + }, + { + "name": "tags", + "type": "Set of String", + "description": "Custom tags for the DNS record. This field has no effect on DNS responses." + }, + { + "name": "tags_modified_on", + "type": "String", + "description": "When the record tags were last modified. Omitted if there are no tags." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time To Live (TTL) of the DNS record in seconds. Setting to 1 means 'automatic'. Value must be between 60 and 86400, with the minimum reduced to 30 for Enterprise zones." + }, + { + "name": "type", + "type": "String", + "description": "Record type.\nAvailable values: \"A\", \"AAAA\", \"CNAME\", \"MX\", \"NS\", \"OPENPGPKEY\", \"PTR\", \"TXT\", \"CAA\", \"CERT\", \"DNSKEY\", \"DS\", \"HTTPS\", \"LOC\", \"NAPTR\", \"SMIMEA\", \"SRV\", \"SSHFP\", \"SVCB\", \"TLSA\", \"URI\"." + } + ] + } + ] + }, + "data-source:cloudflare_dns_zone_transfers_acl": { + "kind": "data-source", + "name": "cloudflare_dns_zone_transfers_acl", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "data \"cloudflare_dns_zone_transfers_acl\" \"example_dns_zone_transfers_acl\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n acl_id = \"23ff594956f20c2a721606e94745a8aa\"\n}", + "required": [ + { + "name": "acl_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "ip_range", + "type": "String", + "description": "Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively." + }, + { + "name": "name", + "type": "String", + "description": "The name of the acl." + } + ] + }, + "resource:cloudflare_dns_zone_transfers_acl": { + "kind": "resource", + "name": "cloudflare_dns_zone_transfers_acl", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "resource \"cloudflare_dns_zone_transfers_acl\" \"example_dns_zone_transfers_acl\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n ip_range = \"192.0.2.53/28\"\n name = \"my-acl-1\"\n}", + "importExample": "$ terraform import cloudflare_dns_zone_transfers_acl.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "ip_range", + "type": "String", + "description": "Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively." + }, + { + "name": "name", + "type": "String", + "description": "The name of the acl." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "list-data-source:cloudflare_dns_zone_transfers_acls": { + "kind": "list-data-source", + "name": "cloudflare_dns_zone_transfers_acls", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "data \"cloudflare_dns_zone_transfers_acls\" \"example_dns_zone_transfers_acls\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "ip_range", + "type": "String", + "description": "Allowed IPv4/IPv6 address range of primary or secondary nameservers. This will be applied for the entire account. The IP range is used to allow additional NOTIFY IPs for secondary zones and IPs Cloudflare allows AXFR/IXFR requests from for primary zones. CIDRs are limited to a maximum of /24 for IPv4 and /64 for IPv6 respectively." + }, + { + "name": "name", + "type": "String", + "description": "The name of the acl." + } + ] + } + ] + }, + "data-source:cloudflare_dns_zone_transfers_incoming": { + "kind": "data-source", + "name": "cloudflare_dns_zone_transfers_incoming", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_dns_zone_transfers_incoming\" \"example_dns_zone_transfers_incoming\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String" + } + ], + "computed": [ + { + "name": "auto_refresh_seconds", + "type": "Number", + "description": "How often should a secondary zone auto refresh regardless of DNS NOTIFY.\nNot applicable for primary zones." + }, + { + "name": "checked_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "created_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "name", + "type": "String", + "description": "Zone name." + }, + { + "name": "peers", + "type": "Set of String", + "description": "A list of peer tags." + }, + { + "name": "soa_serial", + "type": "Number", + "description": "The serial number of the SOA for the given zone." + } + ] + }, + "resource:cloudflare_dns_zone_transfers_incoming": { + "kind": "resource", + "name": "cloudflare_dns_zone_transfers_incoming", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_dns_zone_transfers_incoming\" \"example_dns_zone_transfers_incoming\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n auto_refresh_seconds = 86400\n name = \"www.example.com.\"\n peers = [\"23ff594956f20c2a721606e94745a8aa\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n}", + "importExample": "$ terraform import cloudflare_dns_zone_transfers_incoming.example ''", + "required": [ + { + "name": "name", + "type": "String", + "description": "Zone name." + }, + { + "name": "peers", + "type": "Set of String", + "description": "A list of peer tags." + }, + { + "name": "zone_id", + "type": "String" + } + ], + "optional": [ + { + "name": "auto_refresh_seconds", + "type": "Number", + "description": "How often should a secondary zone auto refresh regardless of DNS NOTIFY.\nNot applicable for primary zones." + } + ], + "computed": [ + { + "name": "checked_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "created_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "soa_serial", + "type": "Number", + "description": "The serial number of the SOA for the given zone." + } + ] + }, + "data-source:cloudflare_dns_zone_transfers_outgoing": { + "kind": "data-source", + "name": "cloudflare_dns_zone_transfers_outgoing", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_dns_zone_transfers_outgoing\" \"example_dns_zone_transfers_outgoing\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String" + } + ], + "computed": [ + { + "name": "checked_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "created_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "last_transferred_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "name", + "type": "String", + "description": "Zone name." + }, + { + "name": "peers", + "type": "Set of String", + "description": "A list of peer tags." + }, + { + "name": "soa_serial", + "type": "Number", + "description": "The serial number of the SOA for the given zone." + } + ] + }, + "resource:cloudflare_dns_zone_transfers_outgoing": { + "kind": "resource", + "name": "cloudflare_dns_zone_transfers_outgoing", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_dns_zone_transfers_outgoing\" \"example_dns_zone_transfers_outgoing\" {\n zone_id = \"269d8f4853475ca241c4e730be286b20\"\n name = \"www.example.com.\"\n peers = [\"23ff594956f20c2a721606e94745a8aa\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n}", + "importExample": "$ terraform import cloudflare_dns_zone_transfers_outgoing.example ''", + "required": [ + { + "name": "name", + "type": "String", + "description": "Zone name." + }, + { + "name": "peers", + "type": "Set of String", + "description": "A list of peer tags." + }, + { + "name": "zone_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "checked_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "created_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "last_transferred_time", + "type": "String", + "description": "The time for a specific event." + }, + { + "name": "soa_serial", + "type": "Number", + "description": "The serial number of the SOA for the given zone." + } + ] + }, + "data-source:cloudflare_dns_zone_transfers_peer": { + "kind": "data-source", + "name": "cloudflare_dns_zone_transfers_peer", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "data \"cloudflare_dns_zone_transfers_peer\" \"example_dns_zone_transfers_peer\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n peer_id = \"23ff594956f20c2a721606e94745a8aa\"\n}", + "required": [ + { + "name": "peer_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "ip", + "type": "String", + "description": "IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to." + }, + { + "name": "ixfr_enable", + "type": "Boolean", + "description": "Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones." + }, + { + "name": "name", + "type": "String", + "description": "The name of the peer." + }, + { + "name": "port", + "type": "Number", + "description": "DNS port of primary or secondary nameserver, depending on what zone this peer is linked to." + }, + { + "name": "tsig_id", + "type": "String", + "description": "TSIG authentication will be used for zone transfer if configured." + } + ] + }, + "resource:cloudflare_dns_zone_transfers_peer": { + "kind": "resource", + "name": "cloudflare_dns_zone_transfers_peer", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "resource \"cloudflare_dns_zone_transfers_peer\" \"example_dns_zone_transfers_peer\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n name = \"my-peer-1\"\n}", + "importExample": "$ terraform import cloudflare_dns_zone_transfers_peer.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The name of the peer." + } + ], + "optional": [ + { + "name": "ip", + "type": "String", + "description": "IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to." + }, + { + "name": "ixfr_enable", + "type": "Boolean", + "description": "Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones." + }, + { + "name": "port", + "type": "Number", + "description": "DNS port of primary or secondary nameserver, depending on what zone this peer is linked to." + }, + { + "name": "tsig_id", + "type": "String", + "description": "TSIG authentication will be used for zone transfer if configured." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "list-data-source:cloudflare_dns_zone_transfers_peers": { + "kind": "list-data-source", + "name": "cloudflare_dns_zone_transfers_peers", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "data \"cloudflare_dns_zone_transfers_peers\" \"example_dns_zone_transfers_peers\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "ip", + "type": "String", + "description": "IPv4/IPv6 address of primary or secondary nameserver, depending on what zone this peer is linked to. For primary zones this IP defines the IP of the secondary nameserver Cloudflare will NOTIFY upon zone changes. For secondary zones this IP defines the IP of the primary nameserver Cloudflare will send AXFR/IXFR requests to." + }, + { + "name": "ixfr_enable", + "type": "Boolean", + "description": "Enable IXFR transfer protocol, default is AXFR. Only applicable to secondary zones." + }, + { + "name": "name", + "type": "String", + "description": "The name of the peer." + }, + { + "name": "port", + "type": "Number", + "description": "DNS port of primary or secondary nameserver, depending on what zone this peer is linked to." + }, + { + "name": "tsig_id", + "type": "String", + "description": "TSIG authentication will be used for zone transfer if configured." + } + ] + } + ] + }, + "data-source:cloudflare_dns_zone_transfers_tsig": { + "kind": "data-source", + "name": "cloudflare_dns_zone_transfers_tsig", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "data \"cloudflare_dns_zone_transfers_tsig\" \"example_dns_zone_transfers_tsig\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n tsig_id = \"69cd1e104af3e6ed3cb344f263fd0d5a\"\n}", + "required": [ + { + "name": "tsig_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "algo", + "type": "String", + "description": "TSIG algorithm." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String", + "description": "TSIG key name." + }, + { + "name": "secret", + "type": "String", + "description": "TSIG secret.", + "sensitive": true + } + ] + }, + "resource:cloudflare_dns_zone_transfers_tsig": { + "kind": "resource", + "name": "cloudflare_dns_zone_transfers_tsig", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "resource \"cloudflare_dns_zone_transfers_tsig\" \"example_dns_zone_transfers_tsig\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n algo = \"hmac-sha512.\"\n name = \"tsig.customer.cf.\"\n secret = \"caf79a7804b04337c9c66ccd7bef9190a1e1679b5dd03d8aa10f7ad45e1a9dab92b417896c15d4d007c7c14194538d2a5d0feffdecc5a7f0e1c570cfa700837c\"\n}", + "importExample": "$ terraform import cloudflare_dns_zone_transfers_tsig.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "algo", + "type": "String", + "description": "TSIG algorithm." + }, + { + "name": "name", + "type": "String", + "description": "TSIG key name." + }, + { + "name": "secret", + "type": "String", + "description": "TSIG secret.", + "sensitive": true + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "list-data-source:cloudflare_dns_zone_transfers_tsigs": { + "kind": "list-data-source", + "name": "cloudflare_dns_zone_transfers_tsigs", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "data \"cloudflare_dns_zone_transfers_tsigs\" \"example_dns_zone_transfers_tsigs\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "algo", + "type": "String", + "description": "TSIG algorithm." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "TSIG key name." + }, + { + "name": "secret", + "type": "String", + "description": "TSIG secret.", + "sensitive": true + } + ] + } + ] + }, + "data-source:cloudflare_email_routing_address": { + "kind": "data-source", + "name": "cloudflare_email_routing_address", + "description": "Accepted Permissions\n\n- `Email Routing Addresses Read`\n- `Email Routing Addresses Write`", + "example": "data \"cloudflare_email_routing_address\" \"example_email_routing_address\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n destination_address_identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "destination_address_identifier", + "type": "String", + "description": "Destination address identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Sorts results in an ascending or descending order.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "verified", + "type": "Boolean", + "description": "Filter by verified destination addresses." + } + ] + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the destination address has been created." + }, + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Destination address identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the destination address was last modified." + }, + { + "name": "tag", + "type": "String", + "description": "Destination address tag. (Deprecated, replaced by destination address identifier)", + "deprecated": "Deprecated." + }, + { + "name": "verified", + "type": "String", + "description": "The date and time the destination address has been verified. Null means not verified yet." + } + ] + }, + "resource:cloudflare_email_routing_address": { + "kind": "resource", + "name": "cloudflare_email_routing_address", + "description": "Accepted Permissions\n\n- `Email Routing Addresses Read`\n- `Email Routing Addresses Write`", + "example": "resource \"cloudflare_email_routing_address\" \"example_email_routing_address\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"user@example.com\"\n}", + "importExample": "$ terraform import cloudflare_email_routing_address.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + } + ], + "optional": [ + { + "name": "status", + "type": "String", + "description": "Destination address status. Non-admin callers may only set verified addresses back to unverified; setting to verified requires admin privileges.\nAvailable values: \"unverified\", \"verified\"." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the destination address has been created." + }, + { + "name": "id", + "type": "String", + "description": "Destination address identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the destination address was last modified." + }, + { + "name": "tag", + "type": "String", + "description": "Destination address tag. (Deprecated, replaced by destination address identifier)", + "deprecated": "Deprecated." + }, + { + "name": "verified", + "type": "String", + "description": "The date and time the destination address has been verified. Null means not verified yet." + } + ] + }, + "list-data-source:cloudflare_email_routing_addresses": { + "kind": "list-data-source", + "name": "cloudflare_email_routing_addresses", + "description": "Accepted Permissions\n\n- `Email Routing Addresses Read`\n- `Email Routing Addresses Write`", + "example": "data \"cloudflare_email_routing_addresses\" \"example_email_routing_addresses\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "direction", + "type": "String", + "description": "Sorts results in an ascending or descending order.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "verified", + "type": "Boolean", + "description": "Filter by verified destination addresses." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and time the destination address has been created." + }, + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Destination address identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the destination address was last modified." + }, + { + "name": "tag", + "type": "String", + "description": "Destination address tag. (Deprecated, replaced by destination address identifier)", + "deprecated": "Deprecated." + }, + { + "name": "verified", + "type": "String", + "description": "The date and time the destination address has been verified. Null means not verified yet." + } + ] + } + ] + }, + "data-source:cloudflare_email_routing_catch_all": { + "kind": "data-source", + "name": "cloudflare_email_routing_catch_all", + "description": "Accepted Permissions\n\n- `Email Routing Rules Read`\n- `Email Routing Rules Write`", + "example": "data \"cloudflare_email_routing_catch_all\" \"example_email_routing_catch_all\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "actions", + "type": "Attributes List", + "description": "List actions for the catch-all routing rule.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Type of action for catch-all rule.\nAvailable values: \"drop\", \"forward\", \"worker\"." + }, + { + "name": "value", + "type": "List of String", + "description": "List of values for the action. Currently limited to a single value." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Routing rule status." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "matchers", + "type": "Attributes List", + "description": "List of matchers for the catch-all routing rule.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Type of matcher. Default is 'all'.\nAvailable values: \"all\"." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Routing rule name." + }, + { + "name": "source", + "type": "String", + "description": "Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\nAvailable values: \"api\", \"wrangler\"." + }, + { + "name": "tag", + "type": "String", + "description": "Routing rule tag. (Deprecated, replaced by routing rule identifier)", + "deprecated": "Deprecated." + } + ] + }, + "resource:cloudflare_email_routing_catch_all": { + "kind": "resource", + "name": "cloudflare_email_routing_catch_all", + "description": "Accepted Permissions\n\n- `Email Routing Rules Read`\n- `Email Routing Rules Write`", + "example": "resource \"cloudflare_email_routing_catch_all\" \"example_email_routing_catch_all\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n actions = [{\n type = \"forward\"\n value = [\"destinationaddress@example.net\"]\n }]\n matchers = [{\n type = \"all\"\n }]\n enabled = true\n name = \"Send to user@example.net rule.\"\n owner_worker_tag = \"a7e6fb77503c41d8a7f3113c6918f10c\"\n source = \"api\"\n}", + "importExample": "$ terraform import cloudflare_email_routing_catch_all.example ''", + "required": [ + { + "name": "actions", + "type": "Attributes List", + "description": "List actions for the catch-all routing rule.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Type of action for catch-all rule.\nAvailable values: \"drop\", \"forward\", \"worker\"." + }, + { + "name": "value", + "type": "List of String", + "description": "List of values for the action. Currently limited to a single value." + } + ] + }, + { + "name": "matchers", + "type": "Attributes List", + "description": "List of matchers for the catch-all routing rule.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Type of matcher. Default is 'all'.\nAvailable values: \"all\"." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Routing rule status." + }, + { + "name": "name", + "type": "String", + "description": "Routing rule name." + }, + { + "name": "owner_worker_tag", + "type": "String", + "description": "Public tag (script_tag) of the Worker that owns this rule. Required when\n`source` is `wrangler`." + }, + { + "name": "source", + "type": "String", + "description": "Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\nAvailable values: \"api\", \"wrangler\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "tag", + "type": "String", + "description": "Routing rule tag. (Deprecated, replaced by routing rule identifier)", + "deprecated": "Deprecated." + } + ] + }, + "data-source:cloudflare_email_routing_dns": { + "kind": "data-source", + "name": "cloudflare_email_routing_dns", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_email_routing_dns\" \"example_email_routing_dns\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n subdomain = \"example.net\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "subdomain", + "type": "String", + "description": "Deprecated. When supplied, the response shape differs from the documented default and is not modeled in generated SDKs. Do not rely on this parameter." + } + ], + "computed": [ + { + "name": "dns", + "type": "Attributes List", + "children": [ + { + "name": "content", + "type": "String", + "description": "DNS record content." + }, + { + "name": "name", + "type": "String", + "description": "DNS record name (or @ for the zone apex)." + }, + { + "name": "priority", + "type": "Number", + "description": "Required for MX, SRV and URI records. Unused by other record types. Records with lower priorities are preferred." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time to live, in seconds, of the DNS record. Must be between 60 and 86400, or 1 for 'automatic'." + }, + { + "name": "type", + "type": "String", + "description": "DNS record type.\nAvailable values: \"A\", \"AAAA\", \"CNAME\", \"HTTPS\", \"TXT\", \"SRV\", \"LOC\", \"MX\", \"NS\", \"CERT\", \"DNSKEY\", \"DS\", \"NAPTR\", \"SMIMEA\", \"SSHFP\", \"SVCB\", \"TLSA\", \"URI\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_email_routing_dns": { + "kind": "resource", + "name": "cloudflare_email_routing_dns", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "resource \"cloudflare_email_routing_dns\" \"example_email_routing_dns\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example.net\"\n}", + "importExample": "$ terraform import cloudflare_email_routing_dns.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "name", + "type": "String", + "description": "Domain of your zone." + }, + { + "name": "subdomain", + "type": "String", + "description": "Deprecated. When supplied, the response shape differs from the documented default and is not modeled in generated SDKs. Do not rely on this parameter." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the settings have been created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "State of the zone settings for Email Routing." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the settings have been modified." + }, + { + "name": "skip_wizard", + "type": "Boolean", + "description": "Flag to check if the user skipped the configuration wizard." + }, + { + "name": "status", + "type": "String", + "description": "Show the state of your account, and the type or configuration error.\nAvailable values: \"ready\", \"unconfigured\", \"misconfigured\", \"misconfigured/locked\", \"unlocked\"." + }, + { + "name": "support_subaddress", + "type": "Boolean", + "description": "Whether subaddressing (plus-addressing) is honored when matching incoming mail against routing rules." + }, + { + "name": "tag", + "type": "String", + "description": "Email Routing settings tag. (Deprecated, replaced by Email Routing settings identifier)", + "deprecated": "Deprecated." + } + ] + }, + "data-source:cloudflare_email_routing_rule": { + "kind": "data-source", + "name": "cloudflare_email_routing_rule", + "description": "Accepted Permissions\n\n- `Email Routing Rules Read`\n- `Email Routing Rules Write`", + "example": "data \"cloudflare_email_routing_rule\" \"example_email_routing_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_identifier = \"a7e6fb77503c41d8a7f3113c6918f10c\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Filter by enabled routing rules." + } + ] + }, + { + "name": "rule_identifier", + "type": "String", + "description": "Routing rule identifier." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "actions", + "type": "Attributes List", + "description": "List actions patterns.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Type of supported action.\nAvailable values: \"drop\", \"forward\", \"worker\"." + }, + { + "name": "value", + "type": "List of String", + "description": "List of values for the action. Currently limited to a single value." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Routing rule status." + }, + { + "name": "id", + "type": "String", + "description": "Routing rule identifier." + }, + { + "name": "matchers", + "type": "Attributes List", + "description": "Matching patterns to forward to your actions.", + "children": [ + { + "name": "field", + "type": "String", + "description": "Field for type matcher.\nAvailable values: \"to\"." + }, + { + "name": "type", + "type": "String", + "description": "Type of matcher.\nAvailable values: \"all\", \"literal\"." + }, + { + "name": "value", + "type": "String", + "description": "Value for matcher." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Routing rule name." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority of the routing rule." + }, + { + "name": "source", + "type": "String", + "description": "Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\nAvailable values: \"api\", \"wrangler\"." + }, + { + "name": "tag", + "type": "String", + "description": "Routing rule tag. (Deprecated, replaced by routing rule identifier)", + "deprecated": "Deprecated." + } + ] + }, + "resource:cloudflare_email_routing_rule": { + "kind": "resource", + "name": "cloudflare_email_routing_rule", + "description": "Accepted Permissions\n\n- `Email Routing Rules Read`\n- `Email Routing Rules Write`", + "example": "resource \"cloudflare_email_routing_rule\" \"example_email_routing_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n actions = [{\n type = \"forward\"\n value = [\"destinationaddress@example.net\"]\n }]\n matchers = [{\n type = \"literal\"\n field = \"to\"\n value = \"test@example.com\"\n }]\n enabled = true\n name = \"Send to user@example.net rule.\"\n owner_worker_tag = \"a7e6fb77503c41d8a7f3113c6918f10c\"\n priority = 0\n source = \"api\"\n}", + "importExample": "$ terraform import cloudflare_email_routing_rule.example '/'", + "required": [ + { + "name": "actions", + "type": "Attributes List", + "description": "List actions patterns.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Type of supported action.\nAvailable values: \"drop\", \"forward\", \"worker\"." + }, + { + "name": "value", + "type": "List of String", + "description": "List of values for the action. Currently limited to a single value." + } + ] + }, + { + "name": "matchers", + "type": "Attributes List", + "description": "Matching patterns to forward to your actions.", + "children": [ + { + "name": "field", + "type": "String", + "description": "Field for type matcher.\nAvailable values: \"to\"." + }, + { + "name": "type", + "type": "String", + "description": "Type of matcher.\nAvailable values: \"all\", \"literal\"." + }, + { + "name": "value", + "type": "String", + "description": "Value for matcher." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Routing rule status." + }, + { + "name": "name", + "type": "String", + "description": "Routing rule name." + }, + { + "name": "owner_worker_tag", + "type": "String", + "description": "Public tag (script_tag) of the Worker that owns this rule. Required when\n`source` is `wrangler`." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority of the routing rule." + }, + { + "name": "source", + "type": "String", + "description": "Who manages the rule. `api` covers dashboard, generic API, and Terraform;\n`wrangler` means the rule is managed by a Worker's wrangler.jsonc. Defaults\nto `api` when omitted on write.\nAvailable values: \"api\", \"wrangler\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Routing rule identifier." + }, + { + "name": "tag", + "type": "String", + "description": "Routing rule tag. (Deprecated, replaced by routing rule identifier)", + "deprecated": "Deprecated." + } + ] + }, + "list-data-source:cloudflare_email_routing_rules": { + "kind": "list-data-source", + "name": "cloudflare_email_routing_rules", + "description": "Accepted Permissions\n\n- `Email Routing Rules Read`\n- `Email Routing Rules Write`", + "example": "data \"cloudflare_email_routing_rules\" \"example_email_routing_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}", + "required": [], + "optional": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Filter by enabled routing rules." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "actions", + "type": "Attributes List", + "description": "List actions patterns.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Type of supported action.\nAvailable values: \"drop\", \"forward\", \"worker\"." + }, + { + "name": "value", + "type": "List of String", + "description": "List of values for the action. Currently limited to a single value." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Routing rule status." + }, + { + "name": "id", + "type": "String", + "description": "Routing rule identifier." + }, + { + "name": "matchers", + "type": "Attributes List", + "description": "Matching patterns to forward to your actions.", + "children": [ + { + "name": "field", + "type": "String", + "description": "Field for type matcher.\nAvailable values: \"to\"." + }, + { + "name": "type", + "type": "String", + "description": "Type of matcher.\nAvailable values: \"all\", \"literal\"." + }, + { + "name": "value", + "type": "String", + "description": "Value for matcher." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Routing rule name." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority of the routing rule." + }, + { + "name": "tag", + "type": "String", + "description": "Routing rule tag. (Deprecated, replaced by routing rule identifier)", + "deprecated": "Deprecated." + } + ] + } + ] + }, + "data-source:cloudflare_email_routing_settings": { + "kind": "data-source", + "name": "cloudflare_email_routing_settings", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_email_routing_settings\" \"example_email_routing_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the settings have been created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "State of the zone settings for Email Routing." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the settings have been modified." + }, + { + "name": "name", + "type": "String", + "description": "Domain of your zone." + }, + { + "name": "skip_wizard", + "type": "Boolean", + "description": "Flag to check if the user skipped the configuration wizard." + }, + { + "name": "status", + "type": "String", + "description": "Show the state of your account, and the type or configuration error.\nAvailable values: \"ready\", \"unconfigured\", \"misconfigured\", \"misconfigured/locked\", \"unlocked\"." + }, + { + "name": "tag", + "type": "String", + "description": "Email Routing settings tag. (Deprecated, replaced by Email Routing settings identifier)", + "deprecated": "Deprecated." + } + ] + }, + "resource:cloudflare_email_routing_settings": { + "kind": "resource", + "name": "cloudflare_email_routing_settings", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "resource \"cloudflare_email_routing_settings\" \"example_email_routing_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "importExample": "$ terraform import cloudflare_email_routing_settings.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "support_subaddress", + "type": "Boolean", + "description": "Whether subaddressing (plus-addressing) is honored when matching incoming mail against routing rules." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the settings have been created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "State of the zone settings for Email Routing." + }, + { + "name": "id", + "type": "String", + "description": "Email Routing settings identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the settings have been modified." + }, + { + "name": "name", + "type": "String", + "description": "Domain of your zone." + }, + { + "name": "skip_wizard", + "type": "Boolean", + "description": "Flag to check if the user skipped the configuration wizard." + }, + { + "name": "status", + "type": "String", + "description": "Show the state of your account, and the type or configuration error.\nAvailable values: \"ready\", \"unconfigured\", \"misconfigured\", \"misconfigured/locked\", \"unlocked\"." + }, + { + "name": "tag", + "type": "String", + "description": "Email Routing settings tag. (Deprecated, replaced by Email Routing settings identifier)", + "deprecated": "Deprecated." + } + ] + }, + "list-data-source:cloudflare_email_security_allow_policies": { + "kind": "list-data-source", + "name": "cloudflare_email_security_allow_policies", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_allow_policies\" \"example_email_security_allow_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n is_acceptable_sender = true\n is_exempt_recipient = true\n is_trusted_sender = true\n order = \"pattern\"\n pattern = \"pattern\"\n pattern_type = \"EMAIL\"\n search = \"search\"\n verify_sender = true\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "is_acceptable_sender", + "type": "Boolean", + "description": "Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious)." + }, + { + "name": "is_exempt_recipient", + "type": "Boolean", + "description": "Filter to show only policies where messages to the recipient bypass all detections." + }, + { + "name": "is_trusted_sender", + "type": "Boolean", + "description": "Filter to show only policies where messages from the sender bypass all detections and link following." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"pattern\", \"created_at\"." + }, + { + "name": "pattern", + "type": "String", + "description": "Filter by exact pattern value." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Filter by pattern type.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + }, + { + "name": "verify_sender", + "type": "Boolean", + "description": "Filter to show only policies that enforce DMARC, SPF, or DKIM authentication." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Allow policy identifier." + }, + { + "name": "is_acceptable_sender", + "type": "Boolean", + "description": "Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply." + }, + { + "name": "is_exempt_recipient", + "type": "Boolean", + "description": "Bypasses all detections for messages to this recipient." + }, + { + "name": "is_recipient", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_regex", + "type": "Boolean" + }, + { + "name": "is_sender", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_spoof", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_trusted_sender", + "type": "Boolean", + "description": "Bypasses all detections and link following for messages from this sender." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "pattern", + "type": "String", + "description": "The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + }, + { + "name": "verify_sender", + "type": "Boolean", + "description": "Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication." + } + ] + } + ] + }, + "data-source:cloudflare_email_security_allow_policy": { + "kind": "data-source", + "name": "cloudflare_email_security_allow_policy", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_allow_policy\" \"example_email_security_allow_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "is_acceptable_sender", + "type": "Boolean", + "description": "Filter to show only policies where messages from the sender are exempted from Spam, Spoof, and Bulk dispositions (not Malicious or Suspicious)." + }, + { + "name": "is_exempt_recipient", + "type": "Boolean", + "description": "Filter to show only policies where messages to the recipient bypass all detections." + }, + { + "name": "is_trusted_sender", + "type": "Boolean", + "description": "Filter to show only policies where messages from the sender bypass all detections and link following." + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"pattern\", \"created_at\"." + }, + { + "name": "pattern", + "type": "String", + "description": "Filter by exact pattern value." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Filter by pattern type.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + }, + { + "name": "verify_sender", + "type": "Boolean", + "description": "Filter to show only policies that enforce DMARC, SPF, or DKIM authentication." + } + ] + }, + { + "name": "policy_id", + "type": "String", + "description": "Allow policy identifier." + } + ], + "computed": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Allow policy identifier." + }, + { + "name": "is_acceptable_sender", + "type": "Boolean", + "description": "Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply." + }, + { + "name": "is_exempt_recipient", + "type": "Boolean", + "description": "Bypasses all detections for messages to this recipient." + }, + { + "name": "is_recipient", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_regex", + "type": "Boolean" + }, + { + "name": "is_sender", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_spoof", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_trusted_sender", + "type": "Boolean", + "description": "Bypasses all detections and link following for messages from this sender." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "pattern", + "type": "String", + "description": "The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + }, + { + "name": "verify_sender", + "type": "Boolean", + "description": "Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication." + } + ] + }, + "resource:cloudflare_email_security_allow_policy": { + "kind": "resource", + "name": "cloudflare_email_security_allow_policy", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "resource \"cloudflare_email_security_allow_policy\" \"example_email_security_allow_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_acceptable_sender = false\n is_exempt_recipient = false\n is_regex = false\n is_trusted_sender = true\n pattern = \"test@example.com\"\n pattern_type = \"EMAIL\"\n verify_sender = true\n comments = \"Trust all messages send from test@example.com\"\n is_recipient = false\n is_sender = true\n is_spoof = false\n}", + "importExample": "$ terraform import cloudflare_email_security_allow_policy.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "is_acceptable_sender", + "type": "Boolean", + "description": "Exempts messages from this sender from Spam, Spoof and Bulk dispositions only; Malicious and Suspicious dispositions still apply." + }, + { + "name": "is_exempt_recipient", + "type": "Boolean", + "description": "Bypasses all detections for messages to this recipient." + }, + { + "name": "is_regex", + "type": "Boolean" + }, + { + "name": "is_trusted_sender", + "type": "Boolean", + "description": "Bypasses all detections and link following for messages from this sender." + }, + { + "name": "pattern", + "type": "String", + "description": "The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + }, + { + "name": "verify_sender", + "type": "Boolean", + "description": "Enforce DMARC, SPF or DKIM authentication. When on, Email Security only honors policies that pass authentication." + } + ], + "optional": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "is_recipient", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_exempt_recipient` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_sender", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_trusted_sender` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "is_spoof", + "type": "Boolean", + "description": "Deprecated as of July 1, 2025. Use `is_acceptable_sender` instead. End of life: July 1, 2026.", + "deprecated": "Deprecated." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Allow policy identifier." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "data-source:cloudflare_email_security_block_sender": { + "kind": "data-source", + "name": "cloudflare_email_security_block_sender", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_block_sender\" \"example_email_security_block_sender\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pattern_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"pattern\", \"created_at\"." + }, + { + "name": "pattern", + "type": "String", + "description": "Filter by pattern value." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Filter by pattern type.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + } + ] + }, + { + "name": "pattern_id", + "type": "String", + "description": "Blocked sender pattern identifier." + } + ], + "computed": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Blocked sender pattern identifier." + }, + { + "name": "is_regex", + "type": "Boolean", + "description": "Whether `pattern` is a regular expression instead of a literal value." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "pattern", + "type": "String", + "description": "The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + } + ] + }, + "resource:cloudflare_email_security_block_sender": { + "kind": "resource", + "name": "cloudflare_email_security_block_sender", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "resource \"cloudflare_email_security_block_sender\" \"example_email_security_block_sender\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_regex = false\n pattern = \"test@example.com\"\n pattern_type = \"EMAIL\"\n comments = \"Block sender with email test@example.com\"\n}", + "importExample": "$ terraform import cloudflare_email_security_block_sender.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "is_regex", + "type": "Boolean", + "description": "Whether `pattern` is a regular expression instead of a literal value." + }, + { + "name": "pattern", + "type": "String", + "description": "The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + } + ], + "optional": [ + { + "name": "comments", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Blocked sender pattern identifier." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_email_security_block_senders": { + "kind": "list-data-source", + "name": "cloudflare_email_security_block_senders", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_block_senders\" \"example_email_security_block_senders\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"pattern\"\n pattern = \"pattern\"\n pattern_type = \"EMAIL\"\n search = \"search\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"pattern\", \"created_at\"." + }, + { + "name": "pattern", + "type": "String", + "description": "Filter by pattern value." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Filter by pattern type.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Blocked sender pattern identifier." + }, + { + "name": "is_regex", + "type": "Boolean", + "description": "Whether `pattern` is a regular expression instead of a literal value." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "pattern", + "type": "String", + "description": "The pattern value to match. The format depends on `pattern_type`: a valid email address for EMAIL (e.g. `user@example.com`), a valid domain name for DOMAIN (e.g. `example.com`), or a plain IPv4 or IPv6 address or CIDR block for IP (e.g. `1.2.3.4`, `1.2.3.0/24`, `2606:4700:4700::1111`, or `2606:4700:4700::/48`); the API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents." + }, + { + "name": "pattern_type", + "type": "String", + "description": "Type of pattern matching.\n- EMAIL: matches a full email address (e.g. `user@example.com`)\n- DOMAIN: matches a domain name (e.g. `example.com`)\n- IP: matches a plain IPv4 or IPv6 address (e.g. `1.2.3.4` or `2606:4700:4700::1111`) or CIDR block (e.g. `1.2.3.0/24` or `2606:4700:4700::/48`). The API rejects private or unique-local, loopback, link-local, unspecified, and IPv4 broadcast addresses, including their IPv4-mapped IPv6 equivalents.\n- UNKNOWN: deprecated; you cannot use this when creating or updating policies, but it may appear on existing entries.\nAvailable values: \"EMAIL\", \"DOMAIN\", \"IP\", \"UNKNOWN\"." + } + ] + } + ] + }, + "data-source:cloudflare_email_security_domain": { + "kind": "data-source", + "name": "cloudflare_email_security_domain", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_domain\" \"example_email_security_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "domain_id", + "type": "String", + "description": "Domain identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "active_delivery_mode", + "type": "String", + "description": "Currently active delivery mode to filter by.\nAvailable values: \"DIRECT\", \"BCC\", \"JOURNAL\", \"API\", \"RETRO_SCAN\"." + }, + { + "name": "allowed_delivery_mode", + "type": "String", + "description": "Delivery mode to filter by.\nAvailable values: \"DIRECT\", \"BCC\", \"JOURNAL\", \"API\", \"RETRO_SCAN\"." + }, + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "domain", + "type": "List of String", + "description": "Domain names to filter by." + }, + { + "name": "integration_id", + "type": "String", + "description": "Integration ID to filter by." + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"domain\", \"created_at\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + }, + { + "name": "status", + "type": "String", + "description": "Filters response to domains with the provided status.\nAvailable values: \"PENDING\", \"ACTIVE\", \"FAILED\", \"TIMEOUT\"." + } + ] + } + ], + "computed": [ + { + "name": "allowed_delivery_modes", + "type": "Set of String" + }, + { + "name": "authorization", + "type": "Attributes", + "children": [ + { + "name": "authorized", + "type": "Boolean" + }, + { + "name": "status_message", + "type": "String" + }, + { + "name": "timestamp", + "type": "String" + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dmarc_status", + "type": "String", + "description": "Available values: \"none\", \"good\", \"invalid\"." + }, + { + "name": "domain", + "type": "String" + }, + { + "name": "drop_dispositions", + "type": "Set of String" + }, + { + "name": "emails_processed", + "type": "Attributes", + "children": [ + { + "name": "timestamp", + "type": "String" + }, + { + "name": "total_emails_processed", + "type": "Number" + }, + { + "name": "total_emails_processed_previous", + "type": "Number" + } + ] + }, + { + "name": "folder", + "type": "String", + "description": "The mailbox folder to scan, for API-scanning domains.\nAvailable values: \"AllItems\", \"Inbox\"." + }, + { + "name": "id", + "type": "String", + "description": "Domain identifier." + }, + { + "name": "inbox_provider", + "type": "String", + "description": "Available values: \"Microsoft\", \"Google\"." + }, + { + "name": "integration_id", + "type": "String" + }, + { + "name": "ip_restrictions", + "type": "Set of String" + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "lookback_hops", + "type": "Number" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "o365_tenant_id", + "type": "String" + }, + { + "name": "regions", + "type": "Set of String" + }, + { + "name": "require_tls_inbound", + "type": "Boolean" + }, + { + "name": "require_tls_outbound", + "type": "Boolean" + }, + { + "name": "spf_status", + "type": "String", + "description": "Available values: \"none\", \"good\", \"neutral\", \"open\", \"invalid\"." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"PENDING\", \"ACTIVE\", \"FAILED\", \"TIMEOUT\"." + }, + { + "name": "transport", + "type": "String" + } + ] + }, + "resource:cloudflare_email_security_domain": { + "kind": "resource", + "name": "cloudflare_email_security_domain", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "resource \"cloudflare_email_security_domain\" \"example_email_security_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n allowed_delivery_modes = [\"DIRECT\"]\n domain = \"domain\"\n drop_dispositions = [\"MALICIOUS\"]\n ip_restrictions = [\"192.0.2.0/24\", \"2001:db8::/32\"]\n regions = [\"GLOBAL\"]\n folder = \"AllItems\"\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n lookback_hops = 1\n require_tls_inbound = true\n require_tls_outbound = true\n transport = \"transport\"\n}", + "importExample": "$ terraform import cloudflare_email_security_domain.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "allowed_delivery_modes", + "type": "Set of String", + "description": "Delivery modes to onboard the domain through." + }, + { + "name": "domain", + "type": "String", + "description": "The email domain to protect." + }, + { + "name": "drop_dispositions", + "type": "Set of String", + "description": "Dispositions to drop instead of delivering, e.g. `[\"MALICIOUS\", \"SPAM\"]`." + }, + { + "name": "ip_restrictions", + "type": "Set of String", + "description": "Source IP ranges mail is accepted from. Any other source is rejected." + }, + { + "name": "regions", + "type": "Set of String", + "description": "Regions that process messages for this domain, e.g. `[\"GLOBAL\"]` or `[\"US\"]`." + } + ], + "optional": [ + { + "name": "folder", + "type": "String", + "description": "The mailbox folder to scan, for API-scanning domains.\nAvailable values: \"AllItems\", \"Inbox\"." + }, + { + "name": "integration_id", + "type": "String", + "description": "Identifier of the CASB integration that authorizes this domain. The integration also enables API scanning, post-delivery actions, and directory sync." + }, + { + "name": "lookback_hops", + "type": "Number", + "description": "Number of hops to trace back through received headers when reconstructing the original message (1-20)." + }, + { + "name": "require_tls_inbound", + "type": "Boolean", + "description": "Require TLS on inbound connections." + }, + { + "name": "require_tls_outbound", + "type": "Boolean", + "description": "Require TLS on outbound connections." + }, + { + "name": "transport", + "type": "String", + "description": "The mail transport hostname for MX/Inline delivery — the MX record Cloudflare delivers email to (e.g. `mx.example.com`)." + } + ], + "computed": [ + { + "name": "authorization", + "type": "Attributes", + "children": [ + { + "name": "authorized", + "type": "Boolean" + }, + { + "name": "status_message", + "type": "String" + }, + { + "name": "timestamp", + "type": "String" + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dmarc_status", + "type": "String", + "description": "Available values: \"none\", \"good\", \"invalid\"." + }, + { + "name": "emails_processed", + "type": "Attributes", + "children": [ + { + "name": "timestamp", + "type": "String" + }, + { + "name": "total_emails_processed", + "type": "Number" + }, + { + "name": "total_emails_processed_previous", + "type": "Number" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Domain identifier." + }, + { + "name": "inbox_provider", + "type": "String", + "description": "Available values: \"Microsoft\", \"Google\"." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "o365_tenant_id", + "type": "String" + }, + { + "name": "spf_status", + "type": "String", + "description": "Available values: \"none\", \"good\", \"neutral\", \"open\", \"invalid\"." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"PENDING\", \"ACTIVE\", \"FAILED\", \"TIMEOUT\"." + } + ] + }, + "list-data-source:cloudflare_email_security_domains": { + "kind": "list-data-source", + "name": "cloudflare_email_security_domains", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_domains\" \"example_email_security_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n active_delivery_mode = \"DIRECT\"\n allowed_delivery_mode = \"DIRECT\"\n direction = \"asc\"\n domain = [\"string\"]\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n order = \"domain\"\n search = \"search\"\n status = \"PENDING\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "active_delivery_mode", + "type": "String", + "description": "Currently active delivery mode to filter by.\nAvailable values: \"DIRECT\", \"BCC\", \"JOURNAL\", \"API\", \"RETRO_SCAN\"." + }, + { + "name": "allowed_delivery_mode", + "type": "String", + "description": "Delivery mode to filter by.\nAvailable values: \"DIRECT\", \"BCC\", \"JOURNAL\", \"API\", \"RETRO_SCAN\"." + }, + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "domain", + "type": "List of String", + "description": "Domain names to filter by." + }, + { + "name": "integration_id", + "type": "String", + "description": "Integration ID to filter by." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"domain\", \"created_at\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + }, + { + "name": "status", + "type": "String", + "description": "Filters response to domains with the provided status.\nAvailable values: \"PENDING\", \"ACTIVE\", \"FAILED\", \"TIMEOUT\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allowed_delivery_modes", + "type": "Set of String" + }, + { + "name": "authorization", + "type": "Attributes", + "children": [ + { + "name": "authorized", + "type": "Boolean" + }, + { + "name": "status_message", + "type": "String" + }, + { + "name": "timestamp", + "type": "String" + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dmarc_status", + "type": "String", + "description": "Available values: \"none\", \"good\", \"invalid\"." + }, + { + "name": "domain", + "type": "String" + }, + { + "name": "drop_dispositions", + "type": "Set of String" + }, + { + "name": "emails_processed", + "type": "Attributes", + "children": [ + { + "name": "timestamp", + "type": "String" + }, + { + "name": "total_emails_processed", + "type": "Number" + }, + { + "name": "total_emails_processed_previous", + "type": "Number" + } + ] + }, + { + "name": "folder", + "type": "String", + "description": "The mailbox folder to scan, for API-scanning domains.\nAvailable values: \"AllItems\", \"Inbox\"." + }, + { + "name": "id", + "type": "String", + "description": "Domain identifier." + }, + { + "name": "inbox_provider", + "type": "String", + "description": "Available values: \"Microsoft\", \"Google\"." + }, + { + "name": "integration_id", + "type": "String" + }, + { + "name": "ip_restrictions", + "type": "Set of String" + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "lookback_hops", + "type": "Number" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "o365_tenant_id", + "type": "String" + }, + { + "name": "regions", + "type": "Set of String" + }, + { + "name": "require_tls_inbound", + "type": "Boolean" + }, + { + "name": "require_tls_outbound", + "type": "Boolean" + }, + { + "name": "spf_status", + "type": "String", + "description": "Available values: \"none\", \"good\", \"neutral\", \"open\", \"invalid\"." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"PENDING\", \"ACTIVE\", \"FAILED\", \"TIMEOUT\"." + }, + { + "name": "transport", + "type": "String" + } + ] + } + ] + }, + "list-data-source:cloudflare_email_security_impersonation_registries": { + "kind": "list-data-source", + "name": "cloudflare_email_security_impersonation_registries", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_impersonation_registries\" \"example_email_security_impersonation_registries\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"name\"\n provenance = \"A1S_INTERNAL\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"name\", \"email\", \"created_at\"." + }, + { + "name": "provenance", + "type": "String", + "description": "Available values: \"A1S_INTERNAL\", \"SNOOPY-CASB_OFFICE_365\", \"SNOOPY-OFFICE_365\", \"SNOOPY-GOOGLE_DIRECTORY\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comments", + "type": "String", + "description": "Optional note describing the entry." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "directory_id", + "type": "Number", + "description": "Identifier of the directory the entry was synced from, when directory-synced." + }, + { + "name": "directory_node_id", + "type": "Number", + "description": "Identifier of the directory node the entry was synced from, when directory-synced." + }, + { + "name": "email", + "type": "String", + "description": "Email address (or pattern) of the protected identity." + }, + { + "name": "external_directory_node_id", + "type": "String", + "description": "Deprecated. External identifier of the directory node.", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "String", + "description": "Impersonation registry entry identifier" + }, + { + "name": "is_email_regex", + "type": "Boolean", + "description": "Whether `email` is a regular expression instead of a literal address." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name of the protected identity." + }, + { + "name": "provenance", + "type": "String", + "description": "Source the entry was created from.\nAvailable values: \"A1S_INTERNAL\", \"SNOOPY-CASB_OFFICE_365\", \"SNOOPY-OFFICE_365\", \"SNOOPY-GOOGLE_DIRECTORY\"." + } + ] + } + ] + }, + "data-source:cloudflare_email_security_impersonation_registry": { + "kind": "data-source", + "name": "cloudflare_email_security_impersonation_registry", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_impersonation_registry\" \"example_email_security_impersonation_registry\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n impersonation_registry_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"name\", \"email\", \"created_at\"." + }, + { + "name": "provenance", + "type": "String", + "description": "Available values: \"A1S_INTERNAL\", \"SNOOPY-CASB_OFFICE_365\", \"SNOOPY-OFFICE_365\", \"SNOOPY-GOOGLE_DIRECTORY\"." + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + } + ] + }, + { + "name": "impersonation_registry_id", + "type": "String", + "description": "Impersonation registry entry identifier" + } + ], + "computed": [ + { + "name": "comments", + "type": "String", + "description": "Optional note describing the entry." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "directory_id", + "type": "Number", + "description": "Identifier of the directory the entry was synced from, when directory-synced." + }, + { + "name": "directory_node_id", + "type": "Number", + "description": "Identifier of the directory node the entry was synced from, when directory-synced." + }, + { + "name": "email", + "type": "String", + "description": "Email address (or pattern) of the protected identity." + }, + { + "name": "external_directory_node_id", + "type": "String", + "description": "Deprecated. External identifier of the directory node.", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "String", + "description": "Impersonation registry entry identifier" + }, + { + "name": "is_email_regex", + "type": "Boolean", + "description": "Whether `email` is a regular expression instead of a literal address." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name of the protected identity." + }, + { + "name": "provenance", + "type": "String", + "description": "Source the entry was created from.\nAvailable values: \"A1S_INTERNAL\", \"SNOOPY-CASB_OFFICE_365\", \"SNOOPY-OFFICE_365\", \"SNOOPY-GOOGLE_DIRECTORY\"." + } + ] + }, + "resource:cloudflare_email_security_impersonation_registry": { + "kind": "resource", + "name": "cloudflare_email_security_impersonation_registry", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "resource \"cloudflare_email_security_impersonation_registry\" \"example_email_security_impersonation_registry\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email = \"john.doe@example.com\"\n is_email_regex = false\n name = \"John Doe\"\n comments = \"comments\"\n directory_id = 0\n directory_node_id = 0\n external_directory_node_id = \"external_directory_node_id\"\n provenance = \"A1S_INTERNAL\"\n}", + "importExample": "$ terraform import cloudflare_email_security_impersonation_registry.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "email", + "type": "String", + "description": "Email address (or pattern) of the protected identity." + }, + { + "name": "is_email_regex", + "type": "Boolean", + "description": "Whether `email` is a regular expression instead of a literal address." + }, + { + "name": "name", + "type": "String", + "description": "Display name of the protected identity." + } + ], + "optional": [ + { + "name": "comments", + "type": "String", + "description": "Optional note describing the entry." + }, + { + "name": "directory_id", + "type": "Number", + "description": "Identifier of the directory the entry was synced from, when directory-synced." + }, + { + "name": "directory_node_id", + "type": "Number", + "description": "Identifier of the directory node the entry was synced from, when directory-synced." + }, + { + "name": "external_directory_node_id", + "type": "String", + "description": "Deprecated. External identifier of the directory node.", + "deprecated": "Deprecated." + }, + { + "name": "provenance", + "type": "String", + "description": "Source the entry was created from.\nAvailable values: \"A1S_INTERNAL\", \"SNOOPY-CASB_OFFICE_365\", \"SNOOPY-OFFICE_365\", \"SNOOPY-GOOGLE_DIRECTORY\"." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Impersonation registry entry identifier" + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "data-source:cloudflare_email_security_trusted_domains": { + "kind": "data-source", + "name": "cloudflare_email_security_trusted_domains", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_trusted_domains\" \"example_email_security_trusted_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n trusted_domain_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "is_recent", + "type": "Boolean", + "description": "Filter to show only recently registered domains that are trusted to prevent triggering Suspicious or Malicious dispositions." + }, + { + "name": "is_similarity", + "type": "Boolean", + "description": "Filter to show only proximity domains (partner or approved domains with similar spelling to connected domains) that prevent Spoof dispositions." + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"pattern\", \"created_at\"." + }, + { + "name": "pattern", + "type": "String" + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + } + ] + }, + { + "name": "trusted_domain_id", + "type": "String", + "description": "Trusted domain identifier" + } + ], + "computed": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Trusted domain identifier" + }, + { + "name": "is_recent", + "type": "Boolean", + "description": "Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition." + }, + { + "name": "is_regex", + "type": "Boolean", + "description": "Whether `pattern` is a regular expression instead of a literal domain." + }, + { + "name": "is_similarity", + "type": "Boolean", + "description": "Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "pattern", + "type": "String", + "description": "The domain pattern to trust, e.g. `example.com`." + } + ] + }, + "resource:cloudflare_email_security_trusted_domains": { + "kind": "resource", + "name": "cloudflare_email_security_trusted_domains", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "resource \"cloudflare_email_security_trusted_domains\" \"example_email_security_trusted_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n is_recent = true\n is_regex = false\n is_similarity = false\n pattern = \"example.com\"\n comments = \"Trusted partner domain\"\n}", + "importExample": "$ terraform import cloudflare_email_security_trusted_domains.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "pattern", + "type": "String", + "description": "The domain pattern to trust, e.g. `example.com`." + } + ], + "optional": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "is_recent", + "type": "Boolean", + "description": "Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition." + }, + { + "name": "is_regex", + "type": "Boolean", + "description": "Whether `pattern` is a regular expression instead of a literal domain." + }, + { + "name": "is_similarity", + "type": "Boolean", + "description": "Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Trusted domain identifier." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_email_security_trusted_domains_list": { + "kind": "list-data-source", + "name": "cloudflare_email_security_trusted_domains_list", + "description": "Accepted Permissions\n\n- `Cloud Email Security: Read`\n- `Cloud Email Security: Write`", + "example": "data \"cloudflare_email_security_trusted_domains_list\" \"example_email_security_trusted_domains_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n is_recent = true\n is_similarity = true\n order = \"pattern\"\n pattern = \"pattern\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "is_recent", + "type": "Boolean", + "description": "Filter to show only recently registered domains that are trusted to prevent triggering Suspicious or Malicious dispositions." + }, + { + "name": "is_similarity", + "type": "Boolean", + "description": "Filter to show only proximity domains (partner or approved domains with similar spelling to connected domains) that prevent Spoof dispositions." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to sort by.\nAvailable values: \"pattern\", \"created_at\"." + }, + { + "name": "pattern", + "type": "String" + }, + { + "name": "search", + "type": "String", + "description": "Search term for filtering records. Behavior may change." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comments", + "type": "String" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Trusted domain identifier" + }, + { + "name": "is_recent", + "type": "Boolean", + "description": "Select to prevent recently registered domains from triggering a Suspicious or Malicious disposition." + }, + { + "name": "is_regex", + "type": "Boolean", + "description": "Whether `pattern` is a regular expression instead of a literal domain." + }, + { + "name": "is_similarity", + "type": "Boolean", + "description": "Select for partner or other approved domains that have similar spelling to your connected domains. Prevents listed domains from triggering a Spoof disposition." + }, + { + "name": "last_modified", + "type": "String", + "description": "Deprecated, use `modified_at` instead. End of life: November 1, 2026.", + "deprecated": "Deprecated." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "pattern", + "type": "String", + "description": "The domain pattern to trust, e.g. `example.com`." + } + ] + } + ] + }, + "data-source:cloudflare_email_sending_subdomain": { + "kind": "data-source", + "name": "cloudflare_email_sending_subdomain", + "example": "data \"cloudflare_email_sending_subdomain\" \"example_email_sending_subdomain\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n subdomain_id = \"aabbccdd11223344aabbccdd11223344\"\n}", + "required": [ + { + "name": "subdomain_id", + "type": "String", + "description": "Sending subdomain identifier." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the destination address has been created." + }, + { + "name": "dkim_selector", + "type": "String", + "description": "The DKIM selector used for email signing. Wildcard rows publish the selector and sign with `d=`." + }, + { + "name": "drop_suppressed_recipients", + "type": "Boolean", + "description": "Whether a send request that includes a recipient suppressed on\nthis subdomain drops that recipient and still delivers to the\nrest, instead of failing the entire request." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Email Sending is enabled on this subdomain." + }, + { + "name": "id", + "type": "String", + "description": "Sending subdomain identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the destination address was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The exact domain name or a leftmost wildcard such as `*.example.com`." + }, + { + "name": "preview_enabled", + "type": "Boolean", + "description": "Whether sent messages from this subdomain can be previewed in the activity log." + }, + { + "name": "return_path_domain", + "type": "String", + "description": "The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`." + }, + { + "name": "tag", + "type": "String", + "description": "Sending subdomain identifier." + } + ] + }, + "resource:cloudflare_email_sending_subdomain": { + "kind": "resource", + "name": "cloudflare_email_sending_subdomain", + "example": "resource \"cloudflare_email_sending_subdomain\" \"example_email_sending_subdomain\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"sub.example.com\"\n}", + "importExample": "$ terraform import cloudflare_email_sending_subdomain.example '/'", + "required": [ + { + "name": "name", + "type": "String", + "description": "The domain name within the zone. A wildcard is allowed only as the complete leftmost label (`*.example.com`) and requires the account wildcard Email Sending entitlement." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "drop_suppressed_recipients", + "type": "Boolean", + "description": "Whether a send request that includes a recipient suppressed on\nthis subdomain drops that recipient and still delivers to the\nrest, instead of failing the entire request." + }, + { + "name": "preview_enabled", + "type": "Boolean", + "description": "Whether sent messages from this subdomain can be previewed in the activity log." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the destination address has been created." + }, + { + "name": "dkim_selector", + "type": "String", + "description": "The DKIM selector used for email signing. Wildcard rows publish the selector and sign with `d=`." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Email Sending is enabled on this subdomain." + }, + { + "name": "id", + "type": "String", + "description": "Sending subdomain identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the destination address was last modified." + }, + { + "name": "return_path_domain", + "type": "String", + "description": "The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`." + }, + { + "name": "tag", + "type": "String", + "description": "Sending subdomain identifier." + } + ] + }, + "list-data-source:cloudflare_email_sending_subdomains": { + "kind": "list-data-source", + "name": "cloudflare_email_sending_subdomains", + "example": "data \"cloudflare_email_sending_subdomains\" \"example_email_sending_subdomains\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and time the destination address has been created." + }, + { + "name": "dkim_selector", + "type": "String", + "description": "The DKIM selector used for email signing. Wildcard rows publish the selector and sign with `d=`." + }, + { + "name": "drop_suppressed_recipients", + "type": "Boolean", + "description": "Whether a send request that includes a recipient suppressed on\nthis subdomain drops that recipient and still delivers to the\nrest, instead of failing the entire request." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Email Sending is enabled on this subdomain." + }, + { + "name": "id", + "type": "String", + "description": "Sending subdomain identifier." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the destination address was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The exact domain name or a leftmost wildcard such as `*.example.com`." + }, + { + "name": "preview_enabled", + "type": "Boolean", + "description": "Whether sent messages from this subdomain can be previewed in the activity log." + }, + { + "name": "return_path_domain", + "type": "String", + "description": "The return-path domain used for bounce handling. Wildcard rows use `cf-bounce.`." + }, + { + "name": "tag", + "type": "String", + "description": "Sending subdomain identifier." + } + ] + } + ] + }, + "data-source:cloudflare_field_extractor": { + "kind": "data-source", + "name": "cloudflare_field_extractor", + "example": "data \"cloudflare_field_extractor\" \"example_field_extractor\" {\n account_id = \"123456\"\n extractor = \"llm_prompts\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID." + }, + { + "name": "extractor", + "type": "String", + "description": "Extractor type." + } + ], + "optional": [], + "computed": [ + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String", + "description": "Human-readable rule description." + }, + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "expression", + "type": "String", + "description": "Wirefilter value expression." + }, + { + "name": "name", + "type": "String", + "description": "Field name." + } + ] + }, + { + "name": "ref", + "type": "String", + "description": "Stable rule identifier." + } + ] + } + ] + }, + "resource:cloudflare_field_extractor": { + "kind": "resource", + "name": "cloudflare_field_extractor", + "example": "resource \"cloudflare_field_extractor\" \"example_field_extractor\" {\n account_id = \"123456\"\n extractor = \"llm_prompts\"\n rules = [{\n fields = [{\n expression = \"x\"\n name = \"x\"\n }]\n ref = \"x\"\n description = \"description\"\n }]\n}", + "importExample": "$ terraform import cloudflare_field_extractor.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID." + }, + { + "name": "extractor", + "type": "String", + "description": "Extractor type." + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "expression", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "ref", + "type": "String" + } + ] + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Extractor type." + } + ] + }, + "data-source:cloudflare_filter": { + "kind": "data-source", + "name": "cloudflare_filter", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_filter\" \"example_filter\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n filter_id = \"372e67954025e0ba6aaa6d586b9e0b61\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String", + "description": "A case-insensitive string to find in the description." + }, + { + "name": "expression", + "type": "String", + "description": "A case-insensitive string to find in the expression." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "The filter ref (a short reference tag) to search for. Must be an exact match." + } + ] + }, + { + "name": "filter_id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the filter." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related filters." + } + ] + }, + "resource:cloudflare_filter": { + "kind": "resource", + "name": "cloudflare_filter", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`\n\n~> `cloudflare_filter` is in a deprecation phase until June 15th, 2025.\n During this time period, this resource is still fully\n supported but you are strongly advised to move to the\n `cloudflare_ruleset` resource. Full details can be found in the\n [developer documentation](https://developers.cloudflare.com/waf/reference/migration-guides/firewall-rules-to-custom-rules/#relevant-changes-for-terraform-users).", + "example": "resource \"cloudflare_filter\" \"example_filter\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n body = [{\n description = \"Restrict access from these browsers on this address range.\"\n expression = \"(http.request.uri.path ~ \\\".*wp-login.php\\\" or http.request.uri.path ~ \\\".*xmlrpc.php\\\") and ip.addr ne 172.16.22.155\"\n paused = false\n ref = \"FIL-100\"\n }]\n}", + "importExample": "$ terraform import cloudflare_filter.example '/'", + "required": [ + { + "name": "body", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the filter." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related filters." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the filter." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related filters." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + } + ] + }, + "list-data-source:cloudflare_filters": { + "kind": "list-data-source", + "name": "cloudflare_filters", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_filters\" \"example_filters\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"372e67954025e0ba6aaa6d586b9e0b61\"\n description = \"browsers\"\n expression = \"php\"\n paused = false\n ref = \"FIL-100\"\n}", + "required": [], + "optional": [ + { + "name": "description", + "type": "String", + "description": "A case-insensitive string to find in the description." + }, + { + "name": "expression", + "type": "String", + "description": "A case-insensitive string to find in the expression." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "The filter ref (a short reference tag) to search for. Must be an exact match." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the filter." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related filters." + } + ] + } + ] + }, + "data-source:cloudflare_firewall_rule": { + "kind": "data-source", + "name": "cloudflare_firewall_rule", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_firewall_rule\" \"example_firewall_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_id = \"372e67954025e0ba6aaa6d586b9e0b60\"\n}", + "required": [], + "optional": [ + { + "name": "rule_id", + "type": "String", + "description": "The unique identifier of the firewall rule." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "action", + "type": "String", + "description": "The action to apply to a matched request. The `log` action is only available on an Enterprise plan.\nAvailable values: \"block\", \"challenge\", \"js_challenge\", \"managed_challenge\", \"allow\", \"log\", \"bypass\"." + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the firewall rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the firewall rule." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the firewall rule is currently paused." + }, + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority." + }, + { + "name": "products", + "type": "List of String" + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related firewall rules." + } + ] + }, + "resource:cloudflare_firewall_rule": { + "kind": "resource", + "name": "cloudflare_firewall_rule", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`\n\n~> `cloudflare_firewall_rule` is in a deprecation phase until June 15th, 2025.\n During this time period, this resource is still\n fully supported but you are strongly advised to move to the\n `cloudflare_ruleset` resource. Full details can be found in the\n [developer documentation](https://developers.cloudflare.com/waf/reference/migration-guides/firewall-rules-to-custom-rules/#relevant-changes-for-terraform-users).", + "example": "resource \"cloudflare_firewall_rule\" \"example_firewall_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = {\n mode = \"challenge\"\n response = {\n body = \"This request has been rate-limited.\"\n content_type = \"text/xml\"\n }\n timeout = 86400\n }\n filter = {\n description = \"Restrict access from these browsers on this address range.\"\n expression = \"(http.request.uri.path ~ \\\".*wp-login.php\\\" or http.request.uri.path ~ \\\".*xmlrpc.php\\\") and ip.addr ne 172.16.22.155\"\n paused = false\n ref = \"FIL-100\"\n }\n}", + "importExample": "$ terraform import cloudflare_firewall_rule.example '/'", + "required": [ + { + "name": "action", + "type": "Attributes", + "description": "The action to perform when the threshold of matched traffic within the configured period is exceeded.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The action to perform.\nAvailable values: \"simulate\", \"ban\", \"challenge\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "response", + "type": "Attributes", + "description": "A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional.\nNotes: If you omit this object, Cloudflare will use the default HTML error page. If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone challenge pages and you should not provide the \"response\" object.", + "children": [ + { + "name": "body", + "type": "String", + "description": "The response body to return. The value must conform to the configured content type." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type of the body. Must be one of the following: `text/plain`, `text/xml`, or `application/json`." + } + ] + }, + { + "name": "timeout", + "type": "Number", + "description": "The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period.\nNotes: If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone's Challenge Passage time and you should not provide this value." + } + ] + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the filter." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related filters." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the firewall rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the firewall rule." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the firewall rule is currently paused." + }, + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority." + }, + { + "name": "products", + "type": "List of String" + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related firewall rules." + } + ] + }, + "list-data-source:cloudflare_firewall_rules": { + "kind": "list-data-source", + "name": "cloudflare_firewall_rules", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_firewall_rules\" \"example_firewall_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"372e67954025e0ba6aaa6d586b9e0b60\"\n action = \"block\"\n description = \"mir\"\n paused = false\n}", + "required": [], + "optional": [ + { + "name": "action", + "type": "String", + "description": "The action to search for. Must be an exact match." + }, + { + "name": "description", + "type": "String", + "description": "A case-insensitive string to find in the description." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the firewall rule." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the firewall rule is currently paused." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to apply to a matched request. The `log` action is only available on an Enterprise plan.\nAvailable values: \"block\", \"challenge\", \"js_challenge\", \"managed_challenge\", \"allow\", \"log\", \"bypass\"." + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the firewall rule." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "deleted", + "type": "Boolean", + "description": "When true, indicates that the firewall rule was deleted." + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the filter." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression. For more information, refer to [Expressions](https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/)." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the filter." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the filter is currently paused." + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related filters." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the firewall rule." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the firewall rule is currently paused." + }, + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority." + }, + { + "name": "products", + "type": "List of String" + }, + { + "name": "ref", + "type": "String", + "description": "A short reference tag. Allows you to select related firewall rules." + } + ] + } + ] + }, + "data-source:cloudflare_flagship_app": { + "kind": "data-source", + "name": "cloudflare_flagship_app", + "description": "Accepted Permissions\n\n- `Flagship Read`", + "example": "data \"cloudflare_flagship_app\" \"example_flagship_app\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the Flagship app." + }, + { + "name": "app_id", + "type": "String", + "description": "Flagship app ID returned when the app was created." + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Flagship app ID returned when the app was created." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "updated_by", + "type": "String", + "description": "Email of the actor who last modified the app, or `edge-gateway` for gateway-authenticated changes." + } + ] + }, + "resource:cloudflare_flagship_app": { + "kind": "resource", + "name": "cloudflare_flagship_app", + "description": "Accepted Permissions\n\n- `Flagship Read`\n- `Flagship Write`", + "example": "resource \"cloudflare_flagship_app\" \"example_flagship_app\" {\n account_id = \"account_id\"\n name = \"x\"\n}", + "importExample": "$ terraform import cloudflare_flagship_app.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the Flagship app." + }, + { + "name": "name", + "type": "String", + "description": "Name of the Flagship app (1–64 letters, numbers, hyphens, or underscores)." + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "updated_by", + "type": "String", + "description": "Email of the actor who last modified the app, or `edge-gateway` for gateway-authenticated changes." + } + ] + }, + "list-data-source:cloudflare_flagship_apps": { + "kind": "list-data-source", + "name": "cloudflare_flagship_apps", + "description": "Accepted Permissions\n\n- `Flagship Read`", + "example": "data \"cloudflare_flagship_apps\" \"example_flagship_apps\" {\n account_id = \"account_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the Flagship app." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "updated_by", + "type": "String", + "description": "Email of the actor who last modified the app, or `edge-gateway` for gateway-authenticated changes." + } + ] + } + ] + }, + "data-source:cloudflare_flagship_flag": { + "kind": "data-source", + "name": "cloudflare_flagship_flag", + "description": "Accepted Permissions\n\n- `Flagship Read`", + "example": "data \"cloudflare_flagship_flag\" \"example_flagship_flag\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n flag_key = \"flag_key\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the Flagship app." + }, + { + "name": "app_id", + "type": "String", + "description": "Flagship app ID returned when the app was created." + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "Max items to return (1–200)." + } + ] + }, + { + "name": "flag_key", + "type": "String", + "description": "Case-sensitive key identifying the flag within the app." + } + ], + "computed": [ + { + "name": "default_variation", + "type": "String", + "description": "Variation served when no rule matches or the flag is disabled. Must be a key in `variations`." + }, + { + "name": "description", + "type": "String", + "description": "Optional operator-facing description. It does not affect flag evaluation." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "When false, the flag bypasses all rules and always serves `default_variation`." + }, + { + "name": "id", + "type": "String", + "description": "Case-sensitive key identifying the flag within the app." + }, + { + "name": "key", + "type": "String", + "description": "Unique identifier for the flag within an app. Used in all evaluation and SDK calls." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.", + "children": [ + { + "name": "conditions", + "type": "Attributes List", + "description": "Conditions the context must satisfy for this rule to match. An empty array matches all contexts.", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "List of String" + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "priority", + "type": "Number", + "description": "Evaluation order; lower numbers are evaluated first. Must be unique across the flag's rules." + }, + { + "name": "rollout", + "type": "Attributes", + "children": [ + { + "name": "attribute", + "type": "String", + "description": "Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request." + }, + { + "name": "percentage", + "type": "Number", + "description": "Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)." + } + ] + }, + { + "name": "serve_variation", + "type": "String", + "description": "Variation served when this rule matches. Must be a key in `variations`." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Value type of the flag's variations. Inferred from the variation values on write, so it may be omitted in requests.\nAvailable values: \"boolean\", \"string\", \"number\", \"json\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "updated_by", + "type": "String" + }, + { + "name": "variations", + "type": "Map of String", + "description": "Map of variation name to value. All values must be the same type (boolean, string, number, or JSON object/array). Each serialized value must be 10KB or smaller." + } + ] + }, + "resource:cloudflare_flagship_flag": { + "kind": "resource", + "name": "cloudflare_flagship_flag", + "description": "Accepted Permissions\n\n- `Flagship Read`\n- `Flagship Write`", + "example": "resource \"cloudflare_flagship_flag\" \"example_flagship_flag\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n default_variation = \"x\"\n enabled = true\n key = \"x\"\n rules = [{\n conditions = [{\n attribute = \"x\"\n operator = \"equals\"\n value = \"string\"\n }]\n priority = 1\n serve_variation = \"x\"\n rollout = {\n percentage = 0\n attribute = \"x\"\n }\n }]\n variations = {\n foo = \"string\"\n }\n description = \"description\"\n type = \"boolean\"\n}", + "importExample": "$ terraform import cloudflare_flagship_flag.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the Flagship app." + }, + { + "name": "app_id", + "type": "String", + "description": "Flagship app ID returned when the app was created." + }, + { + "name": "default_variation", + "type": "String", + "description": "Variation served when no rule matches or the flag is disabled. Must be a key in `variations`." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "When false, the flag bypasses all rules and always serves `default_variation`." + }, + { + "name": "key", + "type": "String", + "description": "Unique identifier for the flag within an app. Used in all evaluation and SDK calls." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.", + "children": [ + { + "name": "conditions", + "type": "Attributes List", + "description": "Conditions the context must satisfy for this rule to match. An empty array matches all contexts.", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "List of String" + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "priority", + "type": "Number", + "description": "Evaluation order; lower numbers are evaluated first. Must be unique across the flag's rules." + }, + { + "name": "rollout", + "type": "Attributes", + "children": [ + { + "name": "attribute", + "type": "String", + "description": "Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request." + }, + { + "name": "percentage", + "type": "Number", + "description": "Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)." + } + ] + }, + { + "name": "serve_variation", + "type": "String", + "description": "Variation served when this rule matches. Must be a key in `variations`." + } + ] + }, + { + "name": "variations", + "type": "Map of String", + "description": "Map of variation name to value. All values must be the same type (boolean, string, number, or JSON object/array). Each serialized value must be 10KB or smaller." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Optional operator-facing description. It does not affect flag evaluation." + }, + { + "name": "type", + "type": "String", + "description": "Deprecated compatibility field. Omit it; the API ignores this value and infers the type from the flag's variations.\nAvailable values: \"boolean\", \"string\", \"number\", \"json\".", + "deprecated": "Deprecated." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Unique identifier for the flag within an app. Used in all evaluation and SDK calls." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "updated_by", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_flagship_flags": { + "kind": "list-data-source", + "name": "cloudflare_flagship_flags", + "description": "Accepted Permissions\n\n- `Flagship Read`", + "example": "data \"cloudflare_flagship_flags\" \"example_flagship_flags\" {\n account_id = \"account_id\"\n app_id = \"app_id\"\n limit = 1\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the Flagship app." + }, + { + "name": "app_id", + "type": "String", + "description": "Flagship app ID returned when the app was created." + } + ], + "optional": [ + { + "name": "limit", + "type": "Number", + "description": "Max items to return (1–200)." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "default_variation", + "type": "String", + "description": "Variation served when no rule matches or the flag is disabled. Must be a key in `variations`." + }, + { + "name": "description", + "type": "String", + "description": "Optional operator-facing description. It does not affect flag evaluation." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "When false, the flag bypasses all rules and always serves `default_variation`." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the flag within an app. Used in all evaluation and SDK calls." + }, + { + "name": "key", + "type": "String", + "description": "Unique identifier for the flag within an app. Used in all evaluation and SDK calls." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "Targeting rules evaluated in ascending `priority`; the first matching rule wins. An empty array means the flag always serves `default_variation`.", + "children": [ + { + "name": "conditions", + "type": "Attributes List", + "description": "Conditions the context must satisfy for this rule to match. An empty array matches all contexts.", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "Attributes List", + "children": [ + { + "name": "attribute", + "type": "String" + }, + { + "name": "clauses", + "type": "List of String" + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "logical_operator", + "type": "String", + "description": "Available values: \"AND\", \"OR\"." + }, + { + "name": "operator", + "type": "String", + "description": "Available values: \"equals\", \"not_equals\", \"greater_than\", \"less_than\", \"greater_than_or_equals\", \"less_than_or_equals\", \"contains\", \"starts_with\", \"ends_with\", \"in\", \"not_in\", \"has\", \"not_has\"." + }, + { + "name": "value", + "type": "String", + "description": "Value to compare against the context attribute. Must be an array for `in` and `not_in`; numeric and ISO-8601 datetime strings are accepted by the ordering operators." + } + ] + }, + { + "name": "priority", + "type": "Number", + "description": "Evaluation order; lower numbers are evaluated first. Must be unique across the flag's rules." + }, + { + "name": "rollout", + "type": "Attributes", + "children": [ + { + "name": "attribute", + "type": "String", + "description": "Context attribute used for sticky bucketing. Defaults to `targetingKey`. If absent at evaluation time, bucketing is random per request." + }, + { + "name": "percentage", + "type": "Number", + "description": "Percentage of matching traffic (0–100, up to 2 decimal places) served this variation. For multi-way splits, use cumulative upper bounds across rules (e.g. 30, 70, 100)." + } + ] + }, + { + "name": "serve_variation", + "type": "String", + "description": "Variation served when this rule matches. Must be a key in `variations`." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Server-inferred value type shared by all of the flag's variations.\nAvailable values: \"boolean\", \"string\", \"number\", \"json\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "updated_by", + "type": "String" + }, + { + "name": "variations", + "type": "Map of String", + "description": "Map of variation name to value. All values share the same type (boolean, string, number, or JSON object/array), and each serialized value stays within 10KB." + } + ] + } + ] + }, + "data-source:cloudflare_google_tag_gateway": { + "kind": "data-source", + "name": "cloudflare_google_tag_gateway", + "description": "Accepted Permissions\n\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`", + "example": "data \"cloudflare_google_tag_gateway\" \"example_google_tag_gateway\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enables or disables Google Tag Gateway for this zone." + }, + { + "name": "endpoint", + "type": "String", + "description": "Specifies the endpoint path for proxying Google Tag Manager requests. Use an absolute path starting with '/', with no nested paths and alphanumeric characters only (e.g. /metrics)." + }, + { + "name": "hide_original_ip", + "type": "Boolean", + "description": "Hides the original client IP address from Google when enabled." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "measurement_id", + "type": "String", + "description": "Specify the Google Tag Manager container or measurement ID (e.g. GTM-XXXXXXX or G-XXXXXXXXXX)." + }, + { + "name": "set_up_tag", + "type": "Boolean", + "description": "Set up the associated Google Tag on the zone automatically when enabled." + } + ] + }, + "resource:cloudflare_google_tag_gateway": { + "kind": "resource", + "name": "cloudflare_google_tag_gateway", + "description": "Accepted Permissions\n\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`", + "example": "resource \"cloudflare_google_tag_gateway\" \"example_google_tag_gateway\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n endpoint = \"/metrics\"\n hide_original_ip = true\n measurement_id = \"GTM-P2F3N47Q\"\n set_up_tag = true\n}", + "importExample": "$ terraform import cloudflare_google_tag_gateway.example ''", + "required": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enables or disables Google Tag Gateway for this zone." + }, + { + "name": "endpoint", + "type": "String", + "description": "Specifies the endpoint path for proxying Google Tag Manager requests. Use an absolute path starting with '/', with no nested paths and alphanumeric characters only (e.g. /metrics)." + }, + { + "name": "hide_original_ip", + "type": "Boolean", + "description": "Hides the original client IP address from Google when enabled." + }, + { + "name": "measurement_id", + "type": "String", + "description": "Specify the Google Tag Manager container or measurement ID (e.g. GTM-XXXXXXX or G-XXXXXXXXXX)." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "set_up_tag", + "type": "Boolean", + "description": "Set up the associated Google Tag on the zone automatically when enabled." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_healthcheck": { + "kind": "data-source", + "name": "cloudflare_healthcheck", + "description": "Accepted Permissions\n\n- `Health Checks Read`\n- `Health Checks Write`", + "example": "data \"cloudflare_healthcheck\" \"example_healthcheck\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n healthcheck_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "healthcheck_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "address", + "type": "String", + "description": "The hostname or IP address of the origin server to run health checks on." + }, + { + "name": "check_regions", + "type": "List of String", + "description": "A list of regions from which to run health checks. Null means Cloudflare will pick a default region." + }, + { + "name": "consecutive_fails", + "type": "Number", + "description": "The number of consecutive fails required from a health check before changing the health to unhealthy." + }, + { + "name": "consecutive_successes", + "type": "Number", + "description": "The number of consecutive successes required from a health check before changing the health to healthy." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description of the health check." + }, + { + "name": "failure_reason", + "type": "String", + "description": "The current failure reason if status is unhealthy." + }, + { + "name": "http_config", + "type": "Attributes", + "description": "Parameters specific to an HTTP or HTTPS health check.", + "children": [ + { + "name": "allow_insecure", + "type": "Boolean", + "description": "Do not validate the certificate when the health check uses HTTPS." + }, + { + "name": "expected_body", + "type": "String", + "description": "A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy." + }, + { + "name": "expected_codes", + "type": "List of String", + "description": "The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check." + }, + { + "name": "follow_redirects", + "type": "Boolean", + "description": "Follow redirects if the origin returns a 3xx status code." + }, + { + "name": "header", + "type": "Map of List of String", + "description": "The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP method to use for the health check.\nAvailable values: \"GET\", \"HEAD\"." + }, + { + "name": "path", + "type": "String", + "description": "The endpoint path to health check against." + }, + { + "name": "port", + "type": "Number", + "description": "Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "interval", + "type": "Number", + "description": "The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "retries", + "type": "Number", + "description": "The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately." + }, + { + "name": "status", + "type": "String", + "description": "The current status of the origin server according to the health check.\nAvailable values: \"unknown\", \"healthy\", \"unhealthy\", \"suspended\"." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "If suspended, no health checks are sent to the origin." + }, + { + "name": "tcp_config", + "type": "Attributes", + "description": "Parameters specific to TCP health check.", + "children": [ + { + "name": "method", + "type": "String", + "description": "The TCP connection method to use for the health check.\nAvailable values: \"connection_established\"." + }, + { + "name": "port", + "type": "Number", + "description": "Port number to connect to for the health check. Defaults to 80." + } + ] + }, + { + "name": "timeout", + "type": "Number", + "description": "The timeout (in seconds) before marking the health check as failed." + }, + { + "name": "type", + "type": "String", + "description": "The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'." + } + ] + }, + "resource:cloudflare_healthcheck": { + "kind": "resource", + "name": "cloudflare_healthcheck", + "description": "Accepted Permissions\n\n- `Health Checks Read`\n- `Health Checks Write`", + "example": "resource \"cloudflare_healthcheck\" \"example_healthcheck\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n address = \"www.example.com\"\n name = \"server-1\"\n check_regions = [\"WEU\", \"ENAM\"]\n consecutive_fails = 0\n consecutive_successes = 0\n description = \"Health check for www.example.com\"\n http_config = {\n allow_insecure = true\n expected_body = \"success\"\n expected_codes = [\"2xx\", \"302\"]\n follow_redirects = true\n header = {\n Host = [\"example.com\"]\n X-App-ID = [\"abc123\"]\n }\n method = \"GET\"\n path = \"/health\"\n port = 0\n }\n interval = 0\n retries = 0\n suspended = true\n tcp_config = {\n method = \"connection_established\"\n port = 0\n }\n timeout = 0\n type = \"HTTPS\"\n}", + "importExample": "$ terraform import cloudflare_healthcheck.example '/'", + "required": [ + { + "name": "address", + "type": "String", + "description": "The hostname or IP address of the origin server to run health checks on." + }, + { + "name": "name", + "type": "String", + "description": "A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "check_regions", + "type": "List of String", + "description": "A list of regions from which to run health checks. Null means Cloudflare will pick a default region." + }, + { + "name": "consecutive_fails", + "type": "Number", + "description": "The number of consecutive fails required from a health check before changing the health to unhealthy." + }, + { + "name": "consecutive_successes", + "type": "Number", + "description": "The number of consecutive successes required from a health check before changing the health to healthy." + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description of the health check." + }, + { + "name": "http_config", + "type": "Attributes", + "description": "Parameters specific to an HTTP or HTTPS health check.", + "children": [ + { + "name": "allow_insecure", + "type": "Boolean", + "description": "Do not validate the certificate when the health check uses HTTPS." + }, + { + "name": "expected_body", + "type": "String", + "description": "A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy." + }, + { + "name": "expected_codes", + "type": "List of String", + "description": "The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check." + }, + { + "name": "follow_redirects", + "type": "Boolean", + "description": "Follow redirects if the origin returns a 3xx status code." + }, + { + "name": "header", + "type": "Map of List of String", + "description": "The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP method to use for the health check.\nAvailable values: \"GET\", \"HEAD\"." + }, + { + "name": "path", + "type": "String", + "description": "The endpoint path to health check against." + }, + { + "name": "port", + "type": "Number", + "description": "Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS." + } + ] + }, + { + "name": "interval", + "type": "Number", + "description": "The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations." + }, + { + "name": "retries", + "type": "Number", + "description": "The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "If suspended, no health checks are sent to the origin." + }, + { + "name": "tcp_config", + "type": "Attributes", + "description": "Parameters specific to TCP health check.", + "children": [ + { + "name": "method", + "type": "String", + "description": "The TCP connection method to use for the health check.\nAvailable values: \"connection_established\"." + }, + { + "name": "port", + "type": "Number", + "description": "Port number to connect to for the health check. Defaults to 80." + } + ] + }, + { + "name": "timeout", + "type": "Number", + "description": "The timeout (in seconds) before marking the health check as failed." + }, + { + "name": "type", + "type": "String", + "description": "The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "failure_reason", + "type": "String", + "description": "The current failure reason if status is unhealthy." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "The current status of the origin server according to the health check.\nAvailable values: \"unknown\", \"healthy\", \"unhealthy\", \"suspended\"." + } + ] + }, + "list-data-source:cloudflare_healthchecks": { + "kind": "list-data-source", + "name": "cloudflare_healthchecks", + "description": "Accepted Permissions\n\n- `Health Checks Read`\n- `Health Checks Write`", + "example": "data \"cloudflare_healthchecks\" \"example_healthchecks\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "address", + "type": "String", + "description": "The hostname or IP address of the origin server to run health checks on." + }, + { + "name": "check_regions", + "type": "List of String", + "description": "A list of regions from which to run health checks. Null means Cloudflare will pick a default region." + }, + { + "name": "consecutive_fails", + "type": "Number", + "description": "The number of consecutive fails required from a health check before changing the health to unhealthy." + }, + { + "name": "consecutive_successes", + "type": "Number", + "description": "The number of consecutive successes required from a health check before changing the health to healthy." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description of the health check." + }, + { + "name": "failure_reason", + "type": "String", + "description": "The current failure reason if status is unhealthy." + }, + { + "name": "http_config", + "type": "Attributes", + "description": "Parameters specific to an HTTP or HTTPS health check.", + "children": [ + { + "name": "allow_insecure", + "type": "Boolean", + "description": "Do not validate the certificate when the health check uses HTTPS." + }, + { + "name": "expected_body", + "type": "String", + "description": "A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy." + }, + { + "name": "expected_codes", + "type": "List of String", + "description": "The expected HTTP response codes (e.g. \"200\") or code ranges (e.g. \"2xx\" for all codes starting with 2) of the health check." + }, + { + "name": "follow_redirects", + "type": "Boolean", + "description": "Follow redirects if the origin returns a 3xx status code." + }, + { + "name": "header", + "type": "Map of List of String", + "description": "The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP method to use for the health check.\nAvailable values: \"GET\", \"HEAD\"." + }, + { + "name": "path", + "type": "String", + "description": "The endpoint path to health check against." + }, + { + "name": "port", + "type": "Number", + "description": "Port number to connect to for the health check. Defaults to 80 if type is HTTP or 443 if type is HTTPS." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "interval", + "type": "Number", + "description": "The interval between each health check. Shorter intervals may give quicker notifications if the origin status changes, but will increase load on the origin as we check from multiple locations." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A short name to identify the health check. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "retries", + "type": "Number", + "description": "The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately." + }, + { + "name": "status", + "type": "String", + "description": "The current status of the origin server according to the health check.\nAvailable values: \"unknown\", \"healthy\", \"unhealthy\", \"suspended\"." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "If suspended, no health checks are sent to the origin." + }, + { + "name": "tcp_config", + "type": "Attributes", + "description": "Parameters specific to TCP health check.", + "children": [ + { + "name": "method", + "type": "String", + "description": "The TCP connection method to use for the health check.\nAvailable values: \"connection_established\"." + }, + { + "name": "port", + "type": "Number", + "description": "Port number to connect to for the health check. Defaults to 80." + } + ] + }, + { + "name": "timeout", + "type": "Number", + "description": "The timeout (in seconds) before marking the health check as failed." + }, + { + "name": "type", + "type": "String", + "description": "The protocol to use for the health check. Currently supported protocols are 'HTTP', 'HTTPS' and 'TCP'." + } + ] + } + ] + }, + "data-source:cloudflare_hostname_tls_setting": { + "kind": "data-source", + "name": "cloudflare_hostname_tls_setting", + "example": "data \"cloudflare_hostname_tls_setting\" \"example_hostname_tls_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n hostname = \"app.example.com\"\n}", + "required": [ + { + "name": "hostname", + "type": "String", + "description": "The hostname for which the tls settings are set." + }, + { + "name": "setting_id", + "type": "String", + "description": "The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.\nAvailable values: \"ciphers\", \"min_tls_version\", \"http2\"." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the tls setting was originally created for this hostname." + }, + { + "name": "status", + "type": "String", + "description": "Deployment status for the given tls setting." + }, + { + "name": "updated_at", + "type": "String", + "description": "This is the time the tls setting was updated." + }, + { + "name": "value", + "type": "String", + "description": "The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`).\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\", \"on\", \"off\"." + } + ] + }, + "resource:cloudflare_hostname_tls_setting": { + "kind": "resource", + "name": "cloudflare_hostname_tls_setting", + "description": "Accepted Permissions\n\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_hostname_tls_setting\" \"example_hostname_tls_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n hostname = \"app.example.com\"\n value = [\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]\n}", + "importExample": "$ terraform import cloudflare_hostname_tls_setting.example '//'", + "required": [ + { + "name": "hostname", + "type": "String", + "description": "The hostname for which the tls settings are set." + }, + { + "name": "setting_id", + "type": "String", + "description": "The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.\nAvailable values: \"ciphers\", \"min_tls_version\", \"http2\"." + }, + { + "name": "value", + "type": "Dynamic", + "description": "The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`).\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\", \"on\", \"off\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the tls setting was originally created for this hostname." + }, + { + "name": "id", + "type": "String", + "description": "The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.\nAvailable values: \"ciphers\", \"min_tls_version\", \"http2\"." + }, + { + "name": "status", + "type": "String", + "description": "Deployment status for the given tls setting." + }, + { + "name": "updated_at", + "type": "String", + "description": "This is the time the tls setting was updated." + } + ] + }, + "list-data-source:cloudflare_hostname_tls_settings": { + "kind": "list-data-source", + "name": "cloudflare_hostname_tls_settings", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_hostname_tls_settings\" \"example_hostname_tls_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n}", + "required": [ + { + "name": "setting_id", + "type": "String", + "description": "The TLS Setting name.\nThe value type depends on the setting:\n- `ciphers`: value is an array of cipher suite strings (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: value is a TLS version string (`\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"`).\n- `http2`: value is `\"on\"` or `\"off\"`.\nAvailable values: \"ciphers\", \"min_tls_version\", \"http2\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "This is the time the tls setting was originally created for this hostname." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname for which the tls settings are set." + }, + { + "name": "status", + "type": "String", + "description": "Deployment status for the given tls setting." + }, + { + "name": "updated_at", + "type": "String", + "description": "This is the time the tls setting was updated." + }, + { + "name": "value", + "type": "String", + "description": "The TLS setting value.\nThe type depends on the `setting_id` used in the request path:\n- `ciphers`: an array of allowed cipher suite strings in BoringSSL format (e.g., `[\"ECDHE-RSA-AES128-GCM-SHA256\", \"AES128-GCM-SHA256\"]`).\n- `min_tls_version`: a string indicating the minimum TLS version — one of `\"1.0\"`, `\"1.1\"`, `\"1.2\"`, or `\"1.3\"` (e.g., `\"1.2\"`).\n- `http2`: a string indicating whether HTTP/2 is enabled — `\"on\"` or `\"off\"` (e.g., `\"on\"`).\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\", \"on\", \"off\"." + } + ] + } + ] + }, + "data-source:cloudflare_hyperdrive_config": { + "kind": "data-source", + "name": "cloudflare_hyperdrive_config", + "description": "Accepted Permissions\n\n- `Hyperdrive Read`\n- `Hyperdrive Write`", + "example": "data \"cloudflare_hyperdrive_config\" \"example_hyperdrive_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hyperdrive_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "hyperdrive_id", + "type": "String", + "description": "Define configurations using a unique string identifier." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Define configurations using a unique string identifier." + } + ], + "computed": [ + { + "name": "caching", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Defines whether caching is disabled." + }, + { + "name": "max_age", + "type": "Number", + "description": "Defines the maximum duration (in seconds) items persist in the cache." + }, + { + "name": "stale_while_revalidate", + "type": "Number", + "description": "Defines the number of seconds the cache may serve a stale response." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "Defines the creation time of the Hyperdrive configuration." + }, + { + "name": "id", + "type": "String", + "description": "Define configurations using a unique string identifier." + }, + { + "name": "integration", + "type": "Attributes", + "description": "Connects to a PlanetScale database using credentials managed by Cloudflare. The Cloudflare account must already be linked to PlanetScale in the Hyperdrive dashboard.", + "children": [ + { + "name": "custom_database_name", + "type": "String", + "description": "The database name to use when connecting. Defaults to `postgres` for PostgreSQL and `mysql` for MySQL." + }, + { + "name": "database_branch_name", + "type": "String", + "description": "The name of the PlanetScale database branch." + }, + { + "name": "database_name", + "type": "String", + "description": "The name of the PlanetScale database." + }, + { + "name": "hyperdrive_config_provider", + "type": "String", + "description": "The database integration provider used by this operation.\nAvailable values: \"planetscale\"." + }, + { + "name": "organization_name", + "type": "String", + "description": "The name of the PlanetScale organization." + }, + { + "name": "scheme", + "type": "String", + "description": "Specifies the URL scheme used to connect to your origin database.\nAvailable values: \"postgres\", \"postgresql\", \"mysql\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "Defines the last modified time of the Hyperdrive configuration." + }, + { + "name": "mtls", + "type": "Attributes", + "description": "mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.", + "children": [ + { + "name": "ca_certificate_id", + "type": "String", + "description": "Define CA certificate ID obtained after uploading CA cert." + }, + { + "name": "mtls_certificate_id", + "type": "String", + "description": "Define mTLS certificate ID obtained after uploading client cert." + }, + { + "name": "sslmode", + "type": "String", + "description": "PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API." + }, + { + "name": "origin", + "type": "Attributes", + "description": "Combines database connection fields with exactly one supported network location.", + "children": [ + { + "name": "access_client_id", + "type": "String", + "description": "Defines the Client ID of the Access token to use when connecting to the origin database." + }, + { + "name": "access_client_secret", + "type": "String", + "description": "Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.", + "sensitive": true + }, + { + "name": "database", + "type": "String", + "description": "Set the name of your origin database." + }, + { + "name": "host", + "type": "String", + "description": "Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed." + }, + { + "name": "password", + "type": "String", + "description": "Set the password needed to access your origin database. The API never returns this write-only value.", + "sensitive": true + }, + { + "name": "port", + "type": "Number", + "description": "Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified." + }, + { + "name": "scheme", + "type": "String", + "description": "Specifies the URL scheme used to connect to your origin database.\nAvailable values: \"postgres\", \"postgresql\", \"mysql\"." + }, + { + "name": "service_id", + "type": "String", + "description": "The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database." + }, + { + "name": "user", + "type": "String", + "description": "Set the user of your origin database." + } + ] + }, + { + "name": "origin_connection_limit", + "type": "Number", + "description": "The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit." + }, + { + "name": "restarted_on", + "type": "String", + "description": "Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted." + } + ] + }, + "resource:cloudflare_hyperdrive_config": { + "kind": "resource", + "name": "cloudflare_hyperdrive_config", + "description": "Accepted Permissions\n\n- `Hyperdrive Read`\n- `Hyperdrive Write`", + "example": "resource \"cloudflare_hyperdrive_config\" \"example_hyperdrive_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example-hyperdrive\"\n origin = {\n database = \"postgres\"\n host = \"database.example.com\"\n password = \"password\"\n port = 5432\n scheme = \"postgres\"\n user = \"postgres\"\n }\n caching = {\n disabled = true\n max_age = 0\n stale_while_revalidate = 0\n }\n integration = jsonencode({})\n mtls = {\n ca_certificate_id = \"00000000-0000-0000-0000-0000000000\"\n mtls_certificate_id = \"00000000-0000-0000-0000-0000000000\"\n sslmode = \"verify-full\"\n }\n origin_connection_limit = 60\n}", + "importExample": "$ terraform import cloudflare_hyperdrive_config.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Define configurations using a unique string identifier." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API." + } + ], + "optional": [ + { + "name": "caching", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean" + }, + { + "name": "max_age", + "type": "Number" + }, + { + "name": "stale_while_revalidate", + "type": "Number" + } + ] + }, + { + "name": "integration", + "type": "String" + }, + { + "name": "mtls", + "type": "Attributes", + "description": "mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.", + "children": [ + { + "name": "ca_certificate_id", + "type": "String", + "description": "Define CA certificate ID obtained after uploading CA cert." + }, + { + "name": "mtls_certificate_id", + "type": "String", + "description": "Define mTLS certificate ID obtained after uploading client cert." + }, + { + "name": "sslmode", + "type": "String", + "description": "PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate." + } + ] + }, + { + "name": "origin", + "type": "Attributes", + "description": "Combines database connection fields with exactly one supported network location.", + "children": [ + { + "name": "access_client_id", + "type": "String", + "description": "Defines the Client ID of the Access token to use when connecting to the origin database." + }, + { + "name": "access_client_secret", + "type": "String", + "description": "Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.", + "sensitive": true + }, + { + "name": "database", + "type": "String", + "description": "Set the name of your origin database." + }, + { + "name": "host", + "type": "String", + "description": "Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed." + }, + { + "name": "password", + "type": "String", + "description": "Set the password needed to access your origin database. The API never returns this write-only value.", + "sensitive": true + }, + { + "name": "port", + "type": "Number", + "description": "Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified." + }, + { + "name": "scheme", + "type": "String", + "description": "Specifies the URL scheme used to connect to your origin database.\nAvailable values: \"postgres\", \"postgresql\", \"mysql\"." + }, + { + "name": "service_id", + "type": "String", + "description": "The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database." + }, + { + "name": "user", + "type": "String", + "description": "Set the user of your origin database." + } + ] + }, + { + "name": "origin_connection_limit", + "type": "Number", + "description": "The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Defines the creation time of the Hyperdrive configuration." + }, + { + "name": "id", + "type": "String", + "description": "Define configurations using a unique string identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Defines the last modified time of the Hyperdrive configuration." + }, + { + "name": "restarted_on", + "type": "String", + "description": "Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted." + } + ] + }, + "list-data-source:cloudflare_hyperdrive_configs": { + "kind": "list-data-source", + "name": "cloudflare_hyperdrive_configs", + "description": "Accepted Permissions\n\n- `Hyperdrive Read`\n- `Hyperdrive Write`", + "example": "data \"cloudflare_hyperdrive_configs\" \"example_hyperdrive_configs\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Define configurations using a unique string identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "caching", + "type": "Attributes", + "children": [ + { + "name": "disabled", + "type": "Boolean", + "description": "Defines whether caching is disabled." + }, + { + "name": "max_age", + "type": "Number", + "description": "Defines the maximum duration (in seconds) items persist in the cache." + }, + { + "name": "stale_while_revalidate", + "type": "Number", + "description": "Defines the number of seconds the cache may serve a stale response." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "Defines the creation time of the Hyperdrive configuration." + }, + { + "name": "id", + "type": "String", + "description": "Define configurations using a unique string identifier." + }, + { + "name": "integration", + "type": "Attributes", + "description": "Connects to a PlanetScale database using credentials managed by Cloudflare. The Cloudflare account must already be linked to PlanetScale in the Hyperdrive dashboard.", + "children": [ + { + "name": "custom_database_name", + "type": "String", + "description": "The database name to use when connecting. Defaults to `postgres` for PostgreSQL and `mysql` for MySQL." + }, + { + "name": "database_branch_name", + "type": "String", + "description": "The name of the PlanetScale database branch." + }, + { + "name": "database_name", + "type": "String", + "description": "The name of the PlanetScale database." + }, + { + "name": "hyperdrive_config_provider", + "type": "String", + "description": "The database integration provider used by this operation.\nAvailable values: \"planetscale\"." + }, + { + "name": "organization_name", + "type": "String", + "description": "The name of the PlanetScale organization." + }, + { + "name": "scheme", + "type": "String", + "description": "Specifies the URL scheme used to connect to your origin database.\nAvailable values: \"postgres\", \"postgresql\", \"mysql\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "Defines the last modified time of the Hyperdrive configuration." + }, + { + "name": "mtls", + "type": "Attributes", + "description": "mTLS configuration for the origin connection. Cannot be used with VPC Service origins; TLS must be managed on the VPC Service.", + "children": [ + { + "name": "ca_certificate_id", + "type": "String", + "description": "Define CA certificate ID obtained after uploading CA cert." + }, + { + "name": "mtls_certificate_id", + "type": "String", + "description": "Define mTLS certificate ID obtained after uploading client cert." + }, + { + "name": "sslmode", + "type": "String", + "description": "PostgreSQL accepts `require`, `verify-ca`, and `verify-full`. MySQL accepts `REQUIRED`, `VERIFY_CA`, and `VERIFY_IDENTITY`. The verify modes require a CA certificate; the require modes cannot be used with a CA certificate." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Hyperdrive configuration. Used to identify the configuration in the Cloudflare dashboard and API." + }, + { + "name": "origin", + "type": "Attributes", + "description": "Combines database connection fields with exactly one supported network location.", + "children": [ + { + "name": "access_client_id", + "type": "String", + "description": "Defines the Client ID of the Access token to use when connecting to the origin database." + }, + { + "name": "access_client_secret", + "type": "String", + "description": "Defines the Client Secret of the Access Token to use when connecting to the origin database. The API never returns this write-only value.", + "sensitive": true + }, + { + "name": "database", + "type": "String", + "description": "Set the name of your origin database." + }, + { + "name": "host", + "type": "String", + "description": "Defines the publicly reachable hostname or IP of your origin database. Private, loopback, and link-local IP addresses are not allowed." + }, + { + "name": "password", + "type": "String", + "description": "Set the password needed to access your origin database. The API never returns this write-only value.", + "sensitive": true + }, + { + "name": "port", + "type": "Number", + "description": "Defines the port of your origin database. Defaults to 5432 for PostgreSQL or 3306 for MySQL if not specified." + }, + { + "name": "scheme", + "type": "String", + "description": "Specifies the URL scheme used to connect to your origin database.\nAvailable values: \"postgres\", \"postgresql\", \"mysql\"." + }, + { + "name": "service_id", + "type": "String", + "description": "The identifier of the Workers VPC Service to connect through. Hyperdrive will egress through the specified VPC Service to reach the origin database." + }, + { + "name": "user", + "type": "String", + "description": "Set the user of your origin database." + } + ] + }, + { + "name": "origin_connection_limit", + "type": "Number", + "description": "The (soft) maximum number of connections the Hyperdrive is allowed to make to the origin database.\n\nMaximum allowed: 20 for free tier accounts, 100 for paid tier accounts.\nIf not specified, defaults to 20 for free tier and 60 for paid tier.\nCertain Cloudflare-managed origins may be permitted a higher limit.\nContact Cloudflare if you need a higher limit." + }, + { + "name": "restarted_on", + "type": "String", + "description": "Defines the last time the Hyperdrive connection pool was explicitly restarted via the restart endpoint. Omitted if the pool has never been explicitly restarted." + } + ] + } + ] + }, + "data-source:cloudflare_image": { + "kind": "data-source", + "name": "cloudflare_image", + "description": "Accepted Permissions\n\n- `Images Read`\n- `Images Write`", + "example": "data \"cloudflare_image\" \"example_image\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n image_id = \"image_id\"\n}", + "required": [ + { + "name": "image_id", + "type": "String", + "description": "Image unique identifier." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + } + ], + "computed": [ + { + "name": "creator", + "type": "String", + "description": "Can set the creator field with an internal user ID." + }, + { + "name": "filename", + "type": "String", + "description": "Image file name." + }, + { + "name": "id", + "type": "String", + "description": "Image unique identifier." + }, + { + "name": "meta", + "type": "String", + "description": "User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes." + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the image can be a accessed only using it's UID. If set to true, a signed token needs to be generated with a signing key to view the image." + }, + { + "name": "uploaded", + "type": "String", + "description": "When the media item was uploaded." + }, + { + "name": "variants", + "type": "List of String", + "description": "Object specifying available variants for an image." + } + ] + }, + "resource:cloudflare_image": { + "kind": "resource", + "name": "cloudflare_image", + "description": "Accepted Permissions\n\n- `Images Read`\n- `Images Write`\n\n~> Set either `file` (base64-encoded image data, e.g. from\n [`filebase64`](https://developer.hashicorp.com/terraform/language/functions/filebase64))\n or `url` (fetched server-side), not both.\n\n~> `require_signed_urls = true` is rejected for images with a custom `id` (API\n error 5410). Since `id` is required here, leave it unset or `false`.", + "example": "resource \"cloudflare_image\" \"example_image\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"id\"\n creator = \"creator\"\n file = \"Example data\"\n metadata = jsonencode({})\n require_signed_urls = true\n url = \"https://example.com/path/to/logo.png\"\n}", + "importExample": "$ terraform import cloudflare_image.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "id", + "type": "String", + "description": "An optional custom unique identifier for your image." + } + ], + "optional": [ + { + "name": "creator", + "type": "String", + "description": "Can set the creator field with an internal user ID." + }, + { + "name": "file", + "type": "String", + "description": "An image binary data. Only needed when type is uploading a file." + }, + { + "name": "metadata", + "type": "String", + "description": "User modifiable key-value store. Can use used for keeping references to another system of record for managing images." + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the image requires a signature token for the access." + }, + { + "name": "url", + "type": "String", + "description": "A URL to fetch an image from origin. Only needed when type is uploading from a URL." + } + ], + "computed": [ + { + "name": "filename", + "type": "String", + "description": "Image file name." + }, + { + "name": "meta", + "type": "String", + "description": "User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes." + }, + { + "name": "uploaded", + "type": "String", + "description": "When the media item was uploaded." + }, + { + "name": "variants", + "type": "List of String", + "description": "Object specifying available variants for an image." + } + ] + }, + "data-source:cloudflare_image_variant": { + "kind": "data-source", + "name": "cloudflare_image_variant", + "description": "Accepted Permissions\n\n- `Images Read`\n- `Images Write`", + "example": "data \"cloudflare_image_variant\" \"example_image_variant\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n variant_id = \"hero\"\n}", + "required": [ + { + "name": "variant_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "variant", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "never_require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the variant can access an image without a signature, regardless of image access control." + }, + { + "name": "options", + "type": "Attributes", + "description": "Allows you to define image resizing sizes for different use cases.", + "children": [ + { + "name": "fit", + "type": "String", + "description": "The fit property describes how the width and height dimensions should be interpreted.\nAvailable values: \"scale-down\", \"contain\", \"cover\", \"crop\", \"pad\"." + }, + { + "name": "height", + "type": "Number", + "description": "Maximum height in image pixels." + }, + { + "name": "metadata", + "type": "String", + "description": "What EXIF data should be preserved in the output image.\nAvailable values: \"keep\", \"copyright\", \"none\"." + }, + { + "name": "width", + "type": "Number", + "description": "Maximum width in image pixels." + } + ] + } + ] + } + ] + }, + "resource:cloudflare_image_variant": { + "kind": "resource", + "name": "cloudflare_image_variant", + "description": "Accepted Permissions\n\n- `Images Read`\n- `Images Write`", + "example": "resource \"cloudflare_image_variant\" \"example_image_variant\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"hero\"\n options = {\n fit = \"scale-down\"\n height = 768\n metadata = \"none\"\n width = 1366\n }\n never_require_signed_urls = true\n}", + "importExample": "$ terraform import cloudflare_image_variant.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "options", + "type": "Attributes", + "description": "Allows you to define image resizing sizes for different use cases.", + "children": [ + { + "name": "fit", + "type": "String", + "description": "The fit property describes how the width and height dimensions should be interpreted.\nAvailable values: \"scale-down\", \"contain\", \"cover\", \"crop\", \"pad\"." + }, + { + "name": "height", + "type": "Number", + "description": "Maximum height in image pixels." + }, + { + "name": "metadata", + "type": "String", + "description": "What EXIF data should be preserved in the output image.\nAvailable values: \"keep\", \"copyright\", \"none\"." + }, + { + "name": "width", + "type": "Number", + "description": "Maximum width in image pixels." + } + ] + } + ], + "optional": [ + { + "name": "never_require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the variant can access an image without a signature, regardless of image access control." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "list-data-source:cloudflare_images": { + "kind": "list-data-source", + "name": "cloudflare_images", + "description": "Accepted Permissions\n\n- `Images Read`\n- `Images Write`", + "example": "data \"cloudflare_images\" \"example_images\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n creator = \"creator\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "creator", + "type": "String", + "description": "Internal user ID set within the creator field. Setting to empty string \"\" will return images where creator field is not set" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "images", + "type": "Attributes List", + "children": [ + { + "name": "creator", + "type": "String", + "description": "Can set the creator field with an internal user ID." + }, + { + "name": "filename", + "type": "String", + "description": "Image file name." + }, + { + "name": "id", + "type": "String", + "description": "Image unique identifier." + }, + { + "name": "meta", + "type": "String", + "description": "User modifiable key-value store. Can be used for keeping references to another system of record for managing images. Metadata must not exceed 1024 bytes." + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the image can be a accessed only using it's UID. If set to true, a signed token needs to be generated with a signing key to view the image." + }, + { + "name": "uploaded", + "type": "String", + "description": "When the media item was uploaded." + }, + { + "name": "variants", + "type": "List of String", + "description": "Object specifying available variants for an image." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_ip_ranges": { + "kind": "data-source", + "name": "cloudflare_ip_ranges", + "example": "data \"cloudflare_ip_ranges\" \"example_ip_ranges\" {\n networks = \"networks\"\n}", + "required": [], + "optional": [ + { + "name": "networks", + "type": "String", + "description": "Specified as `jdcloud` to list IPs used by JD Cloud data centers." + } + ], + "computed": [ + { + "name": "etag", + "type": "String", + "description": "A digest of the IP data. Useful for determining if the data has changed." + }, + { + "name": "ipv4_cidrs", + "type": "List of String", + "description": "List of Cloudflare IPv4 CIDR addresses." + }, + { + "name": "ipv6_cidrs", + "type": "List of String", + "description": "List of Cloudflare IPv6 CIDR addresses." + }, + { + "name": "jdcloud_cidrs", + "type": "List of String", + "description": "List IPv4 and IPv6 CIDRs, only populated if `?networks=jdcloud` is used." + } + ] + }, + "data-source:cloudflare_keyless_certificate": { + "kind": "data-source", + "name": "cloudflare_keyless_certificate", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_keyless_certificate\" \"example_keyless_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n keyless_certificate_id = \"4d2844d2ce78891c34d0b6c0535a291e\"\n}", + "required": [ + { + "name": "keyless_certificate_id", + "type": "String", + "description": "Keyless certificate identifier tag." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the Keyless SSL was created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Keyless SSL is on or off." + }, + { + "name": "host", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "id", + "type": "String", + "description": "Keyless certificate identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Keyless SSL was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Available permissions for the Keyless SSL for the current user requesting the item." + }, + { + "name": "port", + "type": "Number", + "description": "The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server." + }, + { + "name": "status", + "type": "String", + "description": "Status of the Keyless SSL.\nAvailable values: \"active\", \"deleted\"." + }, + { + "name": "tunnel", + "type": "Attributes", + "description": "Configuration for using Keyless SSL through a Cloudflare Tunnel.", + "children": [ + { + "name": "private_ip", + "type": "String", + "description": "Private IP of the Key Server Host." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Cloudflare Tunnel Virtual Network ID." + } + ] + } + ] + }, + "resource:cloudflare_keyless_certificate": { + "kind": "resource", + "name": "cloudflare_keyless_certificate", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_keyless_certificate\" \"example_keyless_certificate\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n certificate = </'", + "required": [ + { + "name": "certificate", + "type": "String", + "description": "The zone's SSL certificate or SSL certificate and intermediate(s)." + }, + { + "name": "host", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "bundle_method", + "type": "String", + "description": "A ubiquitous bundle has the highest probability of being verified everywhere, even by clients using outdated or unusual trust stores. An optimal bundle uses the shortest chain and newest intermediates. And the force bundle verifies the chain, but does not otherwise modify it.\nAvailable values: \"ubiquitous\", \"optimal\", \"force\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Keyless SSL is on or off.", + "deprecated": "Deprecated." + }, + { + "name": "name", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "port", + "type": "Number", + "description": "The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server." + }, + { + "name": "tunnel", + "type": "Attributes", + "description": "Configuration for using Keyless SSL through a Cloudflare Tunnel.", + "children": [ + { + "name": "private_ip", + "type": "String", + "description": "Private IP of the Key Server Host." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Cloudflare Tunnel Virtual Network ID." + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the Keyless SSL was created." + }, + { + "name": "id", + "type": "String", + "description": "Keyless certificate identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Keyless SSL was last modified." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Available permissions for the Keyless SSL for the current user requesting the item." + }, + { + "name": "status", + "type": "String", + "description": "Status of the Keyless SSL.\nAvailable values: \"active\", \"deleted\"." + } + ] + }, + "list-data-source:cloudflare_keyless_certificates": { + "kind": "list-data-source", + "name": "cloudflare_keyless_certificates", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_keyless_certificates\" \"example_keyless_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "When the Keyless SSL was created." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Keyless SSL is on or off." + }, + { + "name": "host", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "id", + "type": "String", + "description": "Keyless certificate identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Keyless SSL was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The keyless SSL name." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Available permissions for the Keyless SSL for the current user requesting the item." + }, + { + "name": "port", + "type": "Number", + "description": "The keyless SSL port used to communicate between Cloudflare and the client's Keyless SSL server." + }, + { + "name": "status", + "type": "String", + "description": "Status of the Keyless SSL.\nAvailable values: \"active\", \"deleted\"." + }, + { + "name": "tunnel", + "type": "Attributes", + "description": "Configuration for using Keyless SSL through a Cloudflare Tunnel.", + "children": [ + { + "name": "private_ip", + "type": "String", + "description": "Private IP of the Key Server Host." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Cloudflare Tunnel Virtual Network ID." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_leaked_credential_check": { + "kind": "data-source", + "name": "cloudflare_leaked_credential_check", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "data \"cloudflare_leaked_credential_check\" \"example_leaked_credential_check\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether or not Leaked Credential Checks are enabled." + } + ] + }, + "resource:cloudflare_leaked_credential_check": { + "kind": "resource", + "name": "cloudflare_leaked_credential_check", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "resource \"cloudflare_leaked_credential_check\" \"example_leaked_credential_check\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}", + "importExample": "$ terraform import cloudflare_leaked_credential_check.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether or not Leaked Credential Checks are enabled." + } + ], + "computed": [] + }, + "data-source:cloudflare_leaked_credential_check_rule": { + "kind": "data-source", + "name": "cloudflare_leaked_credential_check_rule", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "data \"cloudflare_leaked_credential_check_rule\" \"example_leaked_credential_check_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n detection_id = \"18a14bafaa8eb1df04ce683ec18c765e\"\n}", + "required": [ + { + "name": "detection_id", + "type": "String", + "description": "Defines the unique ID for this custom detection." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Defines the unique ID for this custom detection." + }, + { + "name": "password", + "type": "String", + "description": "Defines ehe ruleset expression to use in matching the password in a request." + }, + { + "name": "username", + "type": "String", + "description": "Defines the ruleset expression to use in matching the username in a request." + } + ] + }, + "resource:cloudflare_leaked_credential_check_rule": { + "kind": "resource", + "name": "cloudflare_leaked_credential_check_rule", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "resource \"cloudflare_leaked_credential_check_rule\" \"example_leaked_credential_check_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n password = \"lookup_json_string(http.request.body.raw, \\\"secret\\\")\"\n username = \"lookup_json_string(http.request.body.raw, \\\"user\\\")\"\n}", + "importExample": "$ terraform import cloudflare_leaked_credential_check_rule.example '/'", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [ + { + "name": "password", + "type": "String", + "description": "Defines ehe ruleset expression to use in matching the password in a request." + }, + { + "name": "username", + "type": "String", + "description": "Defines the ruleset expression to use in matching the username in a request." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Defines the unique ID for this custom detection." + } + ] + }, + "list-data-source:cloudflare_leaked_credential_check_rules": { + "kind": "list-data-source", + "name": "cloudflare_leaked_credential_check_rules", + "description": "Accepted Permissions\n\n- `Account WAF Read`\n- `Account WAF Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "data \"cloudflare_leaked_credential_check_rules\" \"example_leaked_credential_check_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "Defines the unique ID for this custom detection." + }, + { + "name": "password", + "type": "String", + "description": "Defines ehe ruleset expression to use in matching the password in a request." + }, + { + "name": "username", + "type": "String", + "description": "Defines the ruleset expression to use in matching the username in a request." + } + ] + } + ] + }, + "data-source:cloudflare_list": { + "kind": "data-source", + "name": "cloudflare_list", + "description": "Accepted Permissions\n\n- `Account Filter Lists Read`", + "example": "data \"cloudflare_list\" \"example_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n}", + "required": [ + { + "name": "list_id", + "type": "String", + "description": "The unique ID of the list." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID for this resource." + }, + { + "name": "search", + "type": "String", + "description": "A search query to filter returned items. Its meaning depends on the list type: IP addresses must start with the provided string, hostnames and bulk redirects must contain the string, and ASNs must match the string exactly." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was created." + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the list." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the list." + }, + { + "name": "items", + "type": "Attributes Set", + "description": "The items in the list. If set, this overwrites all items in the list. Do not use with `cloudflare_list_item`.", + "children": [ + { + "name": "asn", + "type": "Number", + "description": "A non-negative 32 bit integer" + }, + { + "name": "comment", + "type": "String", + "description": "An informative summary of the list item." + }, + { + "name": "hostname", + "type": "Attributes", + "description": "Valid characters for hostnames are ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).", + "children": [ + { + "name": "exclude_exact_hostname", + "type": "Boolean", + "description": "Only applies to wildcard hostnames (e.g., *.example.com). When true (default), only subdomains are blocked. When false, both the root domain and subdomains are blocked." + }, + { + "name": "url_hostname", + "type": "String" + } + ] + }, + { + "name": "ip", + "type": "String", + "description": "An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR." + }, + { + "name": "redirect", + "type": "Attributes", + "description": "The definition of the redirect.", + "children": [ + { + "name": "include_subdomains", + "type": "Boolean" + }, + { + "name": "preserve_path_suffix", + "type": "Boolean" + }, + { + "name": "preserve_query_string", + "type": "Boolean" + }, + { + "name": "source_url", + "type": "String" + }, + { + "name": "status_code", + "type": "Number", + "description": "Available values: 301, 302, 307, 308." + }, + { + "name": "subpath_matching", + "type": "Boolean" + }, + { + "name": "target_url", + "type": "String" + } + ] + } + ] + }, + { + "name": "kind", + "type": "String", + "description": "The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects).\nAvailable values: \"ip\", \"redirect\", \"hostname\", \"asn\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was last modified." + }, + { + "name": "name", + "type": "String", + "description": "An informative name for the list. Use this name in filter and rule expressions." + }, + { + "name": "num_items", + "type": "Number", + "description": "The number of items in the list." + }, + { + "name": "num_referencing_filters", + "type": "Number", + "description": "The number of [filters](/api/resources/filters/) referencing the list." + } + ] + }, + "resource:cloudflare_list": { + "kind": "resource", + "name": "cloudflare_list", + "description": "Accepted Permissions\n\n- `Account Filter Lists Edit`\n- `Account Filter Lists Read`\n\n~> The `cloudflare_list` resource supports defining list items in line with the\n `items` attribute. The provider also has a `cloudflare_list_item` resource for\n managing items as independent resources. Using both in line `items` definitions\n _and_ `cloudflare_list_items` on the same list is not supported and will cause\n Terraform into an irreconcilable state.", + "example": "resource \"cloudflare_list\" \"example_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"ip\"\n name = \"list1\"\n description = \"This is a note\"\n\n items = [\n {\n ip = \"1.1.1.1\"\n },\n {\n ip = \"1.1.1.2\"\n },\n {\n ip = \"1.1.1.3\"\n }\n ]\n}", + "importExample": "$ terraform import cloudflare_list.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID for this resource." + }, + { + "name": "kind", + "type": "String", + "description": "The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects).\nAvailable values: \"ip\", \"redirect\", \"hostname\", \"asn\"." + }, + { + "name": "name", + "type": "String", + "description": "An informative name for the list. Use this name in filter and rule expressions." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the list." + }, + { + "name": "items", + "type": "Attributes Set", + "description": "The items in the list. If set, this overwrites all items in the list. Do not use with `cloudflare_list_item`.", + "children": [ + { + "name": "asn", + "type": "Number", + "description": "A non-negative 32 bit integer" + }, + { + "name": "comment", + "type": "String", + "description": "An informative summary of the list item." + }, + { + "name": "hostname", + "type": "Attributes", + "description": "Valid characters for hostnames are ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).", + "children": [ + { + "name": "exclude_exact_hostname", + "type": "Boolean", + "description": "Only applies to wildcard hostnames (e.g., *.example.com). When true (default), only subdomains are blocked. When false, both the root domain and subdomains are blocked." + }, + { + "name": "url_hostname", + "type": "String" + } + ] + }, + { + "name": "ip", + "type": "String", + "description": "An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR." + }, + { + "name": "redirect", + "type": "Attributes", + "description": "The definition of the redirect.", + "children": [ + { + "name": "include_subdomains", + "type": "Boolean" + }, + { + "name": "preserve_path_suffix", + "type": "Boolean" + }, + { + "name": "preserve_query_string", + "type": "Boolean" + }, + { + "name": "source_url", + "type": "String" + }, + { + "name": "status_code", + "type": "Number", + "description": "Available values: 301, 302, 307, 308." + }, + { + "name": "subpath_matching", + "type": "Boolean" + }, + { + "name": "target_url", + "type": "String" + } + ] + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was created." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the list." + }, + { + "name": "modified_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was last modified." + }, + { + "name": "num_items", + "type": "Number", + "description": "The number of items in the list." + }, + { + "name": "num_referencing_filters", + "type": "Number", + "description": "The number of [filters](/api/resources/filters/) referencing the list." + } + ] + }, + "data-source:cloudflare_list_item": { + "kind": "data-source", + "name": "cloudflare_list_item", + "description": "Accepted Permissions\n\n- `Account Filter Lists Edit`\n- `Account Filter Lists Read`", + "example": "data \"cloudflare_list_item\" \"example_list_item\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n item_id = \"34b12448945f11eaa1b71c4d701ab86e\"\n}", + "required": [ + { + "name": "item_id", + "type": "String", + "description": "Defines the unique ID of the item in the List." + }, + { + "name": "list_id", + "type": "String", + "description": "The unique ID of the list." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID for this resource." + } + ], + "computed": [ + { + "name": "asn", + "type": "Number", + "description": "Defines a non-negative 32 bit integer." + }, + { + "name": "comment", + "type": "String", + "description": "Defines an informative summary of the list item." + }, + { + "name": "created_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was created." + }, + { + "name": "hostname", + "type": "Attributes", + "description": "Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).", + "children": [ + { + "name": "exclude_exact_hostname", + "type": "Boolean", + "description": "Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains." + }, + { + "name": "url_hostname", + "type": "String" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Defines the unique ID of the item in the List." + }, + { + "name": "ip", + "type": "String", + "description": "An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR." + }, + { + "name": "modified_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was last modified." + }, + { + "name": "redirect", + "type": "Attributes", + "description": "The definition of the redirect.", + "children": [ + { + "name": "include_subdomains", + "type": "Boolean" + }, + { + "name": "preserve_path_suffix", + "type": "Boolean" + }, + { + "name": "preserve_query_string", + "type": "Boolean" + }, + { + "name": "source_url", + "type": "String" + }, + { + "name": "status_code", + "type": "Number", + "description": "Available values: 301, 302, 307, 308." + }, + { + "name": "subpath_matching", + "type": "Boolean" + }, + { + "name": "target_url", + "type": "String" + } + ] + } + ] + }, + "resource:cloudflare_list_item": { + "kind": "resource", + "name": "cloudflare_list_item", + "description": "Accepted Permissions\n\n- `Account Filter Lists Edit`\n- `Account Filter Lists Read`", + "example": "resource \"cloudflare_list_item\" \"example_list_item\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n ip = \"10.0.0.1\"\n}", + "importExample": "$ terraform import cloudflare_list_item.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID for this resource." + }, + { + "name": "list_id", + "type": "String", + "description": "The unique ID of the list." + } + ], + "optional": [ + { + "name": "asn", + "type": "Number", + "description": "A non-negative 32 bit integer" + }, + { + "name": "comment", + "type": "String", + "description": "An informative summary of the list item." + }, + { + "name": "hostname", + "type": "Attributes", + "description": "Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).", + "children": [ + { + "name": "exclude_exact_hostname", + "type": "Boolean", + "description": "Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains." + }, + { + "name": "url_hostname", + "type": "String" + } + ] + }, + { + "name": "ip", + "type": "String", + "description": "An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR." + }, + { + "name": "redirect", + "type": "Attributes", + "description": "The definition of the redirect.", + "children": [ + { + "name": "include_subdomains", + "type": "Boolean" + }, + { + "name": "preserve_path_suffix", + "type": "Boolean" + }, + { + "name": "preserve_query_string", + "type": "Boolean" + }, + { + "name": "source_url", + "type": "String" + }, + { + "name": "status_code", + "type": "Number", + "description": "Available values: 301, 302, 307, 308." + }, + { + "name": "subpath_matching", + "type": "Boolean" + }, + { + "name": "target_url", + "type": "String" + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the item was created." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the item in the List." + }, + { + "name": "modified_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the item was last modified." + }, + { + "name": "operation_id", + "type": "String", + "description": "The unique operation ID of the asynchronous action." + } + ] + }, + "list-data-source:cloudflare_list_items": { + "kind": "list-data-source", + "name": "cloudflare_list_items", + "description": "Accepted Permissions\n\n- `Account Filter Lists Edit`\n- `Account Filter Lists Read`", + "example": "data \"cloudflare_list_items\" \"example_list_items\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n list_id = \"2c0fc9fa937b11eaa1b71c4d701ab86e\"\n per_page = 1\n search = \"1.1.1.\"\n}", + "required": [ + { + "name": "list_id", + "type": "String", + "description": "The unique ID of the list." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID for this resource." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "per_page", + "type": "Number", + "description": "Amount of results to include in each paginated response. A non-negative 32 bit integer." + }, + { + "name": "search", + "type": "String", + "description": "A search query to filter returned items. Its meaning depends on the list type: IP addresses must start with the provided string, hostnames and bulk redirects must contain the string, and ASNs must match the string exactly." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "asn", + "type": "Number", + "description": "Defines a non-negative 32 bit integer." + }, + { + "name": "comment", + "type": "String", + "description": "Defines\tan informative summary of the list item." + }, + { + "name": "created_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the item was created." + }, + { + "name": "hostname", + "type": "Attributes", + "description": "Hostnames support ASCII(7) letters from a to z, the digits from 0 to 9, wildcards (*), and the hyphen (-).", + "children": [ + { + "name": "exclude_exact_hostname", + "type": "Boolean", + "description": "Only applies to wildcard hostnames (e.g., *.example.com). When true (default), the rule blocks only subdomains. When false, the rule blocks both the root domain and subdomains." + }, + { + "name": "url_hostname", + "type": "String" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Defines the unique ID of the item in the List." + }, + { + "name": "ip", + "type": "String", + "description": "An IPv4 address, an IPv4 CIDR, an IPv6 address, or an IPv6 CIDR." + }, + { + "name": "modified_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the item was last modified." + }, + { + "name": "redirect", + "type": "Attributes", + "description": "The definition of the redirect.", + "children": [ + { + "name": "include_subdomains", + "type": "Boolean" + }, + { + "name": "preserve_path_suffix", + "type": "Boolean" + }, + { + "name": "preserve_query_string", + "type": "Boolean" + }, + { + "name": "source_url", + "type": "String" + }, + { + "name": "status_code", + "type": "Number", + "description": "Available values: 301, 302, 307, 308." + }, + { + "name": "subpath_matching", + "type": "Boolean" + }, + { + "name": "target_url", + "type": "String" + } + ] + } + ] + } + ] + }, + "list-data-source:cloudflare_lists": { + "kind": "list-data-source", + "name": "cloudflare_lists", + "description": "Accepted Permissions\n\n- `Account Filter Lists Edit`\n- `Account Filter Lists Read`", + "example": "data \"cloudflare_lists\" \"example_lists\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID for this resource." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was created." + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the list." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the list." + }, + { + "name": "kind", + "type": "String", + "description": "The type of the list. Each type supports specific list items (IP addresses, ASNs, hostnames or redirects).\nAvailable values: \"ip\", \"redirect\", \"hostname\", \"asn\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "The RFC 3339 timestamp of when the list was last modified." + }, + { + "name": "name", + "type": "String", + "description": "An informative name for the list. Use this name in filter and rule expressions." + }, + { + "name": "num_items", + "type": "Number", + "description": "The number of items in the list." + }, + { + "name": "num_referencing_filters", + "type": "Number", + "description": "The number of [filters](/api/resources/filters/) referencing the list." + } + ] + } + ] + }, + "data-source:cloudflare_load_balancer": { + "kind": "data-source", + "name": "cloudflare_load_balancer", + "description": "Accepted Permissions\n\n- `Load Balancers Read`\n- `Load Balancers Write`", + "example": "data \"cloudflare_load_balancer\" \"example_load_balancer\" {\n load_balancer_id = \"699d98642c564d2e855e9661899b7252\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "load_balancer_id", + "type": "String" + } + ], + "optional": [ + { + "name": "pop_pools", + "type": "Map of List of String", + "description": "Enterprise only: A mapping of Cloudflare PoP identifiers to a list of pool IDs (ordered by their failover priority) for the PoP (datacenter). Any PoPs not explicitly defined will fall back to using the corresponding country_pool, then region_pool mapping if it exists else to default_pools." + }, + { + "name": "region_pools", + "type": "Map of List of String", + "description": "A mapping of region codes to a list of pool IDs (ordered by their failover priority) for the given region. Any regions not explicitly defined will fall back to using default_pools." + }, + { + "name": "zone_id", + "type": "String" + } + ], + "computed": [ + { + "name": "adaptive_routing", + "type": "Attributes", + "description": "Controls features that modify the routing of requests to pools and origins in response to dynamic conditions, such as during the interval between active health monitoring requests. For example, zero-downtime failover occurs immediately when an origin becomes unavailable due to HTTP 521, 522, or 523 response codes. If there is another healthy origin in the same pool, the request is retried once against this alternate origin.", + "children": [ + { + "name": "failover_across_pools", + "type": "Boolean", + "description": "Extends zero-downtime failover of requests to healthy origins from alternate pools, when no healthy alternate exists in the same pool, according to the failover order defined by traffic and origin steering. When set false (the default) zero-downtime failover will only occur between origins within the same pool. See `session_affinity_attributes` for control over when sessions are broken or reassigned." + } + ] + }, + { + "name": "country_pools", + "type": "Map of List of String", + "description": "A mapping of country codes to a list of pool IDs (ordered by their failover priority) for the given country. Any country not explicitly defined will fall back to using the corresponding region_pool mapping if it exists else to default_pools." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "default_pools", + "type": "List of String", + "description": "A list of pool IDs ordered by their failover priority. Pools defined here are used by default, or when region_pools are not configured for a given region." + }, + { + "name": "description", + "type": "String", + "description": "Object description." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) this load balancer." + }, + { + "name": "fallback_pool", + "type": "String", + "description": "The pool ID to use when all other pools are detected as unhealthy." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "location_strategy", + "type": "Attributes", + "description": "Controls location-based steering for non-proxied requests. See `steering_policy` to learn how steering is affected.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Determines the authoritative location when ECS is not preferred, does not exist in the request, or its GeoIP lookup is unsuccessful.\n- `\"pop\"`: Use the Cloudflare PoP location.\n- `\"resolver_ip\"`: Use the DNS resolver GeoIP location. If the GeoIP lookup is unsuccessful, use the Cloudflare PoP location.\nAvailable values: \"pop\", \"resolver_ip\"." + }, + { + "name": "prefer_ecs", + "type": "String", + "description": "Whether the EDNS Client Subnet (ECS) GeoIP should be preferred as the authoritative location.\n- `\"always\"`: Always prefer ECS.\n- `\"never\"`: Never prefer ECS.\n- `\"proximity\"`: Prefer ECS only when `steering_policy=\"proximity\"`.\n- `\"geo\"`: Prefer ECS only when `steering_policy=\"geo\"`.\nAvailable values: \"always\", \"never\", \"proximity\", \"geo\"." + } + ] + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The DNS hostname to associate with your Load Balancer. If this hostname already exists as a DNS record in Cloudflare's DNS, the Load Balancer will take precedence and the DNS record will not be used." + }, + { + "name": "networks", + "type": "List of String", + "description": "List of networks where Load Balancer or Pool is enabled." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the hostname should be gray clouded (false) or orange clouded (true)." + }, + { + "name": "random_steering", + "type": "Attributes", + "description": "Configures pool weights.\n- `steering_policy=\"random\"`: A random pool is selected with probability proportional to pool weights.\n- `steering_policy=\"least_outstanding_requests\"`: Use pool weights to scale each pool's outstanding requests.\n- `steering_policy=\"least_connections\"`: Use pool weights to scale each pool's open connections.", + "children": [ + { + "name": "default_weight", + "type": "Number", + "description": "The default weight for pools in the load balancer that are not specified in the pool_weights map." + }, + { + "name": "pool_weights", + "type": "Map of Number", + "description": "A mapping of pool IDs to custom weights. The weight is relative to other pools in the load balancer." + } + ] + }, + { + "name": "rules", + "type": "Attributes List", + "description": "BETA Field Not General Access: A list of rules for this load balancer to execute.", + "children": [ + { + "name": "condition", + "type": "String", + "description": "The condition expressions to evaluate. If the condition evaluates to true, the overrides or fixed_response in this rule will be applied. An empty condition is always true. For more details on condition expressions, please see https://developers.cloudflare.com/load-balancing/understand-basics/load-balancing-rules/expressions." + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable this specific rule. It will no longer be evaluated by this load balancer." + }, + { + "name": "fixed_response", + "type": "Attributes", + "description": "A collection of fields used to directly respond to the eyeball instead of routing to a pool. If a fixed_response is supplied the rule will be marked as terminates.", + "children": [ + { + "name": "content_type", + "type": "String", + "description": "The http 'Content-Type' header to include in the response." + }, + { + "name": "location", + "type": "String", + "description": "The http 'Location' header to include in the response." + }, + { + "name": "message_body", + "type": "String", + "description": "Text to include as the http body." + }, + { + "name": "status_code", + "type": "Number", + "description": "The http status code to respond with." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of this rule. Only used for human readability." + }, + { + "name": "overrides", + "type": "Attributes", + "description": "A collection of overrides to apply to the load balancer when this rule's condition is true. All fields are optional.", + "children": [ + { + "name": "adaptive_routing", + "type": "Attributes", + "description": "Controls features that modify the routing of requests to pools and origins in response to dynamic conditions, such as during the interval between active health monitoring requests. For example, zero-downtime failover occurs immediately when an origin becomes unavailable due to HTTP 521, 522, or 523 response codes. If there is another healthy origin in the same pool, the request is retried once against this alternate origin.", + "children": [ + { + "name": "failover_across_pools", + "type": "Boolean", + "description": "Extends zero-downtime failover of requests to healthy origins from alternate pools, when no healthy alternate exists in the same pool, according to the failover order defined by traffic and origin steering. When set false (the default) zero-downtime failover will only occur between origins within the same pool. See `session_affinity_attributes` for control over when sessions are broken or reassigned." + } + ] + }, + { + "name": "country_pools", + "type": "Map of List of String", + "description": "A mapping of country codes to a list of pool IDs (ordered by their failover priority) for the given country. Any country not explicitly defined will fall back to using the corresponding region_pool mapping if it exists else to default_pools." + }, + { + "name": "default_pools", + "type": "List of String", + "description": "A list of pool IDs ordered by their failover priority. Pools defined here are used by default, or when region_pools are not configured for a given region." + }, + { + "name": "fallback_pool", + "type": "String", + "description": "The pool ID to use when all other pools are detected as unhealthy." + }, + { + "name": "location_strategy", + "type": "Attributes", + "description": "Controls location-based steering for non-proxied requests. See `steering_policy` to learn how steering is affected.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Determines the authoritative location when ECS is not preferred, does not exist in the request, or its GeoIP lookup is unsuccessful.\n- `\"pop\"`: Use the Cloudflare PoP location.\n- `\"resolver_ip\"`: Use the DNS resolver GeoIP location. If the GeoIP lookup is unsuccessful, use the Cloudflare PoP location.\nAvailable values: \"pop\", \"resolver_ip\"." + }, + { + "name": "prefer_ecs", + "type": "String", + "description": "Whether the EDNS Client Subnet (ECS) GeoIP should be preferred as the authoritative location.\n- `\"always\"`: Always prefer ECS.\n- `\"never\"`: Never prefer ECS.\n- `\"proximity\"`: Prefer ECS only when `steering_policy=\"proximity\"`.\n- `\"geo\"`: Prefer ECS only when `steering_policy=\"geo\"`.\nAvailable values: \"always\", \"never\", \"proximity\", \"geo\"." + } + ] + }, + { + "name": "pop_pools", + "type": "Map of List of String", + "description": "Enterprise only: A mapping of Cloudflare PoP identifiers to a list of pool IDs (ordered by their failover priority) for the PoP (datacenter). Any PoPs not explicitly defined will fall back to using the corresponding country_pool, then region_pool mapping if it exists else to default_pools." + }, + { + "name": "random_steering", + "type": "Attributes", + "description": "Configures pool weights.\n- `steering_policy=\"random\"`: A random pool is selected with probability proportional to pool weights.\n- `steering_policy=\"least_outstanding_requests\"`: Use pool weights to scale each pool's outstanding requests.\n- `steering_policy=\"least_connections\"`: Use pool weights to scale each pool's open connections.", + "children": [ + { + "name": "default_weight", + "type": "Number", + "description": "The default weight for pools in the load balancer that are not specified in the pool_weights map." + }, + { + "name": "pool_weights", + "type": "Map of Number", + "description": "A mapping of pool IDs to custom weights. The weight is relative to other pools in the load balancer." + } + ] + }, + { + "name": "region_pools", + "type": "Map of List of String", + "description": "A mapping of region codes to a list of pool IDs (ordered by their failover priority) for the given region. Any regions not explicitly defined will fall back to using default_pools." + }, + { + "name": "session_affinity", + "type": "String", + "description": "Specifies the type of session affinity the load balancer should use unless specified as `\"none\"`. The supported types are: - `\"cookie\"`: On the first request to a proxied load balancer, a cookie is generated, encoding information of which origin the request will be forwarded to. Subsequent requests, by the same client to the same load balancer, will be sent to the origin server the cookie encodes, for the duration of the cookie and as long as the origin server remains healthy. If the cookie has expired or the origin server is unhealthy, then a new origin server is calculated and used. - `\"ip_cookie\"`: Behaves the same as `\"cookie\"` except the initial origin selection is stable and based on the client's ip address. - `\"header\"`: On the first request to a proxied load balancer, a session key based on the configured HTTP headers (see `session_affinity_attributes.headers`) is generated, encoding the request headers used for storing in the load balancer session state which origin the request will be forwarded to. Subsequent requests to the load balancer with the same headers will be sent to the same origin server, for the duration of the session and as long as the origin server remains healthy. If the session has been idle for the duration of `session_affinity_ttl` seconds or the origin server is unhealthy, then a new origin server is calculated and used. See `headers` in `session_affinity_attributes` for additional required configuration.\nAvailable values: \"none\", \"cookie\", \"ip_cookie\", \"header\"." + }, + { + "name": "session_affinity_attributes", + "type": "Attributes", + "description": "Configures attributes for session affinity.", + "children": [ + { + "name": "drain_duration", + "type": "Number", + "description": "Configures the drain duration in seconds. This field is only used when session affinity is enabled on the load balancer." + }, + { + "name": "headers", + "type": "List of String", + "description": "Configures the names of HTTP headers to base session affinity on when header `session_affinity` is enabled. At least one HTTP header name must be provided. To specify the exact cookies to be used, include an item in the following format: `\"cookie:,\"` (example) where everything after the colon is a comma-separated list of cookie names. Providing only `\"cookie\"` will result in all cookies being used. The default max number of HTTP header names that can be provided depends on your plan: 5 for Enterprise, 1 for all other plans." + }, + { + "name": "require_all_headers", + "type": "Boolean", + "description": "When header `session_affinity` is enabled, this option can be used to specify how HTTP headers on load balancing requests will be used. The supported values are: - `\"true\"`: Load balancing requests must contain *all* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created. - `\"false\"`: Load balancing requests must contain *at least one* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created." + }, + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on session affinity cookie. Value \"Auto\" will be translated to \"Lax\" or \"None\" depending if Always Use HTTPS is enabled. Note: when using value \"None\", the secure attribute can not be set to \"Never\".\nAvailable values: \"Auto\", \"Lax\", \"None\", \"Strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on session affinity cookie. Value \"Always\" indicates the Secure attribute will be set in the Set-Cookie header, \"Never\" indicates the Secure attribute will not be set, and \"Auto\" will set the Secure attribute depending if Always Use HTTPS is enabled.\nAvailable values: \"Auto\", \"Always\", \"Never\"." + }, + { + "name": "zero_downtime_failover", + "type": "String", + "description": "Configures the zero-downtime failover between origins within a pool when session affinity is enabled. This feature is currently incompatible with Argo, Tiered Cache, and Bandwidth Alliance. The supported values are: - `\"none\"`: No failover takes place for sessions pinned to the origin (default). - `\"temporary\"`: Traffic will be sent to another other healthy origin until the originally pinned origin is available; note that this can potentially result in heavy origin flapping. - `\"sticky\"`: The session affinity cookie is updated and subsequent requests are sent to the new origin. Note: Zero-downtime failover with sticky sessions is currently not supported for session affinity by header.\nAvailable values: \"none\", \"temporary\", \"sticky\"." + } + ] + }, + { + "name": "session_affinity_ttl", + "type": "Number", + "description": "Time, in seconds, until a client's session expires after being created. Once the expiry time has been reached, subsequent requests may get sent to a different origin server. The accepted ranges per `session_affinity` policy are: - `\"cookie\"` / `\"ip_cookie\"`: The current default of 23 hours will be used unless explicitly set. The accepted range of values is between [1800, 604800]. - `\"header\"`: The current default of 1800 seconds will be used unless explicitly set. The accepted range of values is between [30, 3600]. Note: With session affinity by header, sessions only expire after they haven't been used for the number of seconds specified." + }, + { + "name": "steering_policy", + "type": "String", + "description": "Steering Policy for this load balancer.\n- `\"off\"`: Use `default_pools`.\n- `\"geo\"`: Use `region_pools`/`country_pools`/`pop_pools`. For non-proxied requests, the country for `country_pools` is determined by `location_strategy`.\n- `\"random\"`: Select a pool randomly.\n- `\"dynamic_latency\"`: Use round trip time to select the closest pool in default_pools (requires pool health checks).\n- `\"proximity\"`: Use the pools' latitude and longitude to select the closest pool using the Cloudflare PoP location for proxied requests or the location determined by `location_strategy` for non-proxied requests.\n- `\"least_outstanding_requests\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of outstanding requests. Pools with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of open connections. Pools with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\n- `\"\"`: Will map to `\"geo\"` if you use `region_pools`/`country_pools`/`pop_pools` otherwise `\"off\"`.\nAvailable values: \"off\", \"geo\", \"random\", \"dynamic_latency\", \"proximity\", \"least_outstanding_requests\", \"least_connections\", \"\"." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time to live (TTL) of the DNS entry for the IP address returned by this load balancer. This only applies to gray-clouded (unproxied) load balancers." + } + ] + }, + { + "name": "priority", + "type": "Number", + "description": "The order in which rules should be executed in relation to each other. Lower values are executed first. Values do not need to be sequential. If no value is provided for any rule the array order of the rules field will be used to assign a priority." + }, + { + "name": "terminates", + "type": "Boolean", + "description": "If this rule's condition is true, this causes rule evaluation to stop after processing this rule." + } + ] + }, + { + "name": "session_affinity", + "type": "String", + "description": "Specifies the type of session affinity the load balancer should use unless specified as `\"none\"`. The supported types are: - `\"cookie\"`: On the first request to a proxied load balancer, a cookie is generated, encoding information of which origin the request will be forwarded to. Subsequent requests, by the same client to the same load balancer, will be sent to the origin server the cookie encodes, for the duration of the cookie and as long as the origin server remains healthy. If the cookie has expired or the origin server is unhealthy, then a new origin server is calculated and used. - `\"ip_cookie\"`: Behaves the same as `\"cookie\"` except the initial origin selection is stable and based on the client's ip address. - `\"header\"`: On the first request to a proxied load balancer, a session key based on the configured HTTP headers (see `session_affinity_attributes.headers`) is generated, encoding the request headers used for storing in the load balancer session state which origin the request will be forwarded to. Subsequent requests to the load balancer with the same headers will be sent to the same origin server, for the duration of the session and as long as the origin server remains healthy. If the session has been idle for the duration of `session_affinity_ttl` seconds or the origin server is unhealthy, then a new origin server is calculated and used. See `headers` in `session_affinity_attributes` for additional required configuration.\nAvailable values: \"none\", \"cookie\", \"ip_cookie\", \"header\"." + }, + { + "name": "session_affinity_attributes", + "type": "Attributes", + "description": "Configures attributes for session affinity.", + "children": [ + { + "name": "drain_duration", + "type": "Number", + "description": "Configures the drain duration in seconds. This field is only used when session affinity is enabled on the load balancer." + }, + { + "name": "headers", + "type": "List of String", + "description": "Configures the names of HTTP headers to base session affinity on when header `session_affinity` is enabled. At least one HTTP header name must be provided. To specify the exact cookies to be used, include an item in the following format: `\"cookie:,\"` (example) where everything after the colon is a comma-separated list of cookie names. Providing only `\"cookie\"` will result in all cookies being used. The default max number of HTTP header names that can be provided depends on your plan: 5 for Enterprise, 1 for all other plans." + }, + { + "name": "require_all_headers", + "type": "Boolean", + "description": "When header `session_affinity` is enabled, this option can be used to specify how HTTP headers on load balancing requests will be used. The supported values are: - `\"true\"`: Load balancing requests must contain *all* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created. - `\"false\"`: Load balancing requests must contain *at least one* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created." + }, + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on session affinity cookie. Value \"Auto\" will be translated to \"Lax\" or \"None\" depending if Always Use HTTPS is enabled. Note: when using value \"None\", the secure attribute can not be set to \"Never\".\nAvailable values: \"Auto\", \"Lax\", \"None\", \"Strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on session affinity cookie. Value \"Always\" indicates the Secure attribute will be set in the Set-Cookie header, \"Never\" indicates the Secure attribute will not be set, and \"Auto\" will set the Secure attribute depending if Always Use HTTPS is enabled.\nAvailable values: \"Auto\", \"Always\", \"Never\"." + }, + { + "name": "zero_downtime_failover", + "type": "String", + "description": "Configures the zero-downtime failover between origins within a pool when session affinity is enabled. This feature is currently incompatible with Argo, Tiered Cache, and Bandwidth Alliance. The supported values are: - `\"none\"`: No failover takes place for sessions pinned to the origin (default). - `\"temporary\"`: Traffic will be sent to another other healthy origin until the originally pinned origin is available; note that this can potentially result in heavy origin flapping. - `\"sticky\"`: The session affinity cookie is updated and subsequent requests are sent to the new origin. Note: Zero-downtime failover with sticky sessions is currently not supported for session affinity by header.\nAvailable values: \"none\", \"temporary\", \"sticky\"." + } + ] + }, + { + "name": "session_affinity_ttl", + "type": "Number", + "description": "Time, in seconds, until a client's session expires after being created. Once the expiry time has been reached, subsequent requests may get sent to a different origin server. The accepted ranges per `session_affinity` policy are: - `\"cookie\"` / `\"ip_cookie\"`: The current default of 23 hours will be used unless explicitly set. The accepted range of values is between [1800, 604800]. - `\"header\"`: The current default of 1800 seconds will be used unless explicitly set. The accepted range of values is between [30, 3600]. Note: With session affinity by header, sessions only expire after they haven't been used for the number of seconds specified." + }, + { + "name": "steering_policy", + "type": "String", + "description": "Steering Policy for this load balancer.\n- `\"off\"`: Use `default_pools`.\n- `\"geo\"`: Use `region_pools`/`country_pools`/`pop_pools`. For non-proxied requests, the country for `country_pools` is determined by `location_strategy`.\n- `\"random\"`: Select a pool randomly.\n- `\"dynamic_latency\"`: Use round trip time to select the closest pool in default_pools (requires pool health checks).\n- `\"proximity\"`: Use the pools' latitude and longitude to select the closest pool using the Cloudflare PoP location for proxied requests or the location determined by `location_strategy` for non-proxied requests.\n- `\"least_outstanding_requests\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of outstanding requests. Pools with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of open connections. Pools with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\n- `\"\"`: Will map to `\"geo\"` if you use `region_pools`/`country_pools`/`pop_pools` otherwise `\"off\"`.\nAvailable values: \"off\", \"geo\", \"random\", \"dynamic_latency\", \"proximity\", \"least_outstanding_requests\", \"least_connections\", \"\"." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time to live (TTL) of the DNS entry for the IP address returned by this load balancer. This only applies to gray-clouded (unproxied) load balancers." + } + ] + }, + "resource:cloudflare_load_balancer": { + "kind": "resource", + "name": "cloudflare_load_balancer", + "description": "Accepted Permissions\n\n- `Load Balancers Read`\n- `Load Balancers Write`", + "example": "resource \"cloudflare_load_balancer\" \"example_load_balancer\" {\n default_pools = [\"17b5962d775c646f3f9725cbc7a53df4\", \"9290f38c5d07c2e2f4df57b1f61d4196\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n fallback_pool = \"fallback_pool\"\n name = \"www.example.com\"\n zone_id = \"zone_id\"\n adaptive_routing = {\n failover_across_pools = true\n }\n country_pools = {\n GB = [\"abd90f38ced07c2e2f4df50b1f61d4194\"]\n US = [\"de90f38ced07c2e2f4df50b1f61d4194\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n }\n description = \"Load Balancer for www.example.com\"\n enabled = true\n location_strategy = {\n mode = \"resolver_ip\"\n prefer_ecs = \"always\"\n }\n networks = [\"string\"]\n pop_pools = {\n LAX = [\"de90f38ced07c2e2f4df50b1f61d4194\", \"9290f38c5d07c2e2f4df57b1f61d4196\"]\n LHR = [\"abd90f38ced07c2e2f4df50b1f61d4194\", \"f9138c5d07c2e2f4df57b1f61d4196\"]\n SJC = [\"00920f38ce07c2e2f4df50b1f61d4194\"]\n }\n proxied = true\n random_steering = {\n default_weight = 0.2\n pool_weights = {\n \"9290f38c5d07c2e2f4df57b1f61d4196\" = 0.5\n de90f38ced07c2e2f4df50b1f61d4194 = 0.3\n }\n }\n region_pools = {\n ENAM = [\"00920f38ce07c2e2f4df50b1f61d4194\"]\n WNAM = [\"de90f38ced07c2e2f4df50b1f61d4194\", \"9290f38c5d07c2e2f4df57b1f61d4196\"]\n }\n rules = [{\n condition = \"http.request.uri.path contains \\\"/testing\\\"\"\n disabled = true\n fixed_response = {\n content_type = \"application/json\"\n location = \"www.example.com\"\n message_body = \"Testing Hello\"\n status_code = 0\n }\n name = \"route the path /testing to testing datacenter.\"\n overrides = {\n adaptive_routing = {\n failover_across_pools = true\n }\n country_pools = {\n GB = [\"abd90f38ced07c2e2f4df50b1f61d4194\"]\n US = [\"de90f38ced07c2e2f4df50b1f61d4194\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n }\n default_pools = [\"17b5962d775c646f3f9725cbc7a53df4\", \"9290f38c5d07c2e2f4df57b1f61d4196\", \"00920f38ce07c2e2f4df50b1f61d4194\"]\n fallback_pool = \"fallback_pool\"\n location_strategy = {\n mode = \"resolver_ip\"\n prefer_ecs = \"always\"\n }\n pool_default_weight = 0.2\n pool_weights = {\n \"9290f38c5d07c2e2f4df57b1f61d4196\" = 0.5\n de90f38ced07c2e2f4df50b1f61d4194 = 0.3\n }\n pools = [\"17b5962d775c646f3f9725cbc7a53df4\"]\n pop_pools = {\n LAX = [\"de90f38ced07c2e2f4df50b1f61d4194\", \"9290f38c5d07c2e2f4df57b1f61d4196\"]\n LHR = [\"abd90f38ced07c2e2f4df50b1f61d4194\", \"f9138c5d07c2e2f4df57b1f61d4196\"]\n SJC = [\"00920f38ce07c2e2f4df50b1f61d4194\"]\n }\n random_steering = {\n default_weight = 0.2\n pool_weights = {\n \"9290f38c5d07c2e2f4df57b1f61d4196\" = 0.5\n de90f38ced07c2e2f4df50b1f61d4194 = 0.3\n }\n }\n region_pools = {\n ENAM = [\"00920f38ce07c2e2f4df50b1f61d4194\"]\n WNAM = [\"de90f38ced07c2e2f4df50b1f61d4194\", \"9290f38c5d07c2e2f4df57b1f61d4196\"]\n }\n session_affinity = \"cookie\"\n session_affinity_attributes = {\n drain_duration = 100\n headers = [\"x\"]\n require_all_headers = true\n samesite = \"Auto\"\n secure = \"Auto\"\n zero_downtime_failover = \"sticky\"\n }\n session_affinity_ttl = 1800\n steering_policy = \"dynamic_latency\"\n ttl = 30\n }\n priority = 0\n terminates = true\n }]\n session_affinity = \"cookie\"\n session_affinity_attributes = {\n drain_duration = 100\n headers = [\"x\"]\n require_all_headers = true\n samesite = \"Auto\"\n secure = \"Auto\"\n zero_downtime_failover = \"sticky\"\n }\n session_affinity_ttl = 1800\n steering_policy = \"dynamic_latency\"\n ttl = 30\n}", + "importExample": "$ terraform import cloudflare_load_balancer.example '/'", + "required": [ + { + "name": "default_pools", + "type": "List of String", + "description": "A list of pool IDs ordered by their failover priority. Pools defined here are used by default, or when region_pools are not configured for a given region." + }, + { + "name": "fallback_pool", + "type": "String", + "description": "The pool ID to use when all other pools are detected as unhealthy." + }, + { + "name": "name", + "type": "String", + "description": "The DNS hostname to associate with your Load Balancer. If this hostname already exists as a DNS record in Cloudflare's DNS, the Load Balancer will take precedence and the DNS record will not be used." + }, + { + "name": "zone_id", + "type": "String" + } + ], + "optional": [ + { + "name": "adaptive_routing", + "type": "Attributes", + "description": "Controls features that modify the routing of requests to pools and origins in response to dynamic conditions, such as during the interval between active health monitoring requests. For example, zero-downtime failover occurs immediately when an origin becomes unavailable due to HTTP 521, 522, or 523 response codes. If there is another healthy origin in the same pool, the request is retried once against this alternate origin.", + "children": [ + { + "name": "failover_across_pools", + "type": "Boolean", + "description": "Extends zero-downtime failover of requests to healthy origins from alternate pools, when no healthy alternate exists in the same pool, according to the failover order defined by traffic and origin steering. When set false (the default) zero-downtime failover will only occur between origins within the same pool. See `session_affinity_attributes` for control over when sessions are broken or reassigned." + } + ] + }, + { + "name": "country_pools", + "type": "Map of List of String", + "description": "A mapping of country codes to a list of pool IDs (ordered by their failover priority) for the given country. Any country not explicitly defined will fall back to using the corresponding region_pool mapping if it exists else to default_pools." + }, + { + "name": "description", + "type": "String", + "description": "Object description." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) this load balancer." + }, + { + "name": "location_strategy", + "type": "Attributes", + "description": "Controls location-based steering for non-proxied requests. See `steering_policy` to learn how steering is affected.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Determines the authoritative location when ECS is not preferred, does not exist in the request, or its GeoIP lookup is unsuccessful.\n- `\"pop\"`: Use the Cloudflare PoP location.\n- `\"resolver_ip\"`: Use the DNS resolver GeoIP location. If the GeoIP lookup is unsuccessful, use the Cloudflare PoP location.\nAvailable values: \"pop\", \"resolver_ip\"." + }, + { + "name": "prefer_ecs", + "type": "String", + "description": "Whether the EDNS Client Subnet (ECS) GeoIP should be preferred as the authoritative location.\n- `\"always\"`: Always prefer ECS.\n- `\"never\"`: Never prefer ECS.\n- `\"proximity\"`: Prefer ECS only when `steering_policy=\"proximity\"`.\n- `\"geo\"`: Prefer ECS only when `steering_policy=\"geo\"`.\nAvailable values: \"always\", \"never\", \"proximity\", \"geo\"." + } + ] + }, + { + "name": "networks", + "type": "List of String", + "description": "List of networks where Load Balancer or Pool is enabled." + }, + { + "name": "pop_pools", + "type": "Map of List of String", + "description": "Enterprise only: A mapping of Cloudflare PoP identifiers to a list of pool IDs (ordered by their failover priority) for the PoP (datacenter). Any PoPs not explicitly defined will fall back to using the corresponding country_pool, then region_pool mapping if it exists else to default_pools." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the hostname should be gray clouded (false) or orange clouded (true)." + }, + { + "name": "random_steering", + "type": "Attributes", + "description": "Configures pool weights.\n- `steering_policy=\"random\"`: A random pool is selected with probability proportional to pool weights.\n- `steering_policy=\"least_outstanding_requests\"`: Use pool weights to scale each pool's outstanding requests.\n- `steering_policy=\"least_connections\"`: Use pool weights to scale each pool's open connections.", + "children": [ + { + "name": "default_weight", + "type": "Number", + "description": "The default weight for pools in the load balancer that are not specified in the pool_weights map." + }, + { + "name": "pool_weights", + "type": "Map of Number", + "description": "A mapping of pool IDs to custom weights. The weight is relative to other pools in the load balancer." + } + ] + }, + { + "name": "region_pools", + "type": "Map of List of String", + "description": "A mapping of region codes to a list of pool IDs (ordered by their failover priority) for the given region. Any regions not explicitly defined will fall back to using default_pools." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "BETA Field Not General Access: A list of rules for this load balancer to execute.", + "children": [ + { + "name": "condition", + "type": "String", + "description": "The condition expressions to evaluate. If the condition evaluates to true, the overrides or fixed_response in this rule will be applied. An empty condition is always true. For more details on condition expressions, please see https://developers.cloudflare.com/load-balancing/understand-basics/load-balancing-rules/expressions." + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable this specific rule. It will no longer be evaluated by this load balancer." + }, + { + "name": "fixed_response", + "type": "Attributes", + "description": "A collection of fields used to directly respond to the eyeball instead of routing to a pool. If a fixed_response is supplied the rule will be marked as terminates.", + "children": [ + { + "name": "content_type", + "type": "String", + "description": "The http 'Content-Type' header to include in the response." + }, + { + "name": "location", + "type": "String", + "description": "The http 'Location' header to include in the response." + }, + { + "name": "message_body", + "type": "String", + "description": "Text to include as the http body." + }, + { + "name": "status_code", + "type": "Number", + "description": "The http status code to respond with." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of this rule. Only used for human readability." + }, + { + "name": "overrides", + "type": "Attributes", + "description": "A collection of overrides to apply to the load balancer when this rule's condition is true. All fields are optional.", + "children": [ + { + "name": "adaptive_routing", + "type": "Attributes", + "description": "Controls features that modify the routing of requests to pools and origins in response to dynamic conditions, such as during the interval between active health monitoring requests. For example, zero-downtime failover occurs immediately when an origin becomes unavailable due to HTTP 521, 522, or 523 response codes. If there is another healthy origin in the same pool, the request is retried once against this alternate origin.", + "children": [ + { + "name": "failover_across_pools", + "type": "Boolean", + "description": "Extends zero-downtime failover of requests to healthy origins from alternate pools, when no healthy alternate exists in the same pool, according to the failover order defined by traffic and origin steering. When set false (the default) zero-downtime failover will only occur between origins within the same pool. See `session_affinity_attributes` for control over when sessions are broken or reassigned." + } + ] + }, + { + "name": "country_pools", + "type": "Map of List of String", + "description": "A mapping of country codes to a list of pool IDs (ordered by their failover priority) for the given country. Any country not explicitly defined will fall back to using the corresponding region_pool mapping if it exists else to default_pools." + }, + { + "name": "default_pools", + "type": "List of String", + "description": "A list of pool IDs ordered by their failover priority. Pools defined here are used by default, or when region_pools are not configured for a given region." + }, + { + "name": "fallback_pool", + "type": "String", + "description": "The pool ID to use when all other pools are detected as unhealthy." + }, + { + "name": "location_strategy", + "type": "Attributes", + "description": "Controls location-based steering for non-proxied requests. See `steering_policy` to learn how steering is affected.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Determines the authoritative location when ECS is not preferred, does not exist in the request, or its GeoIP lookup is unsuccessful.\n- `\"pop\"`: Use the Cloudflare PoP location.\n- `\"resolver_ip\"`: Use the DNS resolver GeoIP location. If the GeoIP lookup is unsuccessful, use the Cloudflare PoP location.\nAvailable values: \"pop\", \"resolver_ip\"." + }, + { + "name": "prefer_ecs", + "type": "String", + "description": "Whether the EDNS Client Subnet (ECS) GeoIP should be preferred as the authoritative location.\n- `\"always\"`: Always prefer ECS.\n- `\"never\"`: Never prefer ECS.\n- `\"proximity\"`: Prefer ECS only when `steering_policy=\"proximity\"`.\n- `\"geo\"`: Prefer ECS only when `steering_policy=\"geo\"`.\nAvailable values: \"always\", \"never\", \"proximity\", \"geo\"." + } + ] + }, + { + "name": "pop_pools", + "type": "Map of List of String", + "description": "Enterprise only: A mapping of Cloudflare PoP identifiers to a list of pool IDs (ordered by their failover priority) for the PoP (datacenter). Any PoPs not explicitly defined will fall back to using the corresponding country_pool, then region_pool mapping if it exists else to default_pools." + }, + { + "name": "random_steering", + "type": "Attributes", + "description": "Configures pool weights.\n- `steering_policy=\"random\"`: A random pool is selected with probability proportional to pool weights.\n- `steering_policy=\"least_outstanding_requests\"`: Use pool weights to scale each pool's outstanding requests.\n- `steering_policy=\"least_connections\"`: Use pool weights to scale each pool's open connections.", + "children": [ + { + "name": "default_weight", + "type": "Number", + "description": "The default weight for pools in the load balancer that are not specified in the pool_weights map." + }, + { + "name": "pool_weights", + "type": "Map of Number", + "description": "A mapping of pool IDs to custom weights. The weight is relative to other pools in the load balancer." + } + ] + }, + { + "name": "region_pools", + "type": "Map of List of String", + "description": "A mapping of region codes to a list of pool IDs (ordered by their failover priority) for the given region. Any regions not explicitly defined will fall back to using default_pools." + }, + { + "name": "session_affinity", + "type": "String", + "description": "Specifies the type of session affinity the load balancer should use unless specified as `\"none\"`. The supported types are: - `\"cookie\"`: On the first request to a proxied load balancer, a cookie is generated, encoding information of which origin the request will be forwarded to. Subsequent requests, by the same client to the same load balancer, will be sent to the origin server the cookie encodes, for the duration of the cookie and as long as the origin server remains healthy. If the cookie has expired or the origin server is unhealthy, then a new origin server is calculated and used. - `\"ip_cookie\"`: Behaves the same as `\"cookie\"` except the initial origin selection is stable and based on the client's ip address. - `\"header\"`: On the first request to a proxied load balancer, a session key based on the configured HTTP headers (see `session_affinity_attributes.headers`) is generated, encoding the request headers used for storing in the load balancer session state which origin the request will be forwarded to. Subsequent requests to the load balancer with the same headers will be sent to the same origin server, for the duration of the session and as long as the origin server remains healthy. If the session has been idle for the duration of `session_affinity_ttl` seconds or the origin server is unhealthy, then a new origin server is calculated and used. See `headers` in `session_affinity_attributes` for additional required configuration.\nAvailable values: \"none\", \"cookie\", \"ip_cookie\", \"header\"." + }, + { + "name": "session_affinity_attributes", + "type": "Attributes", + "description": "Configures attributes for session affinity.", + "children": [ + { + "name": "drain_duration", + "type": "Number", + "description": "Configures the drain duration in seconds. This field is only used when session affinity is enabled on the load balancer." + }, + { + "name": "headers", + "type": "List of String", + "description": "Configures the names of HTTP headers to base session affinity on when header `session_affinity` is enabled. At least one HTTP header name must be provided. To specify the exact cookies to be used, include an item in the following format: `\"cookie:,\"` (example) where everything after the colon is a comma-separated list of cookie names. Providing only `\"cookie\"` will result in all cookies being used. The default max number of HTTP header names that can be provided depends on your plan: 5 for Enterprise, 1 for all other plans." + }, + { + "name": "require_all_headers", + "type": "Boolean", + "description": "When header `session_affinity` is enabled, this option can be used to specify how HTTP headers on load balancing requests will be used. The supported values are: - `\"true\"`: Load balancing requests must contain *all* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created. - `\"false\"`: Load balancing requests must contain *at least one* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created." + }, + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on session affinity cookie. Value \"Auto\" will be translated to \"Lax\" or \"None\" depending if Always Use HTTPS is enabled. Note: when using value \"None\", the secure attribute can not be set to \"Never\".\nAvailable values: \"Auto\", \"Lax\", \"None\", \"Strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on session affinity cookie. Value \"Always\" indicates the Secure attribute will be set in the Set-Cookie header, \"Never\" indicates the Secure attribute will not be set, and \"Auto\" will set the Secure attribute depending if Always Use HTTPS is enabled.\nAvailable values: \"Auto\", \"Always\", \"Never\"." + }, + { + "name": "zero_downtime_failover", + "type": "String", + "description": "Configures the zero-downtime failover between origins within a pool when session affinity is enabled. This feature is currently incompatible with Argo, Tiered Cache, and Bandwidth Alliance. The supported values are: - `\"none\"`: No failover takes place for sessions pinned to the origin (default). - `\"temporary\"`: Traffic will be sent to another other healthy origin until the originally pinned origin is available; note that this can potentially result in heavy origin flapping. - `\"sticky\"`: The session affinity cookie is updated and subsequent requests are sent to the new origin. Note: Zero-downtime failover with sticky sessions is currently not supported for session affinity by header.\nAvailable values: \"none\", \"temporary\", \"sticky\"." + } + ] + }, + { + "name": "session_affinity_ttl", + "type": "Number", + "description": "Time, in seconds, until a client's session expires after being created. Once the expiry time has been reached, subsequent requests may get sent to a different origin server. The accepted ranges per `session_affinity` policy are: - `\"cookie\"` / `\"ip_cookie\"`: The current default of 23 hours will be used unless explicitly set. The accepted range of values is between [1800, 604800]. - `\"header\"`: The current default of 1800 seconds will be used unless explicitly set. The accepted range of values is between [30, 3600]. Note: With session affinity by header, sessions only expire after they haven't been used for the number of seconds specified." + }, + { + "name": "steering_policy", + "type": "String", + "description": "Steering Policy for this load balancer.\n- `\"off\"`: Use `default_pools`.\n- `\"geo\"`: Use `region_pools`/`country_pools`/`pop_pools`. For non-proxied requests, the country for `country_pools` is determined by `location_strategy`.\n- `\"random\"`: Select a pool randomly.\n- `\"dynamic_latency\"`: Use round trip time to select the closest pool in default_pools (requires pool health checks).\n- `\"proximity\"`: Use the pools' latitude and longitude to select the closest pool using the Cloudflare PoP location for proxied requests or the location determined by `location_strategy` for non-proxied requests.\n- `\"least_outstanding_requests\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of outstanding requests. Pools with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of open connections. Pools with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\n- `\"\"`: Will map to `\"geo\"` if you use `region_pools`/`country_pools`/`pop_pools` otherwise `\"off\"`.\nAvailable values: \"off\", \"geo\", \"random\", \"dynamic_latency\", \"proximity\", \"least_outstanding_requests\", \"least_connections\", \"\"." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time to live (TTL) of the DNS entry for the IP address returned by this load balancer. This only applies to gray-clouded (unproxied) load balancers." + } + ] + }, + { + "name": "priority", + "type": "Number", + "description": "The order in which rules should be executed in relation to each other. Lower values are executed first. Values do not need to be sequential. If no value is provided for any rule the array order of the rules field will be used to assign a priority." + }, + { + "name": "terminates", + "type": "Boolean", + "description": "If this rule's condition is true, this causes rule evaluation to stop after processing this rule." + } + ] + }, + { + "name": "session_affinity", + "type": "String", + "description": "Specifies the type of session affinity the load balancer should use unless specified as `\"none\"`. The supported types are: - `\"cookie\"`: On the first request to a proxied load balancer, a cookie is generated, encoding information of which origin the request will be forwarded to. Subsequent requests, by the same client to the same load balancer, will be sent to the origin server the cookie encodes, for the duration of the cookie and as long as the origin server remains healthy. If the cookie has expired or the origin server is unhealthy, then a new origin server is calculated and used. - `\"ip_cookie\"`: Behaves the same as `\"cookie\"` except the initial origin selection is stable and based on the client's ip address. - `\"header\"`: On the first request to a proxied load balancer, a session key based on the configured HTTP headers (see `session_affinity_attributes.headers`) is generated, encoding the request headers used for storing in the load balancer session state which origin the request will be forwarded to. Subsequent requests to the load balancer with the same headers will be sent to the same origin server, for the duration of the session and as long as the origin server remains healthy. If the session has been idle for the duration of `session_affinity_ttl` seconds or the origin server is unhealthy, then a new origin server is calculated and used. See `headers` in `session_affinity_attributes` for additional required configuration.\nAvailable values: \"none\", \"cookie\", \"ip_cookie\", \"header\"." + }, + { + "name": "session_affinity_attributes", + "type": "Attributes", + "description": "Configures attributes for session affinity.", + "children": [ + { + "name": "drain_duration", + "type": "Number", + "description": "Configures the drain duration in seconds. This field is only used when session affinity is enabled on the load balancer." + }, + { + "name": "headers", + "type": "List of String", + "description": "Configures the names of HTTP headers to base session affinity on when header `session_affinity` is enabled. At least one HTTP header name must be provided. To specify the exact cookies to be used, include an item in the following format: `\"cookie:,\"` (example) where everything after the colon is a comma-separated list of cookie names. Providing only `\"cookie\"` will result in all cookies being used. The default max number of HTTP header names that can be provided depends on your plan: 5 for Enterprise, 1 for all other plans." + }, + { + "name": "require_all_headers", + "type": "Boolean", + "description": "When header `session_affinity` is enabled, this option can be used to specify how HTTP headers on load balancing requests will be used. The supported values are: - `\"true\"`: Load balancing requests must contain *all* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created. - `\"false\"`: Load balancing requests must contain *at least one* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created." + }, + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on session affinity cookie. Value \"Auto\" will be translated to \"Lax\" or \"None\" depending if Always Use HTTPS is enabled. Note: when using value \"None\", the secure attribute can not be set to \"Never\".\nAvailable values: \"Auto\", \"Lax\", \"None\", \"Strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on session affinity cookie. Value \"Always\" indicates the Secure attribute will be set in the Set-Cookie header, \"Never\" indicates the Secure attribute will not be set, and \"Auto\" will set the Secure attribute depending if Always Use HTTPS is enabled.\nAvailable values: \"Auto\", \"Always\", \"Never\"." + }, + { + "name": "zero_downtime_failover", + "type": "String", + "description": "Configures the zero-downtime failover between origins within a pool when session affinity is enabled. This feature is currently incompatible with Argo, Tiered Cache, and Bandwidth Alliance. The supported values are: - `\"none\"`: No failover takes place for sessions pinned to the origin (default). - `\"temporary\"`: Traffic will be sent to another other healthy origin until the originally pinned origin is available; note that this can potentially result in heavy origin flapping. - `\"sticky\"`: The session affinity cookie is updated and subsequent requests are sent to the new origin. Note: Zero-downtime failover with sticky sessions is currently not supported for session affinity by header.\nAvailable values: \"none\", \"temporary\", \"sticky\"." + } + ] + }, + { + "name": "session_affinity_ttl", + "type": "Number", + "description": "Time, in seconds, until a client's session expires after being created. Once the expiry time has been reached, subsequent requests may get sent to a different origin server. The accepted ranges per `session_affinity` policy are: - `\"cookie\"` / `\"ip_cookie\"`: The current default of 23 hours will be used unless explicitly set. The accepted range of values is between [1800, 604800]. - `\"header\"`: The current default of 1800 seconds will be used unless explicitly set. The accepted range of values is between [30, 3600]. Note: With session affinity by header, sessions only expire after they haven't been used for the number of seconds specified." + }, + { + "name": "steering_policy", + "type": "String", + "description": "Steering Policy for this load balancer.\n- `\"off\"`: Use `default_pools`.\n- `\"geo\"`: Use `region_pools`/`country_pools`/`pop_pools`. For non-proxied requests, the country for `country_pools` is determined by `location_strategy`.\n- `\"random\"`: Select a pool randomly.\n- `\"dynamic_latency\"`: Use round trip time to select the closest pool in default_pools (requires pool health checks).\n- `\"proximity\"`: Use the pools' latitude and longitude to select the closest pool using the Cloudflare PoP location for proxied requests or the location determined by `location_strategy` for non-proxied requests.\n- `\"least_outstanding_requests\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of outstanding requests. Pools with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of open connections. Pools with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\n- `\"\"`: Will map to `\"geo\"` if you use `region_pools`/`country_pools`/`pop_pools` otherwise `\"off\"`.\nAvailable values: \"off\", \"geo\", \"random\", \"dynamic_latency\", \"proximity\", \"least_outstanding_requests\", \"least_connections\", \"\"." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time to live (TTL) of the DNS entry for the IP address returned by this load balancer. This only applies to gray-clouded (unproxied) load balancers." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "zone_name", + "type": "String" + } + ] + }, + "data-source:cloudflare_load_balancer_monitor": { + "kind": "data-source", + "name": "cloudflare_load_balancer_monitor", + "description": "Accepted Permissions\n\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`", + "example": "data \"cloudflare_load_balancer_monitor\" \"example_load_balancer_monitor\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor_id = \"f1aba936b94213e5b8dca0c0dbf1f9cc\"\n}", + "required": [ + { + "name": "monitor_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "allow_insecure", + "type": "Boolean", + "description": "Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors." + }, + { + "name": "consecutive_down", + "type": "Number", + "description": "To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times." + }, + { + "name": "consecutive_up", + "type": "Number", + "description": "To be marked healthy the monitored origin must pass this healthcheck N consecutive times." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Object description." + }, + { + "name": "expected_body", + "type": "String", + "description": "A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "expected_codes", + "type": "String", + "description": "The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "follow_redirects", + "type": "Boolean", + "description": "Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "header", + "type": "Map of List of String", + "description": "The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "interval", + "type": "Number", + "description": "The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations." + }, + { + "name": "method", + "type": "String", + "description": "The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "path", + "type": "String", + "description": "The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "port", + "type": "Number", + "description": "The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)." + }, + { + "name": "probe_zone", + "type": "String", + "description": "Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "retries", + "type": "Number", + "description": "The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately." + }, + { + "name": "timeout", + "type": "Number", + "description": "The timeout (in seconds) before marking the health check as failed." + }, + { + "name": "type", + "type": "String", + "description": "The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'.\nAvailable values: \"http\", \"https\", \"tcp\", \"udp_icmp\", \"icmp_ping\", \"smtp\"." + } + ] + }, + "resource:cloudflare_load_balancer_monitor": { + "kind": "resource", + "name": "cloudflare_load_balancer_monitor", + "description": "Accepted Permissions\n\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`", + "example": "resource \"cloudflare_load_balancer_monitor\" \"example_load_balancer_monitor\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n allow_insecure = true\n consecutive_down = 0\n consecutive_up = 0\n description = \"Login page monitor\"\n expected_body = \"alive\"\n expected_codes = \"2xx\"\n follow_redirects = true\n header = {\n Host = [\"example.com\"]\n X-App-ID = [\"abc123\"]\n }\n interval = 0\n method = \"GET\"\n path = \"/health\"\n port = 0\n probe_zone = \"example.com\"\n retries = 0\n timeout = 0\n type = \"https\"\n}", + "importExample": "$ terraform import cloudflare_load_balancer_monitor.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "allow_insecure", + "type": "Boolean", + "description": "Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors." + }, + { + "name": "consecutive_down", + "type": "Number", + "description": "To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times." + }, + { + "name": "consecutive_up", + "type": "Number", + "description": "To be marked healthy the monitored origin must pass this healthcheck N consecutive times." + }, + { + "name": "description", + "type": "String", + "description": "Object description." + }, + { + "name": "expected_body", + "type": "String", + "description": "A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "expected_codes", + "type": "String", + "description": "The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "follow_redirects", + "type": "Boolean", + "description": "Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "header", + "type": "Map of List of String", + "description": "The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "interval", + "type": "Number", + "description": "The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations." + }, + { + "name": "method", + "type": "String", + "description": "The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks." + }, + { + "name": "path", + "type": "String", + "description": "The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "port", + "type": "Number", + "description": "The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)." + }, + { + "name": "probe_zone", + "type": "String", + "description": "Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "retries", + "type": "Number", + "description": "The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately." + }, + { + "name": "timeout", + "type": "Number", + "description": "The timeout (in seconds) before marking the health check as failed." + }, + { + "name": "type", + "type": "String", + "description": "The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'.\nAvailable values: \"http\", \"https\", \"tcp\", \"udp_icmp\", \"icmp_ping\", \"smtp\"." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String" + } + ] + }, + "data-source:cloudflare_load_balancer_monitor_group": { + "kind": "data-source", + "name": "cloudflare_load_balancer_monitor_group", + "example": "data \"cloudflare_load_balancer_monitor_group\" \"example_load_balancer_monitor_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor_group_id = \"17b5962d775c646f3f9725cbc7a53df4\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "monitor_group_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the monitor group was created" + }, + { + "name": "description", + "type": "String", + "description": "A short description of the monitor group" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "members", + "type": "Attributes Set", + "description": "List of monitors in this group", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "The timestamp of when the monitor was added to the group" + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether this monitor is enabled in the group" + }, + { + "name": "monitor_id", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + }, + { + "name": "monitoring_only", + "type": "Boolean", + "description": "Whether this monitor is used for monitoring only (does not affect pool health)" + }, + { + "name": "must_be_healthy", + "type": "Boolean", + "description": "Whether this monitor must be healthy for the pool to be considered healthy" + }, + { + "name": "updated_at", + "type": "String", + "description": "The timestamp of when the monitor group member was last updated" + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the monitor group was last updated" + } + ] + }, + "resource:cloudflare_load_balancer_monitor_group": { + "kind": "resource", + "name": "cloudflare_load_balancer_monitor_group", + "example": "resource \"cloudflare_load_balancer_monitor_group\" \"example_load_balancer_monitor_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n description = \"Primary datacenter monitors\"\n members = [{\n enabled = true\n monitor_id = \"monitor_id\"\n monitoring_only = false\n must_be_healthy = true\n }]\n}", + "importExample": "$ terraform import cloudflare_load_balancer_monitor_group.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "description", + "type": "String", + "description": "A short description of the monitor group" + }, + { + "name": "members", + "type": "Attributes Set", + "description": "List of monitors in this group", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "The timestamp of when the monitor was added to the group" + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether this monitor is enabled in the group" + }, + { + "name": "monitor_id", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + }, + { + "name": "monitoring_only", + "type": "Boolean", + "description": "Whether this monitor is used for monitoring only (does not affect pool health)" + }, + { + "name": "must_be_healthy", + "type": "Boolean", + "description": "Whether this monitor must be healthy for the pool to be considered healthy" + }, + { + "name": "updated_at", + "type": "String", + "description": "The timestamp of when the monitor group member was last updated" + } + ] + } + ], + "optional": [], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the monitor group was created" + }, + { + "name": "id", + "type": "String", + "description": "The ID of the Monitor Group to use for checking the health of origins within this pool." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the monitor group was last updated" + } + ] + }, + "list-data-source:cloudflare_load_balancer_monitor_groups": { + "kind": "list-data-source", + "name": "cloudflare_load_balancer_monitor_groups", + "example": "data \"cloudflare_load_balancer_monitor_groups\" \"example_load_balancer_monitor_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the monitor group was created" + }, + { + "name": "description", + "type": "String", + "description": "A short description of the monitor group" + }, + { + "name": "id", + "type": "String", + "description": "The ID of the Monitor Group to use for checking the health of origins within this pool." + }, + { + "name": "members", + "type": "Attributes Set", + "description": "List of monitors in this group", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "The timestamp of when the monitor was added to the group" + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether this monitor is enabled in the group" + }, + { + "name": "monitor_id", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + }, + { + "name": "monitoring_only", + "type": "Boolean", + "description": "Whether this monitor is used for monitoring only (does not affect pool health)" + }, + { + "name": "must_be_healthy", + "type": "Boolean", + "description": "Whether this monitor must be healthy for the pool to be considered healthy" + }, + { + "name": "updated_at", + "type": "String", + "description": "The timestamp of when the monitor group member was last updated" + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the monitor group was last updated" + } + ] + } + ] + }, + "list-data-source:cloudflare_load_balancer_monitors": { + "kind": "list-data-source", + "name": "cloudflare_load_balancer_monitors", + "description": "Accepted Permissions\n\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`", + "example": "data \"cloudflare_load_balancer_monitors\" \"example_load_balancer_monitors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allow_insecure", + "type": "Boolean", + "description": "Do not validate the certificate when monitor use HTTPS. This parameter is currently only valid for HTTP and HTTPS monitors." + }, + { + "name": "consecutive_down", + "type": "Number", + "description": "To be marked unhealthy the monitored origin must fail this healthcheck N consecutive times." + }, + { + "name": "consecutive_up", + "type": "Number", + "description": "To be marked healthy the monitored origin must pass this healthcheck N consecutive times." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Object description." + }, + { + "name": "expected_body", + "type": "String", + "description": "A case-insensitive sub-string to look for in the response body. If this string is not found, the origin will be marked as unhealthy. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "expected_codes", + "type": "String", + "description": "The expected HTTP response code or code range of the health check. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "follow_redirects", + "type": "Boolean", + "description": "Follow redirects if returned by the origin. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "header", + "type": "Map of List of String", + "description": "The HTTP request headers to send in the health check. It is recommended you set a Host header by default. The User-Agent header cannot be overridden. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "interval", + "type": "Number", + "description": "The interval between each health check. Shorter intervals may improve failover time, but will increase load on the origins as we check from multiple locations." + }, + { + "name": "method", + "type": "String", + "description": "The method to use for the health check. This defaults to 'GET' for HTTP/HTTPS based checks and 'connection_established' for TCP based health checks." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "path", + "type": "String", + "description": "The endpoint path you want to conduct a health check against. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "port", + "type": "Number", + "description": "The port number to connect to for the health check. Required for TCP, UDP, and SMTP checks. HTTP and HTTPS checks should only define the port when using a non-standard port (HTTP: default 80, HTTPS: default 443)." + }, + { + "name": "probe_zone", + "type": "String", + "description": "Assign this monitor to emulate the specified zone while probing. This parameter is only valid for HTTP and HTTPS monitors." + }, + { + "name": "retries", + "type": "Number", + "description": "The number of retries to attempt in case of a timeout before marking the origin as unhealthy. Retries are attempted immediately." + }, + { + "name": "timeout", + "type": "Number", + "description": "The timeout (in seconds) before marking the health check as failed." + }, + { + "name": "type", + "type": "String", + "description": "The protocol to use for the health check. Currently supported protocols are 'HTTP','HTTPS', 'TCP', 'ICMP-PING', 'UDP-ICMP', and 'SMTP'.\nAvailable values: \"http\", \"https\", \"tcp\", \"udp_icmp\", \"icmp_ping\", \"smtp\"." + } + ] + } + ] + }, + "data-source:cloudflare_load_balancer_pool": { + "kind": "data-source", + "name": "cloudflare_load_balancer_pool", + "description": "Accepted Permissions\n\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`", + "example": "data \"cloudflare_load_balancer_pool\" \"example_load_balancer_pool\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pool_id = \"17b5962d775c646f3f9725cbc7a53df4\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "monitor", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + } + ] + }, + { + "name": "pool_id", + "type": "String" + } + ], + "computed": [ + { + "name": "check_regions", + "type": "List of String", + "description": "A list of regions from which to run health checks. Null means every Cloudflare data center." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description of the pool." + }, + { + "name": "disabled_at", + "type": "String", + "description": "This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)." + }, + { + "name": "health_sources", + "type": "List of String", + "description": "A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "latitude", + "type": "Number", + "description": "The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set." + }, + { + "name": "load_shedding", + "type": "Attributes", + "description": "Configures load shedding policies and percentages for the pool.", + "children": [ + { + "name": "default_percent", + "type": "Number", + "description": "The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity." + }, + { + "name": "default_policy", + "type": "String", + "description": "The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs.\nAvailable values: \"random\", \"hash\"." + }, + { + "name": "session_percent", + "type": "Number", + "description": "The percent of existing sessions to shed from the pool, according to the session policy." + }, + { + "name": "session_policy", + "type": "String", + "description": "Only the hash policy is supported for existing sessions (to avoid exponential decay).\nAvailable values: \"hash\"." + } + ] + }, + { + "name": "longitude", + "type": "Number", + "description": "The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set." + }, + { + "name": "minimum_origins", + "type": "Number", + "description": "The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "monitor", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + }, + { + "name": "monitor_group", + "type": "String", + "description": "The ID of the Monitor Group to use for checking the health of origins within this pool." + }, + { + "name": "name", + "type": "String", + "description": "A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed." + }, + { + "name": "networks", + "type": "List of String", + "description": "List of networks where Load Balancer or Pool is enabled." + }, + { + "name": "notification_email", + "type": "String", + "description": "This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list." + }, + { + "name": "notification_filter", + "type": "Attributes", + "description": "Filter pool and origin health notifications by resource type or health status. Use null to reset.", + "children": [ + { + "name": "origin", + "type": "Attributes", + "description": "Filter options for a particular resource type (pool or origin). Use null to reset.", + "children": [ + { + "name": "disable", + "type": "Boolean", + "description": "If set true, disable notifications for this type of resource (pool or origin)." + }, + { + "name": "healthy", + "type": "Boolean", + "description": "If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)." + } + ] + }, + { + "name": "pool", + "type": "Attributes", + "description": "Filter options for a particular resource type (pool or origin). Use null to reset.", + "children": [ + { + "name": "disable", + "type": "Boolean", + "description": "If set true, disable notifications for this type of resource (pool or origin)." + }, + { + "name": "healthy", + "type": "Boolean", + "description": "If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)." + } + ] + } + ] + }, + { + "name": "origin_steering", + "type": "Attributes", + "description": "Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.", + "children": [ + { + "name": "policy", + "type": "String", + "description": "The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\nAvailable values: \"random\", \"hash\", \"least_outstanding_requests\", \"least_connections\"." + } + ] + }, + { + "name": "origins", + "type": "Attributes Set", + "description": "The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set." + }, + { + "name": "disabled_at", + "type": "String", + "description": "This field shows up only if the origin is disabled. This field is set with the time the origin was disabled." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool." + }, + { + "name": "flatten_cname", + "type": "Boolean", + "description": "Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting." + }, + { + "name": "header", + "type": "Attributes", + "description": "The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.", + "children": [ + { + "name": "host", + "type": "List of String", + "description": "The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "A human-identifiable name for the origin." + }, + { + "name": "port", + "type": "Number", + "description": "The port for upstream connections. A value of 0 means the default port for the protocol will be used." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account." + }, + { + "name": "weight", + "type": "Number", + "description": "The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections." + } + ] + } + ] + }, + "resource:cloudflare_load_balancer_pool": { + "kind": "resource", + "name": "cloudflare_load_balancer_pool", + "description": "Accepted Permissions\n\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`", + "example": "resource \"cloudflare_load_balancer_pool\" \"example_load_balancer_pool\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"primary-dc-1\"\n origins = [{\n address = \"0.0.0.0\"\n enabled = true\n flatten_cname = true\n header = {\n host = [\"example.com\"]\n }\n name = \"app-server-1\"\n port = 0\n virtual_network_id = \"a5624d4e-044a-4ff0-b3e1-e2465353d4b4\"\n weight = 0.6\n }]\n description = \"Primary data center - Provider XYZ\"\n enabled = false\n latitude = 0\n load_shedding = {\n default_percent = 0\n default_policy = \"random\"\n session_percent = 0\n session_policy = \"hash\"\n }\n longitude = 0\n minimum_origins = 0\n monitor = \"monitor\"\n monitor_group = \"monitor_group\"\n notification_email = \"someone@example.com,sometwo@example.com\"\n notification_filter = {\n origin = {\n disable = true\n healthy = true\n }\n pool = {\n disable = true\n healthy = false\n }\n }\n origin_steering = {\n policy = \"random\"\n }\n}", + "importExample": "$ terraform import cloudflare_load_balancer_pool.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed." + }, + { + "name": "origins", + "type": "Attributes List", + "description": "The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set." + }, + { + "name": "disabled_at", + "type": "String", + "description": "This field shows up only if the origin is disabled. This field is set with the time the origin was disabled." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool." + }, + { + "name": "flatten_cname", + "type": "Boolean", + "description": "Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting." + }, + { + "name": "header", + "type": "Attributes", + "description": "The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.", + "children": [ + { + "name": "host", + "type": "List of String", + "description": "The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "A human-identifiable name for the origin." + }, + { + "name": "port", + "type": "Number", + "description": "The port for upstream connections. A value of 0 means the default port for the protocol will be used." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account." + }, + { + "name": "weight", + "type": "Number", + "description": "The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections." + } + ] + } + ], + "optional": [ + { + "name": "check_regions", + "type": "List of String", + "description": "A list of regions from which to run health checks. Null means every Cloudflare data center." + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description of the pool." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)." + }, + { + "name": "health_sources", + "type": "List of String", + "description": "A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions." + }, + { + "name": "latitude", + "type": "Number", + "description": "The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set." + }, + { + "name": "load_shedding", + "type": "Attributes", + "description": "Configures load shedding policies and percentages for the pool.", + "children": [ + { + "name": "default_percent", + "type": "Number", + "description": "The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity." + }, + { + "name": "default_policy", + "type": "String", + "description": "The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs.\nAvailable values: \"random\", \"hash\"." + }, + { + "name": "session_percent", + "type": "Number", + "description": "The percent of existing sessions to shed from the pool, according to the session policy." + }, + { + "name": "session_policy", + "type": "String", + "description": "Only the hash policy is supported for existing sessions (to avoid exponential decay).\nAvailable values: \"hash\"." + } + ] + }, + { + "name": "longitude", + "type": "Number", + "description": "The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set." + }, + { + "name": "minimum_origins", + "type": "Number", + "description": "The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool." + }, + { + "name": "monitor", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + }, + { + "name": "monitor_group", + "type": "String", + "description": "The ID of the Monitor Group to use for checking the health of origins within this pool." + }, + { + "name": "notification_email", + "type": "String", + "description": "This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list." + }, + { + "name": "notification_filter", + "type": "Attributes", + "description": "Filter pool and origin health notifications by resource type or health status. Use null to reset.", + "children": [ + { + "name": "origin", + "type": "Attributes", + "description": "Filter options for a particular resource type (pool or origin). Use null to reset.", + "children": [ + { + "name": "disable", + "type": "Boolean", + "description": "If set true, disable notifications for this type of resource (pool or origin)." + }, + { + "name": "healthy", + "type": "Boolean", + "description": "If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)." + } + ] + }, + { + "name": "pool", + "type": "Attributes", + "description": "Filter options for a particular resource type (pool or origin). Use null to reset.", + "children": [ + { + "name": "disable", + "type": "Boolean", + "description": "If set true, disable notifications for this type of resource (pool or origin)." + }, + { + "name": "healthy", + "type": "Boolean", + "description": "If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)." + } + ] + } + ] + }, + { + "name": "origin_steering", + "type": "Attributes", + "description": "Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.", + "children": [ + { + "name": "policy", + "type": "String", + "description": "The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\nAvailable values: \"random\", \"hash\", \"least_outstanding_requests\", \"least_connections\"." + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "disabled_at", + "type": "String", + "description": "This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "networks", + "type": "List of String", + "description": "List of networks where Load Balancer or Pool is enabled." + } + ] + }, + "list-data-source:cloudflare_load_balancer_pools": { + "kind": "list-data-source", + "name": "cloudflare_load_balancer_pools", + "description": "Accepted Permissions\n\n- `Load Balancing: Monitors and Pools Read`\n- `Load Balancing: Monitors and Pools Write`", + "example": "data \"cloudflare_load_balancer_pools\" \"example_load_balancer_pools\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n monitor = \"monitor\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "monitor", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "check_regions", + "type": "List of String", + "description": "A list of regions from which to run health checks. Null means every Cloudflare data center." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description of the pool." + }, + { + "name": "disabled_at", + "type": "String", + "description": "This field shows up only if the pool is disabled. This field is set with the time the pool was disabled at." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) or disable this pool. Disabled pools will not receive traffic and are excluded from health checks. Disabling a pool will cause any load balancers using it to failover to the next pool (if any)." + }, + { + "name": "health_sources", + "type": "List of String", + "description": "A list of health sources, ordered from highest to lowest priority, used to evaluate individual origin health and overall pool health. The load balancer uses the first source that has data and falls back to the next. Currently accepted values are null or the exact array [\"regional\", \"global\"]; any other combination is rejected. Null (the default) behaves like [\"local\", \"global\"]. [\"regional\", \"global\"] makes each region steer on its own health, falling back to the global decision when a region has no fresh data. Setting regional requires at least one region in check_regions." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "latitude", + "type": "Number", + "description": "The latitude of the data center containing the origins used in this pool in decimal degrees. If this is set, longitude must also be set." + }, + { + "name": "load_shedding", + "type": "Attributes", + "description": "Configures load shedding policies and percentages for the pool.", + "children": [ + { + "name": "default_percent", + "type": "Number", + "description": "The percent of traffic to shed from the pool, according to the default policy. Applies to new sessions and traffic without session affinity." + }, + { + "name": "default_policy", + "type": "String", + "description": "The default policy to use when load shedding. A random policy randomly sheds a given percent of requests. A hash policy computes a hash over the CF-Connecting-IP address and sheds all requests originating from a percent of IPs.\nAvailable values: \"random\", \"hash\"." + }, + { + "name": "session_percent", + "type": "Number", + "description": "The percent of existing sessions to shed from the pool, according to the session policy." + }, + { + "name": "session_policy", + "type": "String", + "description": "Only the hash policy is supported for existing sessions (to avoid exponential decay).\nAvailable values: \"hash\"." + } + ] + }, + { + "name": "longitude", + "type": "Number", + "description": "The longitude of the data center containing the origins used in this pool in decimal degrees. If this is set, latitude must also be set." + }, + { + "name": "minimum_origins", + "type": "Number", + "description": "The minimum number of origins that must be healthy for this pool to serve traffic. If the number of healthy origins falls below this number, the pool will be marked unhealthy and will failover to the next available pool." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "monitor", + "type": "String", + "description": "The ID of the Monitor to use for checking the health of origins within this pool." + }, + { + "name": "monitor_group", + "type": "String", + "description": "The ID of the Monitor Group to use for checking the health of origins within this pool." + }, + { + "name": "name", + "type": "String", + "description": "A short name (tag) for the pool. Only alphanumeric characters, hyphens, and underscores are allowed." + }, + { + "name": "networks", + "type": "List of String", + "description": "List of networks where Load Balancer or Pool is enabled." + }, + { + "name": "notification_email", + "type": "String", + "description": "This field is now deprecated. It has been moved to Cloudflare's Centralized Notification service https://developers.cloudflare.com/fundamentals/notifications/. The email address to send health status notifications to. This can be an individual mailbox or a mailing list. Multiple emails can be supplied as a comma delimited list." + }, + { + "name": "notification_filter", + "type": "Attributes", + "description": "Filter pool and origin health notifications by resource type or health status. Use null to reset.", + "children": [ + { + "name": "origin", + "type": "Attributes", + "description": "Filter options for a particular resource type (pool or origin). Use null to reset.", + "children": [ + { + "name": "disable", + "type": "Boolean", + "description": "If set true, disable notifications for this type of resource (pool or origin)." + }, + { + "name": "healthy", + "type": "Boolean", + "description": "If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)." + } + ] + }, + { + "name": "pool", + "type": "Attributes", + "description": "Filter options for a particular resource type (pool or origin). Use null to reset.", + "children": [ + { + "name": "disable", + "type": "Boolean", + "description": "If set true, disable notifications for this type of resource (pool or origin)." + }, + { + "name": "healthy", + "type": "Boolean", + "description": "If present, send notifications only for this health status (e.g. false for only DOWN events). Use null to reset (all events)." + } + ] + } + ] + }, + { + "name": "origin_steering", + "type": "Attributes", + "description": "Configures origin steering for the pool. Controls how origins are selected for new sessions and traffic without session affinity.", + "children": [ + { + "name": "policy", + "type": "String", + "description": "The type of origin steering policy to use.\n- `\"random\"`: Select an origin randomly.\n- `\"hash\"`: Select an origin by computing a hash over the CF-Connecting-IP address.\n- `\"least_outstanding_requests\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of outstanding requests. Origins with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select an origin by taking into consideration origin weights, as well as each origin's number of open connections. Origins with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\nAvailable values: \"random\", \"hash\", \"least_outstanding_requests\", \"least_connections\"." + } + ] + }, + { + "name": "origins", + "type": "Attributes Set", + "description": "The list of origins within this pool. Traffic directed at this pool is balanced across all currently healthy origins, provided the pool itself is healthy.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The IP address (IPv4 or IPv6) of the origin, or its publicly addressable hostname. Hostnames entered here should resolve directly to the origin, and not be a hostname proxied by Cloudflare. To set an internal/reserved address, virtual_network_id must also be set." + }, + { + "name": "disabled_at", + "type": "String", + "description": "This field shows up only if the origin is disabled. This field is set with the time the origin was disabled." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) this origin within the pool. Disabled origins will not receive traffic and are excluded from health checks. The origin will only be disabled for the current pool." + }, + { + "name": "flatten_cname", + "type": "Boolean", + "description": "Whether to flatten CNAME records for this origin, resolving them to A/AAAA records before returning to the client. When true (the default), the director resolves CNAME addresses to their underlying A/AAAA records. When false, the origin address is returned as a raw CNAME record without resolution. This setting mirrors the DNS API record flatten_cname setting." + }, + { + "name": "header", + "type": "Attributes", + "description": "The request header is used to pass additional information with an HTTP request. Currently supported header is 'Host'.", + "children": [ + { + "name": "host", + "type": "List of String", + "description": "The 'Host' header allows to override the hostname set in the HTTP request. Current support is 1 'Host' header override per origin." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "A human-identifiable name for the origin." + }, + { + "name": "port", + "type": "Number", + "description": "The port for upstream connections. A value of 0 means the default port for the protocol will be used." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "The virtual network subnet ID the origin belongs in. Virtual network must also belong to the account." + }, + { + "name": "weight", + "type": "Number", + "description": "The weight of this origin relative to other origins in the pool. Based on the configured weight the total traffic is distributed among origins within the pool.\n- `origin_steering.policy=\"least_outstanding_requests\"`: Use weight to scale the origin's outstanding requests.\n- `origin_steering.policy=\"least_connections\"`: Use weight to scale the origin's open connections." + } + ] + } + ] + } + ] + }, + "list-data-source:cloudflare_load_balancers": { + "kind": "list-data-source", + "name": "cloudflare_load_balancers", + "description": "Accepted Permissions\n\n- `Load Balancers Read`\n- `Load Balancers Write`", + "example": "data \"cloudflare_load_balancers\" \"example_load_balancers\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "adaptive_routing", + "type": "Attributes", + "description": "Controls features that modify the routing of requests to pools and origins in response to dynamic conditions, such as during the interval between active health monitoring requests. For example, zero-downtime failover occurs immediately when an origin becomes unavailable due to HTTP 521, 522, or 523 response codes. If there is another healthy origin in the same pool, the request is retried once against this alternate origin.", + "children": [ + { + "name": "failover_across_pools", + "type": "Boolean", + "description": "Extends zero-downtime failover of requests to healthy origins from alternate pools, when no healthy alternate exists in the same pool, according to the failover order defined by traffic and origin steering. When set false (the default) zero-downtime failover will only occur between origins within the same pool. See `session_affinity_attributes` for control over when sessions are broken or reassigned." + } + ] + }, + { + "name": "country_pools", + "type": "Map of List of String", + "description": "A mapping of country codes to a list of pool IDs (ordered by their failover priority) for the given country. Any country not explicitly defined will fall back to using the corresponding region_pool mapping if it exists else to default_pools." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "default_pools", + "type": "List of String", + "description": "A list of pool IDs ordered by their failover priority. Pools defined here are used by default, or when region_pools are not configured for a given region." + }, + { + "name": "description", + "type": "String", + "description": "Object description." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable (the default) this load balancer." + }, + { + "name": "fallback_pool", + "type": "String", + "description": "The pool ID to use when all other pools are detected as unhealthy." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "location_strategy", + "type": "Attributes", + "description": "Controls location-based steering for non-proxied requests. See `steering_policy` to learn how steering is affected.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Determines the authoritative location when ECS is not preferred, does not exist in the request, or its GeoIP lookup is unsuccessful.\n- `\"pop\"`: Use the Cloudflare PoP location.\n- `\"resolver_ip\"`: Use the DNS resolver GeoIP location. If the GeoIP lookup is unsuccessful, use the Cloudflare PoP location.\nAvailable values: \"pop\", \"resolver_ip\"." + }, + { + "name": "prefer_ecs", + "type": "String", + "description": "Whether the EDNS Client Subnet (ECS) GeoIP should be preferred as the authoritative location.\n- `\"always\"`: Always prefer ECS.\n- `\"never\"`: Never prefer ECS.\n- `\"proximity\"`: Prefer ECS only when `steering_policy=\"proximity\"`.\n- `\"geo\"`: Prefer ECS only when `steering_policy=\"geo\"`.\nAvailable values: \"always\", \"never\", \"proximity\", \"geo\"." + } + ] + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The DNS hostname to associate with your Load Balancer. If this hostname already exists as a DNS record in Cloudflare's DNS, the Load Balancer will take precedence and the DNS record will not be used." + }, + { + "name": "networks", + "type": "List of String", + "description": "List of networks where Load Balancer or Pool is enabled." + }, + { + "name": "pop_pools", + "type": "Map of List of String", + "description": "Enterprise only: A mapping of Cloudflare PoP identifiers to a list of pool IDs (ordered by their failover priority) for the PoP (datacenter). Any PoPs not explicitly defined will fall back to using the corresponding country_pool, then region_pool mapping if it exists else to default_pools." + }, + { + "name": "proxied", + "type": "Boolean", + "description": "Whether the hostname should be gray clouded (false) or orange clouded (true)." + }, + { + "name": "random_steering", + "type": "Attributes", + "description": "Configures pool weights.\n- `steering_policy=\"random\"`: A random pool is selected with probability proportional to pool weights.\n- `steering_policy=\"least_outstanding_requests\"`: Use pool weights to scale each pool's outstanding requests.\n- `steering_policy=\"least_connections\"`: Use pool weights to scale each pool's open connections.", + "children": [ + { + "name": "default_weight", + "type": "Number", + "description": "The default weight for pools in the load balancer that are not specified in the pool_weights map." + }, + { + "name": "pool_weights", + "type": "Map of Number", + "description": "A mapping of pool IDs to custom weights. The weight is relative to other pools in the load balancer." + } + ] + }, + { + "name": "region_pools", + "type": "Map of List of String", + "description": "A mapping of region codes to a list of pool IDs (ordered by their failover priority) for the given region. Any regions not explicitly defined will fall back to using default_pools." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "BETA Field Not General Access: A list of rules for this load balancer to execute.", + "children": [ + { + "name": "condition", + "type": "String", + "description": "The condition expressions to evaluate. If the condition evaluates to true, the overrides or fixed_response in this rule will be applied. An empty condition is always true. For more details on condition expressions, please see https://developers.cloudflare.com/load-balancing/understand-basics/load-balancing-rules/expressions." + }, + { + "name": "disabled", + "type": "Boolean", + "description": "Disable this specific rule. It will no longer be evaluated by this load balancer." + }, + { + "name": "fixed_response", + "type": "Attributes", + "description": "A collection of fields used to directly respond to the eyeball instead of routing to a pool. If a fixed_response is supplied the rule will be marked as terminates.", + "children": [ + { + "name": "content_type", + "type": "String", + "description": "The http 'Content-Type' header to include in the response." + }, + { + "name": "location", + "type": "String", + "description": "The http 'Location' header to include in the response." + }, + { + "name": "message_body", + "type": "String", + "description": "Text to include as the http body." + }, + { + "name": "status_code", + "type": "Number", + "description": "The http status code to respond with." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of this rule. Only used for human readability." + }, + { + "name": "overrides", + "type": "Attributes", + "description": "A collection of overrides to apply to the load balancer when this rule's condition is true. All fields are optional.", + "children": [ + { + "name": "adaptive_routing", + "type": "Attributes", + "description": "Controls features that modify the routing of requests to pools and origins in response to dynamic conditions, such as during the interval between active health monitoring requests. For example, zero-downtime failover occurs immediately when an origin becomes unavailable due to HTTP 521, 522, or 523 response codes. If there is another healthy origin in the same pool, the request is retried once against this alternate origin.", + "children": [ + { + "name": "failover_across_pools", + "type": "Boolean", + "description": "Extends zero-downtime failover of requests to healthy origins from alternate pools, when no healthy alternate exists in the same pool, according to the failover order defined by traffic and origin steering. When set false (the default) zero-downtime failover will only occur between origins within the same pool. See `session_affinity_attributes` for control over when sessions are broken or reassigned." + } + ] + }, + { + "name": "country_pools", + "type": "Map of List of String", + "description": "A mapping of country codes to a list of pool IDs (ordered by their failover priority) for the given country. Any country not explicitly defined will fall back to using the corresponding region_pool mapping if it exists else to default_pools." + }, + { + "name": "default_pools", + "type": "List of String", + "description": "A list of pool IDs ordered by their failover priority. Pools defined here are used by default, or when region_pools are not configured for a given region." + }, + { + "name": "fallback_pool", + "type": "String", + "description": "The pool ID to use when all other pools are detected as unhealthy." + }, + { + "name": "location_strategy", + "type": "Attributes", + "description": "Controls location-based steering for non-proxied requests. See `steering_policy` to learn how steering is affected.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Determines the authoritative location when ECS is not preferred, does not exist in the request, or its GeoIP lookup is unsuccessful.\n- `\"pop\"`: Use the Cloudflare PoP location.\n- `\"resolver_ip\"`: Use the DNS resolver GeoIP location. If the GeoIP lookup is unsuccessful, use the Cloudflare PoP location.\nAvailable values: \"pop\", \"resolver_ip\"." + }, + { + "name": "prefer_ecs", + "type": "String", + "description": "Whether the EDNS Client Subnet (ECS) GeoIP should be preferred as the authoritative location.\n- `\"always\"`: Always prefer ECS.\n- `\"never\"`: Never prefer ECS.\n- `\"proximity\"`: Prefer ECS only when `steering_policy=\"proximity\"`.\n- `\"geo\"`: Prefer ECS only when `steering_policy=\"geo\"`.\nAvailable values: \"always\", \"never\", \"proximity\", \"geo\"." + } + ] + }, + { + "name": "pop_pools", + "type": "Map of List of String", + "description": "Enterprise only: A mapping of Cloudflare PoP identifiers to a list of pool IDs (ordered by their failover priority) for the PoP (datacenter). Any PoPs not explicitly defined will fall back to using the corresponding country_pool, then region_pool mapping if it exists else to default_pools." + }, + { + "name": "random_steering", + "type": "Attributes", + "description": "Configures pool weights.\n- `steering_policy=\"random\"`: A random pool is selected with probability proportional to pool weights.\n- `steering_policy=\"least_outstanding_requests\"`: Use pool weights to scale each pool's outstanding requests.\n- `steering_policy=\"least_connections\"`: Use pool weights to scale each pool's open connections.", + "children": [ + { + "name": "default_weight", + "type": "Number", + "description": "The default weight for pools in the load balancer that are not specified in the pool_weights map." + }, + { + "name": "pool_weights", + "type": "Map of Number", + "description": "A mapping of pool IDs to custom weights. The weight is relative to other pools in the load balancer." + } + ] + }, + { + "name": "region_pools", + "type": "Map of List of String", + "description": "A mapping of region codes to a list of pool IDs (ordered by their failover priority) for the given region. Any regions not explicitly defined will fall back to using default_pools." + }, + { + "name": "session_affinity", + "type": "String", + "description": "Specifies the type of session affinity the load balancer should use unless specified as `\"none\"`. The supported types are: - `\"cookie\"`: On the first request to a proxied load balancer, a cookie is generated, encoding information of which origin the request will be forwarded to. Subsequent requests, by the same client to the same load balancer, will be sent to the origin server the cookie encodes, for the duration of the cookie and as long as the origin server remains healthy. If the cookie has expired or the origin server is unhealthy, then a new origin server is calculated and used. - `\"ip_cookie\"`: Behaves the same as `\"cookie\"` except the initial origin selection is stable and based on the client's ip address. - `\"header\"`: On the first request to a proxied load balancer, a session key based on the configured HTTP headers (see `session_affinity_attributes.headers`) is generated, encoding the request headers used for storing in the load balancer session state which origin the request will be forwarded to. Subsequent requests to the load balancer with the same headers will be sent to the same origin server, for the duration of the session and as long as the origin server remains healthy. If the session has been idle for the duration of `session_affinity_ttl` seconds or the origin server is unhealthy, then a new origin server is calculated and used. See `headers` in `session_affinity_attributes` for additional required configuration.\nAvailable values: \"none\", \"cookie\", \"ip_cookie\", \"header\"." + }, + { + "name": "session_affinity_attributes", + "type": "Attributes", + "description": "Configures attributes for session affinity.", + "children": [ + { + "name": "drain_duration", + "type": "Number", + "description": "Configures the drain duration in seconds. This field is only used when session affinity is enabled on the load balancer." + }, + { + "name": "headers", + "type": "List of String", + "description": "Configures the names of HTTP headers to base session affinity on when header `session_affinity` is enabled. At least one HTTP header name must be provided. To specify the exact cookies to be used, include an item in the following format: `\"cookie:,\"` (example) where everything after the colon is a comma-separated list of cookie names. Providing only `\"cookie\"` will result in all cookies being used. The default max number of HTTP header names that can be provided depends on your plan: 5 for Enterprise, 1 for all other plans." + }, + { + "name": "require_all_headers", + "type": "Boolean", + "description": "When header `session_affinity` is enabled, this option can be used to specify how HTTP headers on load balancing requests will be used. The supported values are: - `\"true\"`: Load balancing requests must contain *all* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created. - `\"false\"`: Load balancing requests must contain *at least one* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created." + }, + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on session affinity cookie. Value \"Auto\" will be translated to \"Lax\" or \"None\" depending if Always Use HTTPS is enabled. Note: when using value \"None\", the secure attribute can not be set to \"Never\".\nAvailable values: \"Auto\", \"Lax\", \"None\", \"Strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on session affinity cookie. Value \"Always\" indicates the Secure attribute will be set in the Set-Cookie header, \"Never\" indicates the Secure attribute will not be set, and \"Auto\" will set the Secure attribute depending if Always Use HTTPS is enabled.\nAvailable values: \"Auto\", \"Always\", \"Never\"." + }, + { + "name": "zero_downtime_failover", + "type": "String", + "description": "Configures the zero-downtime failover between origins within a pool when session affinity is enabled. This feature is currently incompatible with Argo, Tiered Cache, and Bandwidth Alliance. The supported values are: - `\"none\"`: No failover takes place for sessions pinned to the origin (default). - `\"temporary\"`: Traffic will be sent to another other healthy origin until the originally pinned origin is available; note that this can potentially result in heavy origin flapping. - `\"sticky\"`: The session affinity cookie is updated and subsequent requests are sent to the new origin. Note: Zero-downtime failover with sticky sessions is currently not supported for session affinity by header.\nAvailable values: \"none\", \"temporary\", \"sticky\"." + } + ] + }, + { + "name": "session_affinity_ttl", + "type": "Number", + "description": "Time, in seconds, until a client's session expires after being created. Once the expiry time has been reached, subsequent requests may get sent to a different origin server. The accepted ranges per `session_affinity` policy are: - `\"cookie\"` / `\"ip_cookie\"`: The current default of 23 hours will be used unless explicitly set. The accepted range of values is between [1800, 604800]. - `\"header\"`: The current default of 1800 seconds will be used unless explicitly set. The accepted range of values is between [30, 3600]. Note: With session affinity by header, sessions only expire after they haven't been used for the number of seconds specified." + }, + { + "name": "steering_policy", + "type": "String", + "description": "Steering Policy for this load balancer.\n- `\"off\"`: Use `default_pools`.\n- `\"geo\"`: Use `region_pools`/`country_pools`/`pop_pools`. For non-proxied requests, the country for `country_pools` is determined by `location_strategy`.\n- `\"random\"`: Select a pool randomly.\n- `\"dynamic_latency\"`: Use round trip time to select the closest pool in default_pools (requires pool health checks).\n- `\"proximity\"`: Use the pools' latitude and longitude to select the closest pool using the Cloudflare PoP location for proxied requests or the location determined by `location_strategy` for non-proxied requests.\n- `\"least_outstanding_requests\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of outstanding requests. Pools with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of open connections. Pools with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\n- `\"\"`: Will map to `\"geo\"` if you use `region_pools`/`country_pools`/`pop_pools` otherwise `\"off\"`.\nAvailable values: \"off\", \"geo\", \"random\", \"dynamic_latency\", \"proximity\", \"least_outstanding_requests\", \"least_connections\", \"\"." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time to live (TTL) of the DNS entry for the IP address returned by this load balancer. This only applies to gray-clouded (unproxied) load balancers." + } + ] + }, + { + "name": "priority", + "type": "Number", + "description": "The order in which rules should be executed in relation to each other. Lower values are executed first. Values do not need to be sequential. If no value is provided for any rule the array order of the rules field will be used to assign a priority." + }, + { + "name": "terminates", + "type": "Boolean", + "description": "If this rule's condition is true, this causes rule evaluation to stop after processing this rule." + } + ] + }, + { + "name": "session_affinity", + "type": "String", + "description": "Specifies the type of session affinity the load balancer should use unless specified as `\"none\"`. The supported types are: - `\"cookie\"`: On the first request to a proxied load balancer, a cookie is generated, encoding information of which origin the request will be forwarded to. Subsequent requests, by the same client to the same load balancer, will be sent to the origin server the cookie encodes, for the duration of the cookie and as long as the origin server remains healthy. If the cookie has expired or the origin server is unhealthy, then a new origin server is calculated and used. - `\"ip_cookie\"`: Behaves the same as `\"cookie\"` except the initial origin selection is stable and based on the client's ip address. - `\"header\"`: On the first request to a proxied load balancer, a session key based on the configured HTTP headers (see `session_affinity_attributes.headers`) is generated, encoding the request headers used for storing in the load balancer session state which origin the request will be forwarded to. Subsequent requests to the load balancer with the same headers will be sent to the same origin server, for the duration of the session and as long as the origin server remains healthy. If the session has been idle for the duration of `session_affinity_ttl` seconds or the origin server is unhealthy, then a new origin server is calculated and used. See `headers` in `session_affinity_attributes` for additional required configuration.\nAvailable values: \"none\", \"cookie\", \"ip_cookie\", \"header\"." + }, + { + "name": "session_affinity_attributes", + "type": "Attributes", + "description": "Configures attributes for session affinity.", + "children": [ + { + "name": "drain_duration", + "type": "Number", + "description": "Configures the drain duration in seconds. This field is only used when session affinity is enabled on the load balancer." + }, + { + "name": "headers", + "type": "List of String", + "description": "Configures the names of HTTP headers to base session affinity on when header `session_affinity` is enabled. At least one HTTP header name must be provided. To specify the exact cookies to be used, include an item in the following format: `\"cookie:,\"` (example) where everything after the colon is a comma-separated list of cookie names. Providing only `\"cookie\"` will result in all cookies being used. The default max number of HTTP header names that can be provided depends on your plan: 5 for Enterprise, 1 for all other plans." + }, + { + "name": "require_all_headers", + "type": "Boolean", + "description": "When header `session_affinity` is enabled, this option can be used to specify how HTTP headers on load balancing requests will be used. The supported values are: - `\"true\"`: Load balancing requests must contain *all* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created. - `\"false\"`: Load balancing requests must contain *at least one* of the HTTP headers specified by the `headers` session affinity attribute, otherwise sessions aren't created." + }, + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on session affinity cookie. Value \"Auto\" will be translated to \"Lax\" or \"None\" depending if Always Use HTTPS is enabled. Note: when using value \"None\", the secure attribute can not be set to \"Never\".\nAvailable values: \"Auto\", \"Lax\", \"None\", \"Strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on session affinity cookie. Value \"Always\" indicates the Secure attribute will be set in the Set-Cookie header, \"Never\" indicates the Secure attribute will not be set, and \"Auto\" will set the Secure attribute depending if Always Use HTTPS is enabled.\nAvailable values: \"Auto\", \"Always\", \"Never\"." + }, + { + "name": "zero_downtime_failover", + "type": "String", + "description": "Configures the zero-downtime failover between origins within a pool when session affinity is enabled. This feature is currently incompatible with Argo, Tiered Cache, and Bandwidth Alliance. The supported values are: - `\"none\"`: No failover takes place for sessions pinned to the origin (default). - `\"temporary\"`: Traffic will be sent to another other healthy origin until the originally pinned origin is available; note that this can potentially result in heavy origin flapping. - `\"sticky\"`: The session affinity cookie is updated and subsequent requests are sent to the new origin. Note: Zero-downtime failover with sticky sessions is currently not supported for session affinity by header.\nAvailable values: \"none\", \"temporary\", \"sticky\"." + } + ] + }, + { + "name": "session_affinity_ttl", + "type": "Number", + "description": "Time, in seconds, until a client's session expires after being created. Once the expiry time has been reached, subsequent requests may get sent to a different origin server. The accepted ranges per `session_affinity` policy are: - `\"cookie\"` / `\"ip_cookie\"`: The current default of 23 hours will be used unless explicitly set. The accepted range of values is between [1800, 604800]. - `\"header\"`: The current default of 1800 seconds will be used unless explicitly set. The accepted range of values is between [30, 3600]. Note: With session affinity by header, sessions only expire after they haven't been used for the number of seconds specified." + }, + { + "name": "steering_policy", + "type": "String", + "description": "Steering Policy for this load balancer.\n- `\"off\"`: Use `default_pools`.\n- `\"geo\"`: Use `region_pools`/`country_pools`/`pop_pools`. For non-proxied requests, the country for `country_pools` is determined by `location_strategy`.\n- `\"random\"`: Select a pool randomly.\n- `\"dynamic_latency\"`: Use round trip time to select the closest pool in default_pools (requires pool health checks).\n- `\"proximity\"`: Use the pools' latitude and longitude to select the closest pool using the Cloudflare PoP location for proxied requests or the location determined by `location_strategy` for non-proxied requests.\n- `\"least_outstanding_requests\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of outstanding requests. Pools with more pending requests are weighted proportionately less relative to others.\n- `\"least_connections\"`: Select a pool by taking into consideration `random_steering` weights, as well as each pool's number of open connections. Pools with more open connections are weighted proportionately less relative to others. Supported for HTTP/1 and HTTP/2 connections.\n- `\"\"`: Will map to `\"geo\"` if you use `region_pools`/`country_pools`/`pop_pools` otherwise `\"off\"`.\nAvailable values: \"off\", \"geo\", \"random\", \"dynamic_latency\", \"proximity\", \"least_outstanding_requests\", \"least_connections\", \"\"." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time to live (TTL) of the DNS entry for the IP address returned by this load balancer. This only applies to gray-clouded (unproxied) load balancers." + }, + { + "name": "zone_name", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_logpull_retention": { + "kind": "data-source", + "name": "cloudflare_logpull_retention", + "description": "Accepted Permissions\n\n- `Logs Read`\n- `Logs Write`", + "example": "data \"cloudflare_logpull_retention\" \"example_logpull_retention\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "flag", + "type": "Boolean", + "description": "The log retention flag for Logpull API." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_logpull_retention": { + "kind": "resource", + "name": "cloudflare_logpull_retention", + "description": "Accepted Permissions\n\n- `Logs Read`\n- `Logs Write`", + "example": "resource \"cloudflare_logpull_retention\" \"example_logpull_retention\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n flag = true\n}", + "importExample": "$ terraform import cloudflare_logpull_retention.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "flag", + "type": "Boolean", + "description": "The log retention flag for Logpull API." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_logpush_dataset_field": { + "kind": "data-source", + "name": "cloudflare_logpush_dataset_field", + "description": "Accepted Permissions\n\n- `Logs Read`", + "example": "data \"cloudflare_logpush_dataset_field\" \"example_logpush_dataset_field\" {\n dataset_id = \"gateway_dns\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "dataset_id", + "type": "String", + "description": "Name of the dataset. A list of supported datasets can be found on the [Developer Docs](https://developers.cloudflare.com/logs/reference/log-fields/).\nAvailable values: \"access_requests\", \"account_abuse_protection_events\", \"audit_logs\", \"audit_logs_v2\", \"biso_user_actions\", \"casb_findings\", \"device_posture_results\", \"dex_application_tests\", \"dex_device_state_events\", \"dlp_forensic_copies\", \"dns_firewall_logs\", \"dns_logs\", \"email_security_alerts\", \"email_security_post_delivery_events\", \"firewall_events\", \"gateway_dns\", \"gateway_http\", \"gateway_network\", \"http_requests\", \"ipsec_logs\", \"magic_bgp_logs\", \"magic_ids_detections\", \"mcp_portal_logs\", \"mnm_flow_logs\", \"nel_reports\", \"network_analytics_logs\", \"page_shield_events\", \"sinkhole_http_logs\", \"spectrum_events\", \"ssh_logs\", \"turnstile_events\", \"warp_config_changes\", \"warp_toggle_changes\", \"websocket_analytics\", \"workers_trace_events\", \"zaraz_events\", \"zero_trust_network_sessions\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "fields", + "type": "Map of String" + } + ] + }, + "data-source:cloudflare_logpush_dataset_job": { + "kind": "data-source", + "name": "cloudflare_logpush_dataset_job", + "description": "Accepted Permissions\n\n- `Logs Write`", + "example": "data \"cloudflare_logpush_dataset_job\" \"example_logpush_dataset_job\" {\n dataset_id = \"gateway_dns\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "dataset_id", + "type": "String", + "description": "Name of the dataset. A list of supported datasets can be found on the [Developer Docs](https://developers.cloudflare.com/logs/reference/log-fields/).\nAvailable values: \"access_requests\", \"account_abuse_protection_events\", \"audit_logs\", \"audit_logs_v2\", \"biso_user_actions\", \"casb_findings\", \"device_posture_results\", \"dex_application_tests\", \"dex_device_state_events\", \"dlp_forensic_copies\", \"dns_firewall_logs\", \"dns_logs\", \"email_security_alerts\", \"email_security_post_delivery_events\", \"firewall_events\", \"gateway_dns\", \"gateway_http\", \"gateway_network\", \"http_requests\", \"ipsec_logs\", \"magic_bgp_logs\", \"magic_ids_detections\", \"mcp_portal_logs\", \"mnm_flow_logs\", \"nel_reports\", \"network_analytics_logs\", \"page_shield_events\", \"sinkhole_http_logs\", \"spectrum_events\", \"ssh_logs\", \"turnstile_events\", \"warp_config_changes\", \"warp_toggle_changes\", \"websocket_analytics\", \"workers_trace_events\", \"zaraz_events\", \"zero_trust_network_sessions\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset. A list of supported datasets can be found on the [Developer Docs](https://developers.cloudflare.com/logs/reference/log-fields/).\nAvailable values: \"access_requests\", \"account_abuse_protection_events\", \"audit_logs\", \"audit_logs_v2\", \"biso_user_actions\", \"casb_findings\", \"device_posture_results\", \"dex_application_tests\", \"dex_device_state_events\", \"dlp_forensic_copies\", \"dns_firewall_logs\", \"dns_logs\", \"email_security_alerts\", \"email_security_post_delivery_events\", \"firewall_events\", \"gateway_dns\", \"gateway_http\", \"gateway_network\", \"http_requests\", \"ipsec_logs\", \"magic_bgp_logs\", \"magic_ids_detections\", \"mcp_portal_logs\", \"mnm_flow_logs\", \"nel_reports\", \"network_analytics_logs\", \"page_shield_events\", \"sinkhole_http_logs\", \"spectrum_events\", \"ssh_logs\", \"turnstile_events\", \"warp_config_changes\", \"warp_toggle_changes\", \"websocket_analytics\", \"workers_trace_events\", \"zaraz_events\", \"zero_trust_network_sessions\"." + }, + { + "name": "destination_conf", + "type": "String", + "description": "Uniquely identifies a resource (such as an s3 bucket) where data. will be pushed. Additional configuration parameters supported by the destination may be included.", + "sensitive": true + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Flag that indicates if the job is enabled." + }, + { + "name": "error_message", + "type": "String", + "description": "If not null, the job is currently failing. Failures are usually. repetitive (example: no permissions to write to destination bucket). Only the last failure is recorded. On successful execution of a job the error_message and last_error are set to null." + }, + { + "name": "filter_attack_traffic", + "type": "Boolean", + "description": "When true, excludes DDoS attack traffic from logs. This option is supported for the `http_requests`, `firewall_events`, and `network_analytics_logs` datasets." + }, + { + "name": "frequency", + "type": "String", + "description": "This field is deprecated. Please use `max_upload_*` parameters instead. . The frequency at which Cloudflare sends batches of logs to your destination. Setting frequency to high sends your logs in larger quantities of smaller files. Setting frequency to low sends logs in smaller quantities of larger files.\nAvailable values: \"high\", \"low\".", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "Number", + "description": "Unique id of the job." + }, + { + "name": "kind", + "type": "String", + "description": "The kind parameter (optional) is used to differentiate between Logpush and Edge Log Delivery jobs (when supported by the dataset).\nAvailable values: \"\", \"edge\"." + }, + { + "name": "last_complete", + "type": "String", + "description": "Records the last time for which logs have been successfully pushed. If the last successful push was for logs range 2018-07-23T10:00:00Z to 2018-07-23T10:01:00Z then the value of this field will be 2018-07-23T10:01:00Z. If the job has never run or has just been enabled and hasn't run yet then the field will be empty." + }, + { + "name": "last_error", + "type": "String", + "description": "Records the last time the job failed. If not null, the job is currently. failing. If null, the job has either never failed or has run successfully at least once since last failure. See also the error_message field." + }, + { + "name": "logpull_options", + "type": "String", + "description": "This field is deprecated. Use `output_options` instead. Configuration string. It specifies things like requested fields and timestamp formats. If migrating from the logpull api, copy the url (full url or just the query string) of your call here, and logpush will keep on making this call for you, setting start and end times appropriately.", + "deprecated": "Deprecated." + }, + { + "name": "max_upload_bytes", + "type": "Number", + "description": "The maximum uncompressed file size of a batch of logs. This setting value must be between `5 MB` and `1 GB`, or `0` to disable it. Note that you cannot set a minimum file size; this means that log files may be much smaller than this batch size." + }, + { + "name": "max_upload_interval_seconds", + "type": "Number", + "description": "The maximum interval in seconds for log batches. This setting must be between 30 and 300 seconds (5 minutes), or `0` to disable it. Note that you cannot specify a minimum interval for log batches; this means that log files may be sent in shorter intervals than this." + }, + { + "name": "max_upload_records", + "type": "Number", + "description": "The maximum number of log lines per batch. This setting must be between 1000 and 1,000,000 lines, or `0` to disable it. Note that you cannot specify a minimum number of log lines per batch; this means that log files may contain many fewer lines than this." + }, + { + "name": "name", + "type": "String", + "description": "Optional human readable job name. Not unique. Cloudflare suggests. that you set this to a meaningful string, like the domain name, to make it easier to identify your job." + }, + { + "name": "output_options", + "type": "Attributes", + "description": "The structured replacement for `logpull_options`. When including this field, the `logpull_option` field will be ignored.", + "children": [ + { + "name": "batch_prefix", + "type": "String", + "description": "String to be prepended before each batch." + }, + { + "name": "batch_suffix", + "type": "String", + "description": "String to be appended after each batch." + }, + { + "name": "cve_2021_44228", + "type": "Boolean", + "description": "If set to true, will cause all occurrences of `${` in the generated files to be replaced with `x{`." + }, + { + "name": "field_delimiter", + "type": "String", + "description": "String to join fields. This field be ignored when `record_template` is set." + }, + { + "name": "field_names", + "type": "List of String", + "description": "List of field names to be included in the Logpush output. For the moment, there is no option to add all fields at once, so you must specify all the fields names you are interested in." + }, + { + "name": "merge_subrequests", + "type": "Boolean", + "description": "If set to true, subrequests will be merged into the parent request. Only supported for the `http_requests` dataset. Not supported for account-scoped jobs." + }, + { + "name": "output_type", + "type": "String", + "description": "Specifies the output type, such as `ndjson` or `csv`. This sets default values for the rest of the settings, depending on the chosen output type. Some formatting rules, like string quoting, are different between output types.\nAvailable values: \"ndjson\", \"csv\"." + }, + { + "name": "record_delimiter", + "type": "String", + "description": "String to be inserted in-between the records as separator." + }, + { + "name": "record_prefix", + "type": "String", + "description": "String to be prepended before each record." + }, + { + "name": "record_suffix", + "type": "String", + "description": "String to be appended after each record." + }, + { + "name": "record_template", + "type": "String", + "description": "String to use as template for each record instead of the default json key value mapping. All fields used in the template must be present in `field_names` as well, otherwise they will end up as null. Format as a Go `text/template` without any standard functions, like conditionals, loops, sub-templates, etc." + }, + { + "name": "sample_rate", + "type": "Number", + "description": "Specifies the sampling rate as a floating number greater than 0 and at most 1. Sampling is applied on top of filtering, and regardless of the current `sample_interval` of the data." + }, + { + "name": "timestamp_format", + "type": "String", + "description": "String to specify the format for timestamps, such as `unixnano`, `unix`, `rfc3339`, `rfc3339ms` or `rfc3339ns`.\nAvailable values: \"unixnano\", \"unix\", \"rfc3339\", \"rfc3339ms\", \"rfc3339ns\"." + } + ] + } + ] + }, + "data-source:cloudflare_logpush_job": { + "kind": "data-source", + "name": "cloudflare_logpush_job", + "description": "Accepted Permissions\n\n- `Logs Write`", + "example": "data \"cloudflare_logpush_job\" \"example_logpush_job\" {\n job_id = 1\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "job_id", + "type": "Number", + "description": "Unique id of the job." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset. A list of supported datasets can be found on the [Developer Docs](https://developers.cloudflare.com/logs/reference/log-fields/).\nAvailable values: \"access_requests\", \"account_abuse_protection_events\", \"audit_logs\", \"audit_logs_v2\", \"biso_user_actions\", \"casb_findings\", \"device_posture_results\", \"dex_application_tests\", \"dex_device_state_events\", \"dlp_forensic_copies\", \"dns_firewall_logs\", \"dns_logs\", \"email_security_alerts\", \"email_security_post_delivery_events\", \"firewall_events\", \"gateway_dns\", \"gateway_http\", \"gateway_network\", \"http_requests\", \"ipsec_logs\", \"magic_bgp_logs\", \"magic_ids_detections\", \"mcp_portal_logs\", \"mnm_flow_logs\", \"nel_reports\", \"network_analytics_logs\", \"page_shield_events\", \"sinkhole_http_logs\", \"spectrum_events\", \"ssh_logs\", \"turnstile_events\", \"warp_config_changes\", \"warp_toggle_changes\", \"websocket_analytics\", \"workers_trace_events\", \"zaraz_events\", \"zero_trust_network_sessions\"." + }, + { + "name": "destination_conf", + "type": "String", + "description": "Uniquely identifies a resource (such as an s3 bucket) where data. will be pushed. Additional configuration parameters supported by the destination may be included.", + "sensitive": true + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Flag that indicates if the job is enabled." + }, + { + "name": "error_message", + "type": "String", + "description": "If not null, the job is currently failing. Failures are usually. repetitive (example: no permissions to write to destination bucket). Only the last failure is recorded. On successful execution of a job the error_message and last_error are set to null." + }, + { + "name": "filter_attack_traffic", + "type": "Boolean", + "description": "When true, excludes DDoS attack traffic from logs. This option is supported for the `http_requests`, `firewall_events`, and `network_analytics_logs` datasets." + }, + { + "name": "frequency", + "type": "String", + "description": "This field is deprecated. Please use `max_upload_*` parameters instead. . The frequency at which Cloudflare sends batches of logs to your destination. Setting frequency to high sends your logs in larger quantities of smaller files. Setting frequency to low sends logs in smaller quantities of larger files.\nAvailable values: \"high\", \"low\".", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "Number", + "description": "Unique id of the job." + }, + { + "name": "kind", + "type": "String", + "description": "The kind parameter (optional) is used to differentiate between Logpush and Edge Log Delivery jobs (when supported by the dataset).\nAvailable values: \"\", \"edge\"." + }, + { + "name": "last_complete", + "type": "String", + "description": "Records the last time for which logs have been successfully pushed. If the last successful push was for logs range 2018-07-23T10:00:00Z to 2018-07-23T10:01:00Z then the value of this field will be 2018-07-23T10:01:00Z. If the job has never run or has just been enabled and hasn't run yet then the field will be empty." + }, + { + "name": "last_error", + "type": "String", + "description": "Records the last time the job failed. If not null, the job is currently. failing. If null, the job has either never failed or has run successfully at least once since last failure. See also the error_message field." + }, + { + "name": "logpull_options", + "type": "String", + "description": "This field is deprecated. Use `output_options` instead. Configuration string. It specifies things like requested fields and timestamp formats. If migrating from the logpull api, copy the url (full url or just the query string) of your call here, and logpush will keep on making this call for you, setting start and end times appropriately.", + "deprecated": "Deprecated." + }, + { + "name": "max_upload_bytes", + "type": "Number", + "description": "The maximum uncompressed file size of a batch of logs. This setting value must be between `5 MB` and `1 GB`, or `0` to disable it. Note that you cannot set a minimum file size; this means that log files may be much smaller than this batch size." + }, + { + "name": "max_upload_interval_seconds", + "type": "Number", + "description": "The maximum interval in seconds for log batches. This setting must be between 30 and 300 seconds (5 minutes), or `0` to disable it. Note that you cannot specify a minimum interval for log batches; this means that log files may be sent in shorter intervals than this." + }, + { + "name": "max_upload_records", + "type": "Number", + "description": "The maximum number of log lines per batch. This setting must be between 1000 and 1,000,000 lines, or `0` to disable it. Note that you cannot specify a minimum number of log lines per batch; this means that log files may contain many fewer lines than this." + }, + { + "name": "name", + "type": "String", + "description": "Optional human readable job name. Not unique. Cloudflare suggests. that you set this to a meaningful string, like the domain name, to make it easier to identify your job." + }, + { + "name": "output_options", + "type": "Attributes", + "description": "The structured replacement for `logpull_options`. When including this field, the `logpull_option` field will be ignored.", + "children": [ + { + "name": "batch_prefix", + "type": "String", + "description": "String to be prepended before each batch." + }, + { + "name": "batch_suffix", + "type": "String", + "description": "String to be appended after each batch." + }, + { + "name": "cve_2021_44228", + "type": "Boolean", + "description": "If set to true, will cause all occurrences of `${` in the generated files to be replaced with `x{`." + }, + { + "name": "field_delimiter", + "type": "String", + "description": "String to join fields. This field be ignored when `record_template` is set." + }, + { + "name": "field_names", + "type": "List of String", + "description": "List of field names to be included in the Logpush output. For the moment, there is no option to add all fields at once, so you must specify all the fields names you are interested in." + }, + { + "name": "merge_subrequests", + "type": "Boolean", + "description": "If set to true, subrequests will be merged into the parent request. Only supported for the `http_requests` dataset. Not supported for account-scoped jobs." + }, + { + "name": "output_type", + "type": "String", + "description": "Specifies the output type, such as `ndjson` or `csv`. This sets default values for the rest of the settings, depending on the chosen output type. Some formatting rules, like string quoting, are different between output types.\nAvailable values: \"ndjson\", \"csv\"." + }, + { + "name": "record_delimiter", + "type": "String", + "description": "String to be inserted in-between the records as separator." + }, + { + "name": "record_prefix", + "type": "String", + "description": "String to be prepended before each record." + }, + { + "name": "record_suffix", + "type": "String", + "description": "String to be appended after each record." + }, + { + "name": "record_template", + "type": "String", + "description": "String to use as template for each record instead of the default json key value mapping. All fields used in the template must be present in `field_names` as well, otherwise they will end up as null. Format as a Go `text/template` without any standard functions, like conditionals, loops, sub-templates, etc." + }, + { + "name": "sample_rate", + "type": "Number", + "description": "Specifies the sampling rate as a floating number greater than 0 and at most 1. Sampling is applied on top of filtering, and regardless of the current `sample_interval` of the data." + }, + { + "name": "timestamp_format", + "type": "String", + "description": "String to specify the format for timestamps, such as `unixnano`, `unix`, `rfc3339`, `rfc3339ms` or `rfc3339ns`.\nAvailable values: \"unixnano\", \"unix\", \"rfc3339\", \"rfc3339ms\", \"rfc3339ns\"." + } + ] + } + ] + }, + "resource:cloudflare_logpush_job": { + "kind": "resource", + "name": "cloudflare_logpush_job", + "description": "Accepted Permissions\n\n- `Logs Write`", + "example": "resource \"cloudflare_logpush_job\" \"example_logpush_job\" {\n destination_conf = \"s3://mybucket/logs?region=us-west-2\"\n zone_id = \"zone_id\"\n dataset = \"http_requests\"\n enabled = false\n filter = \"{\\\"where\\\":{\\\"and\\\":[{\\\"key\\\":\\\"ClientRequestPath\\\",\\\"operator\\\":\\\"contains\\\",\\\"value\\\":\\\"/static\\\"},{\\\"key\\\":\\\"ClientRequestHost\\\",\\\"operator\\\":\\\"eq\\\",\\\"value\\\":\\\"example.com\\\"}]}}\"\n filter_attack_traffic = true\n frequency = \"high\"\n kind = \"\"\n logpull_options = \"fields=RayID,ClientIP,EdgeStartTimestamp×tamps=rfc3339\"\n max_upload_bytes = 5000000\n max_upload_interval_seconds = 30\n max_upload_records = 1000\n name = \"example.com\"\n output_options = {\n batch_prefix = \"batch_prefix\"\n batch_suffix = \"batch_suffix\"\n cve_2021_44228 = true\n field_delimiter = \"field_delimiter\"\n field_names = [\"ClientIP\", \"EdgeStartTimestamp\", \"RayID\"]\n merge_subrequests = true\n output_type = \"ndjson\"\n record_delimiter = \"record_delimiter\"\n record_prefix = \"record_prefix\"\n record_suffix = \"record_suffix\"\n record_template = \"record_template\"\n sample_rate = 1\n timestamp_format = \"unixnano\"\n }\n ownership_challenge = \"00000000000000000000\"\n}", + "importExample": "$ terraform import cloudflare_logpush_job.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "destination_conf", + "type": "String", + "description": "Uniquely identifies a resource (such as an s3 bucket) where data. will be pushed. Additional configuration parameters supported by the destination may be included.", + "sensitive": true + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset. A list of supported datasets can be found on the [Developer Docs](https://developers.cloudflare.com/logs/reference/log-fields/).\nAvailable values: \"access_requests\", \"account_abuse_protection_events\", \"audit_logs\", \"audit_logs_v2\", \"biso_user_actions\", \"casb_findings\", \"device_posture_results\", \"dex_application_tests\", \"dex_device_state_events\", \"dlp_forensic_copies\", \"dns_firewall_logs\", \"dns_logs\", \"email_security_alerts\", \"email_security_post_delivery_events\", \"firewall_events\", \"gateway_dns\", \"gateway_http\", \"gateway_network\", \"http_requests\", \"ipsec_logs\", \"magic_bgp_logs\", \"magic_ids_detections\", \"mcp_portal_logs\", \"mnm_flow_logs\", \"nel_reports\", \"network_analytics_logs\", \"page_shield_events\", \"sinkhole_http_logs\", \"spectrum_events\", \"ssh_logs\", \"turnstile_events\", \"warp_config_changes\", \"warp_toggle_changes\", \"websocket_analytics\", \"workers_trace_events\", \"zaraz_events\", \"zero_trust_network_sessions\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Flag that indicates if the job is enabled." + }, + { + "name": "filter", + "type": "String", + "description": "The filters to select the events to include and/or remove from your logs. For more information, refer to [Filters](https://developers.cloudflare.com/logs/reference/filters/)." + }, + { + "name": "filter_attack_traffic", + "type": "Boolean", + "description": "When true, excludes DDoS attack traffic from logs. This option is supported for the `http_requests`, `firewall_events`, and `network_analytics_logs` datasets." + }, + { + "name": "frequency", + "type": "String", + "description": "This field is deprecated. Please use `max_upload_*` parameters instead. . The frequency at which Cloudflare sends batches of logs to your destination. Setting frequency to high sends your logs in larger quantities of smaller files. Setting frequency to low sends logs in smaller quantities of larger files.\nAvailable values: \"high\", \"low\".", + "deprecated": "Deprecated." + }, + { + "name": "kind", + "type": "String", + "description": "The kind parameter (optional) is used to differentiate between Logpush and Edge Log Delivery jobs (when supported by the dataset).\nAvailable values: \"\", \"edge\"." + }, + { + "name": "logpull_options", + "type": "String", + "description": "This field is deprecated. Use `output_options` instead. Configuration string. It specifies things like requested fields and timestamp formats. If migrating from the logpull api, copy the url (full url or just the query string) of your call here, and logpush will keep on making this call for you, setting start and end times appropriately.", + "deprecated": "Deprecated." + }, + { + "name": "max_upload_bytes", + "type": "Number", + "description": "The maximum uncompressed file size of a batch of logs. This setting value must be between `5 MB` and `1 GB`, or `0` to disable it. Note that you cannot set a minimum file size; this means that log files may be much smaller than this batch size." + }, + { + "name": "max_upload_interval_seconds", + "type": "Number", + "description": "The maximum interval in seconds for log batches. This setting must be between 30 and 300 seconds (5 minutes), or `0` to disable it. Note that you cannot specify a minimum interval for log batches; this means that log files may be sent in shorter intervals than this." + }, + { + "name": "max_upload_records", + "type": "Number", + "description": "The maximum number of log lines per batch. This setting must be between 1000 and 1,000,000 lines, or `0` to disable it. Note that you cannot specify a minimum number of log lines per batch; this means that log files may contain many fewer lines than this." + }, + { + "name": "name", + "type": "String", + "description": "Optional human readable job name. Not unique. Cloudflare suggests. that you set this to a meaningful string, like the domain name, to make it easier to identify your job." + }, + { + "name": "output_options", + "type": "Attributes", + "description": "The structured replacement for `logpull_options`. When including this field, the `logpull_option` field will be ignored.", + "children": [ + { + "name": "batch_prefix", + "type": "String", + "description": "String to be prepended before each batch." + }, + { + "name": "batch_suffix", + "type": "String", + "description": "String to be appended after each batch." + }, + { + "name": "cve_2021_44228", + "type": "Boolean", + "description": "If set to true, will cause all occurrences of `${` in the generated files to be replaced with `x{`." + }, + { + "name": "field_delimiter", + "type": "String", + "description": "String to join fields. This field be ignored when `record_template` is set." + }, + { + "name": "field_names", + "type": "List of String", + "description": "List of field names to be included in the Logpush output. For the moment, there is no option to add all fields at once, so you must specify all the fields names you are interested in." + }, + { + "name": "merge_subrequests", + "type": "Boolean", + "description": "If set to true, subrequests will be merged into the parent request. Only supported for the `http_requests` dataset. Not supported for account-scoped jobs." + }, + { + "name": "output_type", + "type": "String", + "description": "Specifies the output type, such as `ndjson` or `csv`. This sets default values for the rest of the settings, depending on the chosen output type. Some formatting rules, like string quoting, are different between output types.\nAvailable values: \"ndjson\", \"csv\"." + }, + { + "name": "record_delimiter", + "type": "String", + "description": "String to be inserted in-between the records as separator." + }, + { + "name": "record_prefix", + "type": "String", + "description": "String to be prepended before each record." + }, + { + "name": "record_suffix", + "type": "String", + "description": "String to be appended after each record." + }, + { + "name": "record_template", + "type": "String", + "description": "String to use as template for each record instead of the default json key value mapping. All fields used in the template must be present in `field_names` as well, otherwise they will end up as null. Format as a Go `text/template` without any standard functions, like conditionals, loops, sub-templates, etc." + }, + { + "name": "sample_rate", + "type": "Number", + "description": "Specifies the sampling rate as a floating number greater than 0 and at most 1. Sampling is applied on top of filtering, and regardless of the current `sample_interval` of the data." + }, + { + "name": "timestamp_format", + "type": "String", + "description": "String to specify the format for timestamps, such as `unixnano`, `unix`, `rfc3339`, `rfc3339ms` or `rfc3339ns`.\nAvailable values: \"unixnano\", \"unix\", \"rfc3339\", \"rfc3339ms\", \"rfc3339ns\"." + } + ] + }, + { + "name": "ownership_challenge", + "type": "String", + "description": "Ownership challenge token to prove destination ownership.", + "sensitive": true + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "error_message", + "type": "String", + "description": "If not null, the job is currently failing. Failures are usually. repetitive (example: no permissions to write to destination bucket). Only the last failure is recorded. On successful execution of a job the error_message and last_error are set to null." + }, + { + "name": "id", + "type": "Number", + "description": "Unique id of the job." + }, + { + "name": "last_complete", + "type": "String", + "description": "Records the last time for which logs have been successfully pushed. If the last successful push was for logs range 2018-07-23T10:00:00Z to 2018-07-23T10:01:00Z then the value of this field will be 2018-07-23T10:01:00Z. If the job has never run or has just been enabled and hasn't run yet then the field will be empty." + }, + { + "name": "last_error", + "type": "String", + "description": "Records the last time the job failed. If not null, the job is currently. failing. If null, the job has either never failed or has run successfully at least once since last failure. See also the error_message field." + } + ] + }, + "list-data-source:cloudflare_logpush_jobs": { + "kind": "list-data-source", + "name": "cloudflare_logpush_jobs", + "description": "Accepted Permissions\n\n- `Logs Write`", + "example": "data \"cloudflare_logpush_jobs\" \"example_logpush_jobs\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset. A list of supported datasets can be found on the [Developer Docs](https://developers.cloudflare.com/logs/reference/log-fields/).\nAvailable values: \"access_requests\", \"account_abuse_protection_events\", \"audit_logs\", \"audit_logs_v2\", \"biso_user_actions\", \"casb_findings\", \"device_posture_results\", \"dex_application_tests\", \"dex_device_state_events\", \"dlp_forensic_copies\", \"dns_firewall_logs\", \"dns_logs\", \"email_security_alerts\", \"email_security_post_delivery_events\", \"firewall_events\", \"gateway_dns\", \"gateway_http\", \"gateway_network\", \"http_requests\", \"ipsec_logs\", \"magic_bgp_logs\", \"magic_ids_detections\", \"mcp_portal_logs\", \"mnm_flow_logs\", \"nel_reports\", \"network_analytics_logs\", \"page_shield_events\", \"sinkhole_http_logs\", \"spectrum_events\", \"ssh_logs\", \"turnstile_events\", \"warp_config_changes\", \"warp_toggle_changes\", \"websocket_analytics\", \"workers_trace_events\", \"zaraz_events\", \"zero_trust_network_sessions\"." + }, + { + "name": "destination_conf", + "type": "String", + "description": "Uniquely identifies a resource (such as an s3 bucket) where data. will be pushed. Additional configuration parameters supported by the destination may be included.", + "sensitive": true + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Flag that indicates if the job is enabled." + }, + { + "name": "error_message", + "type": "String", + "description": "If not null, the job is currently failing. Failures are usually. repetitive (example: no permissions to write to destination bucket). Only the last failure is recorded. On successful execution of a job the error_message and last_error are set to null." + }, + { + "name": "filter_attack_traffic", + "type": "Boolean", + "description": "When true, excludes DDoS attack traffic from logs. This option is supported for the `http_requests`, `firewall_events`, and `network_analytics_logs` datasets." + }, + { + "name": "frequency", + "type": "String", + "description": "This field is deprecated. Please use `max_upload_*` parameters instead. . The frequency at which Cloudflare sends batches of logs to your destination. Setting frequency to high sends your logs in larger quantities of smaller files. Setting frequency to low sends logs in smaller quantities of larger files.\nAvailable values: \"high\", \"low\".", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "Number", + "description": "Unique id of the job." + }, + { + "name": "kind", + "type": "String", + "description": "The kind parameter (optional) is used to differentiate between Logpush and Edge Log Delivery jobs (when supported by the dataset).\nAvailable values: \"\", \"edge\"." + }, + { + "name": "last_complete", + "type": "String", + "description": "Records the last time for which logs have been successfully pushed. If the last successful push was for logs range 2018-07-23T10:00:00Z to 2018-07-23T10:01:00Z then the value of this field will be 2018-07-23T10:01:00Z. If the job has never run or has just been enabled and hasn't run yet then the field will be empty." + }, + { + "name": "last_error", + "type": "String", + "description": "Records the last time the job failed. If not null, the job is currently. failing. If null, the job has either never failed or has run successfully at least once since last failure. See also the error_message field." + }, + { + "name": "logpull_options", + "type": "String", + "description": "This field is deprecated. Use `output_options` instead. Configuration string. It specifies things like requested fields and timestamp formats. If migrating from the logpull api, copy the url (full url or just the query string) of your call here, and logpush will keep on making this call for you, setting start and end times appropriately.", + "deprecated": "Deprecated." + }, + { + "name": "max_upload_bytes", + "type": "Number", + "description": "The maximum uncompressed file size of a batch of logs. This setting value must be between `5 MB` and `1 GB`, or `0` to disable it. Note that you cannot set a minimum file size; this means that log files may be much smaller than this batch size." + }, + { + "name": "max_upload_interval_seconds", + "type": "Number", + "description": "The maximum interval in seconds for log batches. This setting must be between 30 and 300 seconds (5 minutes), or `0` to disable it. Note that you cannot specify a minimum interval for log batches; this means that log files may be sent in shorter intervals than this." + }, + { + "name": "max_upload_records", + "type": "Number", + "description": "The maximum number of log lines per batch. This setting must be between 1000 and 1,000,000 lines, or `0` to disable it. Note that you cannot specify a minimum number of log lines per batch; this means that log files may contain many fewer lines than this." + }, + { + "name": "name", + "type": "String", + "description": "Optional human readable job name. Not unique. Cloudflare suggests. that you set this to a meaningful string, like the domain name, to make it easier to identify your job." + }, + { + "name": "output_options", + "type": "Attributes", + "description": "The structured replacement for `logpull_options`. When including this field, the `logpull_option` field will be ignored.", + "children": [ + { + "name": "batch_prefix", + "type": "String", + "description": "String to be prepended before each batch." + }, + { + "name": "batch_suffix", + "type": "String", + "description": "String to be appended after each batch." + }, + { + "name": "cve_2021_44228", + "type": "Boolean", + "description": "If set to true, will cause all occurrences of `${` in the generated files to be replaced with `x{`." + }, + { + "name": "field_delimiter", + "type": "String", + "description": "String to join fields. This field be ignored when `record_template` is set." + }, + { + "name": "field_names", + "type": "List of String", + "description": "List of field names to be included in the Logpush output. For the moment, there is no option to add all fields at once, so you must specify all the fields names you are interested in." + }, + { + "name": "merge_subrequests", + "type": "Boolean", + "description": "If set to true, subrequests will be merged into the parent request. Only supported for the `http_requests` dataset. Not supported for account-scoped jobs." + }, + { + "name": "output_type", + "type": "String", + "description": "Specifies the output type, such as `ndjson` or `csv`. This sets default values for the rest of the settings, depending on the chosen output type. Some formatting rules, like string quoting, are different between output types.\nAvailable values: \"ndjson\", \"csv\"." + }, + { + "name": "record_delimiter", + "type": "String", + "description": "String to be inserted in-between the records as separator." + }, + { + "name": "record_prefix", + "type": "String", + "description": "String to be prepended before each record." + }, + { + "name": "record_suffix", + "type": "String", + "description": "String to be appended after each record." + }, + { + "name": "record_template", + "type": "String", + "description": "String to use as template for each record instead of the default json key value mapping. All fields used in the template must be present in `field_names` as well, otherwise they will end up as null. Format as a Go `text/template` without any standard functions, like conditionals, loops, sub-templates, etc." + }, + { + "name": "sample_rate", + "type": "Number", + "description": "Specifies the sampling rate as a floating number greater than 0 and at most 1. Sampling is applied on top of filtering, and regardless of the current `sample_interval` of the data." + }, + { + "name": "timestamp_format", + "type": "String", + "description": "String to specify the format for timestamps, such as `unixnano`, `unix`, `rfc3339`, `rfc3339ms` or `rfc3339ns`.\nAvailable values: \"unixnano\", \"unix\", \"rfc3339\", \"rfc3339ms\", \"rfc3339ns\"." + } + ] + } + ] + } + ] + }, + "resource:cloudflare_logpush_ownership_challenge": { + "kind": "resource", + "name": "cloudflare_logpush_ownership_challenge", + "description": "Accepted Permissions\n\n- `Logs Write`", + "example": "resource \"cloudflare_logpush_ownership_challenge\" \"example_logpush_ownership_challenge\" {\n destination_conf = \"s3://mybucket/logs?region=us-west-2\"\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "destination_conf", + "type": "String", + "description": "Uniquely identifies a resource (such as an s3 bucket) where data. will be pushed. Additional configuration parameters supported by the destination may be included.", + "sensitive": true + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "filename", + "type": "String" + }, + { + "name": "message", + "type": "String" + }, + { + "name": "valid", + "type": "Boolean" + } + ] + }, + "data-source:cloudflare_magic_network_monitoring_configuration": { + "kind": "data-source", + "name": "cloudflare_magic_network_monitoring_configuration", + "description": "Accepted Permissions\n\n- `Magic Network Monitoring Admin`\n- `Magic Network Monitoring Config Read`\n- `Magic Network Monitoring Config Write`", + "example": "data \"cloudflare_magic_network_monitoring_configuration\" \"example_magic_network_monitoring_configuration\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "default_sampling", + "type": "Number", + "description": "Fallback sampling rate of flow messages being sent in packets per second. This should match the packet sampling rate configured on the router." + }, + { + "name": "name", + "type": "String", + "description": "The account name." + }, + { + "name": "router_ips", + "type": "List of String" + }, + { + "name": "warp_devices", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "Unique identifier for the warp device." + }, + { + "name": "name", + "type": "String", + "description": "Name of the warp device." + }, + { + "name": "router_ip", + "type": "String", + "description": "IPv4 CIDR of the router sourcing flow data associated with this warp device. Only /32 addresses are currently supported." + } + ] + } + ] + }, + "resource:cloudflare_magic_network_monitoring_configuration": { + "kind": "resource", + "name": "cloudflare_magic_network_monitoring_configuration", + "description": "Accepted Permissions\n\n- `Magic Network Monitoring Admin`\n- `Magic Network Monitoring Config Read`\n- `Magic Network Monitoring Config Write`", + "example": "resource \"cloudflare_magic_network_monitoring_configuration\" \"example_magic_network_monitoring_configuration\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n default_sampling = 1\n name = \"cloudflare user\\'s account\"\n router_ips = [\"203.0.113.1\"]\n warp_devices = [{\n id = \"5360368d-b351-4791-abe1-93550dabd351\"\n name = \"My warp device\"\n router_ip = \"203.0.113.1\"\n }]\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The account name." + } + ], + "optional": [ + { + "name": "default_sampling", + "type": "Number", + "description": "Fallback sampling rate of flow messages being sent in packets per second. This should match the packet sampling rate configured on the router." + }, + { + "name": "router_ips", + "type": "List of String" + }, + { + "name": "warp_devices", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "Unique identifier for the warp device." + }, + { + "name": "name", + "type": "String", + "description": "Name of the warp device." + }, + { + "name": "router_ip", + "type": "String", + "description": "IPv4 CIDR of the router sourcing flow data associated with this warp device. Only /32 addresses are currently supported." + } + ] + } + ], + "computed": [] + }, + "data-source:cloudflare_magic_network_monitoring_rule": { + "kind": "data-source", + "name": "cloudflare_magic_network_monitoring_rule", + "description": "Accepted Permissions\n\n- `Magic Network Monitoring Admin`\n- `Magic Network Monitoring Config Read`\n- `Magic Network Monitoring Config Write`", + "example": "data \"cloudflare_magic_network_monitoring_rule\" \"example_magic_network_monitoring_rule\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n rule_id = \"2890e6fa406311ed9b5a23f70f6fb8cf\"\n}", + "required": [ + { + "name": "rule_id", + "type": "String", + "description": "The id of the rule. Must be unique." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "automatic_advertisement", + "type": "Boolean", + "description": "Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit." + }, + { + "name": "bandwidth_threshold", + "type": "Number", + "description": "The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum." + }, + { + "name": "duration", + "type": "String", + "description": "The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"].\nAvailable values: \"1m\", \"5m\", \"10m\", \"15m\", \"20m\", \"30m\", \"45m\", \"60m\"." + }, + { + "name": "id", + "type": "String", + "description": "The id of the rule. Must be unique." + }, + { + "name": "name", + "type": "String", + "description": "The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters." + }, + { + "name": "packet_threshold", + "type": "Number", + "description": "The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum." + }, + { + "name": "prefix_match", + "type": "String", + "description": "Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule.\nAvailable values: \"exact\", \"subnet\", \"supernet\"." + }, + { + "name": "prefixes", + "type": "List of String" + }, + { + "name": "type", + "type": "String", + "description": "MNM rule type.\nAvailable values: \"threshold\", \"zscore\", \"advanced_ddos\"." + }, + { + "name": "zscore_sensitivity", + "type": "String", + "description": "Level of sensitivity set for zscore rules.\nAvailable values: \"low\", \"medium\", \"high\"." + }, + { + "name": "zscore_target", + "type": "String", + "description": "Target of the zscore rule analysis.\nAvailable values: \"bits\", \"packets\"." + } + ] + }, + "resource:cloudflare_magic_network_monitoring_rule": { + "kind": "resource", + "name": "cloudflare_magic_network_monitoring_rule", + "description": "Accepted Permissions\n\n- `Magic Network Monitoring Admin`\n- `Magic Network Monitoring Config Read`\n- `Magic Network Monitoring Config Write`", + "example": "resource \"cloudflare_magic_network_monitoring_rule\" \"example_magic_network_monitoring_rule\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n automatic_advertisement = true\n name = \"my_rule_1\"\n prefixes = [\"203.0.113.1/32\"]\n type = \"zscore\"\n bandwidth_threshold = 1000\n duration = \"1m\"\n packet_threshold = 10000\n prefix_match = \"exact\"\n zscore_sensitivity = \"high\"\n zscore_target = \"bits\"\n}", + "importExample": "$ terraform import cloudflare_magic_network_monitoring_rule.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "automatic_advertisement", + "type": "Boolean", + "description": "Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit." + }, + { + "name": "name", + "type": "String", + "description": "The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters." + }, + { + "name": "prefixes", + "type": "List of String" + }, + { + "name": "type", + "type": "String", + "description": "MNM rule type.\nAvailable values: \"threshold\", \"zscore\", \"advanced_ddos\"." + } + ], + "optional": [ + { + "name": "bandwidth_threshold", + "type": "Number", + "description": "The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum." + }, + { + "name": "duration", + "type": "String", + "description": "The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"].\nAvailable values: \"1m\", \"5m\", \"10m\", \"15m\", \"20m\", \"30m\", \"45m\", \"60m\"." + }, + { + "name": "packet_threshold", + "type": "Number", + "description": "The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum." + }, + { + "name": "prefix_match", + "type": "String", + "description": "Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule.\nAvailable values: \"exact\", \"subnet\", \"supernet\"." + }, + { + "name": "zscore_sensitivity", + "type": "String", + "description": "Level of sensitivity set for zscore rules.\nAvailable values: \"low\", \"medium\", \"high\"." + }, + { + "name": "zscore_target", + "type": "String", + "description": "Target of the zscore rule analysis.\nAvailable values: \"bits\", \"packets\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The id of the rule. Must be unique." + } + ] + }, + "list-data-source:cloudflare_magic_network_monitoring_rules": { + "kind": "list-data-source", + "name": "cloudflare_magic_network_monitoring_rules", + "description": "Accepted Permissions\n\n- `Magic Network Monitoring Admin`\n- `Magic Network Monitoring Config Read`\n- `Magic Network Monitoring Config Write`", + "example": "data \"cloudflare_magic_network_monitoring_rules\" \"example_magic_network_monitoring_rules\" {\n account_id = \"6f91088a406011ed95aed352566e8d4c\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "automatic_advertisement", + "type": "Boolean", + "description": "Toggle on if you would like Cloudflare to automatically advertise the IP Prefixes within the rule via Magic Transit when the rule is triggered. Only available for users of Magic Transit." + }, + { + "name": "bandwidth_threshold", + "type": "Number", + "description": "The number of bits per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum." + }, + { + "name": "duration", + "type": "String", + "description": "The amount of time that the rule threshold must be exceeded to send an alert notification. The final value must be equivalent to one of the following 8 values [\"1m\",\"5m\",\"10m\",\"15m\",\"20m\",\"30m\",\"45m\",\"60m\"].\nAvailable values: \"1m\", \"5m\", \"10m\", \"15m\", \"20m\", \"30m\", \"45m\", \"60m\"." + }, + { + "name": "id", + "type": "String", + "description": "The id of the rule. Must be unique." + }, + { + "name": "name", + "type": "String", + "description": "The name of the rule. Must be unique. Supports characters A-Z, a-z, 0-9, underscore (_), dash (-), period (.), and tilde (~). You can’t have a space in the rule name. Max 256 characters." + }, + { + "name": "packet_threshold", + "type": "Number", + "description": "The number of packets per second for the rule. When this value is exceeded for the set duration, an alert notification is sent. Minimum of 1 and no maximum." + }, + { + "name": "prefix_match", + "type": "String", + "description": "Prefix match type to be applied for a prefix auto advertisement when using an advanced_ddos rule.\nAvailable values: \"exact\", \"subnet\", \"supernet\"." + }, + { + "name": "prefixes", + "type": "List of String" + }, + { + "name": "type", + "type": "String", + "description": "MNM rule type.\nAvailable values: \"threshold\", \"zscore\", \"advanced_ddos\"." + }, + { + "name": "zscore_sensitivity", + "type": "String", + "description": "Level of sensitivity set for zscore rules.\nAvailable values: \"low\", \"medium\", \"high\"." + }, + { + "name": "zscore_target", + "type": "String", + "description": "Target of the zscore rule analysis.\nAvailable values: \"bits\", \"packets\"." + } + ] + } + ] + }, + "data-source:cloudflare_magic_transit_cf1_site": { + "kind": "data-source", + "name": "cloudflare_magic_transit_cf1_site", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_cf1_site\" \"example_magic_transit_cf1_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cf1_site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "cf1_site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-provided description of the CF1 Site." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "location", + "type": "Attributes", + "children": [ + { + "name": "lat", + "type": "Number", + "description": "Latitude of the CF1 Site." + }, + { + "name": "long", + "type": "Number", + "description": "Longitude of the CF1 Site." + }, + { + "name": "name", + "type": "String", + "description": "Name of nearest town, city, or village." + } + ] + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A human-provided name describing the CF1 Site that should be unique within the account." + } + ] + }, + "resource:cloudflare_magic_transit_cf1_site": { + "kind": "resource", + "name": "cloudflare_magic_transit_cf1_site", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "resource \"cloudflare_magic_transit_cf1_site\" \"example_magic_transit_cf1_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n body = [{\n name = \"Pad 34\"\n description = \"Launch Pad 34\"\n location = {\n lat = 28.521339842093845\n long = -80.56092644815843\n name = \"Cape Canaveral\"\n }\n }]\n}", + "importExample": "$ terraform import cloudflare_magic_transit_cf1_site.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "body", + "type": "Attributes List", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-provided description of the CF1 Site." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "location", + "type": "Attributes", + "children": [ + { + "name": "lat", + "type": "Number", + "description": "Latitude of the CF1 Site." + }, + { + "name": "long", + "type": "Number", + "description": "Longitude of the CF1 Site." + }, + { + "name": "name", + "type": "String", + "description": "Name of nearest town, city, or village." + } + ] + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A human-provided name describing the CF1 Site that should be unique within the account." + } + ] + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "A human-provided description of the CF1 Site." + }, + { + "name": "location", + "type": "Attributes", + "children": [ + { + "name": "lat", + "type": "Number", + "description": "Latitude of the CF1 Site." + }, + { + "name": "long", + "type": "Number", + "description": "Longitude of the CF1 Site." + }, + { + "name": "name", + "type": "String", + "description": "Name of nearest town, city, or village." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "A human-provided name describing the CF1 Site that should be unique within the account." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "modified_on", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_magic_transit_cf1_sites": { + "kind": "list-data-source", + "name": "cloudflare_magic_transit_cf1_sites", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_cf1_sites\" \"example_magic_transit_cf1_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-provided description of the CF1 Site." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "location", + "type": "Attributes", + "children": [ + { + "name": "lat", + "type": "Number", + "description": "Latitude of the CF1 Site." + }, + { + "name": "long", + "type": "Number", + "description": "Longitude of the CF1 Site." + }, + { + "name": "name", + "type": "String", + "description": "Name of nearest town, city, or village." + } + ] + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A human-provided name describing the CF1 Site that should be unique within the account." + } + ] + } + ] + }, + "data-source:cloudflare_magic_transit_connector": { + "kind": "data-source", + "name": "cloudflare_magic_transit_connector", + "description": "Accepted Permissions\n\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_connector\" \"example_magic_transit_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connector_id = \"connector_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "connector_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "device_type", + "type": "String", + "description": "Filter connectors by device type.\nAvailable values: \"MANAGED\", \"LICENSED\"." + } + ] + } + ], + "computed": [ + { + "name": "activated", + "type": "Boolean" + }, + { + "name": "device", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "serial_number", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"MANAGED\", \"LICENSED\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "interrupt_window_days_of_week", + "type": "List of String", + "description": "Allowed days of the week for upgrades. Default is all days." + }, + { + "name": "interrupt_window_duration_hours", + "type": "Number" + }, + { + "name": "interrupt_window_embargo_dates", + "type": "List of String", + "description": "List of dates (YYYY-MM-DD) when upgrades are blocked." + }, + { + "name": "interrupt_window_hour_of_day", + "type": "Number" + }, + { + "name": "last_heartbeat", + "type": "String" + }, + { + "name": "last_seen_version", + "type": "String" + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "license_key", + "type": "String" + }, + { + "name": "notes", + "type": "String" + }, + { + "name": "timezone", + "type": "String" + } + ] + }, + "resource:cloudflare_magic_transit_connector": { + "kind": "resource", + "name": "cloudflare_magic_transit_connector", + "example": "resource \"cloudflare_magic_transit_connector\" \"example_magic_transit_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n device = {\n id = \"id\"\n provision_license = true\n serial_number = \"serial_number\"\n }\n activated = true\n interrupt_window_days_of_week = [\"Sunday\"]\n interrupt_window_duration_hours = 1\n interrupt_window_embargo_dates = [\"string\"]\n interrupt_window_hour_of_day = 0\n notes = \"notes\"\n timezone = \"timezone\"\n}", + "importExample": "$ terraform import cloudflare_magic_transit_connector.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier" + }, + { + "name": "device", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "provision_license", + "type": "Boolean", + "description": "Set to true to provision a license key for this connector. Only used during resource creation. This is a write-only field that will not be stored in state." + }, + { + "name": "serial_number", + "type": "String" + } + ] + } + ], + "optional": [ + { + "name": "activated", + "type": "Boolean" + }, + { + "name": "interrupt_window_duration_hours", + "type": "Number" + }, + { + "name": "interrupt_window_hour_of_day", + "type": "Number" + }, + { + "name": "notes", + "type": "String" + }, + { + "name": "timezone", + "type": "String" + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "license_key", + "type": "String", + "description": "License key for the connector. This is only returned on creation and will not be available in subsequent reads.", + "sensitive": true + } + ] + }, + "list-data-source:cloudflare_magic_transit_connectors": { + "kind": "list-data-source", + "name": "cloudflare_magic_transit_connectors", + "description": "Accepted Permissions\n\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_connectors\" \"example_magic_transit_connectors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n device_type = \"MANAGED\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "device_type", + "type": "String", + "description": "Filter connectors by device type.\nAvailable values: \"MANAGED\", \"LICENSED\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "activated", + "type": "Boolean" + }, + { + "name": "device", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "serial_number", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"MANAGED\", \"LICENSED\"." + } + ] + }, + { + "name": "id", + "type": "String" + }, + { + "name": "interrupt_window_days_of_week", + "type": "List of String", + "description": "Allowed days of the week for upgrades. Default is all days." + }, + { + "name": "interrupt_window_duration_hours", + "type": "Number" + }, + { + "name": "interrupt_window_embargo_dates", + "type": "List of String", + "description": "List of dates (YYYY-MM-DD) when upgrades are blocked." + }, + { + "name": "interrupt_window_hour_of_day", + "type": "Number" + }, + { + "name": "last_heartbeat", + "type": "String" + }, + { + "name": "last_seen_version", + "type": "String" + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "license_key", + "type": "String" + }, + { + "name": "notes", + "type": "String" + }, + { + "name": "timezone", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_magic_transit_site": { + "kind": "data-source", + "name": "cloudflare_magic_transit_site", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_site\" \"example_magic_transit_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "connectorid", + "type": "String", + "description": "Identifier" + } + ] + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "connector_id", + "type": "String", + "description": "Magic Connector identifier tag." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "ha_mode", + "type": "Boolean", + "description": "Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "location", + "type": "Attributes", + "description": "Location of site in latitude and longitude.", + "children": [ + { + "name": "lat", + "type": "String", + "description": "Latitude" + }, + { + "name": "lon", + "type": "String", + "description": "Longitude" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the site." + }, + { + "name": "secondary_connector_id", + "type": "String", + "description": "Magic Connector identifier tag. Used when high availability mode is on." + } + ] + }, + "resource:cloudflare_magic_transit_site": { + "kind": "resource", + "name": "cloudflare_magic_transit_site", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "resource \"cloudflare_magic_transit_site\" \"example_magic_transit_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"site_1\"\n connector_id = \"ac60d3d0435248289d446cedd870bcf4\"\n description = \"description\"\n ha_mode = true\n location = {\n lat = \"37.6192\"\n lon = \"122.3816\"\n }\n secondary_connector_id = \"8d67040d3835dbcf46ce29da440dc482\"\n}", + "importExample": "$ terraform import cloudflare_magic_transit_site.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "The name of the site." + } + ], + "optional": [ + { + "name": "connector_id", + "type": "String", + "description": "Magic Connector identifier tag." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "ha_mode", + "type": "Boolean", + "description": "Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode." + }, + { + "name": "location", + "type": "Attributes", + "description": "Location of site in latitude and longitude.", + "children": [ + { + "name": "lat", + "type": "String", + "description": "Latitude" + }, + { + "name": "lon", + "type": "String", + "description": "Longitude" + } + ] + }, + { + "name": "secondary_connector_id", + "type": "String", + "description": "Magic Connector identifier tag. Used when high availability mode is on." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + "data-source:cloudflare_magic_transit_site_acl": { + "kind": "data-source", + "name": "cloudflare_magic_transit_site_acl", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_site_acl\" \"example_magic_transit_site_acl\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n acl_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "acl_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [], + "computed": [ + { + "name": "description", + "type": "String", + "description": "Description for the ACL." + }, + { + "name": "forward_locally", + "type": "Boolean", + "description": "The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "lan_1", + "type": "Attributes", + "children": [ + { + "name": "lan_id", + "type": "String", + "description": "The identifier for the LAN you want to create an ACL policy with." + }, + { + "name": "lan_name", + "type": "String", + "description": "The name of the LAN based on the provided lan_id." + }, + { + "name": "port_ranges", + "type": "List of String", + "description": "Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed." + }, + { + "name": "ports", + "type": "List of Number", + "description": "Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed." + }, + { + "name": "subnets", + "type": "List of String", + "description": "Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed." + } + ] + }, + { + "name": "lan_2", + "type": "Attributes", + "children": [ + { + "name": "lan_id", + "type": "String", + "description": "The identifier for the LAN you want to create an ACL policy with." + }, + { + "name": "lan_name", + "type": "String", + "description": "The name of the LAN based on the provided lan_id." + }, + { + "name": "port_ranges", + "type": "List of String", + "description": "Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed." + }, + { + "name": "ports", + "type": "List of Number", + "description": "Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed." + }, + { + "name": "subnets", + "type": "List of String", + "description": "Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the ACL." + }, + { + "name": "protocols", + "type": "List of String" + }, + { + "name": "unidirectional", + "type": "Boolean", + "description": "The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false." + } + ] + }, + "resource:cloudflare_magic_transit_site_acl": { + "kind": "resource", + "name": "cloudflare_magic_transit_site_acl", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "resource \"cloudflare_magic_transit_site_acl\" \"example_magic_transit_site_acl\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lan_1 = {\n lan_id = \"lan_id\"\n lan_name = \"lan_name\"\n port_ranges = [\"8080-9000\"]\n ports = [1]\n subnets = [\"192.0.2.1\"]\n }\n lan_2 = {\n lan_id = \"lan_id\"\n lan_name = \"lan_name\"\n port_ranges = [\"8080-9000\"]\n ports = [1]\n subnets = [\"192.0.2.1\"]\n }\n name = \"PIN Pad - Cash Register\"\n description = \"Allows local traffic between PIN pads and cash register.\"\n forward_locally = true\n protocols = [\"tcp\"]\n unidirectional = true\n}", + "importExample": "$ terraform import cloudflare_magic_transit_site_acl.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "lan_1", + "type": "Attributes", + "children": [ + { + "name": "lan_id", + "type": "String", + "description": "The identifier for the LAN you want to create an ACL policy with." + }, + { + "name": "lan_name", + "type": "String", + "description": "The name of the LAN based on the provided lan_id." + }, + { + "name": "port_ranges", + "type": "List of String", + "description": "Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed." + }, + { + "name": "ports", + "type": "List of Number", + "description": "Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed." + }, + { + "name": "subnets", + "type": "List of String", + "description": "Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed." + } + ] + }, + { + "name": "lan_2", + "type": "Attributes", + "children": [ + { + "name": "lan_id", + "type": "String", + "description": "The identifier for the LAN you want to create an ACL policy with." + }, + { + "name": "lan_name", + "type": "String", + "description": "The name of the LAN based on the provided lan_id." + }, + { + "name": "port_ranges", + "type": "List of String", + "description": "Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed." + }, + { + "name": "ports", + "type": "List of Number", + "description": "Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed." + }, + { + "name": "subnets", + "type": "List of String", + "description": "Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the ACL." + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Description for the ACL." + }, + { + "name": "forward_locally", + "type": "Boolean", + "description": "The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false." + }, + { + "name": "protocols", + "type": "List of String" + }, + { + "name": "unidirectional", + "type": "Boolean", + "description": "The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + "list-data-source:cloudflare_magic_transit_site_acls": { + "kind": "list-data-source", + "name": "cloudflare_magic_transit_site_acls", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_site_acls\" \"example_magic_transit_site_acls\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "Description for the ACL." + }, + { + "name": "forward_locally", + "type": "Boolean", + "description": "The desired forwarding action for this ACL policy. If set to \"false\", the policy will forward traffic to Cloudflare. If set to \"true\", the policy will forward traffic locally on the Magic Connector. If not included in request, will default to false." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "lan_1", + "type": "Attributes", + "children": [ + { + "name": "lan_id", + "type": "String", + "description": "The identifier for the LAN you want to create an ACL policy with." + }, + { + "name": "lan_name", + "type": "String", + "description": "The name of the LAN based on the provided lan_id." + }, + { + "name": "port_ranges", + "type": "List of String", + "description": "Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed." + }, + { + "name": "ports", + "type": "List of Number", + "description": "Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed." + }, + { + "name": "subnets", + "type": "List of String", + "description": "Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed." + } + ] + }, + { + "name": "lan_2", + "type": "Attributes", + "children": [ + { + "name": "lan_id", + "type": "String", + "description": "The identifier for the LAN you want to create an ACL policy with." + }, + { + "name": "lan_name", + "type": "String", + "description": "The name of the LAN based on the provided lan_id." + }, + { + "name": "port_ranges", + "type": "List of String", + "description": "Array of port ranges on the provided LAN that will be included in the ACL. If no ports or port rangess are provided, communication on any port on this LAN is allowed." + }, + { + "name": "ports", + "type": "List of Number", + "description": "Array of ports on the provided LAN that will be included in the ACL. If no ports or port ranges are provided, communication on any port on this LAN is allowed." + }, + { + "name": "subnets", + "type": "List of String", + "description": "Array of subnet IPs within the LAN that will be included in the ACL. If no subnets are provided, communication on any subnets on this LAN are allowed." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the ACL." + }, + { + "name": "protocols", + "type": "List of String" + }, + { + "name": "unidirectional", + "type": "Boolean", + "description": "The desired traffic direction for this ACL policy. If set to \"false\", the policy will allow bidirectional traffic. If set to \"true\", the policy will only allow traffic in one direction. If not included in request, will default to false." + } + ] + } + ] + }, + "data-source:cloudflare_magic_transit_site_lan": { + "kind": "data-source", + "name": "cloudflare_magic_transit_site_lan", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_site_lan\" \"example_magic_transit_site_lan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lan_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "lan_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [], + "computed": [ + { + "name": "bond_id", + "type": "Number" + }, + { + "name": "ha_link", + "type": "Boolean", + "description": "mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "is_breakout", + "type": "Boolean", + "description": "mark true to use this LAN for source-based breakout traffic" + }, + { + "name": "is_prioritized", + "type": "Boolean", + "description": "mark true to use this LAN for source-based prioritized traffic" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "nat", + "type": "Attributes", + "children": [ + { + "name": "static_prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "physport", + "type": "Number" + }, + { + "name": "routed_subnets", + "type": "Attributes List", + "children": [ + { + "name": "nat", + "type": "Attributes", + "children": [ + { + "name": "static_prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "next_hop", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "static_addressing", + "type": "Attributes", + "description": "If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.", + "children": [ + { + "name": "address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "dhcp_relay", + "type": "Attributes", + "children": [ + { + "name": "server_addresses", + "type": "List of String", + "description": "List of DHCP server IPs." + } + ] + }, + { + "name": "dhcp_server", + "type": "Attributes", + "children": [ + { + "name": "dhcp_options", + "type": "Attributes List", + "description": "Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.", + "children": [ + { + "name": "code", + "type": "Number", + "description": "DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration." + }, + { + "name": "type", + "type": "String", + "description": "The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\nAvailable values: \"text\", \"hex\", \"ip\", \"byte\", \"short\", \"integer\"." + }, + { + "name": "value", + "type": "String", + "description": "The option value, interpreted according to the type field." + } + ] + }, + { + "name": "dhcp_pool_end", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "dhcp_pool_start", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "dns_server", + "type": "String", + "description": "A valid IPv4 address.", + "deprecated": "Deprecated." + }, + { + "name": "dns_servers", + "type": "List of String" + }, + { + "name": "reservations", + "type": "Map of String", + "description": "Mapping of MAC addresses to IP addresses" + } + ] + }, + { + "name": "secondary_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "virtual_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "vlan_tag", + "type": "Number", + "description": "VLAN ID. Use zero for untagged." + } + ] + }, + "resource:cloudflare_magic_transit_site_lan": { + "kind": "resource", + "name": "cloudflare_magic_transit_site_lan", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "resource \"cloudflare_magic_transit_site_lan\" \"example_magic_transit_site_lan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bond_id = 2\n ha_link = true\n is_breakout = true\n is_prioritized = true\n name = \"name\"\n nat = {\n static_prefix = \"192.0.2.0/24\"\n }\n physport = 1\n routed_subnets = [{\n next_hop = \"192.0.2.1\"\n prefix = \"192.0.2.0/24\"\n nat = {\n static_prefix = \"192.0.2.0/24\"\n }\n }]\n static_addressing = {\n address = \"192.0.2.0/24\"\n dhcp_relay = {\n server_addresses = [\"192.0.2.1\"]\n }\n dhcp_server = {\n dhcp_options = [{\n code = 66\n type = \"ip\"\n value = \"10.20.30.40\"\n }]\n dhcp_pool_end = \"192.0.2.1\"\n dhcp_pool_start = \"192.0.2.1\"\n dns_server = \"192.0.2.1\"\n dns_servers = [\"192.0.2.1\"]\n reservations = {\n \"00:11:22:33:44:55\" = \"192.0.2.100\"\n \"AA:BB:CC:DD:EE:FF\" = \"192.168.1.101\"\n }\n }\n secondary_address = \"192.0.2.0/24\"\n virtual_address = \"192.0.2.0/24\"\n }\n vlan_tag = 42\n}", + "importExample": "$ terraform import cloudflare_magic_transit_site_lan.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "bond_id", + "type": "Number" + }, + { + "name": "ha_link", + "type": "Boolean", + "description": "mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link." + }, + { + "name": "is_breakout", + "type": "Boolean", + "description": "mark true to use this LAN for source-based breakout traffic" + }, + { + "name": "is_prioritized", + "type": "Boolean", + "description": "mark true to use this LAN for source-based prioritized traffic" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "nat", + "type": "Attributes", + "children": [ + { + "name": "static_prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "physport", + "type": "Number" + }, + { + "name": "routed_subnets", + "type": "Attributes List", + "children": [ + { + "name": "nat", + "type": "Attributes", + "children": [ + { + "name": "static_prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "next_hop", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "static_addressing", + "type": "Attributes", + "description": "If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.", + "children": [ + { + "name": "address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "dhcp_relay", + "type": "Attributes", + "children": [ + { + "name": "server_addresses", + "type": "List of String", + "description": "List of DHCP server IPs." + } + ] + }, + { + "name": "dhcp_server", + "type": "Attributes", + "children": [ + { + "name": "dhcp_options", + "type": "Attributes List", + "description": "Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.", + "children": [ + { + "name": "code", + "type": "Number", + "description": "DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration." + }, + { + "name": "type", + "type": "String", + "description": "The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\nAvailable values: \"text\", \"hex\", \"ip\", \"byte\", \"short\", \"integer\"." + }, + { + "name": "value", + "type": "String", + "description": "The option value, interpreted according to the type field." + } + ] + }, + { + "name": "dhcp_pool_end", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "dhcp_pool_start", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "dns_server", + "type": "String", + "description": "A valid IPv4 address.", + "deprecated": "Deprecated." + }, + { + "name": "dns_servers", + "type": "List of String" + }, + { + "name": "reservations", + "type": "Map of String", + "description": "Mapping of MAC addresses to IP addresses" + } + ] + }, + { + "name": "secondary_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "virtual_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "vlan_tag", + "type": "Number", + "description": "VLAN ID. Use zero for untagged." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + "list-data-source:cloudflare_magic_transit_site_lans": { + "kind": "list-data-source", + "name": "cloudflare_magic_transit_site_lans", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_site_lans\" \"example_magic_transit_site_lans\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "bond_id", + "type": "Number" + }, + { + "name": "ha_link", + "type": "Boolean", + "description": "mark true to use this LAN for HA probing. only works for site with HA turned on. only one LAN can be set as the ha_link." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "is_breakout", + "type": "Boolean", + "description": "mark true to use this LAN for source-based breakout traffic" + }, + { + "name": "is_prioritized", + "type": "Boolean", + "description": "mark true to use this LAN for source-based prioritized traffic" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "nat", + "type": "Attributes", + "children": [ + { + "name": "static_prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "physport", + "type": "Number" + }, + { + "name": "routed_subnets", + "type": "Attributes List", + "children": [ + { + "name": "nat", + "type": "Attributes", + "children": [ + { + "name": "static_prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "next_hop", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "prefix", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "static_addressing", + "type": "Attributes", + "description": "If the site is not configured in high availability mode, this configuration is optional (if omitted, use DHCP). However, if in high availability mode, static_address is required along with secondary and virtual address.", + "children": [ + { + "name": "address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "dhcp_relay", + "type": "Attributes", + "children": [ + { + "name": "server_addresses", + "type": "List of String", + "description": "List of DHCP server IPs." + } + ] + }, + { + "name": "dhcp_server", + "type": "Attributes", + "children": [ + { + "name": "dhcp_options", + "type": "Attributes List", + "description": "Optional list of custom DHCP options to include in DHCP responses. Only valid when DHCP server is enabled.", + "children": [ + { + "name": "code", + "type": "Number", + "description": "DHCP option number (1-254). Options 0 and 255 are reserved by RFC 2132. Options 3, 6, and 51 are not allowed because they conflict with connector-managed configuration." + }, + { + "name": "type", + "type": "String", + "description": "The type of the option value. text: a string (max 255 bytes). hex: colon-separated hex bytes (e.g. \"01:04:aa:bb:cc\", max 255 bytes). ip: an IPv4 address (e.g. \"10.20.30.40\"). byte: an unsigned integer 0-255 (1 byte). short: an unsigned integer 0-65535 (2 bytes). integer: an unsigned integer 0-4294967295 (4 bytes).\nAvailable values: \"text\", \"hex\", \"ip\", \"byte\", \"short\", \"integer\"." + }, + { + "name": "value", + "type": "String", + "description": "The option value, interpreted according to the type field." + } + ] + }, + { + "name": "dhcp_pool_end", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "dhcp_pool_start", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "dns_server", + "type": "String", + "description": "A valid IPv4 address.", + "deprecated": "Deprecated." + }, + { + "name": "dns_servers", + "type": "List of String" + }, + { + "name": "reservations", + "type": "Map of String", + "description": "Mapping of MAC addresses to IP addresses" + } + ] + }, + { + "name": "secondary_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "virtual_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "vlan_tag", + "type": "Number", + "description": "VLAN ID. Use zero for untagged." + } + ] + } + ] + }, + "data-source:cloudflare_magic_transit_site_wan": { + "kind": "data-source", + "name": "cloudflare_magic_transit_site_wan", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_site_wan\" \"example_magic_transit_site_wan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n wan_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "wan_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [], + "computed": [ + { + "name": "health_check_rate", + "type": "String", + "description": "Magic WAN health check rate for tunnels created on this link. The default value is `mid`.\nAvailable values: \"low\", \"mid\", \"high\"." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "load_balance_inner_flows", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "physport", + "type": "Number" + }, + { + "name": "priority", + "type": "Number", + "description": "Priority of WAN for traffic loadbalancing." + }, + { + "name": "static_addressing", + "type": "Attributes", + "description": "(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.", + "children": [ + { + "name": "address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "gateway_address", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "secondary_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "vlan_tag", + "type": "Number", + "description": "VLAN ID. Use zero for untagged." + } + ] + }, + "resource:cloudflare_magic_transit_site_wan": { + "kind": "resource", + "name": "cloudflare_magic_transit_site_wan", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "resource \"cloudflare_magic_transit_site_wan\" \"example_magic_transit_site_wan\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n physport = 1\n health_check_rate = \"low\"\n load_balance_inner_flows = true\n name = \"name\"\n priority = 0\n static_addressing = {\n address = \"192.0.2.0/24\"\n gateway_address = \"192.0.2.1\"\n secondary_address = \"192.0.2.0/24\"\n }\n vlan_tag = 42\n}", + "importExample": "$ terraform import cloudflare_magic_transit_site_wan.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "physport", + "type": "Number" + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "health_check_rate", + "type": "String", + "description": "Magic WAN health check rate for tunnels created on this link. The default value is `mid`.\nAvailable values: \"low\", \"mid\", \"high\"." + }, + { + "name": "load_balance_inner_flows", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "priority", + "type": "Number" + }, + { + "name": "static_addressing", + "type": "Attributes", + "description": "(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.", + "children": [ + { + "name": "address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "gateway_address", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "secondary_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "vlan_tag", + "type": "Number", + "description": "VLAN ID. Use zero for untagged." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + "list-data-source:cloudflare_magic_transit_site_wans": { + "kind": "list-data-source", + "name": "cloudflare_magic_transit_site_wans", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_site_wans\" \"example_magic_transit_site_wans\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "site_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "health_check_rate", + "type": "String", + "description": "Magic WAN health check rate for tunnels created on this link. The default value is `mid`.\nAvailable values: \"low\", \"mid\", \"high\"." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "load_balance_inner_flows", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "physport", + "type": "Number" + }, + { + "name": "priority", + "type": "Number", + "description": "Priority of WAN for traffic loadbalancing." + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "static_addressing", + "type": "Attributes", + "description": "(optional) if omitted, use DHCP. Submit secondary_address when site is in high availability mode.", + "children": [ + { + "name": "address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + }, + { + "name": "gateway_address", + "type": "String", + "description": "A valid IPv4 address." + }, + { + "name": "secondary_address", + "type": "String", + "description": "A valid CIDR notation representing an IP range." + } + ] + }, + { + "name": "vlan_tag", + "type": "Number", + "description": "VLAN ID. Use zero for untagged." + } + ] + } + ] + }, + "list-data-source:cloudflare_magic_transit_sites": { + "kind": "list-data-source", + "name": "cloudflare_magic_transit_sites", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_transit_sites\" \"example_magic_transit_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connectorid = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "connectorid", + "type": "String", + "description": "Identifier" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "connector_id", + "type": "String", + "description": "Magic Connector identifier tag." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "ha_mode", + "type": "Boolean", + "description": "Site high availability mode. If set to true, the site can have two connectors and runs in high availability mode." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "location", + "type": "Attributes", + "description": "Location of site in latitude and longitude.", + "children": [ + { + "name": "lat", + "type": "String", + "description": "Latitude" + }, + { + "name": "lon", + "type": "String", + "description": "Longitude" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the site." + }, + { + "name": "secondary_connector_id", + "type": "String", + "description": "Magic Connector identifier tag. Used when high availability mode is on." + } + ] + } + ] + }, + "data-source:cloudflare_magic_wan_bgp_filter_profile": { + "kind": "data-source", + "name": "cloudflare_magic_wan_bgp_filter_profile", + "example": "data \"cloudflare_magic_wan_bgp_filter_profile\" \"example_magic_wan_bgp_filter_profile\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n profile_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "profile_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Description of the filter profile" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "match_action", + "type": "String", + "description": "Action to take when a route matches one of the targets in this profile\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Friendly name for the filter profile" + }, + { + "name": "targets", + "type": "List of String", + "description": "List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N." + } + ] + }, + "resource:cloudflare_magic_wan_bgp_filter_profile": { + "kind": "resource", + "name": "cloudflare_magic_wan_bgp_filter_profile", + "example": "resource \"cloudflare_magic_wan_bgp_filter_profile\" \"example_magic_wan_bgp_filter_profile\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n match_action = \"allow\"\n name = \"Allowed On-Prem Imports\"\n targets = [\"10.0.0.0/8{8,32}\"]\n description = \"Allowed corporate subnets from on-premises\"\n}", + "importExample": "$ terraform import cloudflare_magic_wan_bgp_filter_profile.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "match_action", + "type": "String", + "description": "Action to take when a route matches one of the targets in this profile\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "name", + "type": "String", + "description": "Friendly name for the filter profile" + }, + { + "name": "targets", + "type": "List of String", + "description": "List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Description of the filter profile" + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "modified_on", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_magic_wan_bgp_filter_profiles": { + "kind": "list-data-source", + "name": "cloudflare_magic_wan_bgp_filter_profiles", + "example": "data \"cloudflare_magic_wan_bgp_filter_profiles\" \"example_magic_wan_bgp_filter_profiles\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Description of the filter profile" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "match_action", + "type": "String", + "description": "Action to take when a route matches one of the targets in this profile\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Friendly name for the filter profile" + }, + { + "name": "targets", + "type": "List of String", + "description": "List of CIDR prefixes. Each entry may carry an optional suffix that specifies which prefix lengths to match relative to the prefix length N: '{X,Y}' matches prefix lengths in the inclusive range [X, Y] where N <= X <= Y <= max (max is 32 for IPv4, 128 for IPv6), '{X}' matches exactly length X (equivalent to {X,X}), '+' is shorthand for {N, max} (the prefix and all more-specific subnets, including at length N itself; valid even when N is the maximum length). Omit the suffix to match the prefix exactly at length N." + } + ] + } + ] + }, + "data-source:cloudflare_magic_wan_gre_tunnel": { + "kind": "data-source", + "name": "cloudflare_magic_wan_gre_tunnel", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_wan_gre_tunnel\" \"example_magic_wan_gre_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n gre_tunnel_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "gre_tunnel_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "gre_tunnel", + "type": "Attributes", + "children": [ + { + "name": "automatic_return_routing", + "type": "Boolean", + "description": "True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected." + }, + { + "name": "bgp", + "type": "Attributes", + "children": [ + { + "name": "customer_asn", + "type": "Number", + "description": "ASN used on the customer end of the BGP session" + }, + { + "name": "export_filter_id", + "type": "String", + "description": "ID of the BGP filter profile applied to routes advertised to the customer." + }, + { + "name": "extra_prefixes", + "type": "List of String", + "description": "Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table." + }, + { + "name": "import_filter_id", + "type": "String", + "description": "ID of the BGP filter profile applied to routes received from the customer." + }, + { + "name": "md5_key", + "type": "String", + "description": "MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected." + } + ] + }, + { + "name": "bgp_status", + "type": "Attributes", + "children": [ + { + "name": "bgp_state", + "type": "String" + }, + { + "name": "cf_speaker_ip", + "type": "String" + }, + { + "name": "cf_speaker_port", + "type": "Number" + }, + { + "name": "customer_speaker_ip", + "type": "String" + }, + { + "name": "customer_speaker_port", + "type": "Number" + }, + { + "name": "state", + "type": "String", + "description": "Available values: \"BGP_DOWN\", \"BGP_UP\", \"BGP_ESTABLISHING\"." + }, + { + "name": "tcp_established", + "type": "Boolean" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "cloudflare_gre_endpoint", + "type": "String", + "description": "The IP address assigned to the Cloudflare side of the GRE tunnel." + }, + { + "name": "created_on", + "type": "String", + "description": "The date and time the tunnel was created." + }, + { + "name": "customer_gre_endpoint", + "type": "String", + "description": "The IP address assigned to the customer side of the GRE tunnel." + }, + { + "name": "description", + "type": "String", + "description": "An optional description of the GRE tunnel." + }, + { + "name": "health_check", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel.\nAvailable values: \"unidirectional\", \"bidirectional\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether to run healthchecks for a tunnel." + }, + { + "name": "rate", + "type": "String", + "description": "How frequent the health check is run. The default value is `mid`.\nAvailable values: \"low\", \"mid\", \"high\"." + }, + { + "name": "target", + "type": "Attributes", + "description": "The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.", + "children": [ + { + "name": "effective", + "type": "String", + "description": "The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests." + }, + { + "name": "saved", + "type": "String", + "description": "The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The type of healthcheck to run, reply or request. The default value is `reply`.\nAvailable values: \"reply\", \"request\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "interface_address", + "type": "String", + "description": "A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255." + }, + { + "name": "interface_address6", + "type": "String", + "description": "A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127" + }, + { + "name": "modified_on", + "type": "String", + "description": "The date and time the tunnel was last modified." + }, + { + "name": "mtu", + "type": "Number", + "description": "Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576." + }, + { + "name": "name", + "type": "String", + "description": "The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time To Live (TTL) in number of hops of the GRE tunnel." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + "resource:cloudflare_magic_wan_gre_tunnel": { + "kind": "resource", + "name": "cloudflare_magic_wan_gre_tunnel", + "example": "resource \"cloudflare_magic_wan_gre_tunnel\" \"example_magic_wan_gre_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cloudflare_gre_endpoint = \"203.0.113.1\"\n customer_gre_endpoint = \"203.0.113.1\"\n interface_address = \"192.0.2.0/31\"\n name = \"GRE_1\"\n automatic_return_routing = true\n bgp = {\n customer_asn = 0\n export_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n extra_prefixes = [\"string\"]\n import_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n md5_key = \"md5_key\"\n }\n description = \"Tunnel for ISP X\"\n health_check = {\n direction = \"bidirectional\"\n enabled = true\n rate = \"low\"\n target = {\n saved = \"203.0.113.1\"\n }\n type = \"request\"\n }\n interface_address6 = \"2606:54c1:7:0:a9fe:12d2:1:200/127\"\n mtu = 0\n ttl = 0\n}", + "importExample": "$ terraform import cloudflare_magic_wan_gre_tunnel.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "cloudflare_gre_endpoint", + "type": "String", + "description": "The IP address assigned to the Cloudflare side of the GRE tunnel." + }, + { + "name": "customer_gre_endpoint", + "type": "String", + "description": "The IP address assigned to the customer side of the GRE tunnel." + }, + { + "name": "interface_address", + "type": "String", + "description": "A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255." + }, + { + "name": "name", + "type": "String", + "description": "The name of the tunnel. The name cannot contain spaces or special characters, must be 15 characters or less, and cannot share a name with another GRE tunnel." + } + ], + "optional": [ + { + "name": "automatic_return_routing", + "type": "Boolean", + "description": "True if automatic stateful return routing should be enabled for a tunnel, false otherwise." + }, + { + "name": "bgp", + "type": "Attributes", + "children": [ + { + "name": "customer_asn", + "type": "Number", + "description": "ASN used on the customer end of the BGP session" + }, + { + "name": "export_filter_id", + "type": "String", + "description": "UUID of the BGP filter profile to apply to routes advertised by Cloudflare." + }, + { + "name": "extra_prefixes", + "type": "List of String", + "description": "Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table." + }, + { + "name": "import_filter_id", + "type": "String", + "description": "UUID of the BGP filter profile to apply to routes advertised to Cloudflare." + }, + { + "name": "md5_key", + "type": "String", + "description": "MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected." + } + ] + }, + { + "name": "description", + "type": "String", + "description": "An optional description of the GRE tunnel." + }, + { + "name": "health_check", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel.\nAvailable values: \"unidirectional\", \"bidirectional\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether to run healthchecks for a tunnel." + }, + { + "name": "rate", + "type": "String", + "description": "How frequent the health check is run. The default value is `mid`.\nAvailable values: \"low\", \"mid\", \"high\"." + }, + { + "name": "target", + "type": "Attributes", + "description": "The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.", + "children": [ + { + "name": "effective", + "type": "String", + "description": "The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests." + }, + { + "name": "saved", + "type": "String", + "description": "The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The type of healthcheck to run, reply or request. The default value is `reply`.\nAvailable values: \"reply\", \"request\"." + } + ] + }, + { + "name": "interface_address6", + "type": "String", + "description": "A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127" + }, + { + "name": "mtu", + "type": "Number", + "description": "Maximum Transmission Unit (MTU) in bytes for the GRE tunnel. The minimum value is 576." + }, + { + "name": "ttl", + "type": "Number", + "description": "Time To Live (TTL) in number of hops of the GRE tunnel." + } + ], + "computed": [ + { + "name": "bgp_status", + "type": "Attributes", + "children": [ + { + "name": "bgp_state", + "type": "String" + }, + { + "name": "cf_speaker_ip", + "type": "String" + }, + { + "name": "cf_speaker_port", + "type": "Number" + }, + { + "name": "customer_speaker_ip", + "type": "String" + }, + { + "name": "customer_speaker_port", + "type": "Number" + }, + { + "name": "state", + "type": "String", + "description": "Available values: \"BGP_DOWN\", \"BGP_UP\", \"BGP_ESTABLISHING\"." + }, + { + "name": "tcp_established", + "type": "Boolean" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "The date and time the tunnel was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "modified_on", + "type": "String", + "description": "The date and time the tunnel was last modified." + } + ] + }, + "data-source:cloudflare_magic_wan_ipsec_tunnel": { + "kind": "data-source", + "name": "cloudflare_magic_wan_ipsec_tunnel", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_wan_ipsec_tunnel\" \"example_magic_wan_ipsec_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ipsec_tunnel_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "ipsec_tunnel_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "ipsec_tunnel", + "type": "Attributes", + "children": [ + { + "name": "allow_null_cipher", + "type": "Boolean", + "description": "When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)." + }, + { + "name": "automatic_return_routing", + "type": "Boolean", + "description": "True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the `coupler_integration` account flag to be enabled; requests setting this to `true` without that flag will be rejected." + }, + { + "name": "bgp", + "type": "Attributes", + "children": [ + { + "name": "customer_asn", + "type": "Number", + "description": "ASN used on the customer end of the BGP session" + }, + { + "name": "export_filter_id", + "type": "String", + "description": "ID of the BGP filter profile applied to routes advertised to the customer." + }, + { + "name": "extra_prefixes", + "type": "List of String", + "description": "Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table." + }, + { + "name": "import_filter_id", + "type": "String", + "description": "ID of the BGP filter profile applied to routes received from the customer." + }, + { + "name": "md5_key", + "type": "String", + "description": "MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected." + } + ] + }, + { + "name": "bgp_status", + "type": "Attributes", + "children": [ + { + "name": "bgp_state", + "type": "String" + }, + { + "name": "cf_speaker_ip", + "type": "String" + }, + { + "name": "cf_speaker_port", + "type": "Number" + }, + { + "name": "customer_speaker_ip", + "type": "String" + }, + { + "name": "customer_speaker_port", + "type": "Number" + }, + { + "name": "state", + "type": "String", + "description": "Available values: \"BGP_DOWN\", \"BGP_UP\", \"BGP_ESTABLISHING\"." + }, + { + "name": "tcp_established", + "type": "Boolean" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "cloudflare_endpoint", + "type": "String", + "description": "The IP address assigned to the Cloudflare side of the IPsec tunnel." + }, + { + "name": "created_on", + "type": "String", + "description": "The date and time the tunnel was created." + }, + { + "name": "custom_remote_identities", + "type": "Attributes", + "children": [ + { + "name": "fqdn_id", + "type": "String", + "description": "A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom\nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels\ncannot have the same cloudflare_endpoint." + } + ] + }, + { + "name": "customer_endpoint", + "type": "String", + "description": "The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work." + }, + { + "name": "description", + "type": "String", + "description": "An optional description forthe IPsec tunnel." + }, + { + "name": "health_check", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel.\nAvailable values: \"unidirectional\", \"bidirectional\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether to run healthchecks for a tunnel." + }, + { + "name": "rate", + "type": "String", + "description": "How frequent the health check is run. The default value is `mid`.\nAvailable values: \"low\", \"mid\", \"high\"." + }, + { + "name": "target", + "type": "Attributes", + "description": "The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.", + "children": [ + { + "name": "effective", + "type": "String", + "description": "The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests." + }, + { + "name": "saved", + "type": "String", + "description": "The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The type of healthcheck to run, reply or request. The default value is `reply`.\nAvailable values: \"reply\", \"request\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "interface_address", + "type": "String", + "description": "A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255." + }, + { + "name": "interface_address6", + "type": "String", + "description": "A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127" + }, + { + "name": "modified_on", + "type": "String", + "description": "The date and time the tunnel was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the IPsec tunnel. The name cannot share a name with other tunnels." + }, + { + "name": "psk_metadata", + "type": "Attributes", + "description": "The PSK metadata that includes when the PSK was generated.", + "children": [ + { + "name": "last_generated_on", + "type": "String", + "description": "The date and time the tunnel was last modified." + } + ] + }, + { + "name": "replay_protection", + "type": "Boolean", + "description": "If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction." + } + ] + } + ] + }, + "resource:cloudflare_magic_wan_ipsec_tunnel": { + "kind": "resource", + "name": "cloudflare_magic_wan_ipsec_tunnel", + "example": "resource \"cloudflare_magic_wan_ipsec_tunnel\" \"example_magic_wan_ipsec_tunnel\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cloudflare_endpoint = \"203.0.113.1\"\n interface_address = \"192.0.2.0/31\"\n name = \"IPsec_1\"\n automatic_return_routing = true\n bgp = {\n customer_asn = 0\n export_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n extra_prefixes = [\"string\"]\n import_filter_id = \"a1b2c3d4e5f647890a1b2c3d4e5f6789\"\n md5_key = \"md5_key\"\n }\n custom_remote_identities = {\n fqdn_id = \"fqdn_id\"\n }\n customer_endpoint = \"203.0.113.1\"\n description = \"Tunnel for ISP X\"\n health_check = {\n direction = \"bidirectional\"\n enabled = true\n rate = \"low\"\n target = {\n saved = \"203.0.113.1\"\n }\n type = \"request\"\n }\n interface_address6 = \"2606:54c1:7:0:a9fe:12d2:1:200/127\"\n psk = \"O3bwKSjnaoCxDoUxjcq4Rk8ZKkezQUiy\"\n replay_protection = false\n}", + "importExample": "$ terraform import cloudflare_magic_wan_ipsec_tunnel.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "cloudflare_endpoint", + "type": "String", + "description": "The IP address assigned to the Cloudflare side of the IPsec tunnel." + }, + { + "name": "interface_address", + "type": "String", + "description": "A 31-bit prefix (/31 in CIDR notation) supporting two hosts, one for each side of the tunnel. Select the subnet from the following private IP space: 10.0.0.0–10.255.255.255, 172.16.0.0–172.31.255.255, 192.168.0.0–192.168.255.255." + }, + { + "name": "name", + "type": "String", + "description": "The name of the IPsec tunnel. The name cannot share a name with other tunnels." + } + ], + "optional": [ + { + "name": "automatic_return_routing", + "type": "Boolean", + "description": "True if automatic stateful return routing should be enabled for a tunnel, false otherwise." + }, + { + "name": "bgp", + "type": "Attributes", + "children": [ + { + "name": "customer_asn", + "type": "Number", + "description": "ASN used on the customer end of the BGP session" + }, + { + "name": "export_filter_id", + "type": "String", + "description": "UUID of the BGP filter profile to apply to routes advertised by Cloudflare." + }, + { + "name": "extra_prefixes", + "type": "List of String", + "description": "Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table." + }, + { + "name": "import_filter_id", + "type": "String", + "description": "UUID of the BGP filter profile to apply to routes advertised to Cloudflare." + }, + { + "name": "md5_key", + "type": "String", + "description": "MD5 key to use for session authentication.\n\nNote that *this is not a security measure*. MD5 is not a valid security mechanism, and the\nkey is not treated as a secret value. This is *only* supported for preventing\nmisconfiguration, not for defending against malicious attacks.\n\nThe MD5 key, if set, must be of non-zero length and consist only of the following types of\ncharacter:\n\n* ASCII alphanumerics: `[a-zA-Z0-9]`\n* Special characters in the set `'!@#$%^&*()+[]{}<>/.,;:_-~`= \\|`\n\nIn other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A),\nquotation mark (`\"`), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed\n(0x0C), and the question mark (`?`). Requests specifying an MD5 key with one or more of\nthese disallowed characters will be rejected." + } + ] + }, + { + "name": "custom_remote_identities", + "type": "Attributes", + "children": [ + { + "name": "fqdn_id", + "type": "String", + "description": "A custom IKE ID of type FQDN that may be used to identity the IPsec tunnel. The\ngenerated IKE IDs can still be used even if this custom value is specified.\n\nMust be of the form `..custom.ipsec.cloudflare.com`.\n\nThis custom ID does not need to be unique. Two IPsec tunnels may have the same custom \nfqdn_id. However, if another IPsec tunnel has the same value then the two tunnels \ncannot have the same cloudflare_endpoint." + } + ] + }, + { + "name": "customer_endpoint", + "type": "String", + "description": "The IP address assigned to the customer side of the IPsec tunnel. Not required, but must be set for proactive traceroutes to work." + }, + { + "name": "description", + "type": "String", + "description": "An optional description forthe IPsec tunnel." + }, + { + "name": "health_check", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the tunnel and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the tunnel.\nAvailable values: \"unidirectional\", \"bidirectional\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether to run healthchecks for a tunnel." + }, + { + "name": "rate", + "type": "String", + "description": "How frequent the health check is run. The default value is `mid`.\nAvailable values: \"low\", \"mid\", \"high\"." + }, + { + "name": "target", + "type": "Attributes", + "description": "The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to `customer_gre_endpoint address`. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.", + "children": [ + { + "name": "effective", + "type": "String", + "description": "The effective health check target. If 'saved' is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests." + }, + { + "name": "saved", + "type": "String", + "description": "The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The type of healthcheck to run, reply or request. The default value is `reply`.\nAvailable values: \"reply\", \"request\"." + } + ] + }, + { + "name": "interface_address6", + "type": "String", + "description": "A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127" + }, + { + "name": "psk", + "type": "String", + "description": "A randomly generated or provided string for use in the IPsec tunnel.", + "sensitive": true + }, + { + "name": "replay_protection", + "type": "Boolean", + "description": "If `true`, then IPsec replay protection will be supported in the Cloudflare-to-customer direction." + } + ], + "computed": [ + { + "name": "allow_null_cipher", + "type": "Boolean", + "description": "When `true`, the tunnel can use a null-cipher (`ENCR_NULL`) in the ESP tunnel (Phase 2)." + }, + { + "name": "bgp_status", + "type": "Attributes", + "children": [ + { + "name": "bgp_state", + "type": "String" + }, + { + "name": "cf_speaker_ip", + "type": "String" + }, + { + "name": "cf_speaker_port", + "type": "Number" + }, + { + "name": "customer_speaker_ip", + "type": "String" + }, + { + "name": "customer_speaker_port", + "type": "Number" + }, + { + "name": "state", + "type": "String", + "description": "Available values: \"BGP_DOWN\", \"BGP_UP\", \"BGP_ESTABLISHING\"." + }, + { + "name": "tcp_established", + "type": "Boolean" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "The date and time the tunnel was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "modified_on", + "type": "String", + "description": "The date and time the tunnel was last modified." + }, + { + "name": "psk_metadata", + "type": "Attributes", + "description": "The PSK metadata that includes when the PSK was generated.", + "children": [ + { + "name": "last_generated_on", + "type": "String", + "description": "The date and time the tunnel was last modified." + } + ] + } + ] + }, + "data-source:cloudflare_magic_wan_static_route": { + "kind": "data-source", + "name": "cloudflare_magic_wan_static_route", + "description": "Accepted Permissions\n\n- `Magic Transit Read`\n- `Magic Transit Write`\n- `Magic WAN Read`\n- `Magic WAN Write`", + "example": "data \"cloudflare_magic_wan_static_route\" \"example_magic_wan_static_route\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n route_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "route_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "route", + "type": "Attributes", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "When the route was created." + }, + { + "name": "description", + "type": "String", + "description": "An optional human provided description of the static route." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "modified_on", + "type": "String", + "description": "When the route was last modified." + }, + { + "name": "nexthop", + "type": "String", + "description": "The next-hop IP Address for the static route." + }, + { + "name": "prefix", + "type": "String", + "description": "IP Prefix in Classless Inter-Domain Routing format." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority of the static route." + }, + { + "name": "scope", + "type": "Attributes", + "description": "Used only for ECMP routes.", + "children": [ + { + "name": "colo_names", + "type": "List of String", + "description": "List of colo names for the ECMP scope." + }, + { + "name": "colo_regions", + "type": "List of String", + "description": "List of colo regions for the ECMP scope." + } + ] + }, + { + "name": "weight", + "type": "Number", + "description": "Optional weight of the ECMP scope - if provided." + } + ] + } + ] + }, + "resource:cloudflare_magic_wan_static_route": { + "kind": "resource", + "name": "cloudflare_magic_wan_static_route", + "example": "resource \"cloudflare_magic_wan_static_route\" \"example_magic_wan_static_route\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n nexthop = \"203.0.113.1\"\n prefix = \"192.0.2.0/24\"\n priority = 0\n description = \"New route for new prefix 203.0.113.1\"\n scope = {\n colo_names = [\"den01\"]\n colo_regions = [\"APAC\"]\n }\n weight = 0\n}", + "importExample": "$ terraform import cloudflare_magic_wan_static_route.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "nexthop", + "type": "String", + "description": "The next-hop IP Address for the static route." + }, + { + "name": "prefix", + "type": "String", + "description": "IP Prefix in Classless Inter-Domain Routing format." + }, + { + "name": "priority", + "type": "Number", + "description": "Priority of the static route." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "An optional human provided description of the static route." + }, + { + "name": "scope", + "type": "Attributes", + "description": "Used only for ECMP routes.", + "children": [ + { + "name": "colo_names", + "type": "List of String", + "description": "List of colo names for the ECMP scope." + }, + { + "name": "colo_regions", + "type": "List of String", + "description": "List of colo regions for the ECMP scope." + } + ] + }, + { + "name": "weight", + "type": "Number", + "description": "Optional weight of the ECMP scope - if provided." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the route was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "modified_on", + "type": "String", + "description": "When the route was last modified." + } + ] + }, + "data-source:cloudflare_managed_transforms": { + "kind": "data-source", + "name": "cloudflare_managed_transforms", + "description": "Accepted Permissions\n\n- `Account Rulesets Read`\n- `Account Rulesets Write`\n- `Account WAF Read`\n- `Account WAF Write`\n- `Bot Management Read`\n- `Bot Management Write`\n- `Cache Settings Read`\n- `Cache Settings Write`\n- `Config Settings Read`\n- `Config Settings Write`\n- `Custom Errors Read`\n- `Custom Errors Write`\n- `Dynamic URL Redirects Read`\n- `Dynamic URL Redirects Write`\n- `HTTP DDoS Managed Ruleset Read`\n- `HTTP DDoS Managed Ruleset Write`\n- `L4 DDoS Managed Ruleset Read`\n- `L4 DDoS Managed Ruleset Write`\n- `Logs Read`\n- `Logs Write`\n- `Magic Firewall Read`\n- `Magic Firewall Write`\n- `Managed headers Read`\n- `Managed headers Write`\n- `Mass URL Redirects Read`\n- `Mass URL Redirects Write`\n- `Origin Read`\n- `Origin Write`\n- `Response Compression Read`\n- `Response Compression Write`\n- `Sanitize Read`\n- `Sanitize Write`\n- `Select Configuration Read`\n- `Select Configuration Write`\n- `Transform Rules Read`\n- `Transform Rules Write`\n- `Zone Transform Rules Read`\n- `Zone Transform Rules Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "data \"cloudflare_managed_transforms\" \"example_managed_transforms\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique ID of the zone." + }, + { + "name": "managed_request_headers", + "type": "Attributes List", + "description": "The list of Managed Request Transforms.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Managed Transform is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The human-readable identifier of the Managed Transform." + } + ] + }, + { + "name": "managed_response_headers", + "type": "Attributes List", + "description": "The list of Managed Response Transforms.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Managed Transform is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The human-readable identifier of the Managed Transform." + } + ] + } + ] + }, + "resource:cloudflare_managed_transforms": { + "kind": "resource", + "name": "cloudflare_managed_transforms", + "description": "Accepted Permissions\n\n- `Account Rulesets Read`\n- `Account Rulesets Write`\n- `Account WAF Read`\n- `Account WAF Write`\n- `Bot Management Read`\n- `Bot Management Write`\n- `Cache Settings Read`\n- `Cache Settings Write`\n- `Config Settings Read`\n- `Config Settings Write`\n- `Custom Errors Read`\n- `Custom Errors Write`\n- `Dynamic URL Redirects Read`\n- `Dynamic URL Redirects Write`\n- `HTTP DDoS Managed Ruleset Read`\n- `HTTP DDoS Managed Ruleset Write`\n- `L4 DDoS Managed Ruleset Read`\n- `L4 DDoS Managed Ruleset Write`\n- `Logs Read`\n- `Logs Write`\n- `Magic Firewall Read`\n- `Magic Firewall Write`\n- `Managed headers Read`\n- `Managed headers Write`\n- `Mass URL Redirects Read`\n- `Mass URL Redirects Write`\n- `Origin Read`\n- `Origin Write`\n- `Response Compression Read`\n- `Response Compression Write`\n- `Sanitize Read`\n- `Sanitize Write`\n- `Select Configuration Read`\n- `Select Configuration Write`\n- `Transform Rules Read`\n- `Transform Rules Write`\n- `Zone Transform Rules Read`\n- `Zone Transform Rules Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "resource \"cloudflare_managed_transforms\" \"example_managed_transforms\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n managed_request_headers = [{\n id = \"add_bot_protection_headers\"\n enabled = true\n }]\n managed_response_headers = [{\n id = \"add_security_headers\"\n enabled = true\n }]\n}", + "importExample": "$ terraform import cloudflare_managed_transforms.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "optional": [ + { + "name": "managed_request_headers", + "type": "Attributes Set", + "description": "The list of Managed Request Transforms.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Managed Transform is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The human-readable identifier of the Managed Transform." + } + ] + }, + { + "name": "managed_response_headers", + "type": "Attributes Set", + "description": "The list of Managed Response Transforms.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Managed Transform is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The human-readable identifier of the Managed Transform." + } + ] + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique ID of the zone." + } + ] + }, + "data-source:cloudflare_moq_relay": { + "kind": "data-source", + "name": "cloudflare_moq_relay", + "example": "data \"cloudflare_moq_relay\" \"example_moq_relay\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n relay_id = \"a1b2c3d4e5f67890a1b2c3d4e5f67890\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account identifier." + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "asc", + "type": "Boolean", + "description": "Sort order by `created`. When true, results are returned oldest-first\n(ascending); otherwise newest-first (descending, the default)." + }, + { + "name": "created_after", + "type": "String", + "description": "Cursor for pagination. Returns relays created strictly after this\nRFC 3339 timestamp (typically the `created` value of the last item\non the current page, to fetch the next page)." + }, + { + "name": "created_before", + "type": "String", + "description": "Cursor for pagination. Returns relays created strictly before this\nRFC 3339 timestamp (typically the `created` value of the first item\non the current page, to fetch the previous page)." + }, + { + "name": "per_page", + "type": "Number", + "description": "Maximum number of relays to return per page. Values above the maximum are\nclamped to it rather than rejected." + } + ] + }, + { + "name": "relay_id", + "type": "String" + } + ], + "computed": [ + { + "name": "config", + "type": "Attributes", + "description": "upstreams and lingering_subscribe are mutually exclusive.", + "children": [ + { + "name": "lingering_subscribe", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "max_timeout_ms", + "type": "Number", + "description": "Relay-level ceiling on lingering subscribe timeout (ms). Default 30000." + } + ] + }, + { + "name": "upstreams", + "type": "Attributes", + "description": "Upstreams are external MOQT server publishers that a relay falls back\nto when it has no local publisher for a requested namespace/track.", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "upstreams", + "type": "Attributes List", + "description": "Ordered list of upstream MOQT server publishers. Each entry is an\nobject (not a bare string) so per-upstream configuration can be\nadded in the future without another breaking change.", + "children": [ + { + "name": "url", + "type": "String", + "description": "Upstream MOQT server publisher URL. Must be an absolute URL with a\nhost and a scheme the relay can dial: moqt:// (raw QUIC) or https://\n(WebTransport). Validated on update (PUT); rejected with 21013." + } + ] + } + ] + } + ] + }, + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "\"connected\" when active, omitted otherwise.\nAvailable values: \"connected\"." + }, + { + "name": "uid", + "type": "String" + } + ] + }, + "resource:cloudflare_moq_relay": { + "kind": "resource", + "name": "cloudflare_moq_relay", + "example": "resource \"cloudflare_moq_relay\" \"example_moq_relay\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production Live Stream\"\n}", + "importExample": "$ terraform import cloudflare_moq_relay.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account identifier." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name for the relay." + } + ], + "optional": [ + { + "name": "config", + "type": "Attributes", + "description": "upstreams and lingering_subscribe are mutually exclusive.", + "children": [ + { + "name": "lingering_subscribe", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "max_timeout_ms", + "type": "Number", + "description": "Relay-level ceiling on lingering subscribe timeout (ms). Default 30000." + } + ] + }, + { + "name": "upstreams", + "type": "Attributes", + "description": "Upstreams are external MOQT server publishers that a relay falls back\nto when it has no local publisher for a requested namespace/track.", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "upstreams", + "type": "Attributes List", + "description": "Ordered list of upstream MOQT server publishers. Each entry is an\nobject (not a bare string) so per-upstream configuration can be\nadded in the future without another breaking change.", + "children": [ + { + "name": "url", + "type": "String", + "description": "Upstream MOQT server publisher URL. Must be an absolute URL with a\nhost and a scheme the relay can dial: moqt:// (raw QUIC) or https://\n(WebTransport). Validated on update (PUT); rejected with 21013." + } + ] + } + ] + } + ] + } + ], + "computed": [ + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Server-generated unique identifier (32 hex chars)." + }, + { + "name": "modified", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "\"connected\" when active, omitted otherwise.\nAvailable values: \"connected\"." + }, + { + "name": "token_publish_subscribe", + "type": "String", + "description": "Full access token (publish + subscribe). Treat as sensitive.", + "sensitive": true + }, + { + "name": "token_subscribe", + "type": "String", + "description": "Subscribe-only token. Treat as sensitive.", + "sensitive": true + }, + { + "name": "uid", + "type": "String", + "description": "Server-generated unique identifier (32 hex chars)." + } + ] + }, + "list-data-source:cloudflare_moq_relays": { + "kind": "list-data-source", + "name": "cloudflare_moq_relays", + "example": "data \"cloudflare_moq_relays\" \"example_moq_relays\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_after = \"2026-03-27T15:00:00Z\"\n created_before = \"2026-03-27T15:00:00Z\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account identifier." + } + ], + "optional": [ + { + "name": "asc", + "type": "Boolean", + "description": "Sort order by `created`. When true, results are returned oldest-first\n(ascending); otherwise newest-first (descending, the default)." + }, + { + "name": "created_after", + "type": "String", + "description": "Cursor for pagination. Returns relays created strictly after this\nRFC 3339 timestamp (typically the `created` value of the last item\non the current page, to fetch the next page)." + }, + { + "name": "created_before", + "type": "String", + "description": "Cursor for pagination. Returns relays created strictly before this\nRFC 3339 timestamp (typically the `created` value of the first item\non the current page, to fetch the previous page)." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "per_page", + "type": "Number", + "description": "Maximum number of relays to return per page. Values above the maximum are\nclamped to it rather than rejected." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "modified", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "uid", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_mtls_certificate": { + "kind": "data-source", + "name": "cloudflare_mtls_certificate", + "example": "data \"cloudflare_mtls_certificate\" \"example_mtls_certificate\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n mtls_certificate_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "mtls_certificate_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "ca", + "type": "Boolean", + "description": "Indicates whether the certificate is a CA or leaf certificate." + }, + { + "name": "certificates", + "type": "String", + "description": "The uploaded root CA certificate." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "name", + "type": "String", + "description": "Optional unique name for the certificate. Only used for human readability." + }, + { + "name": "serial_number", + "type": "String", + "description": "The certificate serial number." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "This is the time the certificate was uploaded." + } + ] + }, + "resource:cloudflare_mtls_certificate": { + "kind": "resource", + "name": "cloudflare_mtls_certificate", + "example": "resource \"cloudflare_mtls_certificate\" \"example_mtls_certificate\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ca = true\n certificates = </'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "ca", + "type": "Boolean", + "description": "Indicates whether the certificate is a CA or leaf certificate." + }, + { + "name": "certificates", + "type": "String", + "description": "The uploaded root CA certificate or certificate chain. Certificates must be provided in PEM format with the certificate matching the private_key first in the chain." + } + ], + "optional": [ + { + "name": "name", + "type": "String", + "description": "Optional unique name for the certificate. Only used for human readability." + }, + { + "name": "private_key", + "type": "String", + "description": "The private key for the certificate. This field is only needed for specific use cases such as using a custom certificate with Zero Trust's block page.", + "sensitive": true + } + ], + "computed": [ + { + "name": "expires_on", + "type": "String", + "description": "When the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "serial_number", + "type": "String", + "description": "The certificate serial number." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "updated_at", + "type": "String", + "description": "This is the time the certificate was updated." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "This is the time the certificate was uploaded." + } + ] + }, + "data-source:cloudflare_mtls_certificate_associations": { + "kind": "data-source", + "name": "cloudflare_mtls_certificate_associations", + "description": "Accepted Permissions\n\n- `Account: SSL and Certificates Read`\n- `Account: SSL and Certificates Write`", + "example": "data \"cloudflare_mtls_certificate_associations\" \"example_mtls_certificate_associations\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n mtls_certificate_id = \"2458ce5a-0c35-4c7f-82c7-8e9487d3ff60\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "mtls_certificate_id", + "type": "String", + "description": "Certificate identifier tag." + } + ], + "optional": [], + "computed": [ + { + "name": "service", + "type": "String", + "description": "The service using the certificate." + }, + { + "name": "status", + "type": "String", + "description": "Certificate deployment status for the given service." + } + ] + }, + "list-data-source:cloudflare_mtls_certificates": { + "kind": "list-data-source", + "name": "cloudflare_mtls_certificates", + "example": "data \"cloudflare_mtls_certificates\" \"example_mtls_certificates\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "ca", + "type": "Boolean", + "description": "Indicates whether the certificate is a CA or leaf certificate." + }, + { + "name": "certificates", + "type": "String", + "description": "The uploaded root CA certificate." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate expires." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "issuer", + "type": "String", + "description": "The certificate authority that issued the certificate." + }, + { + "name": "name", + "type": "String", + "description": "Optional unique name for the certificate. Only used for human readability." + }, + { + "name": "serial_number", + "type": "String", + "description": "The certificate serial number." + }, + { + "name": "signature", + "type": "String", + "description": "The type of hash used for the certificate." + }, + { + "name": "uploaded_on", + "type": "String", + "description": "This is the time the certificate was uploaded." + } + ] + } + ] + }, + "data-source:cloudflare_nel_setting": { + "kind": "data-source", + "name": "cloudflare_nel_setting", + "description": "Accepted Permissions\n\n- `Zone Settings Read`", + "example": "data \"cloudflare_nel_setting\" \"example_nel_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable. This is false when the zone's plan does not include NEL or the NEL product feature is not enabled." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of the zone." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the setting was last modified. A zero value (0001-01-01T00:00:00Z) indicates the setting has never been explicitly set and is using the default value." + }, + { + "name": "value", + "type": "Attributes", + "description": "The NEL configuration value.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Network Error Logging is enabled for the zone. When enabled, browsers report network errors to Cloudflare's NEL endpoint." + } + ] + } + ] + }, + "resource:cloudflare_nel_setting": { + "kind": "resource", + "name": "cloudflare_nel_setting", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "resource \"cloudflare_nel_setting\" \"example_nel_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = {\n enabled = false\n }\n}", + "importExample": "$ terraform import cloudflare_nel_setting.example ''", + "required": [ + { + "name": "value", + "type": "Attributes", + "description": "The NEL configuration value.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Network Error Logging is enabled for the zone. When enabled, browsers report network errors to Cloudflare's NEL endpoint." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable. This is false when the zone's plan does not include NEL or the NEL product feature is not enabled." + }, + { + "name": "id", + "type": "String", + "description": "Zone setting identifier.\nAvailable values: \"nel\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the setting was last modified. A zero value (0001-01-01T00:00:00Z) indicates the setting has never been explicitly set and is using the default value." + } + ] + }, + "list-data-source:cloudflare_notification_policies": { + "kind": "list-data-source", + "name": "cloudflare_notification_policies", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Notifications Read`\n- `Notifications Write`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_notification_policies\" \"example_notification_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account id" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "alert_interval", + "type": "String", + "description": "Optional specification of how often to re-alert from the same incident, not support on all alert types." + }, + { + "name": "alert_type", + "type": "String", + "description": "Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values.\nAvailable values: \"abuse_report_alert\", \"access_custom_certificate_expiration_type\", \"advanced_ddos_attack_l4_alert\", \"advanced_ddos_attack_l7_alert\", \"advanced_http_alert_error\", \"bgp_hijack_notification\", \"billing_usage_alert\", \"block_notification_block_removed\", \"block_notification_new_block\", \"block_notification_review_rejected\", \"bot_traffic_basic_alert\", \"brand_protection_alert\", \"brand_protection_digest\", \"clickhouse_alert_fw_anomaly\", \"clickhouse_alert_fw_ent_anomaly\", \"cloudforce_one_request_notification\", \"cni_maintenance_notification\", \"custom_analytics\", \"custom_bot_detection_alert\", \"custom_ssl_certificate_event_type\", \"dedicated_ssl_certificate_event_type\", \"device_connectivity_anomaly_alert\", \"dos_attack_l4\", \"dos_attack_l7\", \"expiring_service_token_alert\", \"failing_logpush_job_disabled_alert\", \"fbm_auto_advertisement\", \"fbm_dosd_attack\", \"fbm_volumetric_attack\", \"health_check_status_notification\", \"hostname_aop_custom_certificate_expiration_type\", \"http_alert_edge_error\", \"http_alert_origin_error\", \"image_notification\", \"image_resizing_notification\", \"incident_alert\", \"load_balancing_health_alert\", \"load_balancing_pool_enablement_alert\", \"logo_match_alert\", \"magic_tunnel_health_check_event\", \"magic_wan_tunnel_health\", \"maintenance_event_notification\", \"mtls_certificate_store_certificate_expiration_type\", \"pages_event_alert\", \"radar_notification\", \"real_origin_monitoring\", \"scriptmonitor_alert_new_code_change_detections\", \"scriptmonitor_alert_new_hosts\", \"scriptmonitor_alert_new_malicious_hosts\", \"scriptmonitor_alert_new_malicious_scripts\", \"scriptmonitor_alert_new_malicious_url\", \"scriptmonitor_alert_new_max_length_resource_url\", \"scriptmonitor_alert_new_resources\", \"secondary_dns_all_primaries_failing\", \"secondary_dns_primaries_failing\", \"secondary_dns_warning\", \"secondary_dns_zone_successfully_updated\", \"secondary_dns_zone_validation_warning\", \"security_insights_alert\", \"sentinel_alert\", \"stream_live_notifications\", \"synthetic_test_latency_alert\", \"synthetic_test_low_availability_alert\", \"traffic_anomalies_alert\", \"tunnel_health_event\", \"tunnel_update_event\", \"universal_ssl_event_type\", \"web_analytics_metrics_update\", \"zone_aop_custom_certificate_expiration_type\"." + }, + { + "name": "created", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the Notification policy." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Notification policy is enabled." + }, + { + "name": "filters", + "type": "Attributes", + "description": "Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.", + "children": [ + { + "name": "actions", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "affected_asns", + "type": "List of String", + "description": "Used for configuring radar_notification" + }, + { + "name": "affected_components", + "type": "List of String", + "description": "Used for configuring incident_alert" + }, + { + "name": "affected_locations", + "type": "List of String", + "description": "Used for configuring radar_notification" + }, + { + "name": "airport_code", + "type": "List of String", + "description": "Used for configuring maintenance_event_notification" + }, + { + "name": "alert_trigger_preferences", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "alert_trigger_preferences_value", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "enabled", + "type": "List of String", + "description": "Used for configuring load_balancing_pool_enablement_alert" + }, + { + "name": "environment", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "event", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "event_source", + "type": "List of String", + "description": "Used for configuring load_balancing_health_alert" + }, + { + "name": "event_type", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "group_by", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "health_check_id", + "type": "List of String", + "description": "Used for configuring health_check_status_notification" + }, + { + "name": "incident_impact", + "type": "List of String", + "description": "Used for configuring incident_alert" + }, + { + "name": "input_id", + "type": "List of String", + "description": "Used for configuring stream_live_notifications" + }, + { + "name": "insight_class", + "type": "List of String", + "description": "Used for configuring security_insights_alert" + }, + { + "name": "limit", + "type": "List of String", + "description": "Used for configuring billing_usage_alert" + }, + { + "name": "logo_tag", + "type": "List of String", + "description": "Used for configuring logo_match_alert" + }, + { + "name": "megabits_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "new_health", + "type": "List of String", + "description": "Used for configuring load_balancing_health_alert" + }, + { + "name": "new_status", + "type": "List of String", + "description": "Used for configuring tunnel_health_event" + }, + { + "name": "packets_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "pool_id", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "pop_names", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "product", + "type": "List of String", + "description": "Used for configuring billing_usage_alert" + }, + { + "name": "project_id", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "protocol", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "query_tag", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "requests_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "selectors", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "services", + "type": "List of String", + "description": "Used for configuring clickhouse_alert_fw_ent_anomaly" + }, + { + "name": "slo", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "status", + "type": "List of String", + "description": "Used for configuring health_check_status_notification" + }, + { + "name": "target_hostname", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "target_ip", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "target_zone_name", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "token_id", + "type": "List of String", + "description": "Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens." + }, + { + "name": "traffic_exclusions", + "type": "List of String", + "description": "Used for configuring traffic_anomalies_alert" + }, + { + "name": "tunnel_id", + "type": "List of String", + "description": "Used for configuring tunnel_health_event" + }, + { + "name": "tunnel_name", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "type", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "where", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "zones", + "type": "List of String", + "description": "Usage depends on specific alert type" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of a notification policy" + }, + { + "name": "mechanisms", + "type": "Attributes", + "description": "List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.", + "children": [ + { + "name": "email", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "The email address" + } + ] + }, + { + "name": "pagerduty", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID" + } + ] + }, + { + "name": "webhooks", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID" + } + ] + } + ] + }, + { + "name": "modified", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Name of the policy." + } + ] + } + ] + }, + "data-source:cloudflare_notification_policy": { + "kind": "data-source", + "name": "cloudflare_notification_policy", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Notifications Read`\n- `Notifications Write`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_notification_policy\" \"example_notification_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"0da2b59ef118439d8097bdfb215203c9\"\n}", + "required": [ + { + "name": "policy_id", + "type": "String", + "description": "The unique identifier of a notification policy" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account id" + } + ], + "computed": [ + { + "name": "alert_interval", + "type": "String", + "description": "Optional specification of how often to re-alert from the same incident, not support on all alert types." + }, + { + "name": "alert_type", + "type": "String", + "description": "Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values.\nAvailable values: \"abuse_report_alert\", \"access_custom_certificate_expiration_type\", \"advanced_ddos_attack_l4_alert\", \"advanced_ddos_attack_l7_alert\", \"advanced_http_alert_error\", \"bgp_hijack_notification\", \"billing_usage_alert\", \"block_notification_block_removed\", \"block_notification_new_block\", \"block_notification_review_rejected\", \"bot_traffic_basic_alert\", \"brand_protection_alert\", \"brand_protection_digest\", \"clickhouse_alert_fw_anomaly\", \"clickhouse_alert_fw_ent_anomaly\", \"cloudforce_one_request_notification\", \"cni_maintenance_notification\", \"custom_analytics\", \"custom_bot_detection_alert\", \"custom_ssl_certificate_event_type\", \"dedicated_ssl_certificate_event_type\", \"device_connectivity_anomaly_alert\", \"dos_attack_l4\", \"dos_attack_l7\", \"expiring_service_token_alert\", \"failing_logpush_job_disabled_alert\", \"fbm_auto_advertisement\", \"fbm_dosd_attack\", \"fbm_volumetric_attack\", \"health_check_status_notification\", \"hostname_aop_custom_certificate_expiration_type\", \"http_alert_edge_error\", \"http_alert_origin_error\", \"image_notification\", \"image_resizing_notification\", \"incident_alert\", \"load_balancing_health_alert\", \"load_balancing_pool_enablement_alert\", \"logo_match_alert\", \"magic_tunnel_health_check_event\", \"magic_wan_tunnel_health\", \"maintenance_event_notification\", \"mtls_certificate_store_certificate_expiration_type\", \"pages_event_alert\", \"radar_notification\", \"real_origin_monitoring\", \"scriptmonitor_alert_new_code_change_detections\", \"scriptmonitor_alert_new_hosts\", \"scriptmonitor_alert_new_malicious_hosts\", \"scriptmonitor_alert_new_malicious_scripts\", \"scriptmonitor_alert_new_malicious_url\", \"scriptmonitor_alert_new_max_length_resource_url\", \"scriptmonitor_alert_new_resources\", \"secondary_dns_all_primaries_failing\", \"secondary_dns_primaries_failing\", \"secondary_dns_warning\", \"secondary_dns_zone_successfully_updated\", \"secondary_dns_zone_validation_warning\", \"security_insights_alert\", \"sentinel_alert\", \"stream_live_notifications\", \"synthetic_test_latency_alert\", \"synthetic_test_low_availability_alert\", \"traffic_anomalies_alert\", \"tunnel_health_event\", \"tunnel_update_event\", \"universal_ssl_event_type\", \"web_analytics_metrics_update\", \"zone_aop_custom_certificate_expiration_type\"." + }, + { + "name": "created", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the Notification policy." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Notification policy is enabled." + }, + { + "name": "filters", + "type": "Attributes", + "description": "Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.", + "children": [ + { + "name": "actions", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "affected_asns", + "type": "List of String", + "description": "Used for configuring radar_notification" + }, + { + "name": "affected_components", + "type": "List of String", + "description": "Used for configuring incident_alert" + }, + { + "name": "affected_locations", + "type": "List of String", + "description": "Used for configuring radar_notification" + }, + { + "name": "airport_code", + "type": "List of String", + "description": "Used for configuring maintenance_event_notification" + }, + { + "name": "alert_trigger_preferences", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "alert_trigger_preferences_value", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "enabled", + "type": "List of String", + "description": "Used for configuring load_balancing_pool_enablement_alert" + }, + { + "name": "environment", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "event", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "event_source", + "type": "List of String", + "description": "Used for configuring load_balancing_health_alert" + }, + { + "name": "event_type", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "group_by", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "health_check_id", + "type": "List of String", + "description": "Used for configuring health_check_status_notification" + }, + { + "name": "incident_impact", + "type": "List of String", + "description": "Used for configuring incident_alert" + }, + { + "name": "input_id", + "type": "List of String", + "description": "Used for configuring stream_live_notifications" + }, + { + "name": "insight_class", + "type": "List of String", + "description": "Used for configuring security_insights_alert" + }, + { + "name": "limit", + "type": "List of String", + "description": "Used for configuring billing_usage_alert" + }, + { + "name": "logo_tag", + "type": "List of String", + "description": "Used for configuring logo_match_alert" + }, + { + "name": "megabits_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "new_health", + "type": "List of String", + "description": "Used for configuring load_balancing_health_alert" + }, + { + "name": "new_status", + "type": "List of String", + "description": "Used for configuring tunnel_health_event" + }, + { + "name": "packets_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "pool_id", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "pop_names", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "product", + "type": "List of String", + "description": "Used for configuring billing_usage_alert" + }, + { + "name": "project_id", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "protocol", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "query_tag", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "requests_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "selectors", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "services", + "type": "List of String", + "description": "Used for configuring clickhouse_alert_fw_ent_anomaly" + }, + { + "name": "slo", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "status", + "type": "List of String", + "description": "Used for configuring health_check_status_notification" + }, + { + "name": "target_hostname", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "target_ip", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "target_zone_name", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "token_id", + "type": "List of String", + "description": "Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens." + }, + { + "name": "traffic_exclusions", + "type": "List of String", + "description": "Used for configuring traffic_anomalies_alert" + }, + { + "name": "tunnel_id", + "type": "List of String", + "description": "Used for configuring tunnel_health_event" + }, + { + "name": "tunnel_name", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "type", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "where", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "zones", + "type": "List of String", + "description": "Usage depends on specific alert type" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of a notification policy" + }, + { + "name": "mechanisms", + "type": "Attributes", + "description": "List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.", + "children": [ + { + "name": "email", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "The email address" + } + ] + }, + { + "name": "pagerduty", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID" + } + ] + }, + { + "name": "webhooks", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID" + } + ] + } + ] + }, + { + "name": "modified", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Name of the policy." + } + ] + }, + "resource:cloudflare_notification_policy": { + "kind": "resource", + "name": "cloudflare_notification_policy", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Notifications Read`\n- `Notifications Write`\n- `Zero Trust: PII Read`", + "example": "resource \"cloudflare_notification_policy\" \"example_notification_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n alert_type = \"universal_ssl_event_type\"\n enabled = true\n mechanisms = {\n email = [{\n id = \"id\"\n }]\n pagerduty = [{\n id = \"f174e90afafe4643bbbc4a0ed4fc8415\"\n }]\n webhooks = [{\n id = \"f174e90afafe4643bbbc4a0ed4fc8415\"\n }]\n }\n name = \"SSL Notification Event Policy\"\n alert_interval = \"30m\"\n description = \"Something describing the policy.\"\n filters = {\n actions = [\"string\"]\n affected_asns = [\"string\"]\n affected_components = [\"string\"]\n affected_locations = [\"string\"]\n airport_code = [\"string\"]\n alert_trigger_preferences = [\"string\"]\n alert_trigger_preferences_value = [\"string\"]\n enabled = [\"string\"]\n environment = [\"string\"]\n event = [\"string\"]\n event_source = [\"string\"]\n event_type = [\"string\"]\n group_by = [\"string\"]\n health_check_id = [\"string\"]\n incident_impact = [\"INCIDENT_IMPACT_NONE\"]\n input_id = [\"string\"]\n insight_class = [\"string\"]\n limit = [\"string\"]\n logo_tag = [\"string\"]\n megabits_per_second = [\"string\"]\n new_health = [\"string\"]\n new_status = [\"string\"]\n packets_per_second = [\"string\"]\n pool_id = [\"string\"]\n pop_names = [\"string\"]\n product = [\"string\"]\n project_id = [\"string\"]\n protocol = [\"string\"]\n query_tag = [\"string\"]\n requests_per_second = [\"string\"]\n selectors = [\"string\"]\n services = [\"string\"]\n slo = [\"99.9\"]\n status = [\"string\"]\n target_hostname = [\"string\"]\n target_ip = [\"string\"]\n target_zone_name = [\"string\"]\n token_id = [\"x\"]\n traffic_exclusions = [\"security_events\"]\n tunnel_id = [\"string\"]\n tunnel_name = [\"string\"]\n type = [\"string\"]\n where = [\"string\"]\n zones = [\"string\"]\n }\n}", + "importExample": "$ terraform import cloudflare_notification_policy.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account id" + }, + { + "name": "alert_type", + "type": "String", + "description": "Refers to which event will trigger a Notification dispatch. You can use the endpoint to get available alert types which then will give you a list of possible values.\nAvailable values: \"abuse_report_alert\", \"access_custom_certificate_expiration_type\", \"advanced_ddos_attack_l4_alert\", \"advanced_ddos_attack_l7_alert\", \"advanced_http_alert_error\", \"bgp_hijack_notification\", \"billing_usage_alert\", \"block_notification_block_removed\", \"block_notification_new_block\", \"block_notification_review_rejected\", \"bot_traffic_basic_alert\", \"brand_protection_alert\", \"brand_protection_digest\", \"clickhouse_alert_fw_anomaly\", \"clickhouse_alert_fw_ent_anomaly\", \"cloudforce_one_request_notification\", \"cni_maintenance_notification\", \"custom_analytics\", \"custom_bot_detection_alert\", \"custom_ssl_certificate_event_type\", \"dedicated_ssl_certificate_event_type\", \"device_connectivity_anomaly_alert\", \"dos_attack_l4\", \"dos_attack_l7\", \"expiring_service_token_alert\", \"failing_logpush_job_disabled_alert\", \"fbm_auto_advertisement\", \"fbm_dosd_attack\", \"fbm_volumetric_attack\", \"health_check_status_notification\", \"hostname_aop_custom_certificate_expiration_type\", \"http_alert_edge_error\", \"http_alert_origin_error\", \"image_notification\", \"image_resizing_notification\", \"incident_alert\", \"load_balancing_health_alert\", \"load_balancing_pool_enablement_alert\", \"logo_match_alert\", \"magic_tunnel_health_check_event\", \"magic_wan_tunnel_health\", \"maintenance_event_notification\", \"mtls_certificate_store_certificate_expiration_type\", \"pages_event_alert\", \"radar_notification\", \"real_origin_monitoring\", \"scriptmonitor_alert_new_code_change_detections\", \"scriptmonitor_alert_new_hosts\", \"scriptmonitor_alert_new_malicious_hosts\", \"scriptmonitor_alert_new_malicious_scripts\", \"scriptmonitor_alert_new_malicious_url\", \"scriptmonitor_alert_new_max_length_resource_url\", \"scriptmonitor_alert_new_resources\", \"secondary_dns_all_primaries_failing\", \"secondary_dns_primaries_failing\", \"secondary_dns_warning\", \"secondary_dns_zone_successfully_updated\", \"secondary_dns_zone_validation_warning\", \"security_insights_alert\", \"sentinel_alert\", \"stream_live_notifications\", \"synthetic_test_latency_alert\", \"synthetic_test_low_availability_alert\", \"traffic_anomalies_alert\", \"tunnel_health_event\", \"tunnel_update_event\", \"universal_ssl_event_type\", \"web_analytics_metrics_update\", \"zone_aop_custom_certificate_expiration_type\"." + }, + { + "name": "mechanisms", + "type": "Attributes", + "description": "List of IDs that will be used when dispatching a notification. IDs for email type will be the email address.", + "children": [ + { + "name": "email", + "type": "Attributes Set", + "children": [ + { + "name": "id", + "type": "String", + "description": "The email address" + } + ] + }, + { + "name": "pagerduty", + "type": "Attributes Set", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID" + } + ] + }, + { + "name": "webhooks", + "type": "Attributes Set", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID" + } + ] + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the policy." + } + ], + "optional": [ + { + "name": "alert_interval", + "type": "String", + "description": "Optional specification of how often to re-alert from the same incident, not support on all alert types." + }, + { + "name": "description", + "type": "String", + "description": "Optional description for the Notification policy." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not the Notification policy is enabled." + }, + { + "name": "filters", + "type": "Attributes", + "description": "Optional filters that allow you to be alerted only on a subset of events for that alert type based on some criteria. This is only available for select alert types. See alert type documentation for more details.", + "children": [ + { + "name": "actions", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "affected_asns", + "type": "List of String", + "description": "Used for configuring radar_notification" + }, + { + "name": "affected_components", + "type": "List of String", + "description": "Used for configuring incident_alert" + }, + { + "name": "affected_locations", + "type": "List of String", + "description": "Used for configuring radar_notification" + }, + { + "name": "airport_code", + "type": "List of String", + "description": "Used for configuring maintenance_event_notification" + }, + { + "name": "alert_trigger_preferences", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "alert_trigger_preferences_value", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "enabled", + "type": "List of String", + "description": "Used for configuring load_balancing_pool_enablement_alert" + }, + { + "name": "environment", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "event", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "event_source", + "type": "List of String", + "description": "Used for configuring load_balancing_health_alert" + }, + { + "name": "event_type", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "group_by", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "health_check_id", + "type": "List of String", + "description": "Used for configuring health_check_status_notification" + }, + { + "name": "incident_impact", + "type": "List of String", + "description": "Used for configuring incident_alert" + }, + { + "name": "input_id", + "type": "List of String", + "description": "Used for configuring stream_live_notifications" + }, + { + "name": "insight_class", + "type": "List of String", + "description": "Used for configuring security_insights_alert" + }, + { + "name": "limit", + "type": "List of String", + "description": "Used for configuring billing_usage_alert" + }, + { + "name": "logo_tag", + "type": "List of String", + "description": "Used for configuring logo_match_alert" + }, + { + "name": "megabits_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "new_health", + "type": "List of String", + "description": "Used for configuring load_balancing_health_alert" + }, + { + "name": "new_status", + "type": "List of String", + "description": "Used for configuring tunnel_health_event" + }, + { + "name": "packets_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "pool_id", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "pop_names", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "product", + "type": "List of String", + "description": "Used for configuring billing_usage_alert" + }, + { + "name": "project_id", + "type": "List of String", + "description": "Used for configuring pages_event_alert" + }, + { + "name": "protocol", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "query_tag", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "requests_per_second", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "selectors", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "services", + "type": "List of String", + "description": "Used for configuring clickhouse_alert_fw_ent_anomaly" + }, + { + "name": "slo", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "status", + "type": "List of String", + "description": "Used for configuring health_check_status_notification" + }, + { + "name": "target_hostname", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "target_ip", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l4_alert" + }, + { + "name": "target_zone_name", + "type": "List of String", + "description": "Used for configuring advanced_ddos_attack_l7_alert" + }, + { + "name": "token_id", + "type": "List of String", + "description": "Access service token IDs to include for expiring_service_token_alert. Omit this property to include all current and future service tokens." + }, + { + "name": "traffic_exclusions", + "type": "List of String", + "description": "Used for configuring traffic_anomalies_alert" + }, + { + "name": "tunnel_id", + "type": "List of String", + "description": "Used for configuring tunnel_health_event" + }, + { + "name": "tunnel_name", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "type", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "where", + "type": "List of String", + "description": "Usage depends on specific alert type" + }, + { + "name": "zones", + "type": "List of String", + "description": "Usage depends on specific alert type" + } + ] + } + ], + "computed": [ + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID" + }, + { + "name": "modified", + "type": "String" + } + ] + }, + "data-source:cloudflare_notification_policy_webhooks": { + "kind": "data-source", + "name": "cloudflare_notification_policy_webhooks", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Notifications Read`\n- `Notifications Write`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_notification_policy_webhooks\" \"example_notification_policy_webhooks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n webhook_id = \"b115d5ec15c641ee8b7692c449b5227b\"\n}", + "required": [ + { + "name": "webhook_id", + "type": "String", + "description": "The unique identifier of a webhook" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account id" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the webhook destination was created." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of a webhook" + }, + { + "name": "last_failure", + "type": "String", + "description": "Timestamp of the last time an attempt to dispatch a notification to this webhook failed." + }, + { + "name": "last_success", + "type": "String", + "description": "Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook." + }, + { + "name": "name", + "type": "String", + "description": "The name of the webhook destination. This will be included in the request body when you receive a webhook notification." + }, + { + "name": "secret", + "type": "String", + "description": "Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.", + "sensitive": true + }, + { + "name": "type", + "type": "String", + "description": "Type of webhook endpoint.\nAvailable values: \"datadog\", \"discord\", \"feishu\", \"gchat\", \"generic\", \"opsgenie\", \"slack\", \"splunk\"." + }, + { + "name": "url", + "type": "String", + "description": "The POST endpoint to call when dispatching a notification." + } + ] + }, + "resource:cloudflare_notification_policy_webhooks": { + "kind": "resource", + "name": "cloudflare_notification_policy_webhooks", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Notifications Read`\n- `Notifications Write`\n- `Zero Trust: PII Read`", + "example": "resource \"cloudflare_notification_policy_webhooks\" \"example_notification_policy_webhooks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Slack Webhook\"\n url = \"https://hooks.slack.com/services/Ds3fdBFbV/456464Gdd\"\n secret = \"secret\"\n}", + "importExample": "$ terraform import cloudflare_notification_policy_webhooks.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account id" + }, + { + "name": "name", + "type": "String", + "description": "The name of the webhook destination. This will be included in the request body when you receive a webhook notification." + }, + { + "name": "url", + "type": "String", + "description": "The POST endpoint to call when dispatching a notification." + } + ], + "optional": [ + { + "name": "secret", + "type": "String", + "description": "Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.", + "sensitive": true + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the webhook destination was created." + }, + { + "name": "id", + "type": "String", + "description": "UUID" + }, + { + "name": "last_failure", + "type": "String", + "description": "Timestamp of the last time an attempt to dispatch a notification to this webhook failed." + }, + { + "name": "last_success", + "type": "String", + "description": "Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook." + }, + { + "name": "type", + "type": "String", + "description": "Type of webhook endpoint.\nAvailable values: \"datadog\", \"discord\", \"feishu\", \"gchat\", \"generic\", \"opsgenie\", \"slack\", \"splunk\"." + } + ] + }, + "list-data-source:cloudflare_notification_policy_webhooks_list": { + "kind": "list-data-source", + "name": "cloudflare_notification_policy_webhooks_list", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Notifications Read`\n- `Notifications Write`\n- `Zero Trust: PII Read`", + "example": "data \"cloudflare_notification_policy_webhooks_list\" \"example_notification_policy_webhooks_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account id" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the webhook destination was created." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of a webhook" + }, + { + "name": "last_failure", + "type": "String", + "description": "Timestamp of the last time an attempt to dispatch a notification to this webhook failed." + }, + { + "name": "last_success", + "type": "String", + "description": "Timestamp of the last time Cloudflare was able to successfully dispatch a notification using this webhook." + }, + { + "name": "name", + "type": "String", + "description": "The name of the webhook destination. This will be included in the request body when you receive a webhook notification." + }, + { + "name": "secret", + "type": "String", + "description": "Optional secret that will be passed in the `cf-webhook-auth` header when dispatching generic webhook notifications or formatted for supported destinations. Secrets are not returned in any API response body.", + "sensitive": true + }, + { + "name": "type", + "type": "String", + "description": "Type of webhook endpoint.\nAvailable values: \"datadog\", \"discord\", \"feishu\", \"gchat\", \"generic\", \"opsgenie\", \"slack\", \"splunk\"." + }, + { + "name": "url", + "type": "String", + "description": "The POST endpoint to call when dispatching a notification." + } + ] + } + ] + }, + "data-source:cloudflare_oauth_client": { + "kind": "data-source", + "name": "cloudflare_oauth_client", + "description": "Accepted Permissions\n\n- `OAuth Client Read`", + "example": "data \"cloudflare_oauth_client\" \"example_oauth_client\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n oauth_client_id = \"a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "oauth_client_id", + "type": "String", + "description": "The unique identifier for an OAuth client." + } + ], + "optional": [], + "computed": [ + { + "name": "allowed_cors_origins", + "type": "List of String", + "description": "Array of allowed CORS origins." + }, + { + "name": "client_id", + "type": "String", + "description": "The unique identifier for an OAuth client." + }, + { + "name": "client_name", + "type": "String", + "description": "Human-readable name of the OAuth client." + }, + { + "name": "client_uri", + "type": "String", + "description": "URL of the home page of the client." + }, + { + "name": "client_uri_verification", + "type": "Attributes", + "description": "Client URI domain control verification state.", + "children": [ + { + "name": "status", + "type": "String", + "description": "Current verification status for the client URI host.\nAvailable values: \"pending\", \"in_progress\", \"verified\", \"failed\"." + }, + { + "name": "text", + "type": "String", + "description": "Exact TXT record value that must be added to DNS to prove ownership of the client URI host." + } + ] + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the OAuth client was created." + }, + { + "name": "grant_types", + "type": "List of String", + "description": "Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally." + }, + { + "name": "has_rotated_secret", + "type": "Boolean", + "description": "Indicates whether the client has a rotated secret that has not yet been deleted." + }, + { + "name": "logo_uri", + "type": "String", + "description": "URL of the client's logo." + }, + { + "name": "optional_scopes", + "type": "List of String", + "description": "Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional." + }, + { + "name": "policy_uri", + "type": "String", + "description": "URL that points to a privacy policy document." + }, + { + "name": "post_logout_redirect_uris", + "type": "List of String", + "description": "Array of allowed post-logout redirect URIs." + }, + { + "name": "promoted_at", + "type": "String", + "description": "Timestamp when the OAuth client was promoted to public visibility." + }, + { + "name": "redirect_uris", + "type": "List of String", + "description": "Array of allowed redirect URIs for the client." + }, + { + "name": "response_types", + "type": "List of String", + "description": "Array of OAuth response types the client is allowed to use." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`." + }, + { + "name": "token_endpoint_auth_method", + "type": "String", + "description": "The authentication method the client uses at the token endpoint.\nAvailable values: \"none\", \"client_secret_basic\", \"client_secret_post\"." + }, + { + "name": "tos_uri", + "type": "String", + "description": "URL that points to a terms of service document." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the OAuth client was last updated." + }, + { + "name": "visibility", + "type": "String", + "description": "Visibility of the OAuth client.\nAvailable values: \"public\", \"private\"." + } + ] + }, + "resource:cloudflare_oauth_client": { + "kind": "resource", + "name": "cloudflare_oauth_client", + "description": "Accepted Permissions\n\n- `OAuth Client Read`\n- `OAuth Client Write`", + "example": "resource \"cloudflare_oauth_client\" \"example_oauth_client\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n client_name = \"My OAuth App\"\n grant_types = [\"authorization_code\", \"refresh_token\"]\n redirect_uris = [\"https://example.com/callback\"]\n response_types = [\"code\"]\n scopes = [\"account.read\"]\n token_endpoint_auth_method = \"client_secret_post\"\n allowed_cors_origins = [\"https://example.com\"]\n client_uri = \"https://example.com\"\n logo_uri = \"https://example.com/logo.png\"\n optional_scopes = [\"account.write\"]\n policy_uri = \"https://example.com/privacy\"\n post_logout_redirect_uris = [\"https://example.com/logout\"]\n tos_uri = \"https://example.com/tos\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "client_name", + "type": "String", + "description": "Human-readable name of the OAuth client." + }, + { + "name": "grant_types", + "type": "List of String", + "description": "Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally." + }, + { + "name": "redirect_uris", + "type": "List of String", + "description": "Array of allowed redirect URIs for the client." + }, + { + "name": "response_types", + "type": "List of String", + "description": "Array of OAuth response types the client is allowed to use." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`." + }, + { + "name": "token_endpoint_auth_method", + "type": "String", + "description": "The authentication method the client uses at the token endpoint.\nAvailable values: \"none\", \"client_secret_basic\", \"client_secret_post\"." + } + ], + "optional": [ + { + "name": "allowed_cors_origins", + "type": "List of String", + "description": "Array of allowed CORS origins." + }, + { + "name": "client_uri", + "type": "String", + "description": "URL of the home page of the client." + }, + { + "name": "logo_uri", + "type": "String", + "description": "URL of the client's logo." + }, + { + "name": "oauth_client_id", + "type": "String", + "description": "The unique identifier for an OAuth client." + }, + { + "name": "optional_scopes", + "type": "List of String", + "description": "Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional." + }, + { + "name": "policy_uri", + "type": "String", + "description": "URL that points to a privacy policy document." + }, + { + "name": "post_logout_redirect_uris", + "type": "List of String", + "description": "Array of allowed post-logout redirect URIs." + }, + { + "name": "tos_uri", + "type": "String", + "description": "URL that points to a terms of service document." + }, + { + "name": "visibility", + "type": "String", + "description": "Promote the OAuth client from private to public visibility. Only `public` is accepted; demotion to `private` is not supported. Promotion requires a non-empty client name, logo URI, verified client URI host, and at least one non-identity scope.\nAvailable values: \"public\"." + } + ], + "computed": [ + { + "name": "client_id", + "type": "String", + "description": "The unique identifier for an OAuth client." + }, + { + "name": "client_secret", + "type": "String", + "description": "The client secret. This is the only time the secret is returned in a response.", + "sensitive": true + }, + { + "name": "client_uri_verification", + "type": "Attributes", + "description": "Client URI domain control verification state.", + "children": [ + { + "name": "status", + "type": "String", + "description": "Current verification status for the client URI host.\nAvailable values: \"pending\", \"in_progress\", \"verified\", \"failed\"." + }, + { + "name": "text", + "type": "String", + "description": "Exact TXT record value that must be added to DNS to prove ownership of the client URI host." + } + ] + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the OAuth client was created." + }, + { + "name": "has_rotated_secret", + "type": "Boolean", + "description": "Indicates whether the client has a rotated secret that has not yet been deleted." + }, + { + "name": "promoted_at", + "type": "String", + "description": "Timestamp when the OAuth client was promoted to public visibility." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the OAuth client was last updated." + } + ] + }, + "list-data-source:cloudflare_oauth_clients": { + "kind": "list-data-source", + "name": "cloudflare_oauth_clients", + "description": "Accepted Permissions\n\n- `OAuth Client Read`", + "example": "data \"cloudflare_oauth_clients\" \"example_oauth_clients\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allowed_cors_origins", + "type": "List of String", + "description": "Array of allowed CORS origins." + }, + { + "name": "client_id", + "type": "String", + "description": "The unique identifier for an OAuth client." + }, + { + "name": "client_name", + "type": "String", + "description": "Human-readable name of the OAuth client." + }, + { + "name": "client_uri", + "type": "String", + "description": "URL of the home page of the client." + }, + { + "name": "client_uri_verification", + "type": "Attributes", + "description": "Client URI domain control verification state.", + "children": [ + { + "name": "status", + "type": "String", + "description": "Current verification status for the client URI host.\nAvailable values: \"pending\", \"in_progress\", \"verified\", \"failed\"." + }, + { + "name": "text", + "type": "String", + "description": "Exact TXT record value that must be added to DNS to prove ownership of the client URI host." + } + ] + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the OAuth client was created." + }, + { + "name": "grant_types", + "type": "List of String", + "description": "Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally." + }, + { + "name": "has_rotated_secret", + "type": "Boolean", + "description": "Indicates whether the client has a rotated secret that has not yet been deleted." + }, + { + "name": "logo_uri", + "type": "String", + "description": "URL of the client's logo." + }, + { + "name": "optional_scopes", + "type": "List of String", + "description": "Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional." + }, + { + "name": "policy_uri", + "type": "String", + "description": "URL that points to a privacy policy document." + }, + { + "name": "post_logout_redirect_uris", + "type": "List of String", + "description": "Array of allowed post-logout redirect URIs." + }, + { + "name": "promoted_at", + "type": "String", + "description": "Timestamp when the OAuth client was promoted to public visibility." + }, + { + "name": "redirect_uris", + "type": "List of String", + "description": "Array of allowed redirect URIs for the client." + }, + { + "name": "response_types", + "type": "List of String", + "description": "Array of OAuth response types the client is allowed to use." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`." + }, + { + "name": "token_endpoint_auth_method", + "type": "String", + "description": "The authentication method the client uses at the token endpoint.\nAvailable values: \"none\", \"client_secret_basic\", \"client_secret_post\"." + }, + { + "name": "tos_uri", + "type": "String", + "description": "URL that points to a terms of service document." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the OAuth client was last updated." + }, + { + "name": "visibility", + "type": "String", + "description": "Visibility of the OAuth client.\nAvailable values: \"public\", \"private\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_oauth_scopes": { + "kind": "list-data-source", + "name": "cloudflare_oauth_scopes", + "example": "data \"cloudflare_oauth_scopes\" \"example_oauth_scopes\" {\n\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "category", + "type": "String", + "description": "Category for grouping scopes in the UI." + }, + { + "name": "id", + "type": "String", + "description": "The scope label to use in the scopes array when creating or updating an OAuth client." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name of the OAuth scope." + }, + { + "name": "scopes", + "type": "List of String", + "description": "The underlying resource scopes (Bach scopes) that define which resources this OAuth scope can act upon." + } + ] + } + ] + }, + "data-source:cloudflare_observatory_scheduled_test": { + "kind": "data-source", + "name": "cloudflare_observatory_scheduled_test", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_observatory_scheduled_test\" \"example_observatory_scheduled_test\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n url = \"example.com\"\n region = \"us-central1\"\n}", + "required": [ + { + "name": "url", + "type": "String", + "description": "A URL." + } + ], + "optional": [ + { + "name": "region", + "type": "String", + "description": "A test region.\nAvailable values: \"asia-east1\", \"asia-northeast1\", \"asia-northeast2\", \"asia-south1\", \"asia-southeast1\", \"australia-southeast1\", \"europe-north1\", \"europe-southwest1\", \"europe-west1\", \"europe-west2\", \"europe-west3\", \"europe-west4\", \"europe-west8\", \"europe-west9\", \"me-west1\", \"southamerica-east1\", \"us-central1\", \"us-east1\", \"us-east4\", \"us-south1\", \"us-west1\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "frequency", + "type": "String", + "description": "The frequency of the test.\nAvailable values: \"DAILY\", \"WEEKLY\"." + } + ] + }, + "resource:cloudflare_observatory_scheduled_test": { + "kind": "resource", + "name": "cloudflare_observatory_scheduled_test", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "resource \"cloudflare_observatory_scheduled_test\" \"example_observatory_scheduled_test\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n url = \"example.com\"\n}", + "importExample": "$ terraform import cloudflare_observatory_scheduled_test.example '/'", + "required": [ + { + "name": "url", + "type": "String", + "description": "A URL." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "frequency", + "type": "String", + "description": "The frequency of the scheduled test. Defaults to WEEKLY for free plans, DAILY for paid plans.\nAvailable values: \"DAILY\", \"WEEKLY\"." + }, + { + "name": "region", + "type": "String", + "description": "A test region.\nAvailable values: \"asia-east1\", \"asia-northeast1\", \"asia-northeast2\", \"asia-south1\", \"asia-southeast1\", \"australia-southeast1\", \"europe-north1\", \"europe-southwest1\", \"europe-west1\", \"europe-west2\", \"europe-west3\", \"europe-west4\", \"europe-west8\", \"europe-west9\", \"me-west1\", \"southamerica-east1\", \"us-central1\", \"us-east1\", \"us-east4\", \"us-south1\", \"us-west1\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "A URL." + }, + { + "name": "schedule", + "type": "Attributes", + "description": "The test schedule.", + "children": [ + { + "name": "frequency", + "type": "String", + "description": "The frequency of the test.\nAvailable values: \"DAILY\", \"WEEKLY\"." + }, + { + "name": "region", + "type": "String", + "description": "A test region.\nAvailable values: \"asia-east1\", \"asia-northeast1\", \"asia-northeast2\", \"asia-south1\", \"asia-southeast1\", \"australia-southeast1\", \"europe-north1\", \"europe-southwest1\", \"europe-west1\", \"europe-west2\", \"europe-west3\", \"europe-west4\", \"europe-west8\", \"europe-west9\", \"me-west1\", \"southamerica-east1\", \"us-central1\", \"us-east1\", \"us-east4\", \"us-south1\", \"us-west1\"." + }, + { + "name": "url", + "type": "String", + "description": "A URL." + } + ] + }, + { + "name": "test", + "type": "Attributes", + "children": [ + { + "name": "date", + "type": "String" + }, + { + "name": "desktop_report", + "type": "Attributes", + "description": "The Lighthouse report.", + "children": [ + { + "name": "cls", + "type": "Number", + "description": "Cumulative Layout Shift." + }, + { + "name": "device_type", + "type": "String", + "description": "The type of device.\nAvailable values: \"DESKTOP\", \"MOBILE\"." + }, + { + "name": "error", + "type": "Attributes", + "children": [ + { + "name": "code", + "type": "String", + "description": "The error code of the Lighthouse result.\nAvailable values: \"NOT_REACHABLE\", \"DNS_FAILURE\", \"NOT_HTML\", \"LIGHTHOUSE_TIMEOUT\", \"UNKNOWN\"." + }, + { + "name": "detail", + "type": "String", + "description": "Detailed error message." + }, + { + "name": "final_displayed_url", + "type": "String", + "description": "The final URL displayed to the user." + } + ] + }, + { + "name": "fcp", + "type": "Number", + "description": "First Contentful Paint." + }, + { + "name": "json_report_url", + "type": "String", + "description": "The URL to the full Lighthouse JSON report." + }, + { + "name": "lcp", + "type": "Number", + "description": "Largest Contentful Paint." + }, + { + "name": "performance_score", + "type": "Number", + "description": "The Lighthouse performance score." + }, + { + "name": "si", + "type": "Number", + "description": "Speed Index." + }, + { + "name": "state", + "type": "String", + "description": "The state of the Lighthouse report.\nAvailable values: \"RUNNING\", \"COMPLETE\", \"FAILED\"." + }, + { + "name": "tbt", + "type": "Number", + "description": "Total Blocking Time." + }, + { + "name": "ttfb", + "type": "Number", + "description": "Time To First Byte." + }, + { + "name": "tti", + "type": "Number", + "description": "Time To Interactive." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "mobile_report", + "type": "Attributes", + "description": "The Lighthouse report.", + "children": [ + { + "name": "cls", + "type": "Number", + "description": "Cumulative Layout Shift." + }, + { + "name": "device_type", + "type": "String", + "description": "The type of device.\nAvailable values: \"DESKTOP\", \"MOBILE\"." + }, + { + "name": "error", + "type": "Attributes", + "children": [ + { + "name": "code", + "type": "String", + "description": "The error code of the Lighthouse result.\nAvailable values: \"NOT_REACHABLE\", \"DNS_FAILURE\", \"NOT_HTML\", \"LIGHTHOUSE_TIMEOUT\", \"UNKNOWN\"." + }, + { + "name": "detail", + "type": "String", + "description": "Detailed error message." + }, + { + "name": "final_displayed_url", + "type": "String", + "description": "The final URL displayed to the user." + } + ] + }, + { + "name": "fcp", + "type": "Number", + "description": "First Contentful Paint." + }, + { + "name": "json_report_url", + "type": "String", + "description": "The URL to the full Lighthouse JSON report." + }, + { + "name": "lcp", + "type": "Number", + "description": "Largest Contentful Paint." + }, + { + "name": "performance_score", + "type": "Number", + "description": "The Lighthouse performance score." + }, + { + "name": "si", + "type": "Number", + "description": "Speed Index." + }, + { + "name": "state", + "type": "String", + "description": "The state of the Lighthouse report.\nAvailable values: \"RUNNING\", \"COMPLETE\", \"FAILED\"." + }, + { + "name": "tbt", + "type": "Number", + "description": "Total Blocking Time." + }, + { + "name": "ttfb", + "type": "Number", + "description": "Time To First Byte." + }, + { + "name": "tti", + "type": "Number", + "description": "Time To Interactive." + } + ] + }, + { + "name": "region", + "type": "Attributes", + "description": "A test region with a label.", + "children": [ + { + "name": "label", + "type": "String" + }, + { + "name": "value", + "type": "String", + "description": "A test region.\nAvailable values: \"asia-east1\", \"asia-northeast1\", \"asia-northeast2\", \"asia-south1\", \"asia-southeast1\", \"australia-southeast1\", \"europe-north1\", \"europe-southwest1\", \"europe-west1\", \"europe-west2\", \"europe-west3\", \"europe-west4\", \"europe-west8\", \"europe-west9\", \"me-west1\", \"southamerica-east1\", \"us-central1\", \"us-east1\", \"us-east4\", \"us-south1\", \"us-west1\"." + } + ] + }, + { + "name": "schedule_frequency", + "type": "String", + "description": "The frequency of the test.\nAvailable values: \"DAILY\", \"WEEKLY\"." + }, + { + "name": "url", + "type": "String", + "description": "A URL." + } + ] + } + ] + }, + "data-source:cloudflare_organization": { + "kind": "data-source", + "name": "cloudflare_organization", + "description": "Accepted Permissions\n\n- `User Details Read`\n- `User Details Write`", + "example": "data \"cloudflare_organization\" \"example_organization\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "containing", + "type": "Attributes", + "children": [ + { + "name": "account", + "type": "String", + "description": "Filter the list of organizations to the ones that contain this particular\naccount." + }, + { + "name": "organization", + "type": "String", + "description": "Filter the list of organizations to the ones that contain this particular\norganization." + }, + { + "name": "user", + "type": "String", + "description": "Filter the list of organizations to the ones that contain this particular\nuser.\n\nIMPORTANT: Just because an organization \"contains\" a user is not a\nrepresentation of any authorization or privilege to manage any resources\ntherein. An organization \"containing\" a user simply means the user is managed by\nthat organization." + } + ] + }, + { + "name": "id", + "type": "List of String", + "description": "Only return organizations with the specified IDs (ex. id=foo&id=bar). Send multiple elements\nby repeating the query value." + }, + { + "name": "name", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "(case-insensitive) Filter the list of organizations to where the name contains a particular\nstring." + }, + { + "name": "ends_with", + "type": "String", + "description": "(case-insensitive) Filter the list of organizations to where the name ends with a particular\nstring." + }, + { + "name": "starts_with", + "type": "String", + "description": "(case-insensitive) Filter the list of organizations to where the name starts with a\nparticular string." + } + ] + }, + { + "name": "page_size", + "type": "Number", + "description": "The amount of items to return. Defaults to 10." + }, + { + "name": "page_token", + "type": "String", + "description": "An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token." + }, + { + "name": "parent", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "Filter the list of organizations to the ones that are a sub-organization\nof the specified organization.\n\n\"null\" is a valid value to provide for this parameter. It means \"where\nan organization has no parent (i.e. it is a 'root' organization).\"" + } + ] + } + ] + }, + { + "name": "organization_id", + "type": "String" + } + ], + "computed": [ + { + "name": "create_time", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "meta", + "type": "Attributes", + "children": [ + { + "name": "hierarchy_tags", + "type": "List of String", + "description": "Ordered chain of organization tags from the root organization down to\n(and including) this organization itself. Root organizations return a\nsingle-element array containing their own tag; sub-organizations return\n`[rootTag, ...intermediateTags, parentTag, selfTag]`. Useful for\nconstructing authorization scopes that need to cover every ancestor\nin the hierarchy." + }, + { + "name": "managed_by", + "type": "String" + }, + { + "name": "tenant_flags", + "type": "Attributes", + "description": "Enable features for Organizations.", + "children": [ + { + "name": "account_creation", + "type": "String" + }, + { + "name": "account_creation_applies_tenant_defaults", + "type": "String" + }, + { + "name": "account_deletion", + "type": "String" + }, + { + "name": "account_migration", + "type": "String" + }, + { + "name": "account_mobility", + "type": "String" + }, + { + "name": "enterprise_capability", + "type": "String" + }, + { + "name": "member_management", + "type": "String" + }, + { + "name": "sub_org_creation", + "type": "String" + } + ] + } + ] + }, + { + "name": "name", + "type": "String" + }, + { + "name": "parent", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "profile", + "type": "Attributes", + "children": [ + { + "name": "business_address", + "type": "String" + }, + { + "name": "business_email", + "type": "String" + }, + { + "name": "business_name", + "type": "String" + }, + { + "name": "business_phone", + "type": "String" + }, + { + "name": "external_metadata", + "type": "String" + } + ] + } + ] + }, + "resource:cloudflare_organization": { + "kind": "resource", + "name": "cloudflare_organization", + "description": "Accepted Permissions\n\n- `User Details Write`", + "example": "resource \"cloudflare_organization\" \"example_organization\" {\n name = \"name\"\n parent = {\n id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n }\n profile = {\n business_address = \"business_address\"\n business_email = \"business_email\"\n business_name = \"business_name\"\n business_phone = \"business_phone\"\n external_metadata = \"external_metadata\"\n }\n}", + "importExample": "$ terraform import cloudflare_organization.example ''", + "required": [ + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "parent", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "profile", + "type": "Attributes", + "children": [ + { + "name": "business_address", + "type": "String" + }, + { + "name": "business_email", + "type": "String" + }, + { + "name": "business_name", + "type": "String" + }, + { + "name": "business_phone", + "type": "String" + }, + { + "name": "external_metadata", + "type": "String" + } + ] + } + ], + "computed": [ + { + "name": "create_time", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "meta", + "type": "Attributes", + "children": [ + { + "name": "hierarchy_tags", + "type": "List of String", + "description": "Ordered chain of organization tags from the root organization down to\n(and including) this organization itself. Root organizations return a\nsingle-element array containing their own tag; sub-organizations return\n`[rootTag, ...intermediateTags, parentTag, selfTag]`. Useful for\nconstructing authorization scopes that need to cover every ancestor\nin the hierarchy." + }, + { + "name": "managed_by", + "type": "String" + }, + { + "name": "tenant_flags", + "type": "Attributes", + "description": "Enable features for Organizations.", + "children": [ + { + "name": "account_creation", + "type": "String" + }, + { + "name": "account_creation_applies_tenant_defaults", + "type": "String" + }, + { + "name": "account_deletion", + "type": "String" + }, + { + "name": "account_migration", + "type": "String" + }, + { + "name": "account_mobility", + "type": "String" + }, + { + "name": "enterprise_capability", + "type": "String" + }, + { + "name": "member_management", + "type": "String" + }, + { + "name": "sub_org_creation", + "type": "String" + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_organization_profile": { + "kind": "data-source", + "name": "cloudflare_organization_profile", + "example": "data \"cloudflare_organization_profile\" \"example_organization_profile\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n}", + "required": [ + { + "name": "organization_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "business_address", + "type": "String" + }, + { + "name": "business_email", + "type": "String" + }, + { + "name": "business_name", + "type": "String" + }, + { + "name": "business_phone", + "type": "String" + }, + { + "name": "external_metadata", + "type": "String" + } + ] + }, + "resource:cloudflare_organization_profile": { + "kind": "resource", + "name": "cloudflare_organization_profile", + "example": "resource \"cloudflare_organization_profile\" \"example_organization_profile\" {\n organization_id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n business_address = \"business_address\"\n business_email = \"business_email\"\n business_name = \"business_name\"\n business_phone = \"business_phone\"\n external_metadata = \"external_metadata\"\n}", + "required": [ + { + "name": "business_address", + "type": "String" + }, + { + "name": "business_email", + "type": "String" + }, + { + "name": "business_name", + "type": "String" + }, + { + "name": "business_phone", + "type": "String" + }, + { + "name": "external_metadata", + "type": "String" + }, + { + "name": "organization_id", + "type": "String" + } + ], + "optional": [], + "computed": [] + }, + "list-data-source:cloudflare_organizations": { + "kind": "list-data-source", + "name": "cloudflare_organizations", + "description": "Accepted Permissions\n\n- `User Details Read`\n- `User Details Write`", + "example": "data \"cloudflare_organizations\" \"example_organizations\" {\n id = [\"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"]\n containing = {\n account = \"account\"\n organization = \"organization\"\n user = \"user\"\n }\n name = {\n contains = \"contains\"\n ends_with = \"endsWith\"\n starts_with = \"startsWith\"\n }\n page_size = 0\n page_token = \"page_token\"\n parent = {\n id = \"a7b9c3d2e8f4a1b5c6d0e9f2a3b7c4d8\"\n }\n}", + "required": [], + "optional": [ + { + "name": "containing", + "type": "Attributes", + "children": [ + { + "name": "account", + "type": "String", + "description": "Filter the list of organizations to the ones that contain this particular\naccount." + }, + { + "name": "organization", + "type": "String", + "description": "Filter the list of organizations to the ones that contain this particular\norganization." + }, + { + "name": "user", + "type": "String", + "description": "Filter the list of organizations to the ones that contain this particular\nuser.\n\nIMPORTANT: Just because an organization \"contains\" a user is not a\nrepresentation of any authorization or privilege to manage any resources\ntherein. An organization \"containing\" a user simply means the user is managed by\nthat organization." + } + ] + }, + { + "name": "id", + "type": "List of String", + "description": "Only return organizations with the specified IDs (ex. id=foo&id=bar). Send multiple elements\nby repeating the query value." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "Attributes", + "children": [ + { + "name": "contains", + "type": "String", + "description": "(case-insensitive) Filter the list of organizations to where the name contains a particular\nstring." + }, + { + "name": "ends_with", + "type": "String", + "description": "(case-insensitive) Filter the list of organizations to where the name ends with a particular\nstring." + }, + { + "name": "starts_with", + "type": "String", + "description": "(case-insensitive) Filter the list of organizations to where the name starts with a\nparticular string." + } + ] + }, + { + "name": "page_size", + "type": "Number", + "description": "The amount of items to return. Defaults to 10." + }, + { + "name": "page_token", + "type": "String", + "description": "An opaque token returned from the last list response that when\nprovided will retrieve the next page.\n\nParameters used to filter the retrieved list must remain in subsequent\nrequests with a page token." + }, + { + "name": "parent", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "Filter the list of organizations to the ones that are a sub-organization\nof the specified organization.\n\n\"null\" is a valid value to provide for this parameter. It means \"where\nan organization has no parent (i.e. it is a 'root' organization).\"" + } + ] + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "create_time", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "meta", + "type": "Attributes", + "children": [ + { + "name": "hierarchy_tags", + "type": "List of String", + "description": "Ordered chain of organization tags from the root organization down to\n(and including) this organization itself. Root organizations return a\nsingle-element array containing their own tag; sub-organizations return\n`[rootTag, ...intermediateTags, parentTag, selfTag]`. Useful for\nconstructing authorization scopes that need to cover every ancestor\nin the hierarchy." + }, + { + "name": "managed_by", + "type": "String" + }, + { + "name": "tenant_flags", + "type": "Attributes", + "description": "Enable features for Organizations.", + "children": [ + { + "name": "account_creation", + "type": "String" + }, + { + "name": "account_creation_applies_tenant_defaults", + "type": "String" + }, + { + "name": "account_deletion", + "type": "String" + }, + { + "name": "account_migration", + "type": "String" + }, + { + "name": "account_mobility", + "type": "String" + }, + { + "name": "enterprise_capability", + "type": "String" + }, + { + "name": "member_management", + "type": "String" + }, + { + "name": "sub_org_creation", + "type": "String" + } + ] + } + ] + }, + { + "name": "name", + "type": "String" + }, + { + "name": "parent", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "profile", + "type": "Attributes", + "children": [ + { + "name": "business_address", + "type": "String" + }, + { + "name": "business_email", + "type": "String" + }, + { + "name": "business_name", + "type": "String" + }, + { + "name": "business_phone", + "type": "String" + }, + { + "name": "external_metadata", + "type": "String" + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_origin_ca_certificate": { + "kind": "data-source", + "name": "cloudflare_origin_ca_certificate", + "example": "data \"cloudflare_origin_ca_certificate\" \"example_origin_ca_certificate\" {\n certificate_id = \"328578533902268680212849205732770752308931942346\"\n}", + "required": [], + "optional": [ + { + "name": "certificate_id", + "type": "String", + "description": "The x509 serial number of the Origin CA certificate." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "Limit to the number of records returned." + }, + { + "name": "offset", + "type": "Number", + "description": "Offset the results." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ] + } + ], + "computed": [ + { + "name": "certificate", + "type": "String", + "description": "The Origin CA certificate. Will be newline-encoded." + }, + { + "name": "csr", + "type": "String", + "description": "The Certificate Signing Request (CSR). Must be newline-encoded." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate will expire." + }, + { + "name": "hostnames", + "type": "List of String", + "description": "Array of hostnames or wildcard names bound to the certificate.\nHostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode." + }, + { + "name": "id", + "type": "String", + "description": "The x509 serial number of the Origin CA certificate." + }, + { + "name": "request_type", + "type": "String", + "description": "Signature type desired on certificate (\"origin-rsa\" (rsa), \"origin-ecc\" (ecdsa), or \"keyless-certificate\" (for Keyless SSL servers).\nAvailable values: \"origin-rsa\", \"origin-ecc\", \"keyless-certificate\"." + }, + { + "name": "requested_validity", + "type": "Number", + "description": "The number of days for which the certificate should be valid.\nAvailable values: 7, 30, 90, 365, 730, 1095, 5475." + } + ] + }, + "resource:cloudflare_origin_ca_certificate": { + "kind": "resource", + "name": "cloudflare_origin_ca_certificate", + "example": "resource \"cloudflare_origin_ca_certificate\" \"example_origin_ca_certificate\" {\n csr = <'", + "required": [ + { + "name": "csr", + "type": "String", + "description": "The Certificate Signing Request (CSR). Must be newline-encoded." + }, + { + "name": "hostnames", + "type": "List of String", + "description": "Array of hostnames or wildcard names bound to the certificate.\nHostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode." + }, + { + "name": "request_type", + "type": "String", + "description": "Signature type desired on certificate (\"origin-rsa\" (rsa), \"origin-ecc\" (ecdsa), or \"keyless-certificate\" (for Keyless SSL servers).\nAvailable values: \"origin-rsa\", \"origin-ecc\", \"keyless-certificate\"." + } + ], + "optional": [ + { + "name": "requested_validity", + "type": "Number", + "description": "The number of days for which the certificate should be valid.\nAvailable values: 7, 30, 90, 365, 730, 1095, 5475." + } + ], + "computed": [ + { + "name": "certificate", + "type": "String", + "description": "The Origin CA certificate. Will be newline-encoded." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate will expire." + }, + { + "name": "id", + "type": "String", + "description": "The x509 serial number of the Origin CA certificate." + } + ] + }, + "list-data-source:cloudflare_origin_ca_certificates": { + "kind": "list-data-source", + "name": "cloudflare_origin_ca_certificates", + "example": "data \"cloudflare_origin_ca_certificates\" \"example_origin_ca_certificates\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n limit = 10\n offset = 10\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "limit", + "type": "Number", + "description": "Limit to the number of records returned." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "offset", + "type": "Number", + "description": "Offset the results." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "certificate", + "type": "String", + "description": "The Origin CA certificate. Will be newline-encoded." + }, + { + "name": "csr", + "type": "String", + "description": "The Certificate Signing Request (CSR). Must be newline-encoded." + }, + { + "name": "expires_on", + "type": "String", + "description": "When the certificate will expire." + }, + { + "name": "hostnames", + "type": "List of String", + "description": "Array of hostnames or wildcard names bound to the certificate.\nHostnames must be fully qualified domain names (FQDNs) belonging to zones on your account (e.g., `example.com` or `sub.example.com`). Wildcards are supported only as a `*.` prefix for a single level (e.g., `*.example.com`). Double wildcards (`*.*.example.com`) and interior wildcards (`foo.*.example.com`) are not allowed. The wildcard suffix must be a multi-label domain (`*.example.com` is valid, but `*.com` is not). Unicode/IDN hostnames are accepted and automatically converted to punycode." + }, + { + "name": "id", + "type": "String", + "description": "The x509 serial number of the Origin CA certificate." + }, + { + "name": "request_type", + "type": "String", + "description": "Signature type desired on certificate (\"origin-rsa\" (rsa), \"origin-ecc\" (ecdsa), or \"keyless-certificate\" (for Keyless SSL servers).\nAvailable values: \"origin-rsa\", \"origin-ecc\", \"keyless-certificate\"." + }, + { + "name": "requested_validity", + "type": "Number", + "description": "The number of days for which the certificate should be valid.\nAvailable values: 7, 30, 90, 365, 730, 1095, 5475." + } + ] + } + ] + }, + "data-source:cloudflare_origin_cloud_region": { + "kind": "data-source", + "name": "cloudflare_origin_cloud_region", + "example": "data \"cloudflare_origin_cloud_region\" \"example_origin_cloud_region\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin_ip = \"192.0.2.1\"\n}", + "required": [ + { + "name": "origin_ip", + "type": "String" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String", + "description": "Time this mapping was last modified." + }, + { + "name": "region", + "type": "String", + "description": "Cloud vendor region identifier." + }, + { + "name": "vendor", + "type": "String", + "description": "Cloud vendor hosting the origin.\nAvailable values: \"aws\", \"azure\", \"gcp\", \"oci\"." + } + ] + }, + "resource:cloudflare_origin_cloud_region": { + "kind": "resource", + "name": "cloudflare_origin_cloud_region", + "example": "resource \"cloudflare_origin_cloud_region\" \"example_origin_cloud_region\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n origin_ip = \"192.0.2.1\"\n region = \"us-east-1\"\n vendor = \"aws\"\n}", + "importExample": "$ terraform import cloudflare_origin_cloud_region.example '/'", + "required": [ + { + "name": "origin_ip", + "type": "String", + "description": "Origin IP address (IPv4 or IPv6). For the single PUT endpoint (`PUT /origin/cloud_regions/{origin_ip}`), this field must match the path parameter or the request will be rejected with a 400 error. For the batch PUT endpoint, this field identifies which mapping to upsert." + }, + { + "name": "region", + "type": "String", + "description": "Cloud vendor region identifier. Must be a valid region for the specified vendor as returned by the supported_regions endpoint." + }, + { + "name": "vendor", + "type": "String", + "description": "Cloud vendor hosting the origin. Must be one of the supported vendors.\nAvailable values: \"aws\", \"azure\", \"gcp\", \"oci\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Origin IP address (IPv4 or IPv6). For the single PUT endpoint (`PUT /origin/cloud_regions/{origin_ip}`), this field must match the path parameter or the request will be rejected with a 400 error. For the batch PUT endpoint, this field identifies which mapping to upsert." + }, + { + "name": "modified_on", + "type": "String", + "description": "Time this mapping was last modified." + } + ] + }, + "list-data-source:cloudflare_origin_cloud_regions": { + "kind": "list-data-source", + "name": "cloudflare_origin_cloud_regions", + "example": "data \"cloudflare_origin_cloud_regions\" \"example_origin_cloud_regions\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "The origin IP address (IPv4 or IPv6). Normalized to canonical form (RFC 5952 for IPv6)." + }, + { + "name": "modified_on", + "type": "String", + "description": "Time this mapping was last modified." + }, + { + "name": "origin_ip", + "type": "String", + "description": "The origin IP address (IPv4 or IPv6). Normalized to canonical form (RFC 5952 for IPv6)." + }, + { + "name": "region", + "type": "String", + "description": "Cloud vendor region identifier." + }, + { + "name": "vendor", + "type": "String", + "description": "Cloud vendor hosting the origin.\nAvailable values: \"aws\", \"azure\", \"gcp\", \"oci\"." + } + ] + } + ] + }, + "data-source:cloudflare_origin_tls_compliance_modes": { + "kind": "data-source", + "name": "cloudflare_origin_tls_compliance_modes", + "example": "data \"cloudflare_origin_tls_compliance_modes\" \"example_origin_tls_compliance_modes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + }, + { + "name": "value", + "type": "List of String", + "description": "List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone's origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint." + } + ] + }, + "resource:cloudflare_origin_tls_compliance_modes": { + "kind": "resource", + "name": "cloudflare_origin_tls_compliance_modes", + "example": "resource \"cloudflare_origin_tls_compliance_modes\" \"example_origin_tls_compliance_modes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = [\"fips\", \"pqh\"]\n}", + "importExample": "$ terraform import cloudflare_origin_tls_compliance_modes.example ''", + "required": [ + { + "name": "value", + "type": "List of String", + "description": "List of TLS compliance modes that constrain the key-exchange algorithms Cloudflare may use when establishing the TLS connection to the zone's origin. Currently supported values are `fips` (FIPS-approved curves) and `pqh` (post-quantum hybrid). Future modes (e.g. `cnsa2`) may be added; clients should treat unknown values as opaque strings. Multiple modes are combined as the intersection of their permitted algorithm lists; selections whose intersection is empty are rejected. An empty list clears the constraint." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "data-source:cloudflare_page_rule": { + "kind": "data-source", + "name": "cloudflare_page_rule", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_page_rule\" \"example_page_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pagerule_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "pagerule_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the Page Rule was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the Page Rule was last modified." + }, + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule, used to define which Page Rule is processed\nover another. A higher number indicates a higher priority. For example,\nif you have a catch-all Page Rule (rule A: `/images/*`) but want a more\nspecific Page Rule to take precedence (rule B: `/images/special/*`),\nspecify a higher priority for rule B so it overrides rule A." + }, + { + "name": "status", + "type": "String", + "description": "The status of the Page Rule.\nAvailable values: \"active\", \"disabled\"." + } + ] + }, + "resource:cloudflare_page_rule": { + "kind": "resource", + "name": "cloudflare_page_rule", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_page_rule\" \"example_page_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n target = \"example.com/*\"\n priority = 1\n status = \"active\"\n actions = {\n forwarding_url = {\n url = \"https://example.com/foo\"\n status_code = 301\n }\n }\n}", + "importExample": "$ terraform import cloudflare_page_rule.example '/'", + "required": [ + { + "name": "actions", + "type": "Attributes", + "children": [ + { + "name": "always_use_https", + "type": "Boolean" + }, + { + "name": "automatic_https_rewrites", + "type": "String" + }, + { + "name": "browser_cache_ttl", + "type": "Number" + }, + { + "name": "browser_check", + "type": "String" + }, + { + "name": "bypass_cache_on_cookie", + "type": "String" + }, + { + "name": "cache_by_device_type", + "type": "String" + }, + { + "name": "cache_deception_armor", + "type": "String" + }, + { + "name": "cache_key_fields", + "type": "Attributes", + "children": [ + { + "name": "cookie", + "type": "Attributes", + "children": [ + { + "name": "check_presence", + "type": "List of String" + }, + { + "name": "include", + "type": "List of String" + } + ] + }, + { + "name": "header", + "type": "Attributes", + "children": [ + { + "name": "check_presence", + "type": "List of String" + }, + { + "name": "exclude", + "type": "List of String" + }, + { + "name": "include", + "type": "List of String" + } + ] + }, + { + "name": "host", + "type": "Attributes", + "children": [ + { + "name": "resolved", + "type": "Boolean" + } + ] + }, + { + "name": "query_string", + "type": "Attributes", + "children": [ + { + "name": "exclude", + "type": "List of String" + }, + { + "name": "include", + "type": "List of String" + } + ] + }, + { + "name": "user", + "type": "Attributes", + "children": [ + { + "name": "device_type", + "type": "Boolean" + }, + { + "name": "geo", + "type": "Boolean" + }, + { + "name": "lang", + "type": "Boolean" + } + ] + } + ] + }, + { + "name": "cache_level", + "type": "String" + }, + { + "name": "cache_on_cookie", + "type": "String" + }, + { + "name": "cache_ttl_by_status", + "type": "Map of String" + }, + { + "name": "disable_apps", + "type": "Boolean" + }, + { + "name": "disable_performance", + "type": "Boolean" + }, + { + "name": "disable_security", + "type": "Boolean" + }, + { + "name": "disable_zaraz", + "type": "Boolean" + }, + { + "name": "edge_cache_ttl", + "type": "Number" + }, + { + "name": "email_obfuscation", + "type": "String" + }, + { + "name": "explicit_cache_control", + "type": "String" + }, + { + "name": "forwarding_url", + "type": "Attributes", + "children": [ + { + "name": "status_code", + "type": "Number" + }, + { + "name": "url", + "type": "String" + } + ] + }, + { + "name": "host_header_override", + "type": "String" + }, + { + "name": "ip_geolocation", + "type": "String" + }, + { + "name": "mirage", + "type": "String" + }, + { + "name": "opportunistic_encryption", + "type": "String" + }, + { + "name": "origin_error_page_pass_thru", + "type": "String" + }, + { + "name": "polish", + "type": "String" + }, + { + "name": "resolve_override", + "type": "String" + }, + { + "name": "respect_strong_etag", + "type": "String" + }, + { + "name": "response_buffering", + "type": "String" + }, + { + "name": "rocket_loader", + "type": "String" + }, + { + "name": "security_level", + "type": "String" + }, + { + "name": "sort_query_string_for_cache", + "type": "String" + }, + { + "name": "ssl", + "type": "String" + }, + { + "name": "true_client_ip_header", + "type": "String" + }, + { + "name": "waf", + "type": "String" + } + ] + }, + { + "name": "target", + "type": "String" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule, used to define which Page Rule is processed\nover another. A higher number indicates a higher priority. For example,\nif you have a catch-all Page Rule (rule A: `/images/*`) but want a more\nspecific Page Rule to take precedence (rule B: `/images/special/*`),\nspecify a higher priority for rule B so it overrides rule A." + }, + { + "name": "status", + "type": "String", + "description": "The status of the Page Rule.\nAvailable values: \"active\", \"disabled\"." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the Page Rule was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the Page Rule was last modified." + } + ] + }, + "data-source:cloudflare_page_shield_connections": { + "kind": "data-source", + "name": "cloudflare_page_shield_connections", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_connections\" \"example_page_shield_connections\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n connection_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "connection_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "added_at", + "type": "String" + }, + { + "name": "domain_reported_malicious", + "type": "Boolean" + }, + { + "name": "first_page_url", + "type": "String" + }, + { + "name": "first_seen_at", + "type": "String" + }, + { + "name": "host", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "last_seen_at", + "type": "String" + }, + { + "name": "malicious_domain_categories", + "type": "List of String" + }, + { + "name": "malicious_url_categories", + "type": "List of String" + }, + { + "name": "page_urls", + "type": "List of String" + }, + { + "name": "url", + "type": "String" + }, + { + "name": "url_contains_cdn_cgi_path", + "type": "Boolean" + }, + { + "name": "url_reported_malicious", + "type": "Boolean" + } + ] + }, + "list-data-source:cloudflare_page_shield_connections_list": { + "kind": "list-data-source", + "name": "cloudflare_page_shield_connections_list", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_connections_list\" \"example_page_shield_connections_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n exclude_cdn_cgi = true\n exclude_urls = \"blog.cloudflare.com,www.example\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n per_page = 100\n prioritize_malicious = true\n status = \"active,inactive\"\n urls = \"blog.cloudflare.com,www.example\"\n}", + "required": [], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The direction used to sort returned connections.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "exclude_cdn_cgi", + "type": "Boolean", + "description": "When true, excludes connections seen in a `/cdn-cgi` path from the returned connections. The default value is true." + }, + { + "name": "exclude_urls", + "type": "String", + "description": "Excludes connections whose URL contains one of the URL-encoded URLs separated by commas." + }, + { + "name": "export", + "type": "String", + "description": "Export the list of connections as a file, limited to 50000 entries.\nAvailable values: \"csv\"." + }, + { + "name": "hosts", + "type": "String", + "description": "Includes connections that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order_by", + "type": "String", + "description": "The field used to sort returned connections.\nAvailable values: \"first_seen_at\", \"last_seen_at\"." + }, + { + "name": "page", + "type": "String", + "description": "The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the connections\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of connections" + }, + { + "name": "page_url", + "type": "String", + "description": "Includes connections that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match" + }, + { + "name": "per_page", + "type": "Number", + "description": "The number of results per page." + }, + { + "name": "prioritize_malicious", + "type": "Boolean", + "description": "When true, malicious connections appear first in the returned connections." + }, + { + "name": "status", + "type": "String", + "description": "Filters the returned connections using a comma-separated list of connection statuses. Accepted values: `active`, `infrequent`, and `inactive`. The default value is `active`." + }, + { + "name": "urls", + "type": "String", + "description": "Includes connections whose URL contain one or more URL-encoded URLs separated by commas." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "added_at", + "type": "String" + }, + { + "name": "domain_reported_malicious", + "type": "Boolean" + }, + { + "name": "first_page_url", + "type": "String" + }, + { + "name": "first_seen_at", + "type": "String" + }, + { + "name": "host", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "last_seen_at", + "type": "String" + }, + { + "name": "malicious_domain_categories", + "type": "List of String" + }, + { + "name": "malicious_url_categories", + "type": "List of String" + }, + { + "name": "page_urls", + "type": "List of String" + }, + { + "name": "url", + "type": "String" + }, + { + "name": "url_contains_cdn_cgi_path", + "type": "Boolean" + }, + { + "name": "url_reported_malicious", + "type": "Boolean" + } + ] + } + ] + }, + "data-source:cloudflare_page_shield_cookies": { + "kind": "data-source", + "name": "cloudflare_page_shield_cookies", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_cookies\" \"example_page_shield_cookies\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n cookie_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "cookie_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "domain_attribute", + "type": "String" + }, + { + "name": "expires_attribute", + "type": "String" + }, + { + "name": "first_seen_at", + "type": "String" + }, + { + "name": "host", + "type": "String" + }, + { + "name": "http_only_attribute", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "last_seen_at", + "type": "String" + }, + { + "name": "max_age_attribute", + "type": "Number" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "page_urls", + "type": "List of String" + }, + { + "name": "path_attribute", + "type": "String" + }, + { + "name": "same_site_attribute", + "type": "String", + "description": "Available values: \"lax\", \"strict\", \"none\"." + }, + { + "name": "secure_attribute", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"first_party\", \"unknown\"." + } + ] + }, + "list-data-source:cloudflare_page_shield_cookies_list": { + "kind": "list-data-source", + "name": "cloudflare_page_shield_cookies_list", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_cookies_list\" \"example_page_shield_cookies_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n domain = \"example.com\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n http_only = true\n name = \"session_id\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n path = \"/\"\n per_page = 100\n same_site = \"strict\"\n secure = true\n type = \"first_party\"\n}", + "required": [], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The direction used to sort returned cookies.'\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "domain", + "type": "String", + "description": "Filters the returned cookies that match the specified domain attribute" + }, + { + "name": "export", + "type": "String", + "description": "Export the list of cookies as a file, limited to 50000 entries.\nAvailable values: \"csv\"." + }, + { + "name": "hosts", + "type": "String", + "description": "Includes cookies that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match" + }, + { + "name": "http_only", + "type": "Boolean", + "description": "Filters the returned cookies that are set with HttpOnly" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Filters the returned cookies that match the specified name.\nWildcards are supported at the start and end to support starts with, ends with\nand contains. e.g. session*" + }, + { + "name": "order_by", + "type": "String", + "description": "The field used to sort returned cookies.\nAvailable values: \"first_seen_at\", \"last_seen_at\"." + }, + { + "name": "page", + "type": "String", + "description": "The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the cookies\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of cookies" + }, + { + "name": "page_url", + "type": "String", + "description": "Includes connections that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match" + }, + { + "name": "path", + "type": "String", + "description": "Filters the returned cookies that match the specified path attribute" + }, + { + "name": "per_page", + "type": "Number", + "description": "The number of results per page." + }, + { + "name": "same_site", + "type": "String", + "description": "Filters the returned cookies that match the specified same_site attribute\nAvailable values: \"lax\", \"strict\", \"none\"." + }, + { + "name": "secure", + "type": "Boolean", + "description": "Filters the returned cookies that are set with Secure" + }, + { + "name": "type", + "type": "String", + "description": "Filters the returned cookies that match the specified type attribute\nAvailable values: \"first_party\", \"unknown\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "domain_attribute", + "type": "String" + }, + { + "name": "expires_attribute", + "type": "String" + }, + { + "name": "first_seen_at", + "type": "String" + }, + { + "name": "host", + "type": "String" + }, + { + "name": "http_only_attribute", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "last_seen_at", + "type": "String" + }, + { + "name": "max_age_attribute", + "type": "Number" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "page_urls", + "type": "List of String" + }, + { + "name": "path_attribute", + "type": "String" + }, + { + "name": "same_site_attribute", + "type": "String", + "description": "Available values: \"lax\", \"strict\", \"none\"." + }, + { + "name": "secure_attribute", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"first_party\", \"unknown\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_page_shield_policies": { + "kind": "list-data-source", + "name": "cloudflare_page_shield_policies", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_policies\" \"example_page_shield_policies\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to take if the expression matches\nAvailable values: \"allow\", \"log\", \"add_reporting_directives\"." + }, + { + "name": "description", + "type": "String", + "description": "A description for the policy" + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy is enabled" + }, + { + "name": "expression", + "type": "String", + "description": "The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "value", + "type": "String", + "description": "The policy which will be applied" + } + ] + } + ] + }, + "data-source:cloudflare_page_shield_policy": { + "kind": "data-source", + "name": "cloudflare_page_shield_policy", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_policy\" \"example_page_shield_policy\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "policy_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "action", + "type": "String", + "description": "The action to take if the expression matches\nAvailable values: \"allow\", \"log\", \"add_reporting_directives\"." + }, + { + "name": "description", + "type": "String", + "description": "A description for the policy" + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy is enabled" + }, + { + "name": "expression", + "type": "String", + "description": "The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "value", + "type": "String", + "description": "The policy which will be applied" + } + ] + }, + "resource:cloudflare_page_shield_policy": { + "kind": "resource", + "name": "cloudflare_page_shield_policy", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "resource \"cloudflare_page_shield_policy\" \"example_page_shield_policy\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = \"allow\"\n description = \"Checkout page CSP policy\"\n enabled = true\n expression = \"ends_with(http.request.uri.path, \\\"/checkout\\\")\"\n value = \"script-src \\'none\\';\"\n}", + "importExample": "$ terraform import cloudflare_page_shield_policy.example '/'", + "required": [ + { + "name": "action", + "type": "String", + "description": "The action to take if the expression matches\nAvailable values: \"allow\", \"log\", \"add_reporting_directives\"." + }, + { + "name": "description", + "type": "String", + "description": "A description for the policy" + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy is enabled" + }, + { + "name": "expression", + "type": "String", + "description": "The expression which must match for the policy to be applied, using the Cloudflare Firewall rule expression syntax" + }, + { + "name": "value", + "type": "String", + "description": "The policy which will be applied" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + "data-source:cloudflare_page_shield_scripts": { + "kind": "data-source", + "name": "cloudflare_page_shield_scripts", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_scripts\" \"example_page_shield_scripts\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "script_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "added_at", + "type": "String" + }, + { + "name": "cryptomining_score", + "type": "Number", + "description": "The cryptomining score of the JavaScript content." + }, + { + "name": "dataflow_score", + "type": "Number", + "description": "The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.", + "deprecated": "Deprecated." + }, + { + "name": "domain_reported_malicious", + "type": "Boolean" + }, + { + "name": "fetched_at", + "type": "String", + "description": "The timestamp of when the script was last fetched." + }, + { + "name": "first_page_url", + "type": "String" + }, + { + "name": "first_seen_at", + "type": "String" + }, + { + "name": "hash", + "type": "String", + "description": "The computed hash of the analyzed script." + }, + { + "name": "host", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "js_integrity_score", + "type": "Number", + "description": "The integrity score of the JavaScript content." + }, + { + "name": "last_seen_at", + "type": "String" + }, + { + "name": "magecart_score", + "type": "Number", + "description": "The magecart score of the JavaScript content." + }, + { + "name": "malicious_domain_categories", + "type": "List of String" + }, + { + "name": "malicious_url_categories", + "type": "List of String" + }, + { + "name": "malware_score", + "type": "Number", + "description": "The malware score of the JavaScript content." + }, + { + "name": "obfuscation_score", + "type": "Number", + "description": "The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.", + "deprecated": "Deprecated." + }, + { + "name": "page_urls", + "type": "List of String" + }, + { + "name": "url", + "type": "String" + }, + { + "name": "url_contains_cdn_cgi_path", + "type": "Boolean" + }, + { + "name": "url_reported_malicious", + "type": "Boolean" + }, + { + "name": "versions", + "type": "Attributes List", + "children": [ + { + "name": "cryptomining_score", + "type": "Number", + "description": "The cryptomining score of the JavaScript content." + }, + { + "name": "dataflow_score", + "type": "Number", + "description": "The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.", + "deprecated": "Deprecated." + }, + { + "name": "fetched_at", + "type": "String", + "description": "The timestamp of when the script was last fetched." + }, + { + "name": "hash", + "type": "String", + "description": "The computed hash of the analyzed script." + }, + { + "name": "js_integrity_score", + "type": "Number", + "description": "The integrity score of the JavaScript content." + }, + { + "name": "magecart_score", + "type": "Number", + "description": "The magecart score of the JavaScript content." + }, + { + "name": "malware_score", + "type": "Number", + "description": "The malware score of the JavaScript content." + }, + { + "name": "obfuscation_score", + "type": "Number", + "description": "The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.", + "deprecated": "Deprecated." + } + ] + } + ] + }, + "list-data-source:cloudflare_page_shield_scripts_list": { + "kind": "list-data-source", + "name": "cloudflare_page_shield_scripts_list", + "description": "Accepted Permissions\n\n- `Domain Page Shield`\n- `Domain Page Shield Read`\n- `Page Shield`\n- `Page Shield Read`\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_page_shield_scripts_list\" \"example_page_shield_scripts_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n exclude_urls = \"blog.cloudflare.com,www.example\"\n export = \"csv\"\n hosts = \"blog.cloudflare.com,www.example*,*cloudflare.com\"\n order_by = \"first_seen_at\"\n page = \"2\"\n page_url = \"example.com/page,*/checkout,example.com/*,*checkout*\"\n per_page = 100\n prioritize_malicious = true\n status = \"active,inactive\"\n urls = \"blog.cloudflare.com,www.example\"\n}", + "required": [], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The direction used to sort returned scripts.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "exclude_cdn_cgi", + "type": "Boolean", + "description": "When true, excludes scripts seen in a `/cdn-cgi` path from the returned scripts. The default value is true." + }, + { + "name": "exclude_duplicates", + "type": "Boolean", + "description": "When true, excludes duplicate scripts. We consider a script duplicate of another if their javascript\ncontent matches and they share the same url host and zone hostname. In such case, we return the most\nrecent script for the URL host and zone hostname combination." + }, + { + "name": "exclude_urls", + "type": "String", + "description": "Excludes scripts whose URL contains one of the URL-encoded URLs separated by commas." + }, + { + "name": "export", + "type": "String", + "description": "Export the list of scripts as a file, limited to 50000 entries.\nAvailable values: \"csv\"." + }, + { + "name": "hosts", + "type": "String", + "description": "Includes scripts that match one or more URL-encoded hostnames separated by commas.\n\nWildcards are supported at the start and end of each hostname to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order_by", + "type": "String", + "description": "The field used to sort returned scripts.\nAvailable values: \"first_seen_at\", \"last_seen_at\"." + }, + { + "name": "page", + "type": "String", + "description": "The current page number of the paginated results.\n\nWe additionally support a special value \"all\". When \"all\" is used, the API will return all the scripts\nwith the applied filters in a single page. This feature is best-effort and it may only work for zones with\na low number of scripts" + }, + { + "name": "page_url", + "type": "String", + "description": "Includes scripts that match one or more page URLs (separated by commas) where they were last seen\n\nWildcards are supported at the start and end of each page URL to support starts with, ends with\nand contains. If no wildcards are used, results will be filtered by exact match" + }, + { + "name": "per_page", + "type": "Number", + "description": "The number of results per page." + }, + { + "name": "prioritize_malicious", + "type": "Boolean", + "description": "When true, malicious scripts appear first in the returned scripts." + }, + { + "name": "status", + "type": "String", + "description": "Filters the returned scripts using a comma-separated list of scripts statuses. Accepted values: `active`, `infrequent`, and `inactive`. The default value is `active`." + }, + { + "name": "urls", + "type": "String", + "description": "Includes scripts whose URL contain one or more URL-encoded URLs separated by commas." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "added_at", + "type": "String" + }, + { + "name": "cryptomining_score", + "type": "Number", + "description": "The cryptomining score of the JavaScript content." + }, + { + "name": "dataflow_score", + "type": "Number", + "description": "The dataflow score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.", + "deprecated": "Deprecated." + }, + { + "name": "domain_reported_malicious", + "type": "Boolean" + }, + { + "name": "fetched_at", + "type": "String", + "description": "The timestamp of when the script was last fetched." + }, + { + "name": "first_page_url", + "type": "String" + }, + { + "name": "first_seen_at", + "type": "String" + }, + { + "name": "hash", + "type": "String", + "description": "The computed hash of the analyzed script." + }, + { + "name": "host", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "js_integrity_score", + "type": "Number", + "description": "The integrity score of the JavaScript content." + }, + { + "name": "last_seen_at", + "type": "String" + }, + { + "name": "magecart_score", + "type": "Number", + "description": "The magecart score of the JavaScript content." + }, + { + "name": "malicious_domain_categories", + "type": "List of String" + }, + { + "name": "malicious_url_categories", + "type": "List of String" + }, + { + "name": "malware_score", + "type": "Number", + "description": "The malware score of the JavaScript content." + }, + { + "name": "obfuscation_score", + "type": "Number", + "description": "The obfuscation score of the JavaScript content. This field has been deprecated in favour of js_integrity_score.", + "deprecated": "Deprecated." + }, + { + "name": "page_urls", + "type": "List of String" + }, + { + "name": "url", + "type": "String" + }, + { + "name": "url_contains_cdn_cgi_path", + "type": "Boolean" + }, + { + "name": "url_reported_malicious", + "type": "Boolean" + } + ] + } + ] + }, + "data-source:cloudflare_pages_domain": { + "kind": "data-source", + "name": "cloudflare_pages_domain", + "description": "Accepted Permissions\n\n- `Pages Read`\n- `Pages Write`", + "example": "data \"cloudflare_pages_domain\" \"example_pages_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n domain_name = \"example.com\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "domain_name", + "type": "String", + "description": "Fully qualified domain name for the Pages project, such as `example.com`." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + } + ], + "optional": [], + "computed": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Available values: \"google\", \"lets_encrypt\"." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "domain_id", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Fully qualified domain name for the Pages project, such as `example.com`." + }, + { + "name": "name", + "type": "String", + "description": "Fully qualified domain name for the Pages project, such as `example.com`." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\"." + }, + { + "name": "validation_data", + "type": "Attributes", + "children": [ + { + "name": "error_message", + "type": "String" + }, + { + "name": "method", + "type": "String", + "description": "Available values: \"http\", \"txt\"." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"error\"." + }, + { + "name": "txt_name", + "type": "String" + }, + { + "name": "txt_value", + "type": "String" + } + ] + }, + { + "name": "verification_data", + "type": "Attributes", + "children": [ + { + "name": "error_message", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\"." + } + ] + }, + { + "name": "zone_tag", + "type": "String" + } + ] + }, + "resource:cloudflare_pages_domain": { + "kind": "resource", + "name": "cloudflare_pages_domain", + "description": "Accepted Permissions\n\n- `Pages Read`\n- `Pages Write`\n\n-> A DNS record for the domain is not automatically created. You need to create\n a `cloudflare_record` resource for the domain you want to use.", + "example": "resource \"cloudflare_pages_domain\" \"example_pages_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n name = \"example.com\"\n}", + "importExample": "$ terraform import cloudflare_pages_domain.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "Fully qualified domain name for the Pages project, such as `example.com`." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + } + ], + "optional": [], + "computed": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Available values: \"google\", \"lets_encrypt\"." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "domain_id", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Fully qualified domain name for the Pages project, such as `example.com`." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\"." + }, + { + "name": "validation_data", + "type": "Attributes", + "children": [ + { + "name": "error_message", + "type": "String" + }, + { + "name": "method", + "type": "String", + "description": "Available values: \"http\", \"txt\"." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"error\"." + }, + { + "name": "txt_name", + "type": "String" + }, + { + "name": "txt_value", + "type": "String" + } + ] + }, + { + "name": "verification_data", + "type": "Attributes", + "children": [ + { + "name": "error_message", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\"." + } + ] + }, + { + "name": "zone_tag", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_pages_domains": { + "kind": "list-data-source", + "name": "cloudflare_pages_domains", + "description": "Accepted Permissions\n\n- `Pages Read`\n- `Pages Write`", + "example": "data \"cloudflare_pages_domains\" \"example_pages_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n}", + "required": [ + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "certificate_authority", + "type": "String", + "description": "Available values: \"google\", \"lets_encrypt\"." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "domain_id", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Fully qualified domain name for the Pages project, such as `example.com`." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\"." + }, + { + "name": "validation_data", + "type": "Attributes", + "children": [ + { + "name": "error_message", + "type": "String" + }, + { + "name": "method", + "type": "String", + "description": "Available values: \"http\", \"txt\"." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"error\"." + }, + { + "name": "txt_name", + "type": "String" + }, + { + "name": "txt_value", + "type": "String" + } + ] + }, + { + "name": "verification_data", + "type": "Attributes", + "children": [ + { + "name": "error_message", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\"." + } + ] + }, + { + "name": "zone_tag", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_pages_project": { + "kind": "data-source", + "name": "cloudflare_pages_project", + "description": "Accepted Permissions\n\n- `Pages Read`\n- `Pages Write`", + "example": "data \"cloudflare_pages_project\" \"example_pages_project\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n project_name = \"this-is-my-project-01\"\n}", + "required": [ + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "canonical_deployment", + "type": "Attributes", + "description": "Most recent production deployment of the project.", + "children": [ + { + "name": "aliases", + "type": "List of String", + "description": "A list of alias URLs pointing to this deployment." + }, + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the deployment was created." + }, + { + "name": "deployment_trigger", + "type": "Attributes", + "description": "Info about what caused the deployment.", + "children": [ + { + "name": "metadata", + "type": "Attributes", + "description": "Additional info about the trigger.", + "children": [ + { + "name": "branch", + "type": "String", + "description": "Where the trigger happened." + }, + { + "name": "commit_dirty", + "type": "Boolean", + "description": "Whether the deployment trigger commit was dirty." + }, + { + "name": "commit_hash", + "type": "String", + "description": "Hash of the deployment trigger commit." + }, + { + "name": "commit_message", + "type": "String", + "description": "Message of the deployment trigger commit." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "What caused the deployment.\nAvailable values: \"github:push\", \"ad_hoc\", \"deploy_hook\"." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "environment", + "type": "String", + "description": "Type of deploy.\nAvailable values: \"preview\", \"production\"." + }, + { + "name": "id", + "type": "String", + "description": "Id of the deployment." + }, + { + "name": "is_skipped", + "type": "Boolean", + "description": "Whether the deployment was skipped." + }, + { + "name": "latest_stage", + "type": "Attributes", + "description": "The status of the deployment.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the deployment was last modified." + }, + { + "name": "project_id", + "type": "String", + "description": "Id of the project." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "short_id", + "type": "String", + "description": "Short Id (8 character) of the deployment." + }, + { + "name": "skip_reason", + "type": "String", + "description": "Why the deployment was skipped.\nAvailable values: \"commit_message\", \"preview_deployments_disabled\", \"production_deployments_disabled\", \"path_config\", \"branch_config\", \"pages_to_workers_conversion\", \"superseded_queued_build\"." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "stages", + "type": "Attributes List", + "description": "List of past stages.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "url", + "type": "String", + "description": "The live URL to view this deployment." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the deployment uses functions." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the project was created." + }, + { + "name": "deployment_configs", + "type": "Attributes", + "description": "Configs for deployments in a project.", + "children": [ + { + "name": "preview", + "type": "Attributes", + "description": "Configs for preview deploys.", + "children": [ + { + "name": "ai_bindings", + "type": "Attributes Map", + "description": "Constellation bindings used for Pages Functions.", + "children": [ + { + "name": "project_id", + "type": "String" + } + ] + }, + { + "name": "always_use_latest_compatibility_date", + "type": "Boolean", + "description": "Whether to always use the latest compatibility date for Pages Functions." + }, + { + "name": "analytics_engine_datasets", + "type": "Attributes Map", + "description": "Analytics Engine bindings used for Pages Functions.", + "children": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset." + } + ] + }, + { + "name": "browsers", + "type": "Attributes Map", + "description": "Browser bindings used for Pages Functions." + }, + { + "name": "build_image_major_version", + "type": "Number", + "description": "The major version of the build image to use for Pages Functions." + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Compatibility date used for Pages Functions." + }, + { + "name": "compatibility_flags", + "type": "List of String", + "description": "Compatibility flags used for Pages Functions." + }, + { + "name": "d1_databases", + "type": "Attributes Map", + "description": "D1 databases used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID of the D1 database." + } + ] + }, + { + "name": "durable_object_namespaces", + "type": "Attributes Map", + "description": "Durable Object namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "fail_open", + "type": "Boolean", + "description": "Whether to fail open when the deployment config cannot be applied." + }, + { + "name": "hyperdrive_bindings", + "type": "Attributes Map", + "description": "Hyperdrive bindings used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String" + } + ] + }, + { + "name": "kv_namespaces", + "type": "Attributes Map", + "description": "KV namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the KV namespace." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Limits for Pages Functions.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + } + ] + }, + { + "name": "mtls_certificates", + "type": "Attributes Map", + "description": "mTLS bindings used for Pages Functions.", + "children": [ + { + "name": "certificate_id", + "type": "String" + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement setting used for Pages Functions.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Placement mode." + } + ] + }, + { + "name": "queue_producers", + "type": "Attributes Map", + "description": "Queue Producer bindings used for Pages Functions.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the Queue." + } + ] + }, + { + "name": "r2_buckets", + "type": "Attributes Map", + "description": "R2 buckets used for Pages Functions.", + "children": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the R2 bucket." + }, + { + "name": "name", + "type": "String", + "description": "Name of the R2 bucket." + } + ] + }, + { + "name": "services", + "type": "Attributes Map", + "description": "Services used for Pages Functions.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "The entrypoint to bind to." + }, + { + "name": "environment", + "type": "String", + "description": "The Service environment." + }, + { + "name": "service", + "type": "String", + "description": "The Service name." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "The usage model for Pages Functions.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + }, + { + "name": "vectorize_bindings", + "type": "Attributes Map", + "description": "Vectorize bindings used for Pages Functions.", + "children": [ + { + "name": "index_name", + "type": "String" + } + ] + }, + { + "name": "wrangler_config_hash", + "type": "String", + "description": "Hash of the Wrangler configuration used for the deployment." + } + ] + }, + { + "name": "production", + "type": "Attributes", + "description": "Configs for production deploys.", + "children": [ + { + "name": "ai_bindings", + "type": "Attributes Map", + "description": "Constellation bindings used for Pages Functions.", + "children": [ + { + "name": "project_id", + "type": "String" + } + ] + }, + { + "name": "always_use_latest_compatibility_date", + "type": "Boolean", + "description": "Whether to always use the latest compatibility date for Pages Functions." + }, + { + "name": "analytics_engine_datasets", + "type": "Attributes Map", + "description": "Analytics Engine bindings used for Pages Functions.", + "children": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset." + } + ] + }, + { + "name": "browsers", + "type": "Attributes Map", + "description": "Browser bindings used for Pages Functions." + }, + { + "name": "build_image_major_version", + "type": "Number", + "description": "The major version of the build image to use for Pages Functions." + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Compatibility date used for Pages Functions." + }, + { + "name": "compatibility_flags", + "type": "List of String", + "description": "Compatibility flags used for Pages Functions." + }, + { + "name": "d1_databases", + "type": "Attributes Map", + "description": "D1 databases used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID of the D1 database." + } + ] + }, + { + "name": "durable_object_namespaces", + "type": "Attributes Map", + "description": "Durable Object namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "fail_open", + "type": "Boolean", + "description": "Whether to fail open when the deployment config cannot be applied." + }, + { + "name": "hyperdrive_bindings", + "type": "Attributes Map", + "description": "Hyperdrive bindings used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String" + } + ] + }, + { + "name": "kv_namespaces", + "type": "Attributes Map", + "description": "KV namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the KV namespace." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Limits for Pages Functions.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + } + ] + }, + { + "name": "mtls_certificates", + "type": "Attributes Map", + "description": "mTLS bindings used for Pages Functions.", + "children": [ + { + "name": "certificate_id", + "type": "String" + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement setting used for Pages Functions.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Placement mode." + } + ] + }, + { + "name": "queue_producers", + "type": "Attributes Map", + "description": "Queue Producer bindings used for Pages Functions.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the Queue." + } + ] + }, + { + "name": "r2_buckets", + "type": "Attributes Map", + "description": "R2 buckets used for Pages Functions.", + "children": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the R2 bucket." + }, + { + "name": "name", + "type": "String", + "description": "Name of the R2 bucket." + } + ] + }, + { + "name": "services", + "type": "Attributes Map", + "description": "Services used for Pages Functions.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "The entrypoint to bind to." + }, + { + "name": "environment", + "type": "String", + "description": "The Service environment." + }, + { + "name": "service", + "type": "String", + "description": "The Service name." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "The usage model for Pages Functions.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + }, + { + "name": "vectorize_bindings", + "type": "Attributes Map", + "description": "Vectorize bindings used for Pages Functions.", + "children": [ + { + "name": "index_name", + "type": "String" + } + ] + }, + { + "name": "wrangler_config_hash", + "type": "String", + "description": "Hash of the Wrangler configuration used for the deployment." + } + ] + } + ] + }, + { + "name": "domains", + "type": "List of String", + "description": "A list of associated custom domains for the project." + }, + { + "name": "framework", + "type": "String", + "description": "Framework the project is using." + }, + { + "name": "framework_version", + "type": "String", + "description": "Version of the framework the project is using." + }, + { + "name": "id", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "latest_deployment", + "type": "Attributes", + "description": "Most recent deployment of the project.", + "children": [ + { + "name": "aliases", + "type": "List of String", + "description": "A list of alias URLs pointing to this deployment." + }, + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the deployment was created." + }, + { + "name": "deployment_trigger", + "type": "Attributes", + "description": "Info about what caused the deployment.", + "children": [ + { + "name": "metadata", + "type": "Attributes", + "description": "Additional info about the trigger.", + "children": [ + { + "name": "branch", + "type": "String", + "description": "Where the trigger happened." + }, + { + "name": "commit_dirty", + "type": "Boolean", + "description": "Whether the deployment trigger commit was dirty." + }, + { + "name": "commit_hash", + "type": "String", + "description": "Hash of the deployment trigger commit." + }, + { + "name": "commit_message", + "type": "String", + "description": "Message of the deployment trigger commit." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "What caused the deployment.\nAvailable values: \"github:push\", \"ad_hoc\", \"deploy_hook\"." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "environment", + "type": "String", + "description": "Type of deploy.\nAvailable values: \"preview\", \"production\"." + }, + { + "name": "id", + "type": "String", + "description": "Id of the deployment." + }, + { + "name": "is_skipped", + "type": "Boolean", + "description": "Whether the deployment was skipped." + }, + { + "name": "latest_stage", + "type": "Attributes", + "description": "The status of the deployment.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the deployment was last modified." + }, + { + "name": "project_id", + "type": "String", + "description": "Id of the project." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "short_id", + "type": "String", + "description": "Short Id (8 character) of the deployment." + }, + { + "name": "skip_reason", + "type": "String", + "description": "Why the deployment was skipped.\nAvailable values: \"commit_message\", \"preview_deployments_disabled\", \"production_deployments_disabled\", \"path_config\", \"branch_config\", \"pages_to_workers_conversion\", \"superseded_queued_build\"." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "stages", + "type": "Attributes List", + "description": "List of past stages.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "url", + "type": "String", + "description": "The live URL to view this deployment." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the deployment uses functions." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "preview_script_name", + "type": "String", + "description": "Name of the preview script." + }, + { + "name": "production_branch", + "type": "String", + "description": "Production branch of the project. Used to identify production deployments." + }, + { + "name": "production_script_name", + "type": "String", + "description": "Name of the production script." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "subdomain", + "type": "String", + "description": "The Cloudflare subdomain associated with the project." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the project uses functions." + } + ] + }, + "resource:cloudflare_pages_project": { + "kind": "resource", + "name": "cloudflare_pages_project", + "description": "Accepted Permissions\n\n- `Pages Read`\n- `Pages Write`\n\n-> If you are using a `source` block configuration, you must first have a\n connected GitHub or GitLab account connected to Cloudflare. See the\n [Getting Started with Pages](https://developers.cloudflare.com/pages/get-started/git-integration/)\n documentation on how to link your accounts.", + "example": "resource \"cloudflare_pages_project\" \"example_pages_project\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-pages-app\"\n production_branch = \"main\"\n build_config = {\n build_caching = true\n build_command = \"npm run build\"\n destination_dir = \"build\"\n root_dir = \"/\"\n web_analytics_tag = \"cee1c73f6e4743d0b5e6bb1a0bcaabcc\"\n web_analytics_token = \"021e1057c18547eca7b79f2516f06o7x\"\n }\n deployment_configs = {\n preview = {\n ai_bindings = {\n AI_BINDING = {\n project_id = \"some-project-id\"\n }\n }\n always_use_latest_compatibility_date = false\n analytics_engine_datasets = {\n ANALYTICS_ENGINE_BINDING = {\n dataset = \"api_analytics\"\n }\n }\n browsers = {\n BROWSER = {\n\n }\n }\n build_image_major_version = 3\n compatibility_date = \"2025-01-01T00:00:00Z\"\n compatibility_flags = [\"url_standard\"]\n d1_databases = {\n D1_BINDING = {\n id = \"445e2955-951a-43f8-a35b-a4d0c8138f63\"\n }\n }\n durable_object_namespaces = {\n DO_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n env_vars = {\n foo = {\n type = \"plain_text\"\n value = \"hello world\"\n }\n }\n fail_open = true\n hyperdrive_bindings = {\n HYPERDRIVE = {\n id = \"a76a99bc342644deb02c38d66082262a\"\n }\n }\n kv_namespaces = {\n KV_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n limits = {\n cpu_ms = 100\n }\n mtls_certificates = {\n MTLS = {\n certificate_id = \"d7cdd17c-916f-4cb7-aabe-585eb382ec4e\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n queue_producers = {\n QUEUE_PRODUCER_BINDING = {\n name = \"some-queue\"\n }\n }\n r2_buckets = {\n R2_BINDING = {\n name = \"some-bucket\"\n jurisdiction = \"eu\"\n }\n }\n services = {\n SERVICE_BINDING = {\n service = \"example-worker\"\n entrypoint = \"MyHandler\"\n environment = \"production\"\n }\n }\n usage_model = \"standard\"\n vectorize_bindings = {\n VECTORIZE = {\n index_name = \"my_index\"\n }\n }\n wrangler_config_hash = \"abc123def456\"\n }\n production = {\n ai_bindings = {\n AI_BINDING = {\n project_id = \"some-project-id\"\n }\n }\n always_use_latest_compatibility_date = false\n analytics_engine_datasets = {\n ANALYTICS_ENGINE_BINDING = {\n dataset = \"api_analytics\"\n }\n }\n browsers = {\n BROWSER = {\n\n }\n }\n build_image_major_version = 3\n compatibility_date = \"2025-01-01T00:00:00Z\"\n compatibility_flags = [\"url_standard\"]\n d1_databases = {\n D1_BINDING = {\n id = \"445e2955-951a-43f8-a35b-a4d0c8138f63\"\n }\n }\n durable_object_namespaces = {\n DO_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n env_vars = {\n foo = {\n type = \"plain_text\"\n value = \"hello world\"\n }\n }\n fail_open = true\n hyperdrive_bindings = {\n HYPERDRIVE = {\n id = \"a76a99bc342644deb02c38d66082262a\"\n }\n }\n kv_namespaces = {\n KV_BINDING = {\n namespace_id = \"5eb63bbbe01eeed093cb22bb8f5acdc3\"\n }\n }\n limits = {\n cpu_ms = 100\n }\n mtls_certificates = {\n MTLS = {\n certificate_id = \"d7cdd17c-916f-4cb7-aabe-585eb382ec4e\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n queue_producers = {\n QUEUE_PRODUCER_BINDING = {\n name = \"some-queue\"\n }\n }\n r2_buckets = {\n R2_BINDING = {\n name = \"some-bucket\"\n jurisdiction = \"eu\"\n }\n }\n services = {\n SERVICE_BINDING = {\n service = \"example-worker\"\n entrypoint = \"MyHandler\"\n environment = \"production\"\n }\n }\n usage_model = \"standard\"\n vectorize_bindings = {\n VECTORIZE = {\n index_name = \"my_index\"\n }\n }\n wrangler_config_hash = \"abc123def456\"\n }\n }\n source = {\n config = {\n deployments_enabled = true\n owner = \"my-org\"\n owner_id = \"12345678\"\n path_excludes = [\"string\"]\n path_includes = [\"string\"]\n pr_comments_enabled = true\n preview_branch_excludes = [\"string\"]\n preview_branch_includes = [\"string\"]\n preview_deployment_setting = \"all\"\n production_branch = \"main\"\n production_deployments_enabled = true\n repo_id = \"12345678\"\n repo_name = \"my-repo\"\n }\n type = \"github\"\n }\n}", + "importExample": "$ terraform import cloudflare_pages_project.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "Name for the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "production_branch", + "type": "String", + "description": "Production branch of the project. Used to identify production deployments." + } + ], + "optional": [ + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "deployment_configs", + "type": "Attributes", + "description": "Configs for deployments in a project.", + "children": [ + { + "name": "preview", + "type": "Attributes", + "description": "Configs for preview deploys.", + "children": [ + { + "name": "ai_bindings", + "type": "Attributes Map", + "description": "Constellation bindings used for Pages Functions.", + "children": [ + { + "name": "project_id", + "type": "String" + } + ] + }, + { + "name": "always_use_latest_compatibility_date", + "type": "Boolean", + "description": "Whether to always use the latest compatibility date for Pages Functions." + }, + { + "name": "analytics_engine_datasets", + "type": "Attributes Map", + "description": "Analytics Engine bindings used for Pages Functions.", + "children": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset." + } + ] + }, + { + "name": "browsers", + "type": "Attributes Map", + "description": "Browser bindings used for Pages Functions." + }, + { + "name": "build_image_major_version", + "type": "Number", + "description": "The major version of the build image to use for Pages Functions." + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Compatibility date used for Pages Functions." + }, + { + "name": "compatibility_flags", + "type": "List of String", + "description": "Compatibility flags used for Pages Functions." + }, + { + "name": "d1_databases", + "type": "Attributes Map", + "description": "D1 databases used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID of the D1 database." + } + ] + }, + { + "name": "durable_object_namespaces", + "type": "Attributes Map", + "description": "Durable Object namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "fail_open", + "type": "Boolean", + "description": "Whether to fail open when the deployment config cannot be applied." + }, + { + "name": "hyperdrive_bindings", + "type": "Attributes Map", + "description": "Hyperdrive bindings used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String" + } + ] + }, + { + "name": "kv_namespaces", + "type": "Attributes Map", + "description": "KV namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the KV namespace." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Limits for Pages Functions.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + } + ] + }, + { + "name": "mtls_certificates", + "type": "Attributes Map", + "description": "mTLS bindings used for Pages Functions.", + "children": [ + { + "name": "certificate_id", + "type": "String" + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement setting used for Pages Functions.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Placement mode." + } + ] + }, + { + "name": "queue_producers", + "type": "Attributes Map", + "description": "Queue Producer bindings used for Pages Functions.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the Queue." + } + ] + }, + { + "name": "r2_buckets", + "type": "Attributes Map", + "description": "R2 buckets used for Pages Functions.", + "children": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the R2 bucket." + }, + { + "name": "name", + "type": "String", + "description": "Name of the R2 bucket." + } + ] + }, + { + "name": "services", + "type": "Attributes Map", + "description": "Services used for Pages Functions.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "The entrypoint to bind to." + }, + { + "name": "environment", + "type": "String", + "description": "The Service environment." + }, + { + "name": "service", + "type": "String", + "description": "The Service name." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "The usage model for Pages Functions.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + }, + { + "name": "vectorize_bindings", + "type": "Attributes Map", + "description": "Vectorize bindings used for Pages Functions.", + "children": [ + { + "name": "index_name", + "type": "String" + } + ] + }, + { + "name": "wrangler_config_hash", + "type": "String", + "description": "Hash of the Wrangler configuration used for the deployment." + } + ] + }, + { + "name": "production", + "type": "Attributes", + "description": "Configs for production deploys.", + "children": [ + { + "name": "ai_bindings", + "type": "Attributes Map", + "description": "Constellation bindings used for Pages Functions.", + "children": [ + { + "name": "project_id", + "type": "String" + } + ] + }, + { + "name": "always_use_latest_compatibility_date", + "type": "Boolean", + "description": "Whether to always use the latest compatibility date for Pages Functions." + }, + { + "name": "analytics_engine_datasets", + "type": "Attributes Map", + "description": "Analytics Engine bindings used for Pages Functions.", + "children": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset." + } + ] + }, + { + "name": "browsers", + "type": "Attributes Map", + "description": "Browser bindings used for Pages Functions." + }, + { + "name": "build_image_major_version", + "type": "Number", + "description": "The major version of the build image to use for Pages Functions." + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Compatibility date used for Pages Functions." + }, + { + "name": "compatibility_flags", + "type": "List of String", + "description": "Compatibility flags used for Pages Functions." + }, + { + "name": "d1_databases", + "type": "Attributes Map", + "description": "D1 databases used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID of the D1 database." + } + ] + }, + { + "name": "durable_object_namespaces", + "type": "Attributes Map", + "description": "Durable Object namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "fail_open", + "type": "Boolean", + "description": "Whether to fail open when the deployment config cannot be applied." + }, + { + "name": "hyperdrive_bindings", + "type": "Attributes Map", + "description": "Hyperdrive bindings used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String" + } + ] + }, + { + "name": "kv_namespaces", + "type": "Attributes Map", + "description": "KV namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the KV namespace." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Limits for Pages Functions.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + } + ] + }, + { + "name": "mtls_certificates", + "type": "Attributes Map", + "description": "mTLS bindings used for Pages Functions.", + "children": [ + { + "name": "certificate_id", + "type": "String" + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement setting used for Pages Functions.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Placement mode." + } + ] + }, + { + "name": "queue_producers", + "type": "Attributes Map", + "description": "Queue Producer bindings used for Pages Functions.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the Queue." + } + ] + }, + { + "name": "r2_buckets", + "type": "Attributes Map", + "description": "R2 buckets used for Pages Functions.", + "children": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the R2 bucket." + }, + { + "name": "name", + "type": "String", + "description": "Name of the R2 bucket." + } + ] + }, + { + "name": "services", + "type": "Attributes Map", + "description": "Services used for Pages Functions.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "The entrypoint to bind to." + }, + { + "name": "environment", + "type": "String", + "description": "The Service environment." + }, + { + "name": "service", + "type": "String", + "description": "The Service name." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "The usage model for Pages Functions.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + }, + { + "name": "vectorize_bindings", + "type": "Attributes Map", + "description": "Vectorize bindings used for Pages Functions.", + "children": [ + { + "name": "index_name", + "type": "String" + } + ] + }, + { + "name": "wrangler_config_hash", + "type": "String", + "description": "Hash of the Wrangler configuration used for the deployment." + } + ] + } + ] + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + } + ], + "computed": [ + { + "name": "canonical_deployment", + "type": "Attributes", + "description": "Most recent production deployment of the project.", + "children": [ + { + "name": "aliases", + "type": "List of String", + "description": "A list of alias URLs pointing to this deployment." + }, + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the deployment was created." + }, + { + "name": "deployment_trigger", + "type": "Attributes", + "description": "Info about what caused the deployment.", + "children": [ + { + "name": "metadata", + "type": "Attributes", + "description": "Additional info about the trigger.", + "children": [ + { + "name": "branch", + "type": "String", + "description": "Where the trigger happened." + }, + { + "name": "commit_dirty", + "type": "Boolean", + "description": "Whether the deployment trigger commit was dirty." + }, + { + "name": "commit_hash", + "type": "String", + "description": "Hash of the deployment trigger commit." + }, + { + "name": "commit_message", + "type": "String", + "description": "Message of the deployment trigger commit." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "What caused the deployment.\nAvailable values: \"github:push\", \"ad_hoc\", \"deploy_hook\"." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "environment", + "type": "String", + "description": "Type of deploy.\nAvailable values: \"preview\", \"production\"." + }, + { + "name": "id", + "type": "String", + "description": "Id of the deployment." + }, + { + "name": "is_skipped", + "type": "Boolean", + "description": "Whether the deployment was skipped." + }, + { + "name": "latest_stage", + "type": "Attributes", + "description": "The status of the deployment.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the deployment was last modified." + }, + { + "name": "project_id", + "type": "String", + "description": "Id of the project." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "short_id", + "type": "String", + "description": "Short Id (8 character) of the deployment." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "stages", + "type": "Attributes List", + "description": "List of past stages.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "url", + "type": "String", + "description": "The live URL to view this deployment." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the deployment uses functions." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the project was created." + }, + { + "name": "domains", + "type": "List of String", + "description": "A list of associated custom domains for the project." + }, + { + "name": "framework", + "type": "String", + "description": "Framework the project is using." + }, + { + "name": "framework_version", + "type": "String", + "description": "Version of the framework the project is using." + }, + { + "name": "id", + "type": "String", + "description": "Name for the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "latest_deployment", + "type": "Attributes", + "description": "Most recent deployment of the project.", + "children": [ + { + "name": "aliases", + "type": "List of String", + "description": "A list of alias URLs pointing to this deployment." + }, + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the deployment was created." + }, + { + "name": "deployment_trigger", + "type": "Attributes", + "description": "Info about what caused the deployment.", + "children": [ + { + "name": "metadata", + "type": "Attributes", + "description": "Additional info about the trigger.", + "children": [ + { + "name": "branch", + "type": "String", + "description": "Where the trigger happened." + }, + { + "name": "commit_dirty", + "type": "Boolean", + "description": "Whether the deployment trigger commit was dirty." + }, + { + "name": "commit_hash", + "type": "String", + "description": "Hash of the deployment trigger commit." + }, + { + "name": "commit_message", + "type": "String", + "description": "Message of the deployment trigger commit." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "What caused the deployment.\nAvailable values: \"github:push\", \"ad_hoc\", \"deploy_hook\"." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "environment", + "type": "String", + "description": "Type of deploy.\nAvailable values: \"preview\", \"production\"." + }, + { + "name": "id", + "type": "String", + "description": "Id of the deployment." + }, + { + "name": "is_skipped", + "type": "Boolean", + "description": "Whether the deployment was skipped." + }, + { + "name": "latest_stage", + "type": "Attributes", + "description": "The status of the deployment.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the deployment was last modified." + }, + { + "name": "project_id", + "type": "String", + "description": "Id of the project." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "short_id", + "type": "String", + "description": "Short Id (8 character) of the deployment." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "stages", + "type": "Attributes List", + "description": "List of past stages.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "url", + "type": "String", + "description": "The live URL to view this deployment." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the deployment uses functions." + } + ] + }, + { + "name": "preview_script_name", + "type": "String", + "description": "Name of the preview script." + }, + { + "name": "production_script_name", + "type": "String", + "description": "Name of the production script." + }, + { + "name": "subdomain", + "type": "String", + "description": "The Cloudflare subdomain associated with the project." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the project uses functions." + } + ] + }, + "list-data-source:cloudflare_pages_projects": { + "kind": "list-data-source", + "name": "cloudflare_pages_projects", + "description": "Accepted Permissions\n\n- `Pages Read`\n- `Pages Write`", + "example": "data \"cloudflare_pages_projects\" \"example_pages_projects\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "canonical_deployment", + "type": "Attributes", + "description": "Most recent production deployment of the project.", + "children": [ + { + "name": "aliases", + "type": "List of String", + "description": "A list of alias URLs pointing to this deployment." + }, + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the deployment was created." + }, + { + "name": "deployment_trigger", + "type": "Attributes", + "description": "Info about what caused the deployment.", + "children": [ + { + "name": "metadata", + "type": "Attributes", + "description": "Additional info about the trigger.", + "children": [ + { + "name": "branch", + "type": "String", + "description": "Where the trigger happened." + }, + { + "name": "commit_dirty", + "type": "Boolean", + "description": "Whether the deployment trigger commit was dirty." + }, + { + "name": "commit_hash", + "type": "String", + "description": "Hash of the deployment trigger commit." + }, + { + "name": "commit_message", + "type": "String", + "description": "Message of the deployment trigger commit." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "What caused the deployment.\nAvailable values: \"github:push\", \"ad_hoc\", \"deploy_hook\"." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "environment", + "type": "String", + "description": "Type of deploy.\nAvailable values: \"preview\", \"production\"." + }, + { + "name": "id", + "type": "String", + "description": "Id of the deployment." + }, + { + "name": "is_skipped", + "type": "Boolean", + "description": "Whether the deployment was skipped." + }, + { + "name": "latest_stage", + "type": "Attributes", + "description": "The status of the deployment.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the deployment was last modified." + }, + { + "name": "project_id", + "type": "String", + "description": "Id of the project." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "short_id", + "type": "String", + "description": "Short Id (8 character) of the deployment." + }, + { + "name": "skip_reason", + "type": "String", + "description": "Why the deployment was skipped.\nAvailable values: \"commit_message\", \"preview_deployments_disabled\", \"production_deployments_disabled\", \"path_config\", \"branch_config\", \"pages_to_workers_conversion\", \"superseded_queued_build\"." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "stages", + "type": "Attributes List", + "description": "List of past stages.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "url", + "type": "String", + "description": "The live URL to view this deployment." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the deployment uses functions." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the project was created." + }, + { + "name": "deployment_configs", + "type": "Attributes", + "description": "Configs for deployments in a project.", + "children": [ + { + "name": "preview", + "type": "Attributes", + "description": "Configs for preview deploys.", + "children": [ + { + "name": "ai_bindings", + "type": "Attributes Map", + "description": "Constellation bindings used for Pages Functions.", + "children": [ + { + "name": "project_id", + "type": "String" + } + ] + }, + { + "name": "always_use_latest_compatibility_date", + "type": "Boolean", + "description": "Whether to always use the latest compatibility date for Pages Functions." + }, + { + "name": "analytics_engine_datasets", + "type": "Attributes Map", + "description": "Analytics Engine bindings used for Pages Functions.", + "children": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset." + } + ] + }, + { + "name": "browsers", + "type": "Attributes Map", + "description": "Browser bindings used for Pages Functions." + }, + { + "name": "build_image_major_version", + "type": "Number", + "description": "The major version of the build image to use for Pages Functions." + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Compatibility date used for Pages Functions." + }, + { + "name": "compatibility_flags", + "type": "List of String", + "description": "Compatibility flags used for Pages Functions." + }, + { + "name": "d1_databases", + "type": "Attributes Map", + "description": "D1 databases used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID of the D1 database." + } + ] + }, + { + "name": "durable_object_namespaces", + "type": "Attributes Map", + "description": "Durable Object namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "fail_open", + "type": "Boolean", + "description": "Whether to fail open when the deployment config cannot be applied." + }, + { + "name": "hyperdrive_bindings", + "type": "Attributes Map", + "description": "Hyperdrive bindings used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String" + } + ] + }, + { + "name": "kv_namespaces", + "type": "Attributes Map", + "description": "KV namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the KV namespace." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Limits for Pages Functions.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + } + ] + }, + { + "name": "mtls_certificates", + "type": "Attributes Map", + "description": "mTLS bindings used for Pages Functions.", + "children": [ + { + "name": "certificate_id", + "type": "String" + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement setting used for Pages Functions.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Placement mode." + } + ] + }, + { + "name": "queue_producers", + "type": "Attributes Map", + "description": "Queue Producer bindings used for Pages Functions.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the Queue." + } + ] + }, + { + "name": "r2_buckets", + "type": "Attributes Map", + "description": "R2 buckets used for Pages Functions.", + "children": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the R2 bucket." + }, + { + "name": "name", + "type": "String", + "description": "Name of the R2 bucket." + } + ] + }, + { + "name": "services", + "type": "Attributes Map", + "description": "Services used for Pages Functions.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "The entrypoint to bind to." + }, + { + "name": "environment", + "type": "String", + "description": "The Service environment." + }, + { + "name": "service", + "type": "String", + "description": "The Service name." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "The usage model for Pages Functions.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + }, + { + "name": "vectorize_bindings", + "type": "Attributes Map", + "description": "Vectorize bindings used for Pages Functions.", + "children": [ + { + "name": "index_name", + "type": "String" + } + ] + }, + { + "name": "wrangler_config_hash", + "type": "String", + "description": "Hash of the Wrangler configuration used for the deployment." + } + ] + }, + { + "name": "production", + "type": "Attributes", + "description": "Configs for production deploys.", + "children": [ + { + "name": "ai_bindings", + "type": "Attributes Map", + "description": "Constellation bindings used for Pages Functions.", + "children": [ + { + "name": "project_id", + "type": "String" + } + ] + }, + { + "name": "always_use_latest_compatibility_date", + "type": "Boolean", + "description": "Whether to always use the latest compatibility date for Pages Functions." + }, + { + "name": "analytics_engine_datasets", + "type": "Attributes Map", + "description": "Analytics Engine bindings used for Pages Functions.", + "children": [ + { + "name": "dataset", + "type": "String", + "description": "Name of the dataset." + } + ] + }, + { + "name": "browsers", + "type": "Attributes Map", + "description": "Browser bindings used for Pages Functions." + }, + { + "name": "build_image_major_version", + "type": "Number", + "description": "The major version of the build image to use for Pages Functions." + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Compatibility date used for Pages Functions." + }, + { + "name": "compatibility_flags", + "type": "List of String", + "description": "Compatibility flags used for Pages Functions." + }, + { + "name": "d1_databases", + "type": "Attributes Map", + "description": "D1 databases used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID of the D1 database." + } + ] + }, + { + "name": "durable_object_namespaces", + "type": "Attributes Map", + "description": "Durable Object namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "fail_open", + "type": "Boolean", + "description": "Whether to fail open when the deployment config cannot be applied." + }, + { + "name": "hyperdrive_bindings", + "type": "Attributes Map", + "description": "Hyperdrive bindings used for Pages Functions.", + "children": [ + { + "name": "id", + "type": "String" + } + ] + }, + { + "name": "kv_namespaces", + "type": "Attributes Map", + "description": "KV namespaces used for Pages Functions.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the KV namespace." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Limits for Pages Functions.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + } + ] + }, + { + "name": "mtls_certificates", + "type": "Attributes Map", + "description": "mTLS bindings used for Pages Functions.", + "children": [ + { + "name": "certificate_id", + "type": "String" + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement setting used for Pages Functions.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Placement mode." + } + ] + }, + { + "name": "queue_producers", + "type": "Attributes Map", + "description": "Queue Producer bindings used for Pages Functions.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the Queue." + } + ] + }, + { + "name": "r2_buckets", + "type": "Attributes Map", + "description": "R2 buckets used for Pages Functions.", + "children": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the R2 bucket." + }, + { + "name": "name", + "type": "String", + "description": "Name of the R2 bucket." + } + ] + }, + { + "name": "services", + "type": "Attributes Map", + "description": "Services used for Pages Functions.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "The entrypoint to bind to." + }, + { + "name": "environment", + "type": "String", + "description": "The Service environment." + }, + { + "name": "service", + "type": "String", + "description": "The Service name." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "The usage model for Pages Functions.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + }, + { + "name": "vectorize_bindings", + "type": "Attributes Map", + "description": "Vectorize bindings used for Pages Functions.", + "children": [ + { + "name": "index_name", + "type": "String" + } + ] + }, + { + "name": "wrangler_config_hash", + "type": "String", + "description": "Hash of the Wrangler configuration used for the deployment." + } + ] + } + ] + }, + { + "name": "domains", + "type": "List of String", + "description": "A list of associated custom domains for the project." + }, + { + "name": "framework", + "type": "String", + "description": "Framework the project is using." + }, + { + "name": "framework_version", + "type": "String", + "description": "Version of the framework the project is using." + }, + { + "name": "id", + "type": "String", + "description": "ID of the project." + }, + { + "name": "latest_deployment", + "type": "Attributes", + "description": "Most recent deployment of the project.", + "children": [ + { + "name": "aliases", + "type": "List of String", + "description": "A list of alias URLs pointing to this deployment." + }, + { + "name": "build_config", + "type": "Attributes", + "description": "Configs for the project build process.", + "children": [ + { + "name": "build_caching", + "type": "Boolean", + "description": "Enable build caching for the project." + }, + { + "name": "build_command", + "type": "String", + "description": "Command used to build project." + }, + { + "name": "destination_dir", + "type": "String", + "description": "Assets output directory of the build." + }, + { + "name": "root_dir", + "type": "String", + "description": "Directory to run the command." + }, + { + "name": "web_analytics_tag", + "type": "String", + "description": "The classifying tag for analytics." + }, + { + "name": "web_analytics_token", + "type": "String", + "description": "The auth token for analytics.", + "sensitive": true + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the deployment was created." + }, + { + "name": "deployment_trigger", + "type": "Attributes", + "description": "Info about what caused the deployment.", + "children": [ + { + "name": "metadata", + "type": "Attributes", + "description": "Additional info about the trigger.", + "children": [ + { + "name": "branch", + "type": "String", + "description": "Where the trigger happened." + }, + { + "name": "commit_dirty", + "type": "Boolean", + "description": "Whether the deployment trigger commit was dirty." + }, + { + "name": "commit_hash", + "type": "String", + "description": "Hash of the deployment trigger commit." + }, + { + "name": "commit_message", + "type": "String", + "description": "Message of the deployment trigger commit." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "What caused the deployment.\nAvailable values: \"github:push\", \"ad_hoc\", \"deploy_hook\"." + } + ] + }, + { + "name": "env_vars", + "type": "Attributes Map", + "description": "Environment variables used for builds and Pages Functions.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"plain_text\", \"secret_text\"." + }, + { + "name": "value", + "type": "String", + "description": "Environment variable value.", + "sensitive": true + } + ] + }, + { + "name": "environment", + "type": "String", + "description": "Type of deploy.\nAvailable values: \"preview\", \"production\"." + }, + { + "name": "id", + "type": "String", + "description": "Id of the deployment." + }, + { + "name": "is_skipped", + "type": "Boolean", + "description": "Whether the deployment was skipped." + }, + { + "name": "latest_stage", + "type": "Attributes", + "description": "The status of the deployment.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the deployment was last modified." + }, + { + "name": "project_id", + "type": "String", + "description": "Id of the project." + }, + { + "name": "project_name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "short_id", + "type": "String", + "description": "Short Id (8 character) of the deployment." + }, + { + "name": "skip_reason", + "type": "String", + "description": "Why the deployment was skipped.\nAvailable values: \"commit_message\", \"preview_deployments_disabled\", \"production_deployments_disabled\", \"path_config\", \"branch_config\", \"pages_to_workers_conversion\", \"superseded_queued_build\"." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "stages", + "type": "Attributes List", + "description": "List of past stages.", + "children": [ + { + "name": "ended_on", + "type": "String", + "description": "When the stage ended." + }, + { + "name": "name", + "type": "String", + "description": "The current build stage.\nAvailable values: \"queued\", \"initialize\", \"clone_repo\", \"build\", \"deploy\"." + }, + { + "name": "started_on", + "type": "String", + "description": "When the stage started." + }, + { + "name": "status", + "type": "String", + "description": "State of the current stage.\nAvailable values: \"success\", \"idle\", \"active\", \"failure\", \"canceled\", \"skipped\"." + } + ] + }, + { + "name": "url", + "type": "String", + "description": "The live URL to view this deployment." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the deployment uses functions." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the Pages project. Must begin with a lowercase letter or digit and contain only lowercase letters, digits, and hyphens." + }, + { + "name": "preview_script_name", + "type": "String", + "description": "Name of the preview script." + }, + { + "name": "production_branch", + "type": "String", + "description": "Production branch of the project. Used to identify production deployments." + }, + { + "name": "production_script_name", + "type": "String", + "description": "Name of the production script." + }, + { + "name": "source", + "type": "Attributes", + "description": "Configs for the project source control.", + "children": [ + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "deployments_enabled", + "type": "Boolean", + "description": "Whether to enable automatic deployments when pushing to the source repository.\nWhen disabled, no deployments (production or preview) will be triggered automatically.", + "deprecated": "Deprecated." + }, + { + "name": "owner", + "type": "String", + "description": "The owner of the repository." + }, + { + "name": "owner_id", + "type": "String", + "description": "The owner ID of the repository." + }, + { + "name": "path_excludes", + "type": "List of String", + "description": "A list of paths that should be excluded from triggering a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "path_includes", + "type": "List of String", + "description": "A list of paths that should be watched to trigger a preview deployment. Wildcard syntax (`*`) is supported." + }, + { + "name": "pr_comments_enabled", + "type": "Boolean", + "description": "Whether to enable PR comments." + }, + { + "name": "preview_branch_excludes", + "type": "List of String", + "description": "A list of branches that should not trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_branch_includes", + "type": "List of String", + "description": "A list of branches that should trigger a preview deployment. Wildcard syntax (`*`) is supported. Must be used with `preview_deployment_setting` set to `custom`." + }, + { + "name": "preview_deployment_setting", + "type": "String", + "description": "Controls whether commits to preview branches trigger a preview deployment.\nAvailable values: \"all\", \"none\", \"custom\"." + }, + { + "name": "production_branch", + "type": "String", + "description": "The production branch of the repository." + }, + { + "name": "production_deployments_enabled", + "type": "Boolean", + "description": "Whether to trigger a production deployment on commits to the production branch." + }, + { + "name": "repo_id", + "type": "String", + "description": "The ID of the repository." + }, + { + "name": "repo_name", + "type": "String", + "description": "The name of the repository." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The source control management provider.\nAvailable values: \"github\", \"gitlab\"." + } + ] + }, + { + "name": "subdomain", + "type": "String", + "description": "The Cloudflare subdomain associated with the project." + }, + { + "name": "uses_functions", + "type": "Boolean", + "description": "Whether the project uses functions." + } + ] + } + ] + }, + "data-source:cloudflare_pipeline": { + "kind": "data-source", + "name": "cloudflare_pipeline", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "data \"cloudflare_pipeline\" \"example_pipeline\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n pipeline_id = \"043e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "pipeline_id", + "type": "String", + "description": "Specifies the public ID of the pipeline." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "failure_reason", + "type": "String", + "description": "Indicates the reason for the failure of the Pipeline." + }, + { + "name": "id", + "type": "String", + "description": "Specifies the public ID of the pipeline." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Indicates the name of the Pipeline." + }, + { + "name": "sql", + "type": "String", + "description": "Specifies SQL for the Pipeline processing flow." + }, + { + "name": "status", + "type": "String", + "description": "Indicates the current status of the Pipeline." + }, + { + "name": "tables", + "type": "Attributes List", + "description": "List of streams and sinks used by this pipeline.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Unique identifier for the connection (stream or sink)." + }, + { + "name": "latest", + "type": "Number", + "description": "Latest available version of the connection." + }, + { + "name": "name", + "type": "String", + "description": "Name of the connection." + }, + { + "name": "type", + "type": "String", + "description": "Type of the connection.\nAvailable values: \"stream\", \"sink\"." + }, + { + "name": "version", + "type": "Number", + "description": "Current version of the connection used by this pipeline." + } + ] + } + ] + }, + "resource:cloudflare_pipeline": { + "kind": "resource", + "name": "cloudflare_pipeline", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "resource \"cloudflare_pipeline\" \"example_pipeline\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_pipeline\"\n sql = \"insert into sink select * from source;\"\n}", + "importExample": "$ terraform import cloudflare_pipeline.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + }, + { + "name": "name", + "type": "String", + "description": "Specifies the name of the Pipeline." + }, + { + "name": "sql", + "type": "String", + "description": "Specifies SQL for the Pipeline processing flow." + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "failure_reason", + "type": "String", + "description": "Indicates the reason for the failure of the Pipeline." + }, + { + "name": "id", + "type": "String", + "description": "Indicates a unique identifier for this pipeline." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "Indicates the current status of the Pipeline." + }, + { + "name": "tables", + "type": "Attributes List", + "description": "List of streams and sinks used by this pipeline.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Unique identifier for the connection (stream or sink)." + }, + { + "name": "latest", + "type": "Number", + "description": "Latest available version of the connection." + }, + { + "name": "name", + "type": "String", + "description": "Name of the connection." + }, + { + "name": "type", + "type": "String", + "description": "Type of the connection.\nAvailable values: \"stream\", \"sink\"." + }, + { + "name": "version", + "type": "Number", + "description": "Current version of the connection used by this pipeline." + } + ] + } + ] + }, + "data-source:cloudflare_pipeline_sink": { + "kind": "data-source", + "name": "cloudflare_pipeline_sink", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "data \"cloudflare_pipeline_sink\" \"example_pipeline_sink\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n sink_id = \"0223105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "Filters sinks by name (case-insensitive substring)." + }, + { + "name": "pipeline_id", + "type": "String" + } + ] + }, + { + "name": "sink_id", + "type": "String", + "description": "Specifies the publid ID of the sink." + } + ], + "computed": [ + { + "name": "config", + "type": "Attributes", + "description": "Defines the configuration of the R2 Sink.", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare Account ID for the bucket" + }, + { + "name": "bucket", + "type": "String", + "description": "R2 Bucket to write to" + }, + { + "name": "file_naming", + "type": "Attributes", + "description": "Controls filename prefix/suffix and strategy.", + "children": [ + { + "name": "prefix", + "type": "String", + "description": "The prefix to use in file name. i.e prefix-.parquet" + }, + { + "name": "strategy", + "type": "String", + "description": "Filename generation strategy.\nAvailable values: \"serial\", \"uuid\", \"uuid_v7\", \"ulid\"." + }, + { + "name": "suffix", + "type": "String", + "description": "This will overwrite the default file suffix. i.e .parquet, use with caution" + } + ] + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction this bucket is hosted in" + }, + { + "name": "namespace", + "type": "String", + "description": "Table namespace" + }, + { + "name": "partitioning", + "type": "Attributes", + "description": "Data-layout partitioning for sinks.", + "children": [ + { + "name": "time_pattern", + "type": "String", + "description": "The pattern of the date string" + } + ] + }, + { + "name": "path", + "type": "String", + "description": "Subpath within the bucket to write to" + }, + { + "name": "rolling_policy", + "type": "Attributes", + "description": "Rolling policy for file sinks (when & why to close a file and open a new one).", + "children": [ + { + "name": "file_size_bytes", + "type": "Number", + "description": "Files will be rolled after reaching this number of bytes" + }, + { + "name": "inactivity_seconds", + "type": "Number", + "description": "Number of seconds of inactivity to wait before rolling over to a new file" + }, + { + "name": "interval_seconds", + "type": "Number", + "description": "Number of seconds to wait before rolling over to a new file" + } + ] + }, + { + "name": "table_name", + "type": "String", + "description": "Table name" + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "format", + "type": "Attributes", + "description": "Defines the output data format of a sink.", + "children": [ + { + "name": "compression", + "type": "String", + "description": "Specifies the compression applied to JSON sink output.\nAvailable values: \"uncompressed\", \"gzip\", \"snappy\", \"zstd\", \"lz4\"." + }, + { + "name": "decimal_encoding", + "type": "String", + "description": "Available values: \"number\", \"string\", \"bytes\"." + }, + { + "name": "row_group_bytes", + "type": "Number" + }, + { + "name": "timestamp_format", + "type": "String", + "description": "Available values: \"rfc3339\", \"unix_millis\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"json\", \"parquet\"." + }, + { + "name": "unstructured", + "type": "Boolean" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Specifies the publid ID of the sink." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Defines the name of the Sink." + }, + { + "name": "schema", + "type": "Attributes", + "description": "Defines the schema of the events in the data stream.", + "children": [ + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "metadata_key", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "required", + "type": "Boolean" + }, + { + "name": "sql_name", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"int32\", \"int64\", \"float32\", \"float64\", \"bool\", \"string\", \"binary\", \"timestamp\", \"json\"." + }, + { + "name": "unit", + "type": "String", + "description": "Available values: \"second\", \"millisecond\", \"microsecond\", \"nanosecond\"." + } + ] + }, + { + "name": "inferred", + "type": "Boolean" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Specifies the type of sink.\nAvailable values: \"r2\", \"r2_data_catalog\", \"basin_catalog\"." + } + ] + }, + "resource:cloudflare_pipeline_sink": { + "kind": "resource", + "name": "cloudflare_pipeline_sink", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "resource \"cloudflare_pipeline_sink\" \"example_pipeline_sink\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_sink\"\n type = \"r2\"\n config = {\n account_id = \"account_id\"\n bucket = \"bucket\"\n credentials = {\n access_key_id = \"access_key_id\"\n secret_access_key = \"secret_access_key\"\n }\n file_naming = {\n prefix = \"prefix\"\n strategy = \"serial\"\n suffix = \"suffix\"\n }\n jurisdiction = \"jurisdiction\"\n partitioning = {\n time_pattern = \"year=%Y/month=%m/day=%d/hour=%H\"\n }\n path = \"path\"\n rolling_policy = {\n file_size_bytes = 0\n inactivity_seconds = 1\n interval_seconds = 1\n }\n }\n format = {\n type = \"json\"\n compression = \"uncompressed\"\n decimal_encoding = \"number\"\n timestamp_format = \"rfc3339\"\n unstructured = true\n }\n schema = {\n fields = [{\n type = \"int32\"\n metadata_key = \"metadata_key\"\n name = \"name\"\n required = true\n sql_name = \"sql_name\"\n }]\n inferred = true\n }\n}", + "importExample": "$ terraform import cloudflare_pipeline_sink.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + }, + { + "name": "name", + "type": "String", + "description": "Defines the name of the Sink." + }, + { + "name": "type", + "type": "String", + "description": "Specifies the type of sink.\nAvailable values: \"r2\", \"r2_data_catalog\", \"basin_catalog\"." + } + ], + "optional": [ + { + "name": "config", + "type": "Attributes", + "description": "Defines the configuration of the R2 Sink.", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare Account ID for the bucket" + }, + { + "name": "bucket", + "type": "String", + "description": "R2 Bucket to write to" + }, + { + "name": "credentials", + "type": "Attributes", + "children": [ + { + "name": "access_key_id", + "type": "String", + "description": "Cloudflare Account ID for the bucket" + }, + { + "name": "secret_access_key", + "type": "String", + "description": "Cloudflare Account ID for the bucket", + "sensitive": true + } + ] + }, + { + "name": "file_naming", + "type": "Attributes", + "description": "Controls filename prefix/suffix and strategy.", + "children": [ + { + "name": "prefix", + "type": "String", + "description": "The prefix to use in file name. i.e prefix-.parquet" + }, + { + "name": "strategy", + "type": "String", + "description": "Filename generation strategy.\nAvailable values: \"serial\", \"uuid\", \"uuid_v7\", \"ulid\"." + }, + { + "name": "suffix", + "type": "String", + "description": "This will overwrite the default file suffix. i.e .parquet, use with caution" + } + ] + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction this bucket is hosted in" + }, + { + "name": "namespace", + "type": "String", + "description": "Table namespace" + }, + { + "name": "partitioning", + "type": "Attributes", + "description": "Data-layout partitioning for sinks.", + "children": [ + { + "name": "time_pattern", + "type": "String", + "description": "The pattern of the date string" + } + ] + }, + { + "name": "path", + "type": "String", + "description": "Subpath within the bucket to write to" + }, + { + "name": "rolling_policy", + "type": "Attributes", + "description": "Rolling policy for file sinks (when & why to close a file and open a new one).", + "children": [ + { + "name": "file_size_bytes", + "type": "Number", + "description": "Files will be rolled after reaching this number of bytes" + }, + { + "name": "inactivity_seconds", + "type": "Number", + "description": "Number of seconds of inactivity to wait before rolling over to a new file" + }, + { + "name": "interval_seconds", + "type": "Number", + "description": "Number of seconds to wait before rolling over to a new file" + } + ] + }, + { + "name": "table_name", + "type": "String", + "description": "Table name" + }, + { + "name": "token", + "type": "String", + "description": "Authentication token", + "sensitive": true + } + ] + }, + { + "name": "format", + "type": "Attributes", + "description": "Defines the output data format of a sink.", + "children": [ + { + "name": "compression", + "type": "String", + "description": "Specifies the compression applied to JSON sink output.\nAvailable values: \"uncompressed\", \"gzip\", \"snappy\", \"zstd\", \"lz4\"." + }, + { + "name": "decimal_encoding", + "type": "String", + "description": "Available values: \"number\", \"string\", \"bytes\"." + }, + { + "name": "row_group_bytes", + "type": "Number" + }, + { + "name": "timestamp_format", + "type": "String", + "description": "Available values: \"rfc3339\", \"unix_millis\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"json\", \"parquet\"." + }, + { + "name": "unstructured", + "type": "Boolean" + } + ] + }, + { + "name": "schema", + "type": "Attributes", + "description": "Defines the schema of the events in the data stream.", + "children": [ + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "metadata_key", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "required", + "type": "Boolean" + }, + { + "name": "sql_name", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"int32\", \"int64\", \"float32\", \"float64\", \"bool\", \"string\", \"binary\", \"timestamp\", \"json\"." + }, + { + "name": "unit", + "type": "String", + "description": "Available values: \"second\", \"millisecond\", \"microsecond\", \"nanosecond\"." + } + ] + }, + { + "name": "inferred", + "type": "Boolean" + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Indicates a unique identifier for this sink." + }, + { + "name": "modified_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_pipeline_sinks": { + "kind": "list-data-source", + "name": "cloudflare_pipeline_sinks", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "data \"cloudflare_pipeline_sinks\" \"example_pipeline_sinks\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"x\"\n pipeline_id = \"pipeline_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Filters sinks by name (case-insensitive substring)." + }, + { + "name": "pipeline_id", + "type": "String" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "config", + "type": "Attributes", + "description": "Defines the configuration of the R2 Sink.", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare Account ID for the bucket" + }, + { + "name": "bucket", + "type": "String", + "description": "R2 Bucket to write to" + }, + { + "name": "file_naming", + "type": "Attributes", + "description": "Controls filename prefix/suffix and strategy.", + "children": [ + { + "name": "prefix", + "type": "String", + "description": "The prefix to use in file name. i.e prefix-.parquet" + }, + { + "name": "strategy", + "type": "String", + "description": "Filename generation strategy.\nAvailable values: \"serial\", \"uuid\", \"uuid_v7\", \"ulid\"." + }, + { + "name": "suffix", + "type": "String", + "description": "This will overwrite the default file suffix. i.e .parquet, use with caution" + } + ] + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction this bucket is hosted in" + }, + { + "name": "namespace", + "type": "String", + "description": "Table namespace" + }, + { + "name": "partitioning", + "type": "Attributes", + "description": "Data-layout partitioning for sinks.", + "children": [ + { + "name": "time_pattern", + "type": "String", + "description": "The pattern of the date string" + } + ] + }, + { + "name": "path", + "type": "String", + "description": "Subpath within the bucket to write to" + }, + { + "name": "rolling_policy", + "type": "Attributes", + "description": "Rolling policy for file sinks (when & why to close a file and open a new one).", + "children": [ + { + "name": "file_size_bytes", + "type": "Number", + "description": "Files will be rolled after reaching this number of bytes" + }, + { + "name": "inactivity_seconds", + "type": "Number", + "description": "Number of seconds of inactivity to wait before rolling over to a new file" + }, + { + "name": "interval_seconds", + "type": "Number", + "description": "Number of seconds to wait before rolling over to a new file" + } + ] + }, + { + "name": "table_name", + "type": "String", + "description": "Table name" + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "format", + "type": "Attributes", + "description": "Defines the output data format of a sink.", + "children": [ + { + "name": "compression", + "type": "String", + "description": "Specifies the compression applied to JSON sink output.\nAvailable values: \"uncompressed\", \"gzip\", \"snappy\", \"zstd\", \"lz4\"." + }, + { + "name": "decimal_encoding", + "type": "String", + "description": "Available values: \"number\", \"string\", \"bytes\"." + }, + { + "name": "row_group_bytes", + "type": "Number" + }, + { + "name": "timestamp_format", + "type": "String", + "description": "Available values: \"rfc3339\", \"unix_millis\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"json\", \"parquet\"." + }, + { + "name": "unstructured", + "type": "Boolean" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Indicates a unique identifier for this sink." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Defines the name of the Sink." + }, + { + "name": "schema", + "type": "Attributes", + "description": "Defines the schema of the events in the data stream.", + "children": [ + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "metadata_key", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "required", + "type": "Boolean" + }, + { + "name": "sql_name", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"int32\", \"int64\", \"float32\", \"float64\", \"bool\", \"string\", \"binary\", \"timestamp\", \"json\"." + }, + { + "name": "unit", + "type": "String", + "description": "Available values: \"second\", \"millisecond\", \"microsecond\", \"nanosecond\"." + } + ] + }, + { + "name": "inferred", + "type": "Boolean" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Specifies the type of sink.\nAvailable values: \"r2\", \"r2_data_catalog\", \"basin_catalog\"." + } + ] + } + ] + }, + "data-source:cloudflare_pipeline_stream": { + "kind": "data-source", + "name": "cloudflare_pipeline_stream", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "data \"cloudflare_pipeline_stream\" \"example_pipeline_stream\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n stream_id = \"033e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "Filters streams by name (case-insensitive substring)." + }, + { + "name": "pipeline_id", + "type": "String", + "description": "Specifies the public ID of the pipeline." + } + ] + }, + { + "name": "stream_id", + "type": "String", + "description": "Specifies the public ID of the stream." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "endpoint", + "type": "String", + "description": "Indicates the endpoint URL of this stream." + }, + { + "name": "format", + "type": "Attributes", + "description": "Defines the data format of the events.", + "children": [ + { + "name": "compression", + "type": "String", + "description": "Available values: \"uncompressed\", \"snappy\", \"gzip\", \"zstd\", \"lz4\"." + }, + { + "name": "decimal_encoding", + "type": "String", + "description": "Available values: \"number\", \"string\", \"bytes\"." + }, + { + "name": "row_group_bytes", + "type": "Number" + }, + { + "name": "timestamp_format", + "type": "String", + "description": "Available values: \"rfc3339\", \"unix_millis\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"json\", \"parquet\"." + }, + { + "name": "unstructured", + "type": "Boolean" + } + ] + }, + { + "name": "http", + "type": "Attributes", + "children": [ + { + "name": "authentication", + "type": "Boolean", + "description": "Indicates that authentication is required for the HTTP endpoint." + }, + { + "name": "cors", + "type": "Attributes", + "description": "Specifies the CORS options for the HTTP endpoint.", + "children": [ + { + "name": "origins", + "type": "List of String" + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates that the HTTP endpoint is enabled." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Specifies the public ID of the stream." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Indicates the name of the Stream." + }, + { + "name": "schema", + "type": "Attributes", + "description": "Defines the schema of the events in the data stream.", + "children": [ + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "metadata_key", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "required", + "type": "Boolean" + }, + { + "name": "sql_name", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"int32\", \"int64\", \"float32\", \"float64\", \"bool\", \"string\", \"binary\", \"timestamp\", \"json\"." + }, + { + "name": "unit", + "type": "String", + "description": "Available values: \"second\", \"millisecond\", \"microsecond\", \"nanosecond\"." + } + ] + }, + { + "name": "inferred", + "type": "Boolean" + } + ] + }, + { + "name": "version", + "type": "Number", + "description": "Indicates the current version of this stream." + }, + { + "name": "worker_binding", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates that the worker binding is enabled." + } + ] + } + ] + }, + "resource:cloudflare_pipeline_stream": { + "kind": "resource", + "name": "cloudflare_pipeline_stream", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "resource \"cloudflare_pipeline_stream\" \"example_pipeline_stream\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"my_stream\"\n format = {\n type = \"json\"\n decimal_encoding = \"number\"\n timestamp_format = \"rfc3339\"\n unstructured = true\n }\n http = {\n authentication = false\n enabled = true\n cors = {\n origins = [\"string\"]\n }\n }\n schema = {\n fields = [{\n type = \"int32\"\n metadata_key = \"metadata_key\"\n name = \"name\"\n required = true\n sql_name = \"sql_name\"\n }]\n inferred = true\n }\n worker_binding = {\n enabled = true\n }\n}", + "importExample": "$ terraform import cloudflare_pipeline_stream.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + }, + { + "name": "name", + "type": "String", + "description": "Specifies the name of the Stream." + } + ], + "optional": [ + { + "name": "format", + "type": "Attributes", + "description": "Defines the data format of the events.", + "children": [ + { + "name": "compression", + "type": "String", + "description": "Available values: \"uncompressed\", \"snappy\", \"gzip\", \"zstd\", \"lz4\"." + }, + { + "name": "decimal_encoding", + "type": "String", + "description": "Available values: \"number\", \"string\", \"bytes\"." + }, + { + "name": "row_group_bytes", + "type": "Number" + }, + { + "name": "timestamp_format", + "type": "String", + "description": "Available values: \"rfc3339\", \"unix_millis\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"json\", \"parquet\"." + }, + { + "name": "unstructured", + "type": "Boolean" + } + ] + }, + { + "name": "http", + "type": "Attributes", + "children": [ + { + "name": "authentication", + "type": "Boolean", + "description": "Indicates that authentication is required for the HTTP endpoint." + }, + { + "name": "cors", + "type": "Attributes", + "description": "Specifies the CORS options for the HTTP endpoint.", + "children": [ + { + "name": "origins", + "type": "List of String" + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates that the HTTP endpoint is enabled." + } + ] + }, + { + "name": "schema", + "type": "Attributes", + "description": "Defines the schema of the events in the data stream.", + "children": [ + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "metadata_key", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "required", + "type": "Boolean" + }, + { + "name": "sql_name", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"int32\", \"int64\", \"float32\", \"float64\", \"bool\", \"string\", \"binary\", \"timestamp\", \"json\"." + }, + { + "name": "unit", + "type": "String", + "description": "Available values: \"second\", \"millisecond\", \"microsecond\", \"nanosecond\"." + } + ] + }, + { + "name": "inferred", + "type": "Boolean" + } + ] + }, + { + "name": "worker_binding", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates that the worker binding is enabled." + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "endpoint", + "type": "String", + "description": "Indicates the endpoint URL of this stream." + }, + { + "name": "id", + "type": "String", + "description": "Indicates a unique identifier for this stream." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "version", + "type": "Number", + "description": "Indicates the current version of this stream." + } + ] + }, + "list-data-source:cloudflare_pipeline_streams": { + "kind": "list-data-source", + "name": "cloudflare_pipeline_streams", + "description": "Accepted Permissions\n\n- `Pipelines Read`\n- `Pipelines Write`", + "example": "data \"cloudflare_pipeline_streams\" \"example_pipeline_streams\" {\n account_id = \"0123105f4ecef8ad9ca31a8372d0c353\"\n name = \"x\"\n pipeline_id = \"043e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specifies the public ID of the account." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Filters streams by name (case-insensitive substring)." + }, + { + "name": "pipeline_id", + "type": "String", + "description": "Specifies the public ID of the pipeline." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "endpoint", + "type": "String", + "description": "Indicates the endpoint URL of this stream." + }, + { + "name": "format", + "type": "Attributes", + "description": "Defines the data format of the events.", + "children": [ + { + "name": "compression", + "type": "String", + "description": "Available values: \"uncompressed\", \"snappy\", \"gzip\", \"zstd\", \"lz4\"." + }, + { + "name": "decimal_encoding", + "type": "String", + "description": "Available values: \"number\", \"string\", \"bytes\"." + }, + { + "name": "row_group_bytes", + "type": "Number" + }, + { + "name": "timestamp_format", + "type": "String", + "description": "Available values: \"rfc3339\", \"unix_millis\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"json\", \"parquet\"." + }, + { + "name": "unstructured", + "type": "Boolean" + } + ] + }, + { + "name": "http", + "type": "Attributes", + "children": [ + { + "name": "authentication", + "type": "Boolean", + "description": "Indicates that authentication is required for the HTTP endpoint." + }, + { + "name": "cors", + "type": "Attributes", + "description": "Specifies the CORS options for the HTTP endpoint.", + "children": [ + { + "name": "origins", + "type": "List of String" + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates that the HTTP endpoint is enabled." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Indicates a unique identifier for this stream." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Indicates the name of the Stream." + }, + { + "name": "schema", + "type": "Attributes", + "description": "Defines the schema of the events in the data stream.", + "children": [ + { + "name": "fields", + "type": "Attributes List", + "children": [ + { + "name": "metadata_key", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "required", + "type": "Boolean" + }, + { + "name": "sql_name", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"int32\", \"int64\", \"float32\", \"float64\", \"bool\", \"string\", \"binary\", \"timestamp\", \"json\"." + }, + { + "name": "unit", + "type": "String", + "description": "Available values: \"second\", \"millisecond\", \"microsecond\", \"nanosecond\"." + } + ] + }, + { + "name": "inferred", + "type": "Boolean" + } + ] + }, + { + "name": "version", + "type": "Number", + "description": "Indicates the current version of this stream." + }, + { + "name": "worker_binding", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates that the worker binding is enabled." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_precursor": { + "kind": "data-source", + "name": "cloudflare_precursor", + "example": "data \"cloudflare_precursor\" \"example_precursor\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "default_mode", + "type": "String", + "description": "The zone-level Precursor enforcement mode applied to requests that do\nnot match a more specific enforcement rule.\nAvailable values: \"off\", \"min-friction\", \"max-security\".", + "deprecated": "Deprecated." + }, + { + "name": "enforcement_rules", + "type": "Attributes List", + "description": "The ordered list of enforcement rules for the zone.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "description", + "type": "String", + "description": "An informative description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the rule is active." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression that determines which requests the rule matches." + }, + { + "name": "id", + "type": "String", + "description": "The read-only identifier that Cloudflare assigns to the rule." + }, + { + "name": "mode", + "type": "String", + "description": "The override mode Precursor applies to requests matching an enforcement\nrule. Unlike `default_mode`, this cannot be `off`.\nAvailable values: \"min-friction\", \"max-security\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_precursor": { + "kind": "resource", + "name": "cloudflare_precursor", + "example": "resource \"cloudflare_precursor\" \"example_precursor\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n default_mode = \"min-friction\"\n enforcement_rules = [{\n expression = \"http.request.uri.path eq \\\"/login\\\"\"\n mode = \"max-security\"\n description = \"Ease friction on the login path\"\n enabled = true\n }]\n}", + "importExample": "$ terraform import cloudflare_precursor.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "default_mode", + "type": "String", + "description": "The zone-level Precursor enforcement mode applied to requests that do\nnot match a more specific enforcement rule.\nAvailable values: \"off\", \"min-friction\", \"max-security\".", + "deprecated": "Deprecated." + }, + { + "name": "enforcement_rules", + "type": "Attributes List", + "description": "The ordered list of enforcement rules for the zone.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "description", + "type": "String", + "description": "An informative description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the rule is active." + }, + { + "name": "expression", + "type": "String", + "description": "The filter expression that determines which requests the rule matches." + }, + { + "name": "id", + "type": "String", + "description": "The read-only identifier that Cloudflare assigns to the rule." + }, + { + "name": "mode", + "type": "String", + "description": "The override mode Precursor applies to requests matching an enforcement\nrule. Unlike `default_mode`, this cannot be `off`.\nAvailable values: \"min-friction\", \"max-security\"." + } + ] + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_queue": { + "kind": "data-source", + "name": "cloudflare_queue", + "description": "Accepted Permissions\n\n- `Queues Read`\n- `Queues Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "data \"cloudflare_queue\" \"example_queue\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "queue_id", + "type": "String", + "description": "A Resource identifier." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "A Resource identifier." + } + ], + "computed": [ + { + "name": "consumers", + "type": "Attributes List", + "children": [ + { + "name": "consumer_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "dead_letter_queue", + "type": "String", + "description": "Name of the dead letter queue, or empty string if not configured" + }, + { + "name": "queue_name", + "type": "String" + }, + { + "name": "script_name", + "type": "String", + "description": "Name of a Worker" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "batch_size", + "type": "Number", + "description": "The maximum number of messages to include in a batch." + }, + { + "name": "max_concurrency", + "type": "Number", + "description": "Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)." + }, + { + "name": "max_retries", + "type": "Number", + "description": "The maximum number of retries" + }, + { + "name": "max_wait_time_ms", + "type": "Number", + "description": "The number of milliseconds to wait for a batch to fill up before attempting to deliver it" + }, + { + "name": "retry_delay", + "type": "Number", + "description": "The number of seconds to delay before making the message available for another attempt." + }, + { + "name": "visibility_timeout_ms", + "type": "Number", + "description": "The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"http_pull\"." + } + ] + }, + { + "name": "consumers_total_count", + "type": "Number" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Available values: \"eu\", \"us\", \"fedramp\"." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "producers", + "type": "Attributes List", + "children": [ + { + "name": "bucket_name", + "type": "String" + }, + { + "name": "script", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"r2_bucket\"." + } + ] + }, + { + "name": "producers_total_count", + "type": "Number" + }, + { + "name": "queue_name", + "type": "String" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "delivery_delay", + "type": "Number", + "description": "Number of seconds to delay delivery of all messages to consumers." + }, + { + "name": "delivery_paused", + "type": "Boolean", + "description": "Indicates if message delivery to consumers is currently paused." + }, + { + "name": "message_retention_period", + "type": "Number", + "description": "Number of seconds after which an unconsumed message will be delayed." + } + ] + } + ] + }, + "resource:cloudflare_queue": { + "kind": "resource", + "name": "cloudflare_queue", + "description": "Accepted Permissions\n\n- `Queues Read`\n- `Queues Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "resource \"cloudflare_queue\" \"example_queue\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_name = \"example-queue\"\n jurisdiction = \"eu\"\n}", + "importExample": "$ terraform import cloudflare_queue.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "queue_name", + "type": "String" + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Available values: \"eu\", \"us\", \"fedramp\"." + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "delivery_delay", + "type": "Number", + "description": "Number of seconds to delay delivery of all messages to consumers." + }, + { + "name": "delivery_paused", + "type": "Boolean", + "description": "Indicates if message delivery to consumers is currently paused." + }, + { + "name": "message_retention_period", + "type": "Number", + "description": "Number of seconds after which an unconsumed message will be delayed." + } + ] + } + ], + "computed": [ + { + "name": "consumers", + "type": "Attributes List", + "children": [ + { + "name": "consumer_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "dead_letter_queue", + "type": "String", + "description": "Name of the dead letter queue, or empty string if not configured" + }, + { + "name": "queue_name", + "type": "String" + }, + { + "name": "script_name", + "type": "String", + "description": "Name of a Worker" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "batch_size", + "type": "Number", + "description": "The maximum number of messages to include in a batch." + }, + { + "name": "max_concurrency", + "type": "Number", + "description": "Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)." + }, + { + "name": "max_retries", + "type": "Number", + "description": "The maximum number of retries" + }, + { + "name": "max_wait_time_ms", + "type": "Number", + "description": "The number of milliseconds to wait for a batch to fill up before attempting to deliver it" + }, + { + "name": "retry_delay", + "type": "Number", + "description": "The number of seconds to delay before making the message available for another attempt." + }, + { + "name": "visibility_timeout_ms", + "type": "Number", + "description": "The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"http_pull\"." + } + ] + }, + { + "name": "consumers_total_count", + "type": "Number" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "producers", + "type": "Attributes List", + "children": [ + { + "name": "bucket_name", + "type": "String" + }, + { + "name": "script", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"r2_bucket\"." + } + ] + }, + { + "name": "producers_total_count", + "type": "Number" + }, + { + "name": "queue_id", + "type": "String" + } + ] + }, + "data-source:cloudflare_queue_consumer": { + "kind": "data-source", + "name": "cloudflare_queue_consumer", + "description": "Accepted Permissions\n\n- `Queues Read`\n- `Queues Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "data \"cloudflare_queue_consumer\" \"example_queue_consumer\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n consumer_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "queue_id", + "type": "String", + "description": "A Resource identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "consumer_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "dead_letter_queue", + "type": "String", + "description": "Name of the dead letter queue, or empty string if not configured" + }, + { + "name": "queue_name", + "type": "String" + }, + { + "name": "script_name", + "type": "String", + "description": "Name of a Worker" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "batch_size", + "type": "Number", + "description": "The maximum number of messages to include in a batch." + }, + { + "name": "max_concurrency", + "type": "Number", + "description": "Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)." + }, + { + "name": "max_retries", + "type": "Number", + "description": "The maximum number of retries" + }, + { + "name": "max_wait_time_ms", + "type": "Number", + "description": "The number of milliseconds to wait for a batch to fill up before attempting to deliver it" + }, + { + "name": "retry_delay", + "type": "Number", + "description": "The number of seconds to delay before making the message available for another attempt." + }, + { + "name": "visibility_timeout_ms", + "type": "Number", + "description": "The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"http_pull\"." + } + ] + }, + "resource:cloudflare_queue_consumer": { + "kind": "resource", + "name": "cloudflare_queue_consumer", + "description": "Accepted Permissions\n\n- `Queues Read`\n- `Queues Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "resource \"cloudflare_queue_consumer\" \"example_queue_consumer\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"my-consumer-worker\"\n type = \"worker\"\n dead_letter_queue = \"example-queue\"\n settings = {\n batch_size = 50\n max_concurrency = 10\n max_retries = 3\n max_wait_time_ms = 5000\n retry_delay = 10\n }\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "queue_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"http_pull\", \"notification\"." + } + ], + "optional": [ + { + "name": "dead_letter_queue", + "type": "String" + }, + { + "name": "script_name", + "type": "String", + "description": "Name of a Worker" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "batch_size", + "type": "Number", + "description": "The maximum number of messages to include in a batch." + }, + { + "name": "email", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "The email address." + } + ] + }, + { + "name": "max_concurrency", + "type": "Number", + "description": "Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)." + }, + { + "name": "max_retries", + "type": "Number", + "description": "The maximum number of retries" + }, + { + "name": "max_wait_time_ms", + "type": "Number", + "description": "The number of milliseconds to wait for a batch to fill up before attempting to deliver it" + }, + { + "name": "pagerduty", + "type": "Attributes List", + "description": "PagerDuty notification destinations.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID." + } + ] + }, + { + "name": "retry_delay", + "type": "Number", + "description": "The number of seconds to delay before making the message available for another attempt." + }, + { + "name": "visibility_timeout_ms", + "type": "Number", + "description": "The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt." + }, + { + "name": "webhooks", + "type": "Attributes List", + "description": "Webhook notification destinations.", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID." + } + ] + } + ] + } + ], + "computed": [ + { + "name": "consumer_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "queue_name", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_queue_consumers": { + "kind": "list-data-source", + "name": "cloudflare_queue_consumers", + "description": "Accepted Permissions\n\n- `Queues Read`\n- `Queues Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "data \"cloudflare_queue_consumers\" \"example_queue_consumers\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n queue_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "queue_id", + "type": "String", + "description": "A Resource identifier." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "consumer_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "dead_letter_queue", + "type": "String", + "description": "Name of the dead letter queue, or empty string if not configured" + }, + { + "name": "queue_name", + "type": "String" + }, + { + "name": "script_name", + "type": "String", + "description": "Name of a Worker" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "batch_size", + "type": "Number", + "description": "The maximum number of messages to include in a batch." + }, + { + "name": "max_concurrency", + "type": "Number", + "description": "Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)." + }, + { + "name": "max_retries", + "type": "Number", + "description": "The maximum number of retries" + }, + { + "name": "max_wait_time_ms", + "type": "Number", + "description": "The number of milliseconds to wait for a batch to fill up before attempting to deliver it" + }, + { + "name": "retry_delay", + "type": "Number", + "description": "The number of seconds to delay before making the message available for another attempt." + }, + { + "name": "visibility_timeout_ms", + "type": "Number", + "description": "The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"http_pull\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_queues": { + "kind": "list-data-source", + "name": "cloudflare_queues", + "description": "Accepted Permissions\n\n- `Queues Read`\n- `Queues Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "data \"cloudflare_queues\" \"example_queues\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "consumers", + "type": "Attributes List", + "children": [ + { + "name": "consumer_id", + "type": "String", + "description": "A Resource identifier." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "dead_letter_queue", + "type": "String", + "description": "Name of the dead letter queue, or empty string if not configured" + }, + { + "name": "queue_name", + "type": "String" + }, + { + "name": "script_name", + "type": "String", + "description": "Name of a Worker" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "batch_size", + "type": "Number", + "description": "The maximum number of messages to include in a batch." + }, + { + "name": "max_concurrency", + "type": "Number", + "description": "Maximum number of concurrent consumers that may consume from this Queue. Set to `null` to automatically opt in to the platform's maximum (recommended)." + }, + { + "name": "max_retries", + "type": "Number", + "description": "The maximum number of retries" + }, + { + "name": "max_wait_time_ms", + "type": "Number", + "description": "The number of milliseconds to wait for a batch to fill up before attempting to deliver it" + }, + { + "name": "retry_delay", + "type": "Number", + "description": "The number of seconds to delay before making the message available for another attempt." + }, + { + "name": "visibility_timeout_ms", + "type": "Number", + "description": "The number of milliseconds that a message is exclusively leased. After the timeout, the message becomes available for another attempt." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"http_pull\"." + } + ] + }, + { + "name": "consumers_total_count", + "type": "Number" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Available values: \"eu\", \"us\", \"fedramp\"." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "producers", + "type": "Attributes List", + "children": [ + { + "name": "bucket_name", + "type": "String" + }, + { + "name": "script", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"worker\", \"r2_bucket\"." + } + ] + }, + { + "name": "producers_total_count", + "type": "Number" + }, + { + "name": "queue_id", + "type": "String" + }, + { + "name": "queue_name", + "type": "String" + }, + { + "name": "settings", + "type": "Attributes", + "children": [ + { + "name": "delivery_delay", + "type": "Number", + "description": "Number of seconds to delay delivery of all messages to consumers." + }, + { + "name": "delivery_paused", + "type": "Boolean", + "description": "Indicates if message delivery to consumers is currently paused." + }, + { + "name": "message_retention_period", + "type": "Number", + "description": "Number of seconds after which an unconsumed message will be delayed." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_r2_bucket": { + "kind": "data-source", + "name": "cloudflare_r2_bucket", + "example": "data \"cloudflare_r2_bucket\" \"example_r2_bucket\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}", + "required": [ + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + } + ], + "computed": [ + { + "name": "creation_date", + "type": "String", + "description": "Creation timestamp." + }, + { + "name": "id", + "type": "String", + "description": "Name of the bucket." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction where objects in this bucket are guaranteed to be stored.\nAvailable values: \"default\", \"eu\", \"us\", \"fedramp\", \"fedramp-high\"." + }, + { + "name": "location", + "type": "String", + "description": "Location of the bucket.\nAvailable values: \"apac\", \"eeur\", \"enam\", \"weur\", \"wnam\", \"oc\"." + }, + { + "name": "name", + "type": "String", + "description": "Name of the bucket." + }, + { + "name": "storage_class", + "type": "String", + "description": "Storage class for newly uploaded objects, unless specified otherwise.\nAvailable values: \"Standard\", \"InfrequentAccess\"." + } + ] + }, + "resource:cloudflare_r2_bucket": { + "kind": "resource", + "name": "cloudflare_r2_bucket", + "description": "Accepted Permissions\n\n- `Workers R2 Storage Write`", + "example": "resource \"cloudflare_r2_bucket\" \"example_r2_bucket\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"example-bucket\"\n location = \"apac\"\n storage_class = \"Standard\"\n}", + "importExample": "$ terraform import cloudflare_r2_bucket.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction where objects in this bucket are guaranteed to be stored.\nAvailable values: \"default\", \"eu\", \"fedramp\", \"us\"." + }, + { + "name": "location", + "type": "String", + "description": "Location of the bucket.\nAvailable values: \"apac\", \"eeur\", \"enam\", \"weur\", \"wnam\", \"oc\". Note: `location` is only honored the first time a bucket with a given name is created. If you delete and recreate a bucket with the same name, the original bucket location will be used. It is also a best-effort, not a guarantee, of bucket location." + }, + { + "name": "storage_class", + "type": "String", + "description": "Storage class for newly uploaded objects, unless specified otherwise.\nAvailable values: \"Standard\", \"InfrequentAccess\"." + } + ], + "computed": [ + { + "name": "creation_date", + "type": "String", + "description": "Creation timestamp." + }, + { + "name": "id", + "type": "String", + "description": "Name of the bucket." + } + ] + }, + "data-source:cloudflare_r2_bucket_cors": { + "kind": "data-source", + "name": "cloudflare_r2_bucket_cors", + "example": "data \"cloudflare_r2_bucket_cors\" \"example_r2_bucket_cors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [], + "computed": [ + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "allowed", + "type": "Attributes", + "description": "Object specifying allowed origins, methods and headers for this CORS rule.", + "children": [ + { + "name": "headers", + "type": "List of String", + "description": "Specifies the value for the Access-Control-Allow-Headers header R2 sets when requesting objects in this bucket from a browser. Cross-origin requests that include custom headers (e.g. x-user-id) should specify these headers as AllowedHeaders." + }, + { + "name": "methods", + "type": "List of String", + "description": "Specifies the value for the Access-Control-Allow-Methods header R2 sets when requesting objects in a bucket from a browser." + }, + { + "name": "origins", + "type": "List of String", + "description": "Specifies the value for the Access-Control-Allow-Origin header R2 sets when requesting objects in a bucket from a browser." + } + ] + }, + { + "name": "expose_headers", + "type": "List of String", + "description": "Specifies the headers that can be exposed back, and accessed by, the JavaScript making the cross-origin request. If you need to access headers beyond the safelisted response headers, such as Content-Encoding or cf-cache-status, you must specify it here." + }, + { + "name": "id", + "type": "String", + "description": "Identifier for this rule." + }, + { + "name": "max_age_seconds", + "type": "Number", + "description": "Specifies the amount of time (in seconds) browsers are allowed to cache CORS preflight responses. Browsers may limit this to 2 hours or less, even if the maximum value (86400) is specified." + } + ] + } + ] + }, + "resource:cloudflare_r2_bucket_cors": { + "kind": "resource", + "name": "cloudflare_r2_bucket_cors", + "example": "resource \"cloudflare_r2_bucket_cors\" \"example_r2_bucket_cors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n allowed = {\n methods = [\"GET\"]\n origins = [\"http://localhost:3000\"]\n headers = [\"x-requested-by\"]\n }\n id = \"Allow Local Development\"\n expose_headers = [\"Content-Encoding\"]\n max_age_seconds = 3600\n }]\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the bucket" + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "allowed", + "type": "Attributes", + "description": "Object specifying allowed origins, methods and headers for this CORS rule.", + "children": [ + { + "name": "headers", + "type": "List of String", + "description": "Specifies the value for the Access-Control-Allow-Headers header R2 sets when requesting objects in this bucket from a browser. Cross-origin requests that include custom headers (e.g. x-user-id) should specify these headers as AllowedHeaders." + }, + { + "name": "methods", + "type": "List of String", + "description": "Specifies the value for the Access-Control-Allow-Methods header R2 sets when requesting objects in a bucket from a browser." + }, + { + "name": "origins", + "type": "List of String", + "description": "Specifies the value for the Access-Control-Allow-Origin header R2 sets when requesting objects in a bucket from a browser." + } + ] + }, + { + "name": "expose_headers", + "type": "List of String", + "description": "Specifies the headers that can be exposed back, and accessed by, the JavaScript making the cross-origin request. If you need to access headers beyond the safelisted response headers, such as Content-Encoding or cf-cache-status, you must specify it here." + }, + { + "name": "id", + "type": "String", + "description": "Identifier for this rule." + }, + { + "name": "max_age_seconds", + "type": "Number", + "description": "Specifies the amount of time (in seconds) browsers are allowed to cache CORS preflight responses. Browsers may limit this to 2 hours or less, even if the maximum value (86400) is specified." + } + ] + } + ], + "computed": [] + }, + "data-source:cloudflare_r2_bucket_event_notification": { + "kind": "data-source", + "name": "cloudflare_r2_bucket_event_notification", + "description": "Accepted Permissions\n\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`", + "example": "data \"cloudflare_r2_bucket_event_notification\" \"example_r2_bucket_event_notification\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n queue_id = \"queue_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + }, + { + "name": "queue_id", + "type": "String", + "description": "ID of the Cloudflare Queue that receives notifications for matching R2 object events." + } + ], + "optional": [], + "computed": [ + { + "name": "queue_name", + "type": "String", + "description": "Name of the queue." + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "actions", + "type": "List of String", + "description": "Array of R2 object actions that will trigger notifications." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the rule was created." + }, + { + "name": "description", + "type": "String", + "description": "A description that can be used to identify the event notification rule after creation." + }, + { + "name": "prefix", + "type": "String", + "description": "Notifications will be sent only for objects with this prefix." + }, + { + "name": "rule_id", + "type": "String", + "description": "Rule ID." + }, + { + "name": "suffix", + "type": "String", + "description": "Notifications will be sent only for objects with this suffix." + } + ] + } + ] + }, + "resource:cloudflare_r2_bucket_event_notification": { + "kind": "resource", + "name": "cloudflare_r2_bucket_event_notification", + "description": "Accepted Permissions\n\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`", + "example": "resource \"cloudflare_r2_bucket_event_notification\" \"example_r2_bucket_event_notification\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n queue_id = \"queue_id\"\n rules = [{\n actions = [\"PutObject\", \"CopyObject\"]\n description = \"Notifications from source bucket to queue\"\n prefix = \"img/\"\n suffix = \".jpeg\"\n }]\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + }, + { + "name": "queue_id", + "type": "String", + "description": "ID of the Cloudflare Queue that receives notifications for matching R2 object events." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "Array of rules to drive notifications.", + "children": [ + { + "name": "actions", + "type": "List of String", + "description": "Array of R2 object actions that will trigger notifications." + }, + { + "name": "description", + "type": "String", + "description": "A description that can be used to identify the event notification rule after creation." + }, + { + "name": "prefix", + "type": "String", + "description": "Notifications will be sent only for objects with this prefix." + }, + { + "name": "suffix", + "type": "String", + "description": "Notifications will be sent only for objects with this suffix." + } + ] + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the bucket" + } + ], + "computed": [ + { + "name": "queue_name", + "type": "String", + "description": "Name of the queue." + } + ] + }, + "data-source:cloudflare_r2_bucket_lifecycle": { + "kind": "data-source", + "name": "cloudflare_r2_bucket_lifecycle", + "example": "data \"cloudflare_r2_bucket_lifecycle\" \"example_r2_bucket_lifecycle\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [], + "computed": [ + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "abort_multipart_uploads_transition", + "type": "Attributes", + "description": "Transition to abort ongoing multipart uploads.", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition for lifecycle transitions to apply after an object reaches an age in seconds.", + "children": [ + { + "name": "max_age", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\"." + } + ] + } + ] + }, + { + "name": "conditions", + "type": "Attributes", + "description": "Conditions that apply to all transitions of this rule.", + "children": [ + { + "name": "prefix", + "type": "String", + "description": "Transitions will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads." + } + ] + }, + { + "name": "delete_objects_transition", + "type": "Attributes", + "description": "Transition to delete objects.", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition for lifecycle transitions to apply after an object reaches an age in seconds.", + "children": [ + { + "name": "date", + "type": "String" + }, + { + "name": "max_age", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\", \"Date\"." + } + ] + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not this rule is in effect." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for this rule." + }, + { + "name": "storage_class_transitions", + "type": "Attributes List", + "description": "Transitions to change the storage class of objects.", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition for lifecycle transitions to apply after an object reaches an age in seconds.", + "children": [ + { + "name": "date", + "type": "String" + }, + { + "name": "max_age", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\", \"Date\"." + } + ] + }, + { + "name": "storage_class", + "type": "String", + "description": "Available values: \"InfrequentAccess\"." + } + ] + } + ] + } + ] + }, + "resource:cloudflare_r2_bucket_lifecycle": { + "kind": "resource", + "name": "cloudflare_r2_bucket_lifecycle", + "example": "resource \"cloudflare_r2_bucket_lifecycle\" \"example_r2_bucket_lifecycle\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n id = \"Expire all objects older than 24 hours\"\n conditions = {\n prefix = \"prefix\"\n }\n enabled = true\n abort_multipart_uploads_transition = {\n condition = {\n max_age = 0\n type = \"Age\"\n }\n }\n delete_objects_transition = {\n condition = {\n max_age = 0\n type = \"Age\"\n }\n }\n storage_class_transitions = [{\n condition = {\n max_age = 0\n type = \"Age\"\n }\n storage_class = \"InfrequentAccess\"\n }]\n }]\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the bucket" + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "abort_multipart_uploads_transition", + "type": "Attributes", + "description": "Transition to abort ongoing multipart uploads.", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition for lifecycle transitions to apply after an object reaches an age in seconds.", + "children": [ + { + "name": "max_age", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\"." + } + ] + } + ] + }, + { + "name": "conditions", + "type": "Attributes", + "description": "Conditions that apply to all transitions of this rule.", + "children": [ + { + "name": "prefix", + "type": "String", + "description": "Transitions will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads." + } + ] + }, + { + "name": "delete_objects_transition", + "type": "Attributes", + "description": "Transition to delete objects.", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition for lifecycle transitions to apply after an object reaches an age in seconds.", + "children": [ + { + "name": "date", + "type": "String" + }, + { + "name": "max_age", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\", \"Date\"." + } + ] + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not this rule is in effect." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for this rule." + }, + { + "name": "storage_class_transitions", + "type": "Attributes List", + "description": "Transitions to change the storage class of objects.", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition for lifecycle transitions to apply after an object reaches an age in seconds.", + "children": [ + { + "name": "date", + "type": "String" + }, + { + "name": "max_age", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\", \"Date\"." + } + ] + }, + { + "name": "storage_class", + "type": "String", + "description": "Available values: \"InfrequentAccess\"." + } + ] + } + ] + } + ], + "computed": [] + }, + "data-source:cloudflare_r2_bucket_lock": { + "kind": "data-source", + "name": "cloudflare_r2_bucket_lock", + "example": "data \"cloudflare_r2_bucket_lock\" \"example_r2_bucket_lock\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [], + "computed": [ + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition to apply a lock rule to an object for how long in seconds.", + "children": [ + { + "name": "date", + "type": "String" + }, + { + "name": "max_age_seconds", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\", \"Date\", \"Indefinite\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not this rule is in effect." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for this rule." + }, + { + "name": "prefix", + "type": "String", + "description": "Rule will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads." + } + ] + } + ] + }, + "resource:cloudflare_r2_bucket_lock": { + "kind": "resource", + "name": "cloudflare_r2_bucket_lock", + "example": "resource \"cloudflare_r2_bucket_lock\" \"example_r2_bucket_lock\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n rules = [{\n id = \"Lock all objects for 24 hours\"\n condition = {\n max_age_seconds = 100\n type = \"Age\"\n }\n enabled = true\n prefix = \"prefix\"\n }]\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the bucket" + }, + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "condition", + "type": "Attributes", + "description": "Condition to apply a lock rule to an object for how long in seconds.", + "children": [ + { + "name": "date", + "type": "String" + }, + { + "name": "max_age_seconds", + "type": "Number" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"Age\", \"Date\", \"Indefinite\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not this rule is in effect." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for this rule." + }, + { + "name": "prefix", + "type": "String", + "description": "Rule will only apply to objects/uploads in the bucket that start with the given prefix, an empty prefix can be provided to scope rule to all objects/uploads." + } + ] + } + ], + "computed": [] + }, + "data-source:cloudflare_r2_bucket_sippy": { + "kind": "data-source", + "name": "cloudflare_r2_bucket_sippy", + "example": "data \"cloudflare_r2_bucket_sippy\" \"example_r2_bucket_sippy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [], + "computed": [ + { + "name": "destination", + "type": "Attributes", + "description": "Details about the configured destination bucket.", + "children": [ + { + "name": "access_key_id", + "type": "String", + "description": "ID of the Cloudflare API token used when writing objects to this\nbucket." + }, + { + "name": "account", + "type": "String" + }, + { + "name": "bucket", + "type": "String", + "description": "Name of the bucket on the provider." + }, + { + "name": "r2_bucket_sippy_provider", + "type": "String", + "description": "Available values: \"r2\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "State of Sippy for this bucket." + }, + { + "name": "source", + "type": "Attributes", + "description": "Details about the configured source bucket.", + "children": [ + { + "name": "bucket", + "type": "String", + "description": "Name of the bucket on the provider (AWS, GCS only)." + }, + { + "name": "bucket_url", + "type": "String", + "description": "S3-compatible URL (Generic S3-compatible providers only)." + }, + { + "name": "container", + "type": "String", + "description": "Name of the Azure Blob Storage container (Azure only)." + }, + { + "name": "r2_bucket_sippy_provider", + "type": "String", + "description": "Available values: \"aws\", \"gcs\", \"s3\", \"azure\"." + }, + { + "name": "region", + "type": "String", + "description": "Region where the bucket resides (AWS only)." + } + ] + } + ] + }, + "resource:cloudflare_r2_bucket_sippy": { + "kind": "resource", + "name": "cloudflare_r2_bucket_sippy", + "description": "Accepted Permissions\n\n- `Workers R2 Storage Write`", + "example": "resource \"cloudflare_r2_bucket_sippy\" \"example_r2_bucket_sippy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n destination = {\n access_key_id = \"accessKeyId\"\n cloud_provider = \"r2\"\n secret_access_key = \"secretAccessKey\"\n }\n source = {\n access_key_id = \"accessKeyId\"\n bucket = \"bucket\"\n cloud_provider = \"aws\"\n region = \"region\"\n secret_access_key = \"secretAccessKey\"\n }\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + } + ], + "optional": [ + { + "name": "destination", + "type": "Attributes", + "description": "R2 bucket to copy objects to.", + "children": [ + { + "name": "access_key_id", + "type": "String", + "description": "ID of a Cloudflare API token.\nThis is the value labelled \"Access Key ID\" when creating an API.\ntoken from the [R2 dashboard](https://dash.cloudflare.com/?to=/:account/r2/api-tokens).\n\nSippy will use this token when writing objects to R2, so it is\nbest to scope this token to the bucket you're enabling Sippy for." + }, + { + "name": "cloud_provider", + "type": "String", + "description": "Available values: \"r2\"." + }, + { + "name": "secret_access_key", + "type": "String", + "description": "Value of a Cloudflare API token.\nThis is the value labelled \"Secret Access Key\" when creating an API.\ntoken from the [R2 dashboard](https://dash.cloudflare.com/?to=/:account/r2/api-tokens).\n\nSippy will use this token when writing objects to R2, so it is\nbest to scope this token to the bucket you're enabling Sippy for.", + "sensitive": true + } + ] + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the bucket" + }, + { + "name": "source", + "type": "Attributes", + "description": "AWS S3 bucket to copy objects from.", + "children": [ + { + "name": "access_key_id", + "type": "String", + "description": "Access Key ID of an IAM credential (ideally scoped to a single S3 bucket)." + }, + { + "name": "account_key", + "type": "String", + "description": "Access key for the Azure Storage account. Mutually exclusive with sasToken.", + "sensitive": true + }, + { + "name": "account_name", + "type": "String", + "description": "Name of the Azure Storage account." + }, + { + "name": "bucket", + "type": "String", + "description": "Name of the AWS S3 bucket." + }, + { + "name": "bucket_url", + "type": "String", + "description": "URL to the S3-compatible API of the bucket." + }, + { + "name": "client_email", + "type": "String", + "description": "Client email of an IAM credential (ideally scoped to a single GCS bucket)." + }, + { + "name": "cloud_provider", + "type": "String", + "description": "Available values: \"aws\", \"gcs\", \"s3\", \"azure\"." + }, + { + "name": "container", + "type": "String", + "description": "Name of the Azure Blob Storage container." + }, + { + "name": "private_key", + "type": "String", + "description": "Private Key of an IAM credential (ideally scoped to a single GCS bucket).", + "sensitive": true + }, + { + "name": "region", + "type": "String", + "description": "AWS region containing the source S3 bucket." + }, + { + "name": "sas_token", + "type": "String", + "description": "Shared Access Signature token for the Azure Storage account. Mutually exclusive with accountKey.", + "sensitive": true + }, + { + "name": "secret_access_key", + "type": "String", + "description": "Secret Access Key of an IAM credential (ideally scoped to a single S3 bucket).", + "sensitive": true + } + ] + } + ], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "State of Sippy for this bucket." + } + ] + }, + "data-source:cloudflare_r2_custom_domain": { + "kind": "data-source", + "name": "cloudflare_r2_custom_domain", + "description": "Accepted Permissions\n\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`", + "example": "data \"cloudflare_r2_custom_domain\" \"example_r2_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n domain = \"example-domain/custom-domain.com\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + }, + { + "name": "domain", + "type": "String", + "description": "Name of the custom domain." + } + ], + "optional": [], + "computed": [ + { + "name": "ciphers", + "type": "List of String", + "description": "An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether this bucket is publicly accessible at the specified custom domain." + }, + { + "name": "min_tls", + "type": "String", + "description": "Minimum TLS Version the custom domain will accept for incoming connections. If not set, defaults to 1.0.\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\"." + }, + { + "name": "status", + "type": "Attributes", + "children": [ + { + "name": "ownership", + "type": "String", + "description": "Ownership status of the domain.\nAvailable values: \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\", \"unknown\"." + }, + { + "name": "ssl", + "type": "String", + "description": "SSL certificate status.\nAvailable values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"error\", \"unknown\"." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Zone ID of the custom domain resides in." + }, + { + "name": "zone_name", + "type": "String", + "description": "Zone that the custom domain resides in." + } + ] + }, + "resource:cloudflare_r2_custom_domain": { + "kind": "resource", + "name": "cloudflare_r2_custom_domain", + "description": "Accepted Permissions\n\n- `Workers R2 Storage Read`\n- `Workers R2 Storage Write`", + "example": "resource \"cloudflare_r2_custom_domain\" \"example_r2_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n domain = \"prefix.example-domain.com\"\n enabled = true\n zone_id = \"36ca64a6d92827b8a6b90be344bb1bfd\"\n ciphers = [\"string\"]\n min_tls = \"1.0\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + }, + { + "name": "domain", + "type": "String", + "description": "Name of the custom domain to be added." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable public bucket access at the custom domain. If undefined, the domain will be enabled." + }, + { + "name": "zone_id", + "type": "String", + "description": "Zone ID of the custom domain." + } + ], + "optional": [ + { + "name": "ciphers", + "type": "List of String", + "description": "An allowlist of ciphers for TLS termination. These ciphers must be in the BoringSSL format." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the bucket" + }, + { + "name": "min_tls", + "type": "String", + "description": "Minimum TLS Version the custom domain will accept for incoming connections. If not set, defaults to 1.0.\nAvailable values: \"1.0\", \"1.1\", \"1.2\", \"1.3\"." + } + ], + "computed": [ + { + "name": "status", + "type": "Attributes", + "children": [ + { + "name": "ownership", + "type": "String", + "description": "Ownership status of the domain.\nAvailable values: \"pending\", \"active\", \"deactivated\", \"blocked\", \"error\", \"unknown\"." + }, + { + "name": "ssl", + "type": "String", + "description": "SSL certificate status.\nAvailable values: \"initializing\", \"pending\", \"active\", \"deactivated\", \"error\", \"unknown\"." + } + ] + }, + { + "name": "zone_name", + "type": "String", + "description": "Zone that the custom domain resides in." + } + ] + }, + "data-source:cloudflare_r2_data_catalog": { + "kind": "data-source", + "name": "cloudflare_r2_data_catalog", + "description": "Accepted Permissions\n\n- `Workers R2 Data Catalog Read`\n- `Workers R2 Data Catalog Write`", + "example": "data \"cloudflare_r2_data_catalog\" \"example_r2_data_catalog\" {\n account_id = \"0123456789abcdef0123456789abcdef\"\n bucket_name = \"my-data-bucket\"\n}", + "required": [ + { + "name": "bucket_name", + "type": "String", + "description": "Specifies the R2 bucket name." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Use this to identify the account." + } + ], + "computed": [ + { + "name": "bucket", + "type": "String", + "description": "Specifies the associated R2 bucket name." + }, + { + "name": "credential_status", + "type": "String", + "description": "Shows the credential configuration status.\nAvailable values: \"present\", \"absent\"." + }, + { + "name": "id", + "type": "String", + "description": "Specifies the R2 bucket name." + }, + { + "name": "maintenance_config", + "type": "Attributes", + "description": "Configures maintenance for the catalog.", + "children": [ + { + "name": "compaction", + "type": "Attributes", + "description": "Configures compaction for catalog maintenance.", + "children": [ + { + "name": "state", + "type": "String", + "description": "Specifies the state of maintenance operations.\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "target_size_mb", + "type": "String", + "description": "Sets the target file size for compaction in megabytes. Defaults to \"128\".\nAvailable values: \"64\", \"128\", \"256\", \"512\"." + } + ] + }, + { + "name": "interval", + "type": "String", + "description": "Scheduling interval between normal table maintenance runs." + }, + { + "name": "snapshot_expiration", + "type": "Attributes", + "description": "Configures snapshot expiration settings.", + "children": [ + { + "name": "max_snapshot_age", + "type": "String", + "description": "Specifies the maximum age for snapshots. The system deletes snapshots older than this age.\nFormat: where unit is d (days), h (hours), m (minutes), or s (seconds).\nExamples: \"7d\" (7 days), \"48h\" (48 hours), \"2880m\" (2,880 minutes).\nDefaults to \"7d\"." + }, + { + "name": "min_snapshots_to_keep", + "type": "Number", + "description": "Specifies the minimum number of snapshots to retain. Defaults to 100." + }, + { + "name": "state", + "type": "String", + "description": "Specifies the state of maintenance operations.\nAvailable values: \"enabled\", \"disabled\"." + } + ] + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Specifies the catalog name (generated from account and bucket name)." + }, + { + "name": "status", + "type": "String", + "description": "Indicates the status of the catalog.\nAvailable values: \"active\", \"inactive\"." + } + ] + }, + "resource:cloudflare_r2_data_catalog": { + "kind": "resource", + "name": "cloudflare_r2_data_catalog", + "description": "Accepted Permissions\n\n- `Workers R2 Data Catalog Read`\n- `Workers R2 Data Catalog Write`", + "example": "resource \"cloudflare_r2_data_catalog\" \"example_r2_data_catalog\" {\n account_id = \"0123456789abcdef0123456789abcdef\"\n bucket_name = \"my-data-bucket\"\n}", + "importExample": "$ terraform import cloudflare_r2_data_catalog.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Use this to identify the account." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Specifies the R2 bucket name." + } + ], + "optional": [], + "computed": [ + { + "name": "bucket", + "type": "String", + "description": "Specifies the associated R2 bucket name." + }, + { + "name": "credential_status", + "type": "String", + "description": "Shows the credential configuration status.\nAvailable values: \"present\", \"absent\"." + }, + { + "name": "id", + "type": "String", + "description": "Use this to uniquely identify the activated catalog." + }, + { + "name": "maintenance_config", + "type": "Attributes", + "description": "Configures maintenance for the catalog.", + "children": [ + { + "name": "compaction", + "type": "Attributes", + "description": "Configures compaction for catalog maintenance.", + "children": [ + { + "name": "state", + "type": "String", + "description": "Specifies the state of maintenance operations.\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "target_size_mb", + "type": "String", + "description": "Sets the target file size for compaction in megabytes. Defaults to \"128\".\nAvailable values: \"64\", \"128\", \"256\", \"512\"." + } + ] + }, + { + "name": "interval", + "type": "String", + "description": "Scheduling interval between normal table maintenance runs." + }, + { + "name": "snapshot_expiration", + "type": "Attributes", + "description": "Configures snapshot expiration settings.", + "children": [ + { + "name": "max_snapshot_age", + "type": "String", + "description": "Specifies the maximum age for snapshots. The system deletes snapshots older than this age.\nFormat: where unit is d (days), h (hours), m (minutes), or s (seconds).\nExamples: \"7d\" (7 days), \"48h\" (48 hours), \"2880m\" (2,880 minutes).\nDefaults to \"7d\"." + }, + { + "name": "min_snapshots_to_keep", + "type": "Number", + "description": "Specifies the minimum number of snapshots to retain. Defaults to 100." + }, + { + "name": "state", + "type": "String", + "description": "Specifies the state of maintenance operations.\nAvailable values: \"enabled\", \"disabled\"." + } + ] + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Specifies the catalog name (generated from account and bucket name)." + }, + { + "name": "status", + "type": "String", + "description": "Indicates the status of the catalog.\nAvailable values: \"active\", \"inactive\"." + } + ] + }, + "resource:cloudflare_r2_managed_domain": { + "kind": "resource", + "name": "cloudflare_r2_managed_domain", + "example": "resource \"cloudflare_r2_managed_domain\" \"example_r2_managed_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n bucket_name = \"example-bucket\"\n enabled = true\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID that owns the R2 resource." + }, + { + "name": "bucket_name", + "type": "String", + "description": "Name of the bucket." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable public bucket access at the r2.dev domain." + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Jurisdiction of the bucket" + } + ], + "computed": [ + { + "name": "bucket_id", + "type": "String", + "description": "Bucket ID." + }, + { + "name": "domain", + "type": "String", + "description": "Domain name of the bucket's r2.dev domain." + } + ] + }, + "data-source:cloudflare_rate_limit": { + "kind": "data-source", + "name": "cloudflare_rate_limit", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_rate_limit\" \"example_rate_limit\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rate_limit_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}", + "required": [ + { + "name": "rate_limit_id", + "type": "String", + "description": "Defines the unique identifier of the rate limit." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "action", + "type": "Attributes", + "description": "The action to perform when the threshold of matched traffic within the configured period is exceeded.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The action to perform.\nAvailable values: \"simulate\", \"ban\", \"challenge\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "response", + "type": "Attributes", + "description": "A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional.\nNotes: If you omit this object, Cloudflare will use the default HTML error page. If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone challenge pages and you should not provide the \"response\" object.", + "children": [ + { + "name": "body", + "type": "String", + "description": "The response body to return. The value must conform to the configured content type." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type of the body. Must be one of the following: `text/plain`, `text/xml`, or `application/json`." + } + ] + }, + { + "name": "timeout", + "type": "Number", + "description": "The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period.\nNotes: If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone's Challenge Passage time and you should not provide this value." + } + ] + }, + { + "name": "bypass", + "type": "Attributes List", + "description": "Criteria specifying when the current rate limit should be bypassed. You can specify that the rate limit should not apply to one or more URLs.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Available values: \"url\"." + }, + { + "name": "value", + "type": "String", + "description": "The URL to bypass." + } + ] + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the rule. This value is sanitized and any tags will be removed." + }, + { + "name": "disabled", + "type": "Boolean", + "description": "When true, indicates that the rate limit is currently disabled." + }, + { + "name": "id", + "type": "String", + "description": "Defines the unique identifier of the rate limit." + }, + { + "name": "match", + "type": "Attributes", + "description": "Determines which traffic the rate limit counts towards the threshold.", + "children": [ + { + "name": "headers", + "type": "Attributes List", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the response header to match." + }, + { + "name": "op", + "type": "String", + "description": "The operator used when matching: `eq` means \"equal\" and `ne` means \"not equal\".\nAvailable values: \"eq\", \"ne\"." + }, + { + "name": "value", + "type": "String", + "description": "The value of the response header, which must match exactly." + } + ] + }, + { + "name": "request", + "type": "Attributes", + "children": [ + { + "name": "methods", + "type": "List of String", + "description": "The HTTP methods to match. You can specify a subset (for example, `['POST','PUT']`) or all methods (`['_ALL_']`). This field is optional when creating a rate limit." + }, + { + "name": "schemes", + "type": "List of String", + "description": "The HTTP schemes to match. You can specify one scheme (`['HTTPS']`), both schemes (`['HTTP','HTTPS']`), or all schemes (`['_ALL_']`). This field is optional." + }, + { + "name": "url", + "type": "String", + "description": "The URL pattern to match, composed of a host and a path such as `example.org/path*`. Normalization is applied before the pattern is matched. `*` wildcards are expanded to match applicable traffic. Query strings are not matched. Set the value to `*` to match all traffic to your zone." + } + ] + }, + { + "name": "response", + "type": "Attributes", + "children": [ + { + "name": "origin_traffic", + "type": "Boolean", + "description": "When true, only the uncached traffic served from your origin servers will count towards rate limiting. In this case, any cached traffic served by Cloudflare will not count towards rate limiting. This field is optional.\nNotes: This field is deprecated. Instead, use response headers and set \"origin_traffic\" to \"false\" to avoid legacy behaviour interacting with the \"response_headers\" property." + } + ] + } + ] + }, + { + "name": "period", + "type": "Number", + "description": "The time in seconds (an integer value) to count matching traffic. If the count exceeds the configured threshold within this period, Cloudflare will perform the configured action." + }, + { + "name": "threshold", + "type": "Number", + "description": "The threshold that will trigger the configured mitigation action. Configure this value along with the `period` property to establish a threshold per period." + } + ] + }, + "resource:cloudflare_rate_limit": { + "kind": "resource", + "name": "cloudflare_rate_limit", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`\n\n~> `cloudflare_rate_limit` is in a deprecation phase until June 15th, 2025.\n During this time period, this resource is still\n fully supported but you are strongly advised to move to the\n `cloudflare_ruleset` resource. Full details can be found in the\n [developer documentation](https://developers.cloudflare.com/waf/reference/migration-guides/old-rate-limiting-deprecation/#relevant-changes-for-terraform-users).", + "example": "resource \"cloudflare_rate_limit\" \"example_rate_limit\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = {\n mode = \"challenge\"\n response = {\n body = \"This request has been rate-limited.\"\n content_type = \"text/xml\"\n }\n timeout = 86400\n }\n match = {\n headers = [{\n name = \"Cf-Cache-Status\"\n op = \"ne\"\n value = \"HIT\"\n }]\n request = {\n methods = [\"GET\", \"POST\"]\n schemes = [\"HTTP\", \"HTTPS\"]\n url = \"*.example.org/path*\"\n }\n response = {\n origin_traffic = true\n }\n }\n period = 900\n threshold = 60\n}", + "importExample": "$ terraform import cloudflare_rate_limit.example '/'", + "required": [ + { + "name": "action", + "type": "Attributes", + "description": "The action to perform when the threshold of matched traffic within the configured period is exceeded.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The action to perform.\nAvailable values: \"simulate\", \"ban\", \"challenge\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "response", + "type": "Attributes", + "description": "A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional.\nNotes: If you omit this object, Cloudflare will use the default HTML error page. If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone challenge pages and you should not provide the \"response\" object.", + "children": [ + { + "name": "body", + "type": "String", + "description": "The response body to return. The value must conform to the configured content type." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type of the body. Must be one of the following: `text/plain`, `text/xml`, or `application/json`." + } + ] + }, + { + "name": "timeout", + "type": "Number", + "description": "The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period.\nNotes: If \"mode\" is \"challenge\", \"managed_challenge\", or \"js_challenge\", Cloudflare will use the zone's Challenge Passage time and you should not provide this value." + } + ] + }, + { + "name": "match", + "type": "Attributes", + "description": "Determines which traffic the rate limit counts towards the threshold.", + "children": [ + { + "name": "headers", + "type": "Attributes List", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the response header to match." + }, + { + "name": "op", + "type": "String", + "description": "The operator used when matching: `eq` means \"equal\" and `ne` means \"not equal\".\nAvailable values: \"eq\", \"ne\"." + }, + { + "name": "value", + "type": "String", + "description": "The value of the response header, which must match exactly." + } + ] + }, + { + "name": "request", + "type": "Attributes", + "children": [ + { + "name": "methods", + "type": "List of String", + "description": "The HTTP methods to match. You can specify a subset (for example, `['POST','PUT']`) or all methods (`['_ALL_']`). This field is optional when creating a rate limit." + }, + { + "name": "schemes", + "type": "List of String", + "description": "The HTTP schemes to match. You can specify one scheme (`['HTTPS']`), both schemes (`['HTTP','HTTPS']`), or all schemes (`['_ALL_']`). This field is optional." + }, + { + "name": "url", + "type": "String", + "description": "The URL pattern to match, composed of a host and a path such as `example.org/path*`. Normalization is applied before the pattern is matched. `*` wildcards are expanded to match applicable traffic. Query strings are not matched. Set the value to `*` to match all traffic to your zone." + } + ] + }, + { + "name": "response", + "type": "Attributes", + "children": [ + { + "name": "origin_traffic", + "type": "Boolean", + "description": "When true, only the uncached traffic served from your origin servers will count towards rate limiting. In this case, any cached traffic served by Cloudflare will not count towards rate limiting. This field is optional.\nNotes: This field is deprecated. Instead, use response headers and set \"origin_traffic\" to \"false\" to avoid legacy behaviour interacting with the \"response_headers\" property." + } + ] + } + ] + }, + { + "name": "period", + "type": "Number", + "description": "The time in seconds (an integer value) to count matching traffic. If the count exceeds the configured threshold within this period, Cloudflare will perform the configured action." + }, + { + "name": "threshold", + "type": "Number", + "description": "The threshold that will trigger the configured mitigation action. Configure this value along with the `period` property to establish a threshold per period." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [ + { + "name": "rate_limit_id", + "type": "String", + "description": "Defines the unique identifier of the rate limit." + } + ], + "computed": [] + }, + "data-source:cloudflare_regional_hostname": { + "kind": "data-source", + "name": "cloudflare_regional_hostname", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "data \"cloudflare_regional_hostname\" \"example_regional_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"foo.example.com\"\n}", + "required": [ + { + "name": "hostname", + "type": "String", + "description": "DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the regional hostname was created" + }, + { + "name": "id", + "type": "String", + "description": "DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`" + }, + { + "name": "region_key", + "type": "String", + "description": "Identifying key for the region" + }, + { + "name": "routing", + "type": "String", + "description": "Configure which routing method to use for the regional hostname" + } + ] + }, + "resource:cloudflare_regional_hostname": { + "kind": "resource", + "name": "cloudflare_regional_hostname", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "resource \"cloudflare_regional_hostname\" \"example_regional_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"foo.example.com\"\n region_key = \"ca\"\n routing = \"dns\"\n}", + "importExample": "$ terraform import cloudflare_regional_hostname.example '/'", + "required": [ + { + "name": "hostname", + "type": "String", + "description": "DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`" + }, + { + "name": "region_key", + "type": "String", + "description": "Identifying key for the region" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "routing", + "type": "String", + "description": "Configure which routing method to use for the regional hostname" + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the regional hostname was created" + }, + { + "name": "id", + "type": "String", + "description": "DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`" + } + ] + }, + "list-data-source:cloudflare_regional_hostnames": { + "kind": "list-data-source", + "name": "cloudflare_regional_hostnames", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "data \"cloudflare_regional_hostnames\" \"example_regional_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "When the regional hostname was created" + }, + { + "name": "hostname", + "type": "String", + "description": "DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`" + }, + { + "name": "id", + "type": "String", + "description": "DNS hostname to be regionalized, must be a subdomain of the zone. Wildcards are supported for one level, e.g `*.example.com`" + }, + { + "name": "region_key", + "type": "String", + "description": "Identifying key for the region" + }, + { + "name": "routing", + "type": "String", + "description": "Configure which routing method to use for the regional hostname" + } + ] + } + ] + }, + "data-source:cloudflare_regional_tiered_cache": { + "kind": "data-source", + "name": "cloudflare_regional_tiered_cache", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_regional_tiered_cache\" \"example_regional_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + }, + { + "name": "value", + "type": "String", + "description": "Value of the Regional Tiered Cache zone setting.\nAvailable values: \"on\", \"off\"." + } + ] + }, + "resource:cloudflare_regional_tiered_cache": { + "kind": "resource", + "name": "cloudflare_regional_tiered_cache", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_regional_tiered_cache\" \"example_regional_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}", + "importExample": "$ terraform import cloudflare_regional_tiered_cache.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "value", + "type": "String", + "description": "Value of the Regional Tiered Cache zone setting.\nAvailable values: \"on\", \"off\"." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "data-source:cloudflare_registrar_domain": { + "kind": "data-source", + "name": "cloudflare_registrar_domain", + "example": "data \"cloudflare_registrar_domain\" \"example_registrar_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_name = \"example.com\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "domain_name", + "type": "String", + "description": "Provides a fully qualified domain name (FQDN), including the extension\n(e.g., `example.com`, `mybrand.app`). The domain name uniquely identifies\na registration. Cloudflare permits only one registration per domain, making\nthe domain name a natural idempotency key for registration requests." + } + ], + "optional": [], + "computed": [] + }, + "resource:cloudflare_registrar_domain": { + "kind": "resource", + "name": "cloudflare_registrar_domain", + "example": "resource \"cloudflare_registrar_domain\" \"example_registrar_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_name = \"example.com\"\n auto_renew = true\n locked = false\n privacy = true\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "domain_name", + "type": "String", + "description": "Provides a fully qualified domain name (FQDN), including the extension\n(e.g., `example.com`, `mybrand.app`). The domain name uniquely identifies\na registration. Cloudflare permits only one registration per domain, making\nthe domain name a natural idempotency key for registration requests." + } + ], + "optional": [ + { + "name": "auto_renew", + "type": "Boolean", + "description": "Auto-renew controls whether subscription is automatically renewed upon domain expiration." + }, + { + "name": "locked", + "type": "Boolean", + "description": "Shows whether a registrar lock is in place for a domain." + }, + { + "name": "privacy", + "type": "Boolean", + "description": "Privacy option controls redacting WHOIS information." + } + ], + "computed": [] + }, + "list-data-source:cloudflare_registrar_domains": { + "kind": "list-data-source", + "name": "cloudflare_registrar_domains", + "example": "data \"cloudflare_registrar_domains\" \"example_registrar_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "available", + "type": "Boolean", + "description": "Shows if a domain is available for transferring into Cloudflare Registrar." + }, + { + "name": "can_register", + "type": "Boolean", + "description": "Indicates eligibility to register the domain as a new domain." + }, + { + "name": "created_at", + "type": "String", + "description": "Shows time of creation." + }, + { + "name": "current_registrar", + "type": "String", + "description": "Shows name of current registrar." + }, + { + "name": "expires_at", + "type": "String", + "description": "Shows when domain name registration expires." + }, + { + "name": "id", + "type": "String", + "description": "Domain identifier." + }, + { + "name": "locked", + "type": "Boolean", + "description": "Shows whether a registrar lock is in place for a domain." + }, + { + "name": "registrant_contact", + "type": "Attributes", + "description": "Shows contact information for domain registrant.", + "children": [ + { + "name": "address", + "type": "String", + "description": "Address." + }, + { + "name": "address2", + "type": "String", + "description": "Optional address line for unit, floor, suite, etc." + }, + { + "name": "city", + "type": "String", + "description": "City." + }, + { + "name": "country", + "type": "String", + "description": "The country in which the user lives." + }, + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "fax", + "type": "String", + "description": "Contact fax number." + }, + { + "name": "first_name", + "type": "String", + "description": "User's first name." + }, + { + "name": "id", + "type": "String", + "description": "Contact Identifier." + }, + { + "name": "last_name", + "type": "String", + "description": "User's last name." + }, + { + "name": "organization", + "type": "String", + "description": "Name of organization." + }, + { + "name": "phone", + "type": "String", + "description": "User's telephone number." + }, + { + "name": "state", + "type": "String", + "description": "State." + }, + { + "name": "zip", + "type": "String", + "description": "The zipcode or postal code where the user lives." + } + ] + }, + { + "name": "registry_statuses", + "type": "String", + "description": "A comma-separated list of registry status codes. Refer to [EPP Status Codes](https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en) for the full list." + }, + { + "name": "supported_tld", + "type": "Boolean", + "description": "Indicates whether Cloudflare Registrar currently supports a particular TLD. Refer to [TLD Policies](https://www.cloudflare.com/tld-policies/) for a list of supported TLDs." + }, + { + "name": "transfer_in", + "type": "Attributes", + "description": "Statuses for domain transfers into Cloudflare Registrar.", + "children": [ + { + "name": "accept_foa", + "type": "String", + "description": "Status of the registrant authorization step.\nAvailable values: \"needed\", \"ok\"." + }, + { + "name": "approve_transfer", + "type": "String", + "description": "Status of the registry transfer-approval step.\nAvailable values: \"needed\", \"ok\", \"pending\", \"trying\", \"rejected\", \"unknown\"." + }, + { + "name": "can_cancel_transfer", + "type": "Boolean", + "description": "Indicates if cancellation is still possible." + }, + { + "name": "disable_privacy", + "type": "String", + "description": "Status of the privacy-guard disabling step at the foreign registrar.\nAvailable values: \"needed\", \"ok\", \"unknown\"." + }, + { + "name": "enter_auth_code", + "type": "String", + "description": "Status of the auth-code entry and verification step.\nAvailable values: \"needed\", \"ok\", \"pending\", \"trying\", \"rejected\"." + }, + { + "name": "unlock_domain", + "type": "String", + "description": "Status of the domain-unlock step at the foreign registrar.\nAvailable values: \"needed\", \"ok\", \"pending\", \"trying\", \"unknown\"." + } + ] + }, + { + "name": "updated_at", + "type": "String", + "description": "Last updated." + } + ] + } + ] + }, + "data-source:cloudflare_resource_group": { + "kind": "data-source", + "name": "cloudflare_resource_group", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_resource_group\" \"example_resource_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "resource_group_id", + "type": "String", + "description": "Resource Group identifier tag." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the resource group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the resource group.", + "children": [ + { + "name": "key", + "type": "String" + }, + { + "name": "value", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the resource group." + }, + { + "name": "scope", + "type": "Attributes List", + "description": "The scope associated to the resource group", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Account ID etc.)" + }, + { + "name": "objects", + "type": "Attributes List", + "description": "A list of scope objects for additional context.", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Zone ID etc.)" + } + ] + } + ] + } + ] + }, + "list-data-source:cloudflare_resource_groups": { + "kind": "list-data-source", + "name": "cloudflare_resource_groups", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_resource_groups\" \"example_resource_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"NameOfTheResourceGroup\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "id", + "type": "String", + "description": "ID of the resource group to be fetched." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Name of the resource group to be fetched." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the resource group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the resource group.", + "children": [ + { + "name": "key", + "type": "String" + }, + { + "name": "value", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the resource group." + }, + { + "name": "scope", + "type": "Attributes List", + "description": "The scope associated to the resource group", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Account ID etc.)" + }, + { + "name": "objects", + "type": "Attributes List", + "description": "A list of scope objects for additional context.", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Zone ID etc.)" + } + ] + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_ruleset": { + "kind": "data-source", + "name": "cloudflare_ruleset", + "example": "data \"cloudflare_ruleset\" \"example_ruleset\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n id = \"2f2feab2026849078ba485f918791bdc\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The unique ID of the account." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the ruleset." + }, + { + "name": "ruleset_id", + "type": "String", + "description": "The unique ID of the ruleset.", + "deprecated": "Deprecated." + }, + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "computed": [ + { + "name": "description", + "type": "String", + "description": "An informative description of the ruleset." + }, + { + "name": "kind", + "type": "String", + "description": "The kind of the ruleset.\nAvailable values: \"managed\", \"custom\", \"root\", \"zone\"." + }, + { + "name": "last_updated", + "type": "String", + "description": "The timestamp of when the ruleset was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The human-readable name of the ruleset." + }, + { + "name": "phase", + "type": "String", + "description": "The phase of the ruleset.\nAvailable values: \"ddos_l4\", \"ddos_l7\", \"http_config_settings\", \"http_custom_errors\", \"http_log_custom_fields\", \"http_ratelimit\", \"http_request_cache_settings\", \"http_request_dynamic_redirect\", \"http_request_firewall_custom\", \"http_request_firewall_managed\", \"http_request_late_transform\", \"http_request_origin\", \"http_request_redirect\", \"http_request_sanitize\", \"http_request_sbfm\", \"http_request_transform\", \"http_response_cache_settings\", \"http_response_compression\", \"http_response_firewall_managed\", \"http_response_headers_transform\", \"magic_transit\", \"magic_transit_ids_managed\", \"magic_transit_managed\", \"magic_transit_ratelimit\"." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "The list of rules in the ruleset.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to perform when the rule matches.\nAvailable values: \"block\", \"challenge\", \"compress_response\", \"ddos_dynamic\", \"execute\", \"force_connection_close\", \"js_challenge\", \"log\", \"log_custom_field\", \"managed_challenge\", \"redirect\", \"rewrite\", \"route\", \"score\", \"serve_error\", \"set_cache_control\", \"set_cache_settings\", \"set_cache_tags\", \"set_config\", \"skip\"." + }, + { + "name": "action_parameters", + "type": "Attributes", + "description": "The parameters configuring the rule's action.", + "children": [ + { + "name": "additional_cacheable_ports", + "type": "List of Number", + "description": "A list of additional ports that caching should be enabled on." + }, + { + "name": "algorithms", + "type": "Attributes List", + "description": "Custom order for compression algorithms.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the compression algorithm to enable.\nAvailable values: \"none\", \"auto\", \"default\", \"gzip\", \"brotli\", \"zstd\"." + } + ] + }, + { + "name": "asset_name", + "type": "String", + "description": "The name of a custom asset to serve as the response." + }, + { + "name": "automatic_https_rewrites", + "type": "Boolean", + "description": "Whether to enable Automatic HTTPS Rewrites." + }, + { + "name": "autominify", + "type": "Attributes", + "description": "Which file extensions to minify automatically.", + "children": [ + { + "name": "css", + "type": "Boolean", + "description": "Whether to minify CSS files." + }, + { + "name": "html", + "type": "Boolean", + "description": "Whether to minify HTML files." + }, + { + "name": "js", + "type": "Boolean", + "description": "Whether to minify JavaScript files." + } + ] + }, + { + "name": "bic", + "type": "Boolean", + "description": "Whether to enable Browser Integrity Check (BIC)." + }, + { + "name": "browser_ttl", + "type": "Attributes", + "description": "How long client browsers should cache the response. Cloudflare cache purge will not purge content cached on client browsers, so high browser TTLs may lead to stale content.", + "children": [ + { + "name": "default", + "type": "Number", + "description": "The browser TTL (in seconds) if you choose the \"override_origin\" mode." + }, + { + "name": "mode", + "type": "String", + "description": "The browser TTL mode.\nAvailable values: \"respect_origin\", \"bypass_by_default\", \"override_origin\", \"bypass\"." + } + ] + }, + { + "name": "cache", + "type": "Boolean", + "description": "Whether the request's response from the origin is eligible for caching. Caching itself will still depend on the cache control header and your other caching configurations." + }, + { + "name": "cache_key", + "type": "Attributes", + "description": "Which components of the request are included in or excluded from the cache key Cloudflare uses to store the response in cache.", + "children": [ + { + "name": "cache_by_device_type", + "type": "Boolean", + "description": "Whether to separate cached content based on the visitor's device type." + }, + { + "name": "cache_deception_armor", + "type": "Boolean", + "description": "Whether to protect from web cache deception attacks, while allowing static assets to be cached." + }, + { + "name": "custom_key", + "type": "Attributes", + "description": "Which components of the request are included or excluded from the cache key.", + "children": [ + { + "name": "cookie", + "type": "Attributes", + "description": "Which cookies to include in the cache key.", + "children": [ + { + "name": "check_presence", + "type": "List of String", + "description": "A list of cookies to check for the presence of. The presence of these cookies is included in the cache key." + }, + { + "name": "include", + "type": "List of String", + "description": "A list of cookies to include in the cache key." + } + ] + }, + { + "name": "header", + "type": "Attributes", + "description": "Which headers to include in the cache key.", + "children": [ + { + "name": "check_presence", + "type": "List of String", + "description": "A list of headers to check for the presence of. The presence of these headers is included in the cache key." + }, + { + "name": "contains", + "type": "Map of List of String", + "description": "A mapping of header names to a list of values. If a header is present in the request and contains any of the values provided, its value is included in the cache key." + }, + { + "name": "exclude_origin", + "type": "Boolean", + "description": "Whether to exclude the origin header in the cache key." + }, + { + "name": "include", + "type": "List of String", + "description": "A list of headers to include in the cache key." + } + ] + }, + { + "name": "host", + "type": "Attributes", + "description": "How to use the host in the cache key.", + "children": [ + { + "name": "resolved", + "type": "Boolean", + "description": "Whether to use the resolved host in the cache key." + } + ] + }, + { + "name": "query_string", + "type": "Attributes", + "description": "Which query string parameters to include in or exclude from the cache key.", + "children": [ + { + "name": "exclude", + "type": "Attributes", + "description": "Which query string parameters to exclude from the cache key.", + "children": [ + { + "name": "all", + "type": "Boolean", + "description": "Whether to exclude all query string parameters from the cache key." + }, + { + "name": "list", + "type": "List of String", + "description": "A list of query string parameters to exclude from the cache key." + } + ] + }, + { + "name": "include", + "type": "Attributes", + "description": "Which query string parameters to include in the cache key.", + "children": [ + { + "name": "all", + "type": "Boolean", + "description": "Whether to include all query string parameters in the cache key." + }, + { + "name": "list", + "type": "List of String", + "description": "A list of query string parameters to include in the cache key." + } + ] + } + ] + }, + { + "name": "user", + "type": "Attributes", + "description": "How to use characteristics of the request user agent in the cache key.", + "children": [ + { + "name": "device_type", + "type": "Boolean", + "description": "Whether to use the user agent's device type in the cache key." + }, + { + "name": "geo", + "type": "Boolean", + "description": "Whether to use the user agents's country in the cache key." + }, + { + "name": "lang", + "type": "Boolean", + "description": "Whether to use the user agent's language in the cache key." + } + ] + } + ] + }, + { + "name": "ignore_query_strings_order", + "type": "Boolean", + "description": "Whether to treat requests with the same query parameters the same, regardless of the order those query parameters are in." + } + ] + }, + { + "name": "cache_reserve", + "type": "Attributes", + "description": "Settings to determine whether the request's response from origin is eligible for Cache Reserve (requires a Cache Reserve add-on plan).", + "children": [ + { + "name": "eligible", + "type": "Boolean", + "description": "Whether Cache Reserve is enabled. If this is true and a request meets eligibility criteria, Cloudflare will write the resource to Cache Reserve." + }, + { + "name": "minimum_file_size", + "type": "Number", + "description": "The minimum file size eligible for storage in Cache Reserve." + } + ] + }, + { + "name": "content", + "type": "String", + "description": "The response content." + }, + { + "name": "content_converter", + "type": "Boolean", + "description": "Whether to enable content conversion (e.g., HTML to Markdown)." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type header to set with the error response.\nAvailable values: \"application/json\", \"text/html\", \"text/plain\", \"text/xml\"." + }, + { + "name": "cookie_fields", + "type": "Attributes List", + "description": "The cookie fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the cookie." + } + ] + }, + { + "name": "disable_apps", + "type": "Boolean", + "description": "Whether to disable Cloudflare Apps." + }, + { + "name": "disable_rum", + "type": "Boolean", + "description": "Whether to disable Real User Monitoring (RUM)." + }, + { + "name": "disable_zaraz", + "type": "Boolean", + "description": "Whether to disable Zaraz." + }, + { + "name": "edge_ttl", + "type": "Attributes", + "description": "How long the Cloudflare edge network should cache the response.", + "children": [ + { + "name": "default", + "type": "Number", + "description": "The edge TTL (in seconds) if you choose the \"override_origin\" mode." + }, + { + "name": "mode", + "type": "String", + "description": "The edge TTL mode.\nAvailable values: \"respect_origin\", \"bypass_by_default\", \"override_origin\"." + }, + { + "name": "status_code_ttl", + "type": "Attributes List", + "description": "A list of TTLs to apply to specific status codes or status code ranges.", + "children": [ + { + "name": "status_code", + "type": "Number", + "description": "A single status code to apply the TTL to." + }, + { + "name": "status_code_range", + "type": "Attributes", + "description": "A range of status codes to apply the TTL to.", + "children": [ + { + "name": "from", + "type": "Number", + "description": "The lower bound of the range." + }, + { + "name": "to", + "type": "Number", + "description": "The upper bound of the range." + } + ] + }, + { + "name": "value", + "type": "Number", + "description": "The time to cache the response for (in seconds). A value of 0 is equivalent to setting the cache control header with the value \"no-cache\". A value of -1 is equivalent to setting the cache control header with the value of \"no-store\"." + } + ] + } + ] + }, + { + "name": "email_obfuscation", + "type": "Boolean", + "description": "Whether to enable Email Obfuscation." + }, + { + "name": "expression", + "type": "String", + "description": "An expression to generate cache tags for set_cache_tags action." + }, + { + "name": "fonts", + "type": "Boolean", + "description": "Whether to enable Cloudflare Fonts." + }, + { + "name": "from_list", + "type": "Attributes", + "description": "A redirect based on a bulk list lookup.", + "children": [ + { + "name": "key", + "type": "String", + "description": "An expression that evaluates to the list lookup key." + }, + { + "name": "name", + "type": "String", + "description": "The name of the list to match against." + } + ] + }, + { + "name": "from_value", + "type": "Attributes", + "description": "A redirect based on the request properties.", + "children": [ + { + "name": "preserve_query_string", + "type": "Boolean", + "description": "Whether to keep the query string of the original request." + }, + { + "name": "status_code", + "type": "Number", + "description": "The status code to use for the redirect." + }, + { + "name": "target_url", + "type": "Attributes", + "description": "A URL to redirect the request to.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a URL to redirect the request to." + }, + { + "name": "value", + "type": "String", + "description": "A URL to redirect the request to." + } + ] + } + ] + }, + { + "name": "headers", + "type": "Attributes Map", + "description": "A map of headers to rewrite.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a value for the header." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform on the header.\nAvailable values: \"add\", \"set\", \"remove\"." + }, + { + "name": "value", + "type": "String", + "description": "A static value for the header." + } + ] + }, + { + "name": "host_header", + "type": "String", + "description": "A value to rewrite the HTTP host header to." + }, + { + "name": "hotlink_protection", + "type": "Boolean", + "description": "Whether to enable Hotlink Protection." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the ruleset to execute." + }, + { + "name": "immutable", + "type": "Attributes", + "description": "Set the immutable cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "increment", + "type": "Number", + "description": "A delta to change the score by, which can be either positive or negative." + }, + { + "name": "matched_data", + "type": "Attributes", + "description": "The configuration to use for matched data logging.", + "children": [ + { + "name": "public_key", + "type": "String", + "description": "The public key to encrypt matched data logs with." + } + ] + }, + { + "name": "max_age", + "type": "Attributes", + "description": "Set the max-age cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "mirage", + "type": "Boolean", + "description": "Whether to enable Mirage." + }, + { + "name": "must_revalidate", + "type": "Attributes", + "description": "Set the must-revalidate cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "must_understand", + "type": "Attributes", + "description": "Set the must-understand cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "no_cache", + "type": "Attributes", + "description": "Set the no-cache cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "qualifiers", + "type": "List of String", + "description": "The qualifiers for the directive." + } + ] + }, + { + "name": "no_store", + "type": "Attributes", + "description": "Set the no-store cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "no_transform", + "type": "Attributes", + "description": "Set the no-transform cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform for set_cache_tags action.\nAvailable values: \"set\", \"add\", \"remove\"." + }, + { + "name": "opportunistic_encryption", + "type": "Boolean", + "description": "Whether to enable Opportunistic Encryption." + }, + { + "name": "origin", + "type": "Attributes", + "description": "An origin to route to.", + "children": [ + { + "name": "host", + "type": "String", + "description": "A resolved host to route to." + }, + { + "name": "port", + "type": "Number", + "description": "A destination port to route to." + } + ] + }, + { + "name": "origin_cache_control", + "type": "Boolean", + "description": "Whether Cloudflare will aim to strictly adhere to RFC 7234." + }, + { + "name": "origin_error_page_passthru", + "type": "Boolean", + "description": "Whether to generate Cloudflare error pages for issues from the origin server." + }, + { + "name": "origin_range_requests", + "type": "Attributes", + "description": "Controls whether Cloudflare fetches a large asset from the origin as a series of range requests instead of one whole-body request.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Whether to use range requests. `default` is the behaviour the zone gets without this rule.\nAvailable values: \"on\", \"off\", \"default\"." + } + ] + }, + { + "name": "overrides", + "type": "Attributes", + "description": "A set of overrides to apply to the target ruleset.", + "children": [ + { + "name": "action", + "type": "String", + "description": "An action to override all rules with. This option has lower precedence than rule and category overrides." + }, + { + "name": "categories", + "type": "Attributes List", + "description": "A list of category-level overrides. This option has the second-highest precedence after rule-level overrides.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to override rules in the category with." + }, + { + "name": "category", + "type": "String", + "description": "The name of the category to override." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable execution of rules in the category." + }, + { + "name": "sensitivity_level", + "type": "String", + "description": "The sensitivity level to use for rules in the category. This option is only applicable for DDoS phases.\nAvailable values: \"default\", \"medium\", \"low\", \"eoff\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable execution of all rules. This option has lower precedence than rule and category overrides." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "A list of rule-level overrides. This option has the highest precedence.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to override the rule with." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable execution of the rule." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the rule to override." + }, + { + "name": "score_threshold", + "type": "Number", + "description": "The score threshold to use for the rule." + }, + { + "name": "sensitivity_level", + "type": "String", + "description": "The sensitivity level to use for the rule. This option is only applicable for DDoS phases.\nAvailable values: \"default\", \"medium\", \"low\", \"eoff\"." + } + ] + }, + { + "name": "sensitivity_level", + "type": "String", + "description": "A sensitivity level to set for all rules. This option has lower precedence than rule and category overrides and is only applicable for DDoS phases.\nAvailable values: \"default\", \"medium\", \"low\", \"eoff\"." + } + ] + }, + { + "name": "phases", + "type": "List of String", + "description": "A list of phases to skip the execution of. This option is incompatible with the rulesets option.\nAvailable values: \"ddos_l4\", \"ddos_l7\", \"http_config_settings\", \"http_custom_errors\", \"http_log_custom_fields\", \"http_ratelimit\", \"http_request_cache_settings\", \"http_request_dynamic_redirect\", \"http_request_firewall_custom\", \"http_request_firewall_managed\", \"http_request_late_transform\", \"http_request_origin\", \"http_request_redirect\", \"http_request_sanitize\", \"http_request_sbfm\", \"http_request_transform\", \"http_response_cache_settings\", \"http_response_compression\", \"http_response_firewall_managed\", \"http_response_headers_transform\", \"magic_transit\", \"magic_transit_ids_managed\", \"magic_transit_managed\", \"magic_transit_ratelimit\"." + }, + { + "name": "polish", + "type": "String", + "description": "The Polish level to configure.\nAvailable values: \"off\", \"lossless\", \"lossy\", \"webp\"." + }, + { + "name": "private", + "type": "Attributes", + "description": "Set the private cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "qualifiers", + "type": "List of String", + "description": "The qualifiers for the directive." + } + ] + }, + { + "name": "products", + "type": "List of String", + "description": "A list of legacy security products to skip the execution of.\nAvailable values: \"bic\", \"hot\", \"rateLimit\", \"securityLevel\", \"uaBlock\", \"waf\", \"zoneLockdown\"." + }, + { + "name": "proxy_revalidate", + "type": "Attributes", + "description": "Set the proxy-revalidate cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "public", + "type": "Attributes", + "description": "Set the public cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "raw_response_fields", + "type": "Attributes List", + "description": "The raw response fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the response header." + }, + { + "name": "preserve_duplicates", + "type": "Boolean", + "description": "Whether to log duplicate values of the same header." + } + ] + }, + { + "name": "read_timeout", + "type": "Number", + "description": "A timeout value between two successive read operations to use for your origin server. Historically, the timeout value between two read options from Cloudflare to an origin server is 100 seconds. If you are attempting to reduce HTTP 524 errors because of timeouts from an origin server, try increasing this timeout value." + }, + { + "name": "redirects_for_ai_training", + "type": "Boolean", + "description": "Whether to redirect verified AI training crawlers to canonical URLs." + }, + { + "name": "request_body_buffering", + "type": "String", + "description": "The request body buffering mode to configure.\nAvailable values: \"none\", \"standard\", \"full\"." + }, + { + "name": "request_fields", + "type": "Attributes List", + "description": "The raw request fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the header." + } + ] + }, + { + "name": "respect_strong_etags", + "type": "Boolean", + "description": "Whether Cloudflare should respect strong ETag (entity tag) headers. If false, Cloudflare converts strong ETag headers to weak ETag headers." + }, + { + "name": "response", + "type": "Attributes", + "description": "The response to show when the block is applied.", + "children": [ + { + "name": "content", + "type": "String", + "description": "The content to return." + }, + { + "name": "content_type", + "type": "String", + "description": "The type of the content to return." + }, + { + "name": "status_code", + "type": "Number", + "description": "The status code to return." + } + ] + }, + { + "name": "response_body_buffering", + "type": "String", + "description": "The response body buffering mode to configure.\nAvailable values: \"none\", \"standard\"." + }, + { + "name": "response_fields", + "type": "Attributes List", + "description": "The transformed response fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the response header." + }, + { + "name": "preserve_duplicates", + "type": "Boolean", + "description": "Whether to log duplicate values of the same header." + } + ] + }, + { + "name": "rocket_loader", + "type": "Boolean", + "description": "Whether to enable Rocket Loader." + }, + { + "name": "rules", + "type": "Map of List of String", + "description": "A mapping of ruleset IDs to a list of rule IDs in that ruleset to skip the execution of. This option is incompatible with the ruleset option." + }, + { + "name": "ruleset", + "type": "String", + "description": "A ruleset to skip the execution of. This option is incompatible with the rulesets option.\nAvailable values: \"current\"." + }, + { + "name": "rulesets", + "type": "List of String", + "description": "A list of ruleset IDs to skip the execution of. This option is incompatible with the ruleset and phases options." + }, + { + "name": "s_maxage", + "type": "Attributes", + "description": "Set the s-maxage cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "security_level", + "type": "String", + "description": "The Security Level to configure.\nAvailable values: \"off\", \"essentially_off\", \"low\", \"medium\", \"high\", \"under_attack\"." + }, + { + "name": "serve_stale", + "type": "Attributes", + "description": "When to serve stale content from cache.", + "children": [ + { + "name": "disable_stale_while_updating", + "type": "Boolean", + "description": "Whether Cloudflare should disable serving stale content while getting the latest content from the origin." + } + ] + }, + { + "name": "server_side_excludes", + "type": "Boolean", + "description": "Whether to enable Server-Side Excludes." + }, + { + "name": "sni", + "type": "Attributes", + "description": "A Server Name Indication (SNI) override.", + "children": [ + { + "name": "value", + "type": "String", + "description": "A value to override the SNI to." + } + ] + }, + { + "name": "ssl", + "type": "String", + "description": "The SSL level to configure.\nAvailable values: \"off\", \"flexible\", \"full\", \"strict\", \"origin_pull\"." + }, + { + "name": "stale_if_error", + "type": "Attributes", + "description": "Set the stale-if-error cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "stale_while_revalidate", + "type": "Attributes", + "description": "Set the stale-while-revalidate cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "status_code", + "type": "Number", + "description": "The status code to use for the error." + }, + { + "name": "strip_etags", + "type": "Boolean", + "description": "Whether to strip the ETag header from the response." + }, + { + "name": "strip_last_modified", + "type": "Boolean", + "description": "Whether to strip the Last-Modified header from the response." + }, + { + "name": "strip_set_cookie", + "type": "Boolean", + "description": "Whether to strip the Set-Cookie header from the response." + }, + { + "name": "sxg", + "type": "Boolean", + "description": "Whether to enable Signed Exchanges (SXG)." + }, + { + "name": "transformed_request_fields", + "type": "Attributes List", + "description": "The transformed request fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the header." + } + ] + }, + { + "name": "uri", + "type": "Attributes", + "description": "A URI rewrite.", + "children": [ + { + "name": "origin", + "type": "Boolean", + "description": "Whether to propagate the rewritten URI to origin." + }, + { + "name": "path", + "type": "Attributes", + "description": "A URI path rewrite.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a value to rewrite the URI path to." + }, + { + "name": "value", + "type": "String", + "description": "A value to rewrite the URI path to." + } + ] + }, + { + "name": "query", + "type": "Attributes", + "description": "A URI query rewrite.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a value to rewrite the URI query to." + }, + { + "name": "value", + "type": "String", + "description": "A value to rewrite the URI query to." + } + ] + } + ] + }, + { + "name": "values", + "type": "List of String", + "description": "The cache tag values for set_cache_tags action." + }, + { + "name": "vary", + "type": "Attributes", + "description": "Controls how cached responses vary based on request headers. `default` is required and applies to any Vary response header that does not have a per-header override.", + "children": [ + { + "name": "default", + "type": "Attributes", + "description": "Controls how response Vary headers without a per-header override contribute to the cache key.", + "children": [ + { + "name": "action", + "type": "String", + "description": "How the header value is treated when building the cache key.\nAvailable values: \"bypass\", \"passthrough\", \"normalize\"." + } + ] + }, + { + "name": "headers", + "type": "Attributes Map", + "description": "A mapping of lowercase request header names to their vary configuration.", + "children": [ + { + "name": "action", + "type": "String", + "description": "How the header value is treated when building the cache key.\nAvailable values: \"bypass\", \"passthrough\", \"normalize\"." + }, + { + "name": "languages", + "type": "List of String", + "description": "The set of languages to normalize against. Only valid for the `accept-language` header." + }, + { + "name": "media_types", + "type": "List of String", + "description": "The set of media types to normalize against. Only valid for the `accept` header." + } + ] + } + ] + } + ] + }, + { + "name": "categories", + "type": "List of String", + "description": "The categories of the rule." + }, + { + "name": "description", + "type": "String", + "description": "An informative description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the rule should be executed." + }, + { + "name": "exposed_credential_check", + "type": "Attributes", + "description": "Configuration for exposed credential checking.", + "children": [ + { + "name": "password_expression", + "type": "String", + "description": "An expression that selects the password used in the credentials check." + }, + { + "name": "username_expression", + "type": "String", + "description": "An expression that selects the user ID used in the credentials check." + } + ] + }, + { + "name": "expression", + "type": "String", + "description": "The expression defining which traffic will match the rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the rule." + }, + { + "name": "logging", + "type": "Attributes", + "description": "An object configuring the rule's logging behavior.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to generate a log when the rule matches." + } + ] + }, + { + "name": "ratelimit", + "type": "Attributes", + "description": "An object configuring the rule's rate limit behavior.", + "children": [ + { + "name": "characteristics", + "type": "List of String", + "description": "Characteristics of the request on which the rate limit counter will be incremented." + }, + { + "name": "counting_expression", + "type": "String", + "description": "An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule's expression." + }, + { + "name": "mitigation_timeout", + "type": "Number", + "description": "Period of time in seconds after which the action will be disabled following its first execution." + }, + { + "name": "period", + "type": "Number", + "description": "Period in seconds over which the counter is being incremented." + }, + { + "name": "requests_per_period", + "type": "Number", + "description": "The threshold of requests per period after which the action will be executed for the first time." + }, + { + "name": "requests_to_origin", + "type": "Boolean", + "description": "Whether counting is only performed when an origin is reached." + }, + { + "name": "score_per_period", + "type": "Number", + "description": "The score threshold per period for which the action will be executed the first time." + }, + { + "name": "score_response_header_name", + "type": "String", + "description": "A response header name provided by the origin, which contains the score to increment rate limit counter with." + } + ] + }, + { + "name": "ref", + "type": "String", + "description": "The reference of the rule (the rule's ID by default)." + } + ] + }, + { + "name": "version", + "type": "String", + "description": "The version of the ruleset." + } + ] + }, + "resource:cloudflare_ruleset": { + "kind": "resource", + "name": "cloudflare_ruleset", + "example": "resource \"cloudflare_ruleset\" \"example_ruleset\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n name = \"My ruleset\"\n phase = \"http_request_firewall_custom\"\n kind = \"root\"\n description = \"A description for my ruleset.\"\n rules = [\n {\n description = \"Block the request.\"\n expression = \"ip.src ne 1.1.1.1\"\n action = \"block\"\n ref = \"my_rule\"\n }\n ]\n}", + "importExample": "$ terraform import cloudflare_ruleset.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "kind", + "type": "String", + "description": "The kind of the ruleset.\nAvailable values: \"managed\", \"custom\", \"root\", \"zone\"." + }, + { + "name": "name", + "type": "String", + "description": "The human-readable name of the ruleset." + }, + { + "name": "phase", + "type": "String", + "description": "The phase of the ruleset.\nAvailable values: \"ddos_l4\", \"ddos_l7\", \"http_config_settings\", \"http_custom_errors\", \"http_log_custom_fields\", \"http_ratelimit\", \"http_request_cache_settings\", \"http_request_dynamic_redirect\", \"http_request_firewall_custom\", \"http_request_firewall_managed\", \"http_request_late_transform\", \"http_request_origin\", \"http_request_redirect\", \"http_request_sanitize\", \"http_request_sbfm\", \"http_request_transform\", \"http_response_cache_settings\", \"http_response_compression\", \"http_response_firewall_managed\", \"http_response_headers_transform\", \"magic_transit\", \"magic_transit_ids_managed\", \"magic_transit_managed\", \"magic_transit_ratelimit\"." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The unique ID of the account." + }, + { + "name": "description", + "type": "String", + "description": "An informative description of the ruleset." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "The list of rules in the ruleset.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to perform when the rule matches.\nAvailable values: \"block\", \"challenge\", \"compress_response\", \"ddos_dynamic\", \"execute\", \"force_connection_close\", \"js_challenge\", \"log\", \"log_custom_field\", \"managed_challenge\", \"redirect\", \"rewrite\", \"route\", \"score\", \"serve_error\", \"set_cache_control\", \"set_cache_settings\", \"set_cache_tags\", \"set_config\", \"skip\"." + }, + { + "name": "action_parameters", + "type": "Attributes", + "description": "The parameters configuring the rule's action.", + "children": [ + { + "name": "additional_cacheable_ports", + "type": "List of Number", + "description": "A list of additional ports that caching should be enabled on." + }, + { + "name": "algorithms", + "type": "Attributes List", + "description": "Custom order for compression algorithms.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the compression algorithm to enable.\nAvailable values: \"none\", \"auto\", \"default\", \"gzip\", \"brotli\", \"zstd\"." + } + ] + }, + { + "name": "asset_name", + "type": "String", + "description": "The name of a custom asset to serve as the response." + }, + { + "name": "automatic_https_rewrites", + "type": "Boolean", + "description": "Whether to enable Automatic HTTPS Rewrites." + }, + { + "name": "autominify", + "type": "Attributes", + "description": "Which file extensions to minify automatically.", + "children": [ + { + "name": "css", + "type": "Boolean", + "description": "Whether to minify CSS files." + }, + { + "name": "html", + "type": "Boolean", + "description": "Whether to minify HTML files." + }, + { + "name": "js", + "type": "Boolean", + "description": "Whether to minify JavaScript files." + } + ] + }, + { + "name": "bic", + "type": "Boolean", + "description": "Whether to enable Browser Integrity Check (BIC)." + }, + { + "name": "browser_ttl", + "type": "Attributes", + "description": "How long client browsers should cache the response. Cloudflare cache purge will not purge content cached on client browsers, so high browser TTLs may lead to stale content.", + "children": [ + { + "name": "default", + "type": "Number", + "description": "The browser TTL (in seconds) if you choose the \"override_origin\" mode." + }, + { + "name": "mode", + "type": "String", + "description": "The browser TTL mode.\nAvailable values: \"respect_origin\", \"bypass_by_default\", \"override_origin\", \"bypass\"." + } + ] + }, + { + "name": "cache", + "type": "Boolean", + "description": "Whether the request's response from the origin is eligible for caching. Caching itself will still depend on the cache control header and your other caching configurations." + }, + { + "name": "cache_key", + "type": "Attributes", + "description": "Which components of the request are included in or excluded from the cache key Cloudflare uses to store the response in cache.", + "children": [ + { + "name": "cache_by_device_type", + "type": "Boolean", + "description": "Whether to separate cached content based on the visitor's device type." + }, + { + "name": "cache_deception_armor", + "type": "Boolean", + "description": "Whether to protect from web cache deception attacks, while allowing static assets to be cached." + }, + { + "name": "custom_key", + "type": "Attributes", + "description": "Which components of the request are included or excluded from the cache key.", + "children": [ + { + "name": "cookie", + "type": "Attributes", + "description": "Which cookies to include in the cache key.", + "children": [ + { + "name": "check_presence", + "type": "List of String", + "description": "A list of cookies to check for the presence of. The presence of these cookies is included in the cache key." + }, + { + "name": "include", + "type": "List of String", + "description": "A list of cookies to include in the cache key." + } + ] + }, + { + "name": "header", + "type": "Attributes", + "description": "Which headers to include in the cache key.", + "children": [ + { + "name": "check_presence", + "type": "List of String", + "description": "A list of headers to check for the presence of. The presence of these headers is included in the cache key." + }, + { + "name": "contains", + "type": "Map of List of String", + "description": "A mapping of header names to a list of values. If a header is present in the request and contains any of the values provided, its value is included in the cache key." + }, + { + "name": "exclude_origin", + "type": "Boolean", + "description": "Whether to exclude the origin header in the cache key." + }, + { + "name": "include", + "type": "List of String", + "description": "A list of headers to include in the cache key." + } + ] + }, + { + "name": "host", + "type": "Attributes", + "description": "How to use the host in the cache key.", + "children": [ + { + "name": "resolved", + "type": "Boolean", + "description": "Whether to use the resolved host in the cache key." + } + ] + }, + { + "name": "query_string", + "type": "Attributes", + "description": "Which query string parameters to include in or exclude from the cache key.", + "children": [ + { + "name": "exclude", + "type": "Attributes", + "description": "Which query string parameters to exclude from the cache key.", + "children": [ + { + "name": "all", + "type": "Boolean", + "description": "Whether to exclude all query string parameters from the cache key." + }, + { + "name": "list", + "type": "List of String", + "description": "A list of query string parameters to exclude from the cache key." + } + ] + }, + { + "name": "include", + "type": "Attributes", + "description": "Which query string parameters to include in the cache key.", + "children": [ + { + "name": "all", + "type": "Boolean", + "description": "Whether to include all query string parameters in the cache key." + }, + { + "name": "list", + "type": "List of String", + "description": "A list of query string parameters to include in the cache key." + } + ] + } + ] + }, + { + "name": "user", + "type": "Attributes", + "description": "How to use characteristics of the request user agent in the cache key.", + "children": [ + { + "name": "device_type", + "type": "Boolean", + "description": "Whether to use the user agent's device type in the cache key." + }, + { + "name": "geo", + "type": "Boolean", + "description": "Whether to use the user agents's country in the cache key." + }, + { + "name": "lang", + "type": "Boolean", + "description": "Whether to use the user agent's language in the cache key." + } + ] + } + ] + }, + { + "name": "ignore_query_strings_order", + "type": "Boolean", + "description": "Whether to treat requests with the same query parameters the same, regardless of the order those query parameters are in." + } + ] + }, + { + "name": "cache_reserve", + "type": "Attributes", + "description": "Settings to determine whether the request's response from origin is eligible for Cache Reserve (requires a Cache Reserve add-on plan).", + "children": [ + { + "name": "eligible", + "type": "Boolean", + "description": "Whether Cache Reserve is enabled. If this is true and a request meets eligibility criteria, Cloudflare will write the resource to Cache Reserve." + }, + { + "name": "minimum_file_size", + "type": "Number", + "description": "The minimum file size eligible for storage in Cache Reserve." + } + ] + }, + { + "name": "content", + "type": "String", + "description": "The response content." + }, + { + "name": "content_converter", + "type": "Boolean", + "description": "Whether to enable content conversion (e.g., HTML to Markdown)." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type header to set with the error response.\nAvailable values: \"application/json\", \"text/html\", \"text/plain\", \"text/xml\"." + }, + { + "name": "cookie_fields", + "type": "Attributes List", + "description": "The cookie fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the cookie." + } + ] + }, + { + "name": "disable_apps", + "type": "Boolean", + "description": "Whether to disable Cloudflare Apps." + }, + { + "name": "disable_rum", + "type": "Boolean", + "description": "Whether to disable Real User Monitoring (RUM)." + }, + { + "name": "disable_zaraz", + "type": "Boolean", + "description": "Whether to disable Zaraz." + }, + { + "name": "edge_ttl", + "type": "Attributes", + "description": "How long the Cloudflare edge network should cache the response.", + "children": [ + { + "name": "default", + "type": "Number", + "description": "The edge TTL (in seconds) if you choose the \"override_origin\" mode." + }, + { + "name": "mode", + "type": "String", + "description": "The edge TTL mode.\nAvailable values: \"respect_origin\", \"bypass_by_default\", \"override_origin\"." + }, + { + "name": "status_code_ttl", + "type": "Attributes List", + "description": "A list of TTLs to apply to specific status codes or status code ranges.", + "children": [ + { + "name": "status_code", + "type": "Number", + "description": "A single status code to apply the TTL to." + }, + { + "name": "status_code_range", + "type": "Attributes", + "description": "A range of status codes to apply the TTL to.", + "children": [ + { + "name": "from", + "type": "Number", + "description": "The lower bound of the range." + }, + { + "name": "to", + "type": "Number", + "description": "The upper bound of the range." + } + ] + }, + { + "name": "value", + "type": "Number", + "description": "The time to cache the response for (in seconds). A value of 0 is equivalent to setting the cache control header with the value \"no-cache\". A value of -1 is equivalent to setting the cache control header with the value of \"no-store\"." + } + ] + } + ] + }, + { + "name": "email_obfuscation", + "type": "Boolean", + "description": "Whether to enable Email Obfuscation." + }, + { + "name": "expression", + "type": "String", + "description": "An expression to generate cache tags for set_cache_tags action." + }, + { + "name": "fonts", + "type": "Boolean", + "description": "Whether to enable Cloudflare Fonts." + }, + { + "name": "from_list", + "type": "Attributes", + "description": "A redirect based on a bulk list lookup.", + "children": [ + { + "name": "key", + "type": "String", + "description": "An expression that evaluates to the list lookup key." + }, + { + "name": "name", + "type": "String", + "description": "The name of the list to match against." + } + ] + }, + { + "name": "from_value", + "type": "Attributes", + "description": "A redirect based on the request properties.", + "children": [ + { + "name": "preserve_query_string", + "type": "Boolean", + "description": "Whether to keep the query string of the original request." + }, + { + "name": "status_code", + "type": "Number", + "description": "The status code to use for the redirect." + }, + { + "name": "target_url", + "type": "Attributes", + "description": "A URL to redirect the request to.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a URL to redirect the request to." + }, + { + "name": "value", + "type": "String", + "description": "A URL to redirect the request to." + } + ] + } + ] + }, + { + "name": "headers", + "type": "Attributes Map", + "description": "A map of headers to rewrite.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a value for the header." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform on the header.\nAvailable values: \"add\", \"set\", \"remove\"." + }, + { + "name": "value", + "type": "String", + "description": "A static value for the header." + } + ] + }, + { + "name": "host_header", + "type": "String", + "description": "A value to rewrite the HTTP host header to." + }, + { + "name": "hotlink_protection", + "type": "Boolean", + "description": "Whether to enable Hotlink Protection." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the ruleset to execute." + }, + { + "name": "immutable", + "type": "Attributes", + "description": "Set the immutable cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "increment", + "type": "Number", + "description": "A delta to change the score by, which can be either positive or negative." + }, + { + "name": "matched_data", + "type": "Attributes", + "description": "The configuration to use for matched data logging.", + "children": [ + { + "name": "public_key", + "type": "String", + "description": "The public key to encrypt matched data logs with." + } + ] + }, + { + "name": "max_age", + "type": "Attributes", + "description": "Set the max-age cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "mirage", + "type": "Boolean", + "description": "Whether to enable Mirage." + }, + { + "name": "must_revalidate", + "type": "Attributes", + "description": "Set the must-revalidate cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "must_understand", + "type": "Attributes", + "description": "Set the must-understand cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "no_cache", + "type": "Attributes", + "description": "Set the no-cache cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "qualifiers", + "type": "List of String", + "description": "The qualifiers for the directive." + } + ] + }, + { + "name": "no_store", + "type": "Attributes", + "description": "Set the no-store cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "no_transform", + "type": "Attributes", + "description": "Set the no-transform cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform for set_cache_tags action.\nAvailable values: \"set\", \"add\", \"remove\"." + }, + { + "name": "opportunistic_encryption", + "type": "Boolean", + "description": "Whether to enable Opportunistic Encryption." + }, + { + "name": "origin", + "type": "Attributes", + "description": "An origin to route to.", + "children": [ + { + "name": "host", + "type": "String", + "description": "A resolved host to route to." + }, + { + "name": "port", + "type": "Number", + "description": "A destination port to route to." + } + ] + }, + { + "name": "origin_cache_control", + "type": "Boolean", + "description": "Whether Cloudflare will aim to strictly adhere to RFC 7234." + }, + { + "name": "origin_error_page_passthru", + "type": "Boolean", + "description": "Whether to generate Cloudflare error pages for issues from the origin server." + }, + { + "name": "origin_range_requests", + "type": "Attributes", + "description": "Controls whether Cloudflare fetches a large asset from the origin as a series of range requests instead of one whole-body request.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Whether to use range requests. `default` is the behaviour the zone gets without this rule.\nAvailable values: \"on\", \"off\", \"default\"." + } + ] + }, + { + "name": "overrides", + "type": "Attributes", + "description": "A set of overrides to apply to the target ruleset.", + "children": [ + { + "name": "action", + "type": "String", + "description": "An action to override all rules with. This option has lower precedence than rule and category overrides." + }, + { + "name": "categories", + "type": "Attributes List", + "description": "A list of category-level overrides. This option has the second-highest precedence after rule-level overrides.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to override rules in the category with." + }, + { + "name": "category", + "type": "String", + "description": "The name of the category to override." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable execution of rules in the category." + }, + { + "name": "sensitivity_level", + "type": "String", + "description": "The sensitivity level to use for rules in the category. This option is only applicable for DDoS phases.\nAvailable values: \"default\", \"medium\", \"low\", \"eoff\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable execution of all rules. This option has lower precedence than rule and category overrides." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "A list of rule-level overrides. This option has the highest precedence.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to override the rule with." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to enable execution of the rule." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the rule to override." + }, + { + "name": "score_threshold", + "type": "Number", + "description": "The score threshold to use for the rule." + }, + { + "name": "sensitivity_level", + "type": "String", + "description": "The sensitivity level to use for the rule. This option is only applicable for DDoS phases.\nAvailable values: \"default\", \"medium\", \"low\", \"eoff\"." + } + ] + }, + { + "name": "sensitivity_level", + "type": "String", + "description": "A sensitivity level to set for all rules. This option has lower precedence than rule and category overrides and is only applicable for DDoS phases.\nAvailable values: \"default\", \"medium\", \"low\", \"eoff\"." + } + ] + }, + { + "name": "phases", + "type": "List of String", + "description": "A list of phases to skip the execution of. This option is incompatible with the rulesets option.\nAvailable values: \"ddos_l4\", \"ddos_l7\", \"http_config_settings\", \"http_custom_errors\", \"http_log_custom_fields\", \"http_ratelimit\", \"http_request_cache_settings\", \"http_request_dynamic_redirect\", \"http_request_firewall_custom\", \"http_request_firewall_managed\", \"http_request_late_transform\", \"http_request_origin\", \"http_request_redirect\", \"http_request_sanitize\", \"http_request_sbfm\", \"http_request_transform\", \"http_response_cache_settings\", \"http_response_compression\", \"http_response_firewall_managed\", \"http_response_headers_transform\", \"magic_transit\", \"magic_transit_ids_managed\", \"magic_transit_managed\", \"magic_transit_ratelimit\"." + }, + { + "name": "polish", + "type": "String", + "description": "The Polish level to configure.\nAvailable values: \"off\", \"lossless\", \"lossy\", \"webp\"." + }, + { + "name": "private", + "type": "Attributes", + "description": "Set the private cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "qualifiers", + "type": "List of String", + "description": "The qualifiers for the directive." + } + ] + }, + { + "name": "products", + "type": "List of String", + "description": "A list of legacy security products to skip the execution of.\nAvailable values: \"bic\", \"hot\", \"rateLimit\", \"securityLevel\", \"uaBlock\", \"waf\", \"zoneLockdown\"." + }, + { + "name": "proxy_revalidate", + "type": "Attributes", + "description": "Set the proxy-revalidate cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "public", + "type": "Attributes", + "description": "Set the public cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + } + ] + }, + { + "name": "raw_response_fields", + "type": "Attributes List", + "description": "The raw response fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the response header." + }, + { + "name": "preserve_duplicates", + "type": "Boolean", + "description": "Whether to log duplicate values of the same header." + } + ] + }, + { + "name": "read_timeout", + "type": "Number", + "description": "A timeout value between two successive read operations to use for your origin server. Historically, the timeout value between two read options from Cloudflare to an origin server is 100 seconds. If you are attempting to reduce HTTP 524 errors because of timeouts from an origin server, try increasing this timeout value." + }, + { + "name": "redirects_for_ai_training", + "type": "Boolean", + "description": "Whether to redirect verified AI training crawlers to canonical URLs." + }, + { + "name": "request_body_buffering", + "type": "String", + "description": "The request body buffering mode to configure.\nAvailable values: \"none\", \"standard\", \"full\"." + }, + { + "name": "request_fields", + "type": "Attributes List", + "description": "The raw request fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the header." + } + ] + }, + { + "name": "respect_strong_etags", + "type": "Boolean", + "description": "Whether Cloudflare should respect strong ETag (entity tag) headers. If false, Cloudflare converts strong ETag headers to weak ETag headers." + }, + { + "name": "response", + "type": "Attributes", + "description": "The response to show when the block is applied.", + "children": [ + { + "name": "content", + "type": "String", + "description": "The content to return." + }, + { + "name": "content_type", + "type": "String", + "description": "The type of the content to return." + }, + { + "name": "status_code", + "type": "Number", + "description": "The status code to return." + } + ] + }, + { + "name": "response_body_buffering", + "type": "String", + "description": "The response body buffering mode to configure.\nAvailable values: \"none\", \"standard\"." + }, + { + "name": "response_fields", + "type": "Attributes List", + "description": "The transformed response fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the response header." + }, + { + "name": "preserve_duplicates", + "type": "Boolean", + "description": "Whether to log duplicate values of the same header." + } + ] + }, + { + "name": "rocket_loader", + "type": "Boolean", + "description": "Whether to enable Rocket Loader." + }, + { + "name": "rules", + "type": "Map of List of String", + "description": "A mapping of ruleset IDs to a list of rule IDs in that ruleset to skip the execution of. This option is incompatible with the ruleset option." + }, + { + "name": "ruleset", + "type": "String", + "description": "A ruleset to skip the execution of. This option is incompatible with the rulesets option.\nAvailable values: \"current\"." + }, + { + "name": "rulesets", + "type": "List of String", + "description": "A list of ruleset IDs to skip the execution of. This option is incompatible with the ruleset and phases options." + }, + { + "name": "s_maxage", + "type": "Attributes", + "description": "Set the s-maxage cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "security_level", + "type": "String", + "description": "The Security Level to configure.\nAvailable values: \"off\", \"essentially_off\", \"low\", \"medium\", \"high\", \"under_attack\"." + }, + { + "name": "serve_stale", + "type": "Attributes", + "description": "When to serve stale content from cache.", + "children": [ + { + "name": "disable_stale_while_updating", + "type": "Boolean", + "description": "Whether Cloudflare should disable serving stale content while getting the latest content from the origin." + } + ] + }, + { + "name": "server_side_excludes", + "type": "Boolean", + "description": "Whether to enable Server-Side Excludes." + }, + { + "name": "sni", + "type": "Attributes", + "description": "A Server Name Indication (SNI) override.", + "children": [ + { + "name": "value", + "type": "String", + "description": "A value to override the SNI to." + } + ] + }, + { + "name": "ssl", + "type": "String", + "description": "The SSL level to configure.\nAvailable values: \"off\", \"flexible\", \"full\", \"strict\", \"origin_pull\"." + }, + { + "name": "stale_if_error", + "type": "Attributes", + "description": "Set the stale-if-error cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "stale_while_revalidate", + "type": "Attributes", + "description": "Set the stale-while-revalidate cache control directive.", + "children": [ + { + "name": "cloudflare_only", + "type": "Boolean", + "description": "Whether to apply the directive only to Cloudflare's cache." + }, + { + "name": "operation", + "type": "String", + "description": "The operation to perform.\nAvailable values: \"set\", \"remove\"." + }, + { + "name": "value", + "type": "Number", + "description": "The value for the directive in seconds." + } + ] + }, + { + "name": "status_code", + "type": "Number", + "description": "The status code to use for the error." + }, + { + "name": "strip_etags", + "type": "Boolean", + "description": "Whether to strip the ETag header from the response." + }, + { + "name": "strip_last_modified", + "type": "Boolean", + "description": "Whether to strip the Last-Modified header from the response." + }, + { + "name": "strip_set_cookie", + "type": "Boolean", + "description": "Whether to strip the Set-Cookie header from the response." + }, + { + "name": "sxg", + "type": "Boolean", + "description": "Whether to enable Signed Exchanges (SXG)." + }, + { + "name": "transformed_request_fields", + "type": "Attributes List", + "description": "The transformed request fields to log.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the header." + } + ] + }, + { + "name": "uri", + "type": "Attributes", + "description": "A URI rewrite.", + "children": [ + { + "name": "path", + "type": "Attributes", + "description": "A URI path rewrite.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a value to rewrite the URI path to." + }, + { + "name": "value", + "type": "String", + "description": "A value to rewrite the URI path to." + } + ] + }, + { + "name": "query", + "type": "Attributes", + "description": "A URI query rewrite.", + "children": [ + { + "name": "expression", + "type": "String", + "description": "An expression that evaluates to a value to rewrite the URI query to." + }, + { + "name": "value", + "type": "String", + "description": "A value to rewrite the URI query to." + } + ] + } + ] + }, + { + "name": "values", + "type": "List of String", + "description": "The cache tag values for set_cache_tags action." + }, + { + "name": "vary", + "type": "Attributes", + "description": "Controls how cached responses vary based on request headers. `default` is required and applies to any Vary response header that does not have a per-header override.", + "children": [ + { + "name": "default", + "type": "Attributes", + "description": "Controls how response Vary headers without a per-header override contribute to the cache key.", + "children": [ + { + "name": "action", + "type": "String", + "description": "How the header value is treated when building the cache key.\nAvailable values: \"bypass\", \"passthrough\", \"normalize\"." + } + ] + }, + { + "name": "headers", + "type": "Attributes Map", + "description": "A mapping of lowercase request header names to their vary configuration.", + "children": [ + { + "name": "action", + "type": "String", + "description": "How the header value is treated when building the cache key.\nAvailable values: \"bypass\", \"passthrough\", \"normalize\"." + }, + { + "name": "languages", + "type": "List of String", + "description": "The set of languages to normalize against. Only valid for the `accept-language` header." + }, + { + "name": "media_types", + "type": "List of String", + "description": "The set of media types to normalize against. Only valid for the `accept` header." + } + ] + } + ] + } + ] + }, + { + "name": "description", + "type": "String", + "description": "An informative description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the rule should be executed." + }, + { + "name": "exposed_credential_check", + "type": "Attributes", + "description": "Configuration for exposed credential checking.", + "children": [ + { + "name": "password_expression", + "type": "String", + "description": "An expression that selects the password used in the credentials check." + }, + { + "name": "username_expression", + "type": "String", + "description": "An expression that selects the user ID used in the credentials check." + } + ] + }, + { + "name": "expression", + "type": "String", + "description": "The expression defining which traffic will match the rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the rule." + }, + { + "name": "logging", + "type": "Attributes", + "description": "An object configuring the rule's logging behavior.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether to generate a log when the rule matches." + } + ] + }, + { + "name": "ratelimit", + "type": "Attributes", + "description": "An object configuring the rule's rate limit behavior.", + "children": [ + { + "name": "characteristics", + "type": "List of String", + "description": "Characteristics of the request on which the rate limit counter will be incremented." + }, + { + "name": "counting_expression", + "type": "String", + "description": "An expression that defines when the rate limit counter should be incremented. It defaults to the same as the rule's expression." + }, + { + "name": "mitigation_timeout", + "type": "Number", + "description": "Period of time in seconds after which the action will be disabled following its first execution." + }, + { + "name": "period", + "type": "Number", + "description": "Period in seconds over which the counter is being incremented." + }, + { + "name": "requests_per_period", + "type": "Number", + "description": "The threshold of requests per period after which the action will be executed for the first time." + }, + { + "name": "requests_to_origin", + "type": "Boolean", + "description": "Whether counting is only performed when an origin is reached." + }, + { + "name": "score_per_period", + "type": "Number", + "description": "The score threshold per period for which the action will be executed the first time." + }, + { + "name": "score_response_header_name", + "type": "String", + "description": "A response header name provided by the origin, which contains the score to increment rate limit counter with." + } + ] + }, + { + "name": "ref", + "type": "String", + "description": "The reference of the rule (the rule's ID by default)." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique ID of the ruleset." + }, + { + "name": "last_updated", + "type": "String", + "description": "The timestamp of when the ruleset was last modified." + }, + { + "name": "version", + "type": "String", + "description": "The version of the ruleset." + } + ] + }, + "list-data-source:cloudflare_rulesets": { + "kind": "list-data-source", + "name": "cloudflare_rulesets", + "example": "data \"cloudflare_rulesets\" \"example_rulesets\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The unique ID of the account." + }, + { + "name": "max_items", + "type": "Number", + "description": "Maximum number of rulesets to fetch (defaults to 1000)." + }, + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes Set", + "description": "A list of rulesets. The returned information will not include the rules in each ruleset.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "description", + "type": "String", + "description": "An informative description of the ruleset.", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the ruleset.", + "deprecated": "Deprecated." + }, + { + "name": "kind", + "type": "String", + "description": "The kind of the ruleset.\nAvailable values: \"managed\", \"custom\", \"root\", \"zone\".", + "deprecated": "Deprecated." + }, + { + "name": "last_updated", + "type": "String", + "description": "The timestamp of when the ruleset was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The human-readable name of the ruleset.", + "deprecated": "Deprecated." + }, + { + "name": "phase", + "type": "String", + "description": "The phase of the ruleset.\nAvailable values: \"ddos_l4\", \"ddos_l7\", \"http_config_settings\", \"http_custom_errors\", \"http_log_custom_fields\", \"http_ratelimit\", \"http_request_cache_settings\", \"http_request_dynamic_redirect\", \"http_request_firewall_custom\", \"http_request_firewall_managed\", \"http_request_late_transform\", \"http_request_origin\", \"http_request_redirect\", \"http_request_sanitize\", \"http_request_sbfm\", \"http_request_transform\", \"http_response_compression\", \"http_response_firewall_managed\", \"http_response_headers_transform\", \"magic_transit\", \"magic_transit_ids_managed\", \"magic_transit_managed\", \"magic_transit_ratelimit\".", + "deprecated": "Deprecated." + }, + { + "name": "version", + "type": "String", + "description": "The version of the ruleset." + } + ] + }, + { + "name": "rulesets", + "type": "Attributes Set", + "description": "A list of rulesets. The returned information will not include the rules in each ruleset.", + "children": [ + { + "name": "description", + "type": "String", + "description": "An informative description of the ruleset." + }, + { + "name": "id", + "type": "String", + "description": "The unique ID of the ruleset." + }, + { + "name": "kind", + "type": "String", + "description": "The kind of the ruleset.\nAvailable values: \"managed\", \"custom\", \"root\", \"zone\"." + }, + { + "name": "last_updated", + "type": "String", + "description": "The timestamp of when the ruleset was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The human-readable name of the ruleset." + }, + { + "name": "phase", + "type": "String", + "description": "The phase of the ruleset.\nAvailable values: \"ddos_l4\", \"ddos_l7\", \"http_config_settings\", \"http_custom_errors\", \"http_log_custom_fields\", \"http_ratelimit\", \"http_request_cache_settings\", \"http_request_dynamic_redirect\", \"http_request_firewall_custom\", \"http_request_firewall_managed\", \"http_request_late_transform\", \"http_request_origin\", \"http_request_redirect\", \"http_request_sanitize\", \"http_request_sbfm\", \"http_request_transform\", \"http_response_compression\", \"http_response_firewall_managed\", \"http_response_headers_transform\", \"magic_transit\", \"magic_transit_ids_managed\", \"magic_transit_managed\", \"magic_transit_ratelimit\"." + }, + { + "name": "version", + "type": "String", + "description": "The version of the ruleset." + } + ] + } + ] + }, + "data-source:cloudflare_schema_validation_operation_settings": { + "kind": "data-source", + "name": "cloudflare_schema_validation_operation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_schema_validation_operation_settings\" \"example_schema_validation_operation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "operation_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "mitigation_action", + "type": "String", + "description": "When set, this applies a mitigation action to this operation which supersedes a global schema validation setting just for this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\nAvailable values: \"log\", \"block\", \"none\"." + } + ] + }, + "resource:cloudflare_schema_validation_operation_settings": { + "kind": "resource", + "name": "cloudflare_schema_validation_operation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "resource \"cloudflare_schema_validation_operation_settings\" \"example_schema_validation_operation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n operation_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n mitigation_action = \"block\"\n}", + "required": [ + { + "name": "mitigation_action", + "type": "String", + "description": "When set, this applies a mitigation action to this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\n - `null` - clears any mitigation action\nAvailable values: \"log\", \"block\", \"none\"." + }, + { + "name": "operation_id", + "type": "String", + "description": "UUID." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [] + }, + "list-data-source:cloudflare_schema_validation_operation_settings_list": { + "kind": "list-data-source", + "name": "cloudflare_schema_validation_operation_settings_list", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_schema_validation_operation_settings_list\" \"example_schema_validation_operation_settings_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "mitigation_action", + "type": "String", + "description": "When set, this applies a mitigation action to this operation which supersedes a global schema validation setting just for this operation\n\n - `\"log\"` - log request when request does not conform to schema for this operation\n - `\"block\"` - deny access to the site when request does not conform to schema for this operation\n - `\"none\"` - will skip mitigation for this operation\nAvailable values: \"log\", \"block\", \"none\"." + }, + { + "name": "operation_id", + "type": "String", + "description": "UUID." + } + ] + } + ] + }, + "data-source:cloudflare_schema_validation_schemas": { + "kind": "data-source", + "name": "cloudflare_schema_validation_schemas", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_schema_validation_schemas\" \"example_schema_validation_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n schema_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n omit_source = true\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "validation_enabled", + "type": "Boolean", + "description": "Filter for enabled schemas" + } + ] + }, + { + "name": "omit_source", + "type": "Boolean", + "description": "Omit the source-files of schemas and only retrieve their meta-data." + }, + { + "name": "schema_id", + "type": "String", + "description": "UUID." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "kind", + "type": "String", + "description": "The kind of the schema\nAvailable values: \"openapi_v3\"." + }, + { + "name": "name", + "type": "String", + "description": "A human-readable name for the schema" + }, + { + "name": "source", + "type": "String", + "description": "The raw schema, e.g., the OpenAPI schema, either as JSON or YAML" + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "An indicator if this schema is enabled" + } + ] + }, + "resource:cloudflare_schema_validation_schemas": { + "kind": "resource", + "name": "cloudflare_schema_validation_schemas", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "resource \"cloudflare_schema_validation_schemas\" \"example_schema_validation_schemas\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n kind = \"openapi_v3\"\n name = \"petstore schema\"\n source = \"\"\n validation_enabled = true\n}", + "importExample": "$ terraform import cloudflare_schema_validation_schemas.example '/'", + "required": [ + { + "name": "kind", + "type": "String", + "description": "The kind of the schema\nAvailable values: \"openapi_v3\"." + }, + { + "name": "name", + "type": "String", + "description": "A human-readable name for the schema" + }, + { + "name": "source", + "type": "String", + "description": "The raw schema, e.g., the OpenAPI schema, either as JSON or YAML" + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "An indicator if this schema is enabled" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "omit_source", + "type": "Boolean", + "description": "Omit the source-files of schemas and only retrieve their meta-data." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "A unique identifier of this schema" + }, + { + "name": "schema_id", + "type": "String", + "description": "A unique identifier of this schema" + } + ] + }, + "list-data-source:cloudflare_schema_validation_schemas_list": { + "kind": "list-data-source", + "name": "cloudflare_schema_validation_schemas_list", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_schema_validation_schemas_list\" \"example_schema_validation_schemas_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_enabled = true\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "omit_source", + "type": "Boolean", + "description": "Omit the source-files of schemas and only retrieve their meta-data." + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "Filter for enabled schemas" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "A unique identifier of this schema" + }, + { + "name": "kind", + "type": "String", + "description": "The kind of the schema\nAvailable values: \"openapi_v3\"." + }, + { + "name": "name", + "type": "String", + "description": "A human-readable name for the schema" + }, + { + "name": "schema_id", + "type": "String", + "description": "A unique identifier of this schema" + }, + { + "name": "source", + "type": "String", + "description": "The raw schema, e.g., the OpenAPI schema, either as JSON or YAML" + }, + { + "name": "validation_enabled", + "type": "Boolean", + "description": "An indicator if this schema is enabled" + } + ] + } + ] + }, + "data-source:cloudflare_schema_validation_settings": { + "kind": "data-source", + "name": "cloudflare_schema_validation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_schema_validation_settings\" \"example_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "validation_default_mitigation_action", + "type": "String", + "description": "The default mitigation action used\n\nMitigation actions are as follows:\n\n - `log` - log request when request does not conform to schema\n - `block` - deny access to the site when request does not conform to schema\n - `none` - skip running schema validation\nAvailable values: \"none\", \"log\", \"block\"." + }, + { + "name": "validation_override_mitigation_action", + "type": "String", + "description": "When not null, this overrides global both zone level and operation level mitigation actions. This can serve as a quick way to disable schema validation for the whole zone.\n\n - `\"none\"` will skip running schema validation entirely for the request\nAvailable values: \"none\"." + } + ] + }, + "resource:cloudflare_schema_validation_settings": { + "kind": "resource", + "name": "cloudflare_schema_validation_settings", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "resource \"cloudflare_schema_validation_settings\" \"example_schema_validation_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n validation_default_mitigation_action = \"block\"\n validation_override_mitigation_action = \"none\"\n}", + "required": [ + { + "name": "validation_default_mitigation_action", + "type": "String", + "description": "The default mitigation action used\nMitigation actions are as follows:\n\n - `\"log\"` - log request when request does not conform to schema\n - `\"block\"` - deny access to the site when request does not conform to schema\n - `\"none\"` - skip running schema validation\nAvailable values: \"none\", \"log\", \"block\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "validation_override_mitigation_action", + "type": "String", + "description": "When set, this overrides both zone level and operation level mitigation actions.\n\n - `\"none\"` - skip running schema validation entirely for the request\n - `null` - clears any existing override\nAvailable values: \"none\"." + } + ], + "computed": [] + }, + "data-source:cloudflare_secrets_store": { + "kind": "data-source", + "name": "cloudflare_secrets_store", + "description": "Accepted Permissions\n\n- `Secrets Store Read`\n- `Secrets Store Write`", + "example": "data \"cloudflare_secrets_store\" \"example_secrets_store\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account Identifier" + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to sort objects.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order", + "type": "String", + "description": "Order stores by values in the given field.\nAvailable values: \"name\", \"created\", \"modified\"." + } + ] + }, + { + "name": "store_id", + "type": "String", + "description": "Store Identifier" + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "When the secret was created." + }, + { + "name": "id", + "type": "String", + "description": "Store Identifier" + }, + { + "name": "modified", + "type": "String", + "description": "When the secret was modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the store." + } + ] + }, + "resource:cloudflare_secrets_store": { + "kind": "resource", + "name": "cloudflare_secrets_store", + "description": "Accepted Permissions\n\n- `Secrets Store Read`\n- `Secrets Store Write`", + "example": "resource \"cloudflare_secrets_store\" \"example_secrets_store\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n name = \"service_x_keys\"\n}", + "importExample": "$ terraform import cloudflare_secrets_store.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The name of the store." + } + ], + "optional": [ + { + "name": "force", + "type": "Boolean", + "description": "When true, cascade-deletes all secrets in the store before deleting the store itself.\nRequired when deleting a non-empty store. Without this parameter, attempting to\ndelete a non-empty store returns 409." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "When the secret was created." + }, + { + "name": "id", + "type": "String", + "description": "Store Identifier." + }, + { + "name": "modified", + "type": "String", + "description": "When the secret was modified." + } + ] + }, + "data-source:cloudflare_secrets_store_secret": { + "kind": "data-source", + "name": "cloudflare_secrets_store_secret", + "description": "Accepted Permissions\n\n- `Secrets Store Read`\n- `Secrets Store Write`", + "example": "data \"cloudflare_secrets_store_secret\" \"example_secrets_store_secret\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n secret_id = \"3fd85f74b32742f1bff64a85009dda07\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account Identifier" + }, + { + "name": "store_id", + "type": "String", + "description": "Store Identifier" + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to sort objects.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order", + "type": "String", + "description": "Order secrets by values in the given field.\nAvailable values: \"name\", \"comment\", \"created\", \"modified\", \"status\"." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Only secrets with the given scopes will be returned." + }, + { + "name": "search", + "type": "String", + "description": "Search secrets using a filter string, filtering across name and comment." + } + ] + }, + { + "name": "secret_id", + "type": "String", + "description": "Secret identifier tag." + } + ], + "computed": [ + { + "name": "comment", + "type": "String", + "description": "Freeform text describing the secret." + }, + { + "name": "created", + "type": "String", + "description": "When the secret was created." + }, + { + "name": "id", + "type": "String", + "description": "Secret identifier tag." + }, + { + "name": "modified", + "type": "String", + "description": "When the secret was modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the secret." + }, + { + "name": "scopes", + "type": "List of String", + "description": "The list of services that can use this secret." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"pending\", \"active\", \"deleted\"." + } + ] + }, + "resource:cloudflare_secrets_store_secret": { + "kind": "resource", + "name": "cloudflare_secrets_store_secret", + "description": "Accepted Permissions\n\n- `Secrets Store Read`\n- `Secrets Store Write`", + "example": "resource \"cloudflare_secrets_store_secret\" \"example_secrets_store_secret\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"MY_API_KEY\"\n scopes = [\"workers\"]\n value = \"my-secret-value\"\n}", + "importExample": "$ terraform import cloudflare_secrets_store_secret.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account Identifier" + }, + { + "name": "name", + "type": "String", + "description": "The name of the secret" + }, + { + "name": "scopes", + "type": "List of String", + "description": "The list of services that can use this secret. Valid values are `workers`, `ai_gateway`, `dex`, and `access`. Must be listed in alphabetical order." + }, + { + "name": "store_id", + "type": "String", + "description": "Store Identifier" + }, + { + "name": "value", + "type": "String", + "description": "The value of the secret. Maximum 64 KiB (65,536 bytes). Note that this is 'write only' - no API response will provide this value, it is only used to create/modify secrets.", + "sensitive": true + } + ], + "optional": [ + { + "name": "comment", + "type": "String", + "description": "Freeform text describing the secret" + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "When the secret was created." + }, + { + "name": "id", + "type": "String", + "description": "Secret identifier tag." + }, + { + "name": "modified", + "type": "String", + "description": "When the secret was modified." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"pending\", \"active\", \"deleted\"." + } + ] + }, + "list-data-source:cloudflare_secrets_store_secrets": { + "kind": "list-data-source", + "name": "cloudflare_secrets_store_secrets", + "description": "Accepted Permissions\n\n- `Secrets Store Read`\n- `Secrets Store Write`", + "example": "data \"cloudflare_secrets_store_secrets\" \"example_secrets_store_secrets\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n store_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n scopes = [\"workers\"]\n search = \"search\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "store_id", + "type": "String" + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "Direction to sort objects.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Order secrets by values in the given field.\nAvailable values: \"name\", \"comment\", \"created\", \"modified\", \"status\"." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Only secrets with the given scopes will be returned." + }, + { + "name": "search", + "type": "String", + "description": "Search secrets using a filter string, filtering across name and comment." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comment", + "type": "String", + "description": "Freeform text describing the secret." + }, + { + "name": "created", + "type": "String", + "description": "When the secret was created." + }, + { + "name": "id", + "type": "String", + "description": "Secret identifier tag." + }, + { + "name": "modified", + "type": "String", + "description": "When the secret was modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the secret." + }, + { + "name": "scopes", + "type": "List of String", + "description": "The list of services that can use this secret." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"pending\", \"active\", \"deleted\"." + }, + { + "name": "store_id", + "type": "String", + "description": "Store Identifier." + } + ] + } + ] + }, + "list-data-source:cloudflare_secrets_stores": { + "kind": "list-data-source", + "name": "cloudflare_secrets_stores", + "description": "Accepted Permissions\n\n- `Secrets Store Read`\n- `Secrets Store Write`", + "example": "data \"cloudflare_secrets_stores\" \"example_secrets_stores\" {\n account_id = \"985e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account Identifier." + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "Direction to sort objects.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Order stores by values in the given field.\nAvailable values: \"name\", \"created\", \"modified\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Account Identifier." + }, + { + "name": "created", + "type": "String", + "description": "When the secret was created." + }, + { + "name": "id", + "type": "String", + "description": "Store Identifier." + }, + { + "name": "modified", + "type": "String", + "description": "When the secret was modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the store." + } + ] + } + ] + }, + "data-source:cloudflare_share": { + "kind": "data-source", + "name": "cloudflare_share", + "example": "data \"cloudflare_share\" \"example_share\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_recipient_counts = true\n include_resources = true\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to sort objects.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "kind", + "type": "String", + "description": "Filter shares by kind.\nAvailable values: \"sent\", \"received\"." + }, + { + "name": "order", + "type": "String", + "description": "Order shares by values in the given field.\nAvailable values: \"name\", \"created\"." + }, + { + "name": "resource_types", + "type": "List of String", + "description": "Filter share resources by resource_types." + }, + { + "name": "status", + "type": "String", + "description": "Filter shares by status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + }, + { + "name": "tag", + "type": "List of String", + "description": "Filter shares by tag. Each value is either `key=value` (matches shares whose tags contain that key/value pair) or `key` alone (matches shares that have any value for that key). May be repeated; multiple `tag` parameters are ANDed together. Maximum 20 `tag` parameters per request." + }, + { + "name": "target_type", + "type": "String", + "description": "Filter shares by target_type.\nAvailable values: \"account\", \"organization\"." + } + ] + }, + { + "name": "include_recipient_counts", + "type": "Boolean", + "description": "Include recipient counts in the response." + }, + { + "name": "include_resources", + "type": "Boolean", + "description": "Include resources in the response." + }, + { + "name": "share_id", + "type": "String", + "description": "Share identifier tag." + } + ], + "computed": [ + { + "name": "account_name", + "type": "String", + "description": "The display name of an account." + }, + { + "name": "associated_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "associating_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "disassociated_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "disassociating_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "id", + "type": "String", + "description": "Share identifier tag." + }, + { + "name": "kind", + "type": "String", + "description": "Available values: \"sent\", \"received\"." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the share." + }, + { + "name": "organization_id", + "type": "String", + "description": "Organization identifier." + }, + { + "name": "resources", + "type": "Attributes List", + "description": "A list of resources that are part of the share. This field is only included when requested via the 'include_resources' parameter.", + "children": [ + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "meta", + "type": "String", + "description": "Resource Metadata." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resource_account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_type", + "type": "String", + "description": "Resource Type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "status", + "type": "String", + "description": "Resource Status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"active\", \"deleting\", \"deleted\"." + }, + { + "name": "target_type", + "type": "String", + "description": "Available values: \"account\", \"organization\"." + } + ] + }, + "resource:cloudflare_share": { + "kind": "resource", + "name": "cloudflare_share", + "example": "resource \"cloudflare_share\" \"example_share\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Shared WAF Managed Rule\"\n recipients = [{\n organization_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n recipient_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n }]\n resources = [{\n meta = jsonencode({})\n resource_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_type = \"custom-ruleset\"\n }]\n}", + "importExample": "$ terraform import cloudflare_share.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "name", + "type": "String", + "description": "The name of the share." + }, + { + "name": "recipients", + "type": "Attributes List", + "children": [ + { + "name": "organization_id", + "type": "String", + "description": "Organization identifier." + }, + { + "name": "recipient_account_id", + "type": "String", + "description": "The account that will receive the share." + } + ] + }, + { + "name": "resources", + "type": "Attributes List", + "children": [ + { + "name": "meta", + "type": "String", + "description": "Resource Metadata." + }, + { + "name": "resource_account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_type", + "type": "String", + "description": "Resource Type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + } + ] + } + ], + "optional": [ + { + "name": "include_recipient_counts", + "type": "Boolean", + "description": "Include recipient counts in the response." + }, + { + "name": "include_resources", + "type": "Boolean", + "description": "Include resources in the response." + } + ], + "computed": [ + { + "name": "account_name", + "type": "String", + "description": "The display name of an account." + }, + { + "name": "associated_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "associating_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "disassociated_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "disassociating_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "id", + "type": "String", + "description": "Share identifier tag." + }, + { + "name": "kind", + "type": "String", + "description": "Available values: \"sent\", \"received\"." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "organization_id", + "type": "String", + "description": "Organization identifier." + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"active\", \"deleting\", \"deleted\"." + }, + { + "name": "target_type", + "type": "String", + "description": "Available values: \"account\", \"organization\"." + } + ] + }, + "data-source:cloudflare_share_recipient": { + "kind": "data-source", + "name": "cloudflare_share_recipient", + "example": "data \"cloudflare_share_recipient\" \"example_share_recipient\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n recipient_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_resources = true\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "recipient_id", + "type": "String", + "description": "Share Recipient identifier tag." + }, + { + "name": "share_id", + "type": "String", + "description": "Share identifier tag." + } + ], + "optional": [ + { + "name": "include_resources", + "type": "Boolean", + "description": "Include resources in the response." + } + ], + "computed": [ + { + "name": "association_status", + "type": "String", + "description": "The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\nAvailable values: \"associating\", \"associated\", \"disassociating\", \"disassociated\"." + }, + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Recipient identifier tag." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resources", + "type": "Attributes List", + "children": [ + { + "name": "error", + "type": "String", + "description": "Share Recipient error message." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "terminal", + "type": "Boolean", + "description": "Whether the error is terminal or will be continually retried." + } + ] + } + ] + }, + "resource:cloudflare_share_recipient": { + "kind": "resource", + "name": "cloudflare_share_recipient", + "example": "resource \"cloudflare_share_recipient\" \"example_share_recipient\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n organization_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n recipient_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "importExample": "$ terraform import cloudflare_share_recipient.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "share_id", + "type": "String", + "description": "Share identifier tag." + } + ], + "optional": [ + { + "name": "include_resources", + "type": "Boolean", + "description": "Include resources in the response." + }, + { + "name": "organization_id", + "type": "String", + "description": "Organization identifier." + }, + { + "name": "recipient_account_id", + "type": "String", + "description": "The account that will receive the share." + } + ], + "computed": [ + { + "name": "association_status", + "type": "String", + "description": "The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\nAvailable values: \"associating\", \"associated\", \"disassociating\", \"disassociated\"." + }, + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Recipient identifier tag." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resources", + "type": "Attributes List", + "children": [ + { + "name": "error", + "type": "String", + "description": "Share Recipient error message." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "terminal", + "type": "Boolean", + "description": "Whether the error is terminal or will be continually retried." + } + ] + } + ] + }, + "list-data-source:cloudflare_share_recipients": { + "kind": "list-data-source", + "name": "cloudflare_share_recipients", + "example": "data \"cloudflare_share_recipients\" \"example_share_recipients\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n include_resources = true\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "share_id", + "type": "String", + "description": "Share identifier tag." + } + ], + "optional": [ + { + "name": "include_resources", + "type": "Boolean", + "description": "Include resources in the response." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "association_status", + "type": "String", + "description": "The current state of the recipient relative to the share. The\n`desired_association_status` (not exposed in the response) tracks the\ntarget state set by the API; the background reconciliation workflow\ndrives `current_association_status` toward it.\n\n- `associating` — The recipient was recently added; the workflow is\n pushing shared resources into the recipient account.\n- `associated` — Shared resources have been successfully applied to\n the recipient account.\n- `disassociating` — The recipient was removed (via DELETE or PUT\n replacement); the workflow is removing shared resources from the\n recipient account.\n- `disassociated` — Shared resources have been removed from the\n recipient account. The recipient record remains in the database.\nAvailable values: \"associating\", \"associated\", \"disassociating\", \"disassociated\"." + }, + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Recipient identifier tag." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resources", + "type": "Attributes List", + "children": [ + { + "name": "error", + "type": "String", + "description": "Share Recipient error message." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "terminal", + "type": "Boolean", + "description": "Whether the error is terminal or will be continually retried." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_share_resource": { + "kind": "data-source", + "name": "cloudflare_share_resource", + "example": "data \"cloudflare_share_resource\" \"example_share_resource\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n share_resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "share_id", + "type": "String", + "description": "Share identifier tag." + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "resource_type", + "type": "String", + "description": "Filter share resources by resource_type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + }, + { + "name": "status", + "type": "String", + "description": "Filter share resources by status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + } + ] + }, + { + "name": "share_resource_id", + "type": "String", + "description": "Share Resource identifier." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "meta", + "type": "String", + "description": "Resource Metadata." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resource_account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_type", + "type": "String", + "description": "Resource Type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "status", + "type": "String", + "description": "Resource Status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + } + ] + }, + "resource:cloudflare_share_resource": { + "kind": "resource", + "name": "cloudflare_share_resource", + "example": "resource \"cloudflare_share_resource\" \"example_share_resource\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n meta = jsonencode({})\n resource_account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n resource_type = \"custom-ruleset\"\n}", + "importExample": "$ terraform import cloudflare_share_resource.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "meta", + "type": "String", + "description": "Resource Metadata." + }, + { + "name": "resource_account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_type", + "type": "String", + "description": "Resource Type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + }, + { + "name": "share_id", + "type": "String", + "description": "Share identifier tag." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "status", + "type": "String", + "description": "Resource Status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + } + ] + }, + "list-data-source:cloudflare_share_resources": { + "kind": "list-data-source", + "name": "cloudflare_share_resources", + "example": "data \"cloudflare_share_resources\" \"example_share_resources\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n share_id = \"3fd85f74b32742f1bff64a85009dda07\"\n resource_type = \"custom-ruleset\"\n status = \"active\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "share_id", + "type": "String", + "description": "Share identifier tag." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "resource_type", + "type": "String", + "description": "Filter share resources by resource_type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + }, + { + "name": "status", + "type": "String", + "description": "Filter share resources by status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "meta", + "type": "String", + "description": "Resource Metadata." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resource_account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_type", + "type": "String", + "description": "Resource Type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "status", + "type": "String", + "description": "Resource Status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_shares": { + "kind": "list-data-source", + "name": "cloudflare_shares", + "example": "data \"cloudflare_shares\" \"example_shares\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n include_recipient_counts = true\n include_resources = true\n kind = \"sent\"\n resource_types = [\"custom-ruleset\"]\n status = \"active\"\n tag = [\"env=production\"]\n target_type = \"account\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "Direction to sort objects.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "include_recipient_counts", + "type": "Boolean", + "description": "Include recipient counts in the response." + }, + { + "name": "include_resources", + "type": "Boolean", + "description": "Include resources in the response." + }, + { + "name": "kind", + "type": "String", + "description": "Filter shares by kind.\nAvailable values: \"sent\", \"received\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Order shares by values in the given field.\nAvailable values: \"name\", \"created\"." + }, + { + "name": "resource_types", + "type": "List of String", + "description": "Filter share resources by resource_types." + }, + { + "name": "status", + "type": "String", + "description": "Filter shares by status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + }, + { + "name": "tag", + "type": "List of String", + "description": "Filter shares by tag. Each value is either `key=value` (matches shares whose tags contain that key/value pair) or `key` alone (matches shares that have any value for that key). May be repeated; multiple `tag` parameters are ANDed together. Maximum 20 `tag` parameters per request." + }, + { + "name": "target_type", + "type": "String", + "description": "Filter shares by target_type.\nAvailable values: \"account\", \"organization\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "account_name", + "type": "String", + "description": "The display name of an account." + }, + { + "name": "associated_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'associated' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "associating_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'associating' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "disassociated_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'disassociated' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "disassociating_recipient_count", + "type": "Number", + "description": "The number of recipients in the 'disassociating' state. This field is only included when requested via the 'include_recipient_counts' parameter." + }, + { + "name": "id", + "type": "String", + "description": "Share identifier tag." + }, + { + "name": "kind", + "type": "String", + "description": "Available values: \"sent\", \"received\"." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "name", + "type": "String", + "description": "The name of the share." + }, + { + "name": "organization_id", + "type": "String", + "description": "Organization identifier." + }, + { + "name": "resources", + "type": "Attributes List", + "description": "A list of resources that are part of the share. This field is only included when requested via the 'include_resources' parameter.", + "children": [ + { + "name": "created", + "type": "String", + "description": "When the share was created." + }, + { + "name": "id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "meta", + "type": "String", + "description": "Resource Metadata." + }, + { + "name": "modified", + "type": "String", + "description": "When the share was modified." + }, + { + "name": "resource_account_id", + "type": "String", + "description": "Account identifier." + }, + { + "name": "resource_id", + "type": "String", + "description": "Share Resource identifier." + }, + { + "name": "resource_type", + "type": "String", + "description": "Resource Type.\nAvailable values: \"custom-ruleset\", \"gateway-policy\", \"gateway-destination-ip\", \"gateway-block-page-settings\", \"gateway-extended-email-matching\", \"idp-federation-grant\", \"trust-grant\"." + }, + { + "name": "resource_version", + "type": "Number", + "description": "Resource Version." + }, + { + "name": "status", + "type": "String", + "description": "Resource Status.\nAvailable values: \"active\", \"deleting\", \"deleted\"." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"active\", \"deleting\", \"deleted\"." + }, + { + "name": "target_type", + "type": "String", + "description": "Available values: \"account\", \"organization\"." + } + ] + } + ] + }, + "data-source:cloudflare_snippet": { + "kind": "data-source", + "name": "cloudflare_snippet", + "description": "Accepted Permissions\n\n- `Snippets Read`\n- `Snippets Write`", + "example": "data \"cloudflare_snippet\" \"example_snippet\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n snippet_name = \"my_snippet\"\n}", + "required": [ + { + "name": "snippet_name", + "type": "String", + "description": "Identify the snippet." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Indicates when the snippet was created." + }, + { + "name": "id", + "type": "String", + "description": "Identify the snippet." + }, + { + "name": "modified_on", + "type": "String", + "description": "Indicates when the snippet was last modified." + } + ] + }, + "resource:cloudflare_snippet": { + "kind": "resource", + "name": "cloudflare_snippet", + "description": "Accepted Permissions\n\n- `Snippets Read`\n- `Snippets Write`", + "example": "resource \"cloudflare_snippet\" \"example_snippet\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n snippet_name = \"my_snippet\"\n files = [\n {\n name = \"main.js\"\n content = <<-EOT\n export default {\n async fetch(request) {\n return new Response('Hello, World!');\n }\n }\n EOT\n }\n ]\n metadata = {\n main_module = \"main.js\"\n }\n}", + "importExample": "$ terraform import cloudflare_snippet.example '/'", + "required": [ + { + "name": "files", + "type": "List of Object", + "description": "The list of files belonging to the snippet.", + "children": [ + { + "name": "content", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "metadata", + "type": "Attributes", + "description": "Provide metadata about the snippet.", + "children": [ + { + "name": "main_module", + "type": "String", + "description": "Specify the name of the file that contains the main module of the snippet." + } + ] + }, + { + "name": "snippet_name", + "type": "String", + "description": "Identify the snippet." + }, + { + "name": "zone_id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Indicates when the snippet was created." + }, + { + "name": "id", + "type": "String", + "description": "Identify the snippet." + }, + { + "name": "modified_on", + "type": "String", + "description": "Indicates when the snippet was last modified." + } + ] + }, + "list-data-source:cloudflare_snippet_list": { + "kind": "list-data-source", + "name": "cloudflare_snippet_list", + "description": "Accepted Permissions\n\n- `Snippets Read`\n- `Snippets Write`", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "Indicates when the snippet was created." + }, + { + "name": "id", + "type": "String", + "description": "Identify the snippet." + }, + { + "name": "modified_on", + "type": "String", + "description": "Indicates when the snippet was last modified." + }, + { + "name": "snippet_name", + "type": "String", + "description": "Identify the snippet." + } + ] + } + ] + }, + "data-source:cloudflare_snippet_rules": { + "kind": "data-source", + "name": "cloudflare_snippet_rules", + "description": "Accepted Permissions\n\n- `Snippets Read`\n- `Snippets Write`", + "example": "data \"cloudflare_snippet_rules\" \"example_snippet_rules\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ] + }, + "resource:cloudflare_snippet_rules": { + "kind": "resource", + "name": "cloudflare_snippet_rules", + "description": "Accepted Permissions\n\n- `Snippets Read`\n- `Snippets Write`", + "example": "resource \"cloudflare_snippet_rules\" \"example_snippet_rules\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n rules = [{\n expression = \"ip.src eq 1.1.1.1\"\n snippet_name = \"my_snippet\"\n description = \"Execute my_snippet when IP address is 1.1.1.1.\"\n enabled = true\n }]\n}", + "importExample": "$ terraform import cloudflare_snippet_rules.example ''", + "required": [ + { + "name": "rules", + "type": "Attributes List", + "description": "Lists snippet rules.", + "children": [ + { + "name": "description", + "type": "String", + "description": "Provide an informative description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether to execute the rule." + }, + { + "name": "expression", + "type": "String", + "description": "Define the expression that determines which traffic matches the rule." + }, + { + "name": "id", + "type": "String", + "description": "Specify the unique ID of the rule." + }, + { + "name": "last_updated", + "type": "String", + "description": "Specify the timestamp of when the rule was last modified." + }, + { + "name": "snippet_name", + "type": "String", + "description": "Identify the snippet." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ] + }, + "list-data-source:cloudflare_snippet_rules_list": { + "kind": "list-data-source", + "name": "cloudflare_snippet_rules_list", + "description": "Accepted Permissions\n\n- `Snippets Read`\n- `Snippets Write`", + "example": "data \"cloudflare_snippet_rules_list\" \"example_snippet_rules_list\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Use this field to specify the unique ID of the zone." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "Provide an informative description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether to execute the rule." + }, + { + "name": "expression", + "type": "String", + "description": "Define the expression that determines which traffic matches the rule." + }, + { + "name": "id", + "type": "String", + "description": "Specify the unique ID of the rule." + }, + { + "name": "last_updated", + "type": "String", + "description": "Specify the timestamp of when the rule was last modified." + }, + { + "name": "snippet_name", + "type": "String", + "description": "Identify the snippet." + } + ] + } + ] + }, + "data-source:cloudflare_snippets": { + "kind": "data-source", + "name": "cloudflare_snippets", + "example": "data \"cloudflare_snippets\" \"example_snippets\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}", + "required": [ + { + "name": "snippet_name", + "type": "String", + "description": "The identifying name of the snippet." + }, + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the snippet was created." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the snippet was last modified." + } + ] + }, + "resource:cloudflare_snippets": { + "kind": "resource", + "name": "cloudflare_snippets", + "required": [ + { + "name": "files", + "type": "List of String", + "description": "The list of files belonging to the snippet." + }, + { + "name": "metadata", + "type": "Attributes", + "description": "Metadata about the snippet.", + "children": [ + { + "name": "main_module", + "type": "String", + "description": "Name of the file that contains the main module of the snippet." + } + ] + }, + { + "name": "snippet_name", + "type": "String", + "description": "The identifying name of the snippet." + }, + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the snippet was created." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the snippet was last modified." + } + ] + }, + "list-data-source:cloudflare_snippets_list": { + "kind": "list-data-source", + "name": "cloudflare_snippets_list", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the snippet was created." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the snippet was last modified." + }, + { + "name": "snippet_name", + "type": "String", + "description": "The identifying name of the snippet." + } + ] + } + ] + }, + "data-source:cloudflare_spectrum_application": { + "kind": "data-source", + "name": "cloudflare_spectrum_application", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_spectrum_application\" \"example_spectrum_application\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n app_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "app_id", + "type": "String", + "description": "App identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Sets the direction by which results are ordered.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order", + "type": "String", + "description": "Application field by which results are ordered.\nAvailable values: \"protocol\", \"app_id\", \"created_on\", \"modified_on\", \"dns\"." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Zone identifier." + } + ], + "computed": [ + { + "name": "argo_smart_routing", + "type": "Boolean", + "description": "Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"." + }, + { + "name": "created_on", + "type": "String", + "description": "When the Application was created." + }, + { + "name": "dns", + "type": "Attributes", + "description": "The name and type of DNS record for the Spectrum application.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the DNS record associated with the application." + }, + { + "name": "type", + "type": "String", + "description": "The type of DNS record associated with the application.\nAvailable values: \"CNAME\", \"ADDRESS\"." + } + ] + }, + { + "name": "edge_ips", + "type": "Attributes", + "description": "The anycast edge IP configuration for the hostname of this application.", + "children": [ + { + "name": "connectivity", + "type": "String", + "description": "The IP versions supported for inbound connections on Spectrum anycast IPs.\nAvailable values: \"all\", \"ipv4\", \"ipv6\"." + }, + { + "name": "ips", + "type": "List of String", + "description": "The array of customer owned IPs we broadcast via anycast for this hostname and application." + }, + { + "name": "type", + "type": "String", + "description": "The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names.\nAvailable values: \"dynamic\", \"static\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "App identifier." + }, + { + "name": "ip_firewall", + "type": "Boolean", + "description": "Enables IP Access Rules for this application.\nNotes: Only available for TCP applications." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Application was last modified." + }, + { + "name": "origin_direct", + "type": "List of String", + "description": "List of origin IP addresses. Array may contain multiple IP addresses for load balancing." + }, + { + "name": "origin_dns", + "type": "Attributes", + "description": "The name and type of DNS record for the Spectrum application.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the DNS record associated with the origin." + }, + { + "name": "ttl", + "type": "Number", + "description": "The TTL of our resolution of your DNS record in seconds." + }, + { + "name": "type", + "type": "String", + "description": "The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records.\nAvailable values: \"\", \"A\", \"AAAA\", \"SRV\"." + } + ] + }, + { + "name": "origin_port", + "type": "Dynamic", + "description": "The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field." + }, + { + "name": "origin_worker_id", + "type": "String", + "description": "Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"." + }, + { + "name": "protocol", + "type": "String", + "description": "The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`." + }, + { + "name": "proxy_protocol", + "type": "String", + "description": "Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol.\nAvailable values: \"off\", \"v1\", \"v2\", \"simple\"." + }, + { + "name": "tls", + "type": "String", + "description": "The type of TLS termination associated with the application.\nAvailable values: \"off\", \"flexible\", \"full\", \"strict\"." + }, + { + "name": "traffic_type", + "type": "String", + "description": "Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`.\nAvailable values: \"direct\", \"http\", \"https\", \"worker\"." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks." + } + ] + }, + "resource:cloudflare_spectrum_application": { + "kind": "resource", + "name": "cloudflare_spectrum_application", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "resource \"cloudflare_spectrum_application\" \"example_spectrum_application\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dns = {\n name = \"ssh.example.com\"\n type = \"CNAME\"\n }\n protocol = \"tcp/22\"\n traffic_type = \"direct\"\n argo_smart_routing = true\n edge_ips = {\n connectivity = \"all\"\n type = \"dynamic\"\n }\n ip_firewall = false\n origin_direct = [\"tcp://127.0.0.1:8080\"]\n origin_dns = {\n name = \"origin.example.com\"\n ttl = 600\n type = \"\"\n }\n origin_port = 22\n origin_worker_id = \"277b7815c871434b960b60729659000a\"\n proxy_protocol = \"off\"\n tls = \"off\"\n virtual_network_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "importExample": "$ terraform import cloudflare_spectrum_application.example '/'", + "required": [ + { + "name": "dns", + "type": "Attributes", + "description": "The name and type of DNS record for the Spectrum application.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the DNS record associated with the application." + }, + { + "name": "type", + "type": "String", + "description": "The type of DNS record associated with the application.\nAvailable values: \"CNAME\", \"ADDRESS\"." + } + ] + }, + { + "name": "protocol", + "type": "String", + "description": "The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`." + }, + { + "name": "zone_id", + "type": "String", + "description": "Zone identifier." + } + ], + "optional": [ + { + "name": "argo_smart_routing", + "type": "Boolean", + "description": "Enables Argo Smart Routing for this application.\nNotes: Only available for TCP or UDP applications with traffic_type set to \"direct\"." + }, + { + "name": "edge_ips", + "type": "Attributes", + "description": "The anycast edge IP configuration for the hostname of this application.", + "children": [ + { + "name": "connectivity", + "type": "String", + "description": "The IP versions supported for inbound connections on Spectrum anycast IPs.\nAvailable values: \"all\", \"ipv4\", \"ipv6\"." + }, + { + "name": "ips", + "type": "List of String", + "description": "The array of customer owned IPs we broadcast via anycast for this hostname and application." + }, + { + "name": "type", + "type": "String", + "description": "The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names.\nAvailable values: \"dynamic\", \"static\"." + } + ] + }, + { + "name": "ip_firewall", + "type": "Boolean", + "description": "Enables IP Access Rules for this application.\nNotes: Only available for TCP applications." + }, + { + "name": "origin_direct", + "type": "List of String", + "description": "List of origin IP addresses. Array may contain multiple IP addresses for load balancing." + }, + { + "name": "origin_dns", + "type": "Attributes", + "description": "The name and type of DNS record for the Spectrum application.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the DNS record associated with the origin." + }, + { + "name": "ttl", + "type": "Number", + "description": "The TTL of our resolution of your DNS record in seconds." + }, + { + "name": "type", + "type": "String", + "description": "The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records.\nAvailable values: \"\", \"A\", \"AAAA\", \"SRV\"." + } + ] + }, + { + "name": "origin_port", + "type": "Dynamic", + "description": "The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field." + }, + { + "name": "origin_worker_id", + "type": "String", + "description": "Optional Worker script tag (worker ID) to use as the application's origin. Only supported for TCP applications with traffic_type \"worker\"; mutually exclusive with origin_direct, origin_dns, origin_port, proxy_protocol, and argo_smart_routing. tls may only be \"off\" or \"flexible\"." + }, + { + "name": "proxy_protocol", + "type": "String", + "description": "Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol.\nAvailable values: \"off\", \"v1\", \"v2\", \"simple\"." + }, + { + "name": "tls", + "type": "String", + "description": "The type of TLS termination associated with the application.\nAvailable values: \"off\", \"flexible\", \"full\", \"strict\"." + }, + { + "name": "traffic_type", + "type": "String", + "description": "Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly. When set to \"worker\", traffic is sent to the Worker specified by `origin_worker_id`.\nAvailable values: \"direct\", \"http\", \"https\", \"worker\"." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "Optional UUID of a virtual network for routing origin traffic through tunnel virtual networks." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the Application was created." + }, + { + "name": "id", + "type": "String", + "description": "App identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Application was last modified." + } + ] + }, + "list-data-source:cloudflare_spectrum_applications": { + "kind": "list-data-source", + "name": "cloudflare_spectrum_applications", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_spectrum_applications\" \"example_spectrum_applications\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "Sets the direction by which results are ordered.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Application field by which results are ordered.\nAvailable values: \"protocol\", \"app_id\", \"created_on\", \"modified_on\", \"dns\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Zone identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "argo_smart_routing", + "type": "Boolean", + "description": "Enables Argo Smart Routing for this application.\nNotes: Only available for TCP applications with traffic_type set to \"direct\"." + }, + { + "name": "created_on", + "type": "String", + "description": "When the Application was created." + }, + { + "name": "dns", + "type": "Attributes", + "description": "The name and type of DNS record for the Spectrum application.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the DNS record associated with the application." + }, + { + "name": "type", + "type": "String", + "description": "The type of DNS record associated with the application.\nAvailable values: \"CNAME\", \"ADDRESS\"." + } + ] + }, + { + "name": "edge_ips", + "type": "Attributes", + "description": "The anycast edge IP configuration for the hostname of this application.", + "children": [ + { + "name": "connectivity", + "type": "String", + "description": "The IP versions supported for inbound connections on Spectrum anycast IPs.\nAvailable values: \"all\", \"ipv4\", \"ipv6\"." + }, + { + "name": "ips", + "type": "List of String", + "description": "The array of customer owned IPs we broadcast via anycast for this hostname and application." + }, + { + "name": "type", + "type": "String", + "description": "The type of edge IP configuration specified. Dynamically allocated edge IPs use Spectrum anycast IPs in accordance with the connectivity you specify. Only valid with CNAME DNS names.\nAvailable values: \"dynamic\", \"static\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "App identifier." + }, + { + "name": "ip_firewall", + "type": "Boolean", + "description": "Enables IP Access Rules for this application.\nNotes: Only available for TCP applications." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the Application was last modified." + }, + { + "name": "origin_direct", + "type": "List of String", + "description": "List of origin IP addresses. Array may contain multiple IP addresses for load balancing." + }, + { + "name": "origin_dns", + "type": "Attributes", + "description": "The name and type of DNS record for the Spectrum application.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the DNS record associated with the origin." + }, + { + "name": "ttl", + "type": "Number", + "description": "The TTL of our resolution of your DNS record in seconds." + }, + { + "name": "type", + "type": "String", + "description": "The type of DNS record associated with the origin. \"\" is used to specify a combination of A/AAAA records.\nAvailable values: \"\", \"A\", \"AAAA\", \"SRV\"." + } + ] + }, + { + "name": "origin_port", + "type": "Dynamic", + "description": "The destination port at the origin. Only specified in conjunction with origin_dns. May use an integer to specify a single origin port, for example `1000`, or a string to specify a range of origin ports, for example `\"1000-2000\"`.\nNotes: If specifying a port range, the number of ports in the range must match the number of ports specified in the \"protocol\" field." + }, + { + "name": "protocol", + "type": "String", + "description": "The port configuration at Cloudflare's edge. May specify a single port, for example `\"tcp/1000\"`, or a range of ports, for example `\"tcp/1000-2000\"`." + }, + { + "name": "proxy_protocol", + "type": "String", + "description": "Enables Proxy Protocol to the origin. Refer to [Enable Proxy protocol](https://developers.cloudflare.com/spectrum/getting-started/proxy-protocol/) for implementation details on PROXY Protocol V1, PROXY Protocol V2, and Simple Proxy Protocol.\nAvailable values: \"off\", \"v1\", \"v2\", \"simple\"." + }, + { + "name": "tls", + "type": "String", + "description": "The type of TLS termination associated with the application.\nAvailable values: \"off\", \"flexible\", \"full\", \"strict\"." + }, + { + "name": "traffic_type", + "type": "String", + "description": "Determines how data travels from the edge to your origin. When set to \"direct\", Spectrum will send traffic directly to your origin, and the application's type is derived from the `protocol`. When set to \"http\" or \"https\", Spectrum will apply Cloudflare's HTTP/HTTPS features as it sends traffic to your origin, and the application type matches this property exactly.\nAvailable values: \"direct\", \"http\", \"https\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_spectrum_protocols": { + "kind": "list-data-source", + "name": "cloudflare_spectrum_protocols", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_spectrum_protocols\" \"example_spectrum_protocols\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Zone identifier." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "The full name of the application protocol." + }, + { + "name": "name", + "type": "String", + "description": "The short name of the application protocol." + }, + { + "name": "ports", + "type": "List of Number", + "description": "The available listening ports for the given protocol." + }, + { + "name": "transport", + "type": "String", + "description": "The transport layer protocol used by the application protocol" + } + ] + } + ] + }, + "data-source:cloudflare_sso_connector": { + "kind": "data-source", + "name": "cloudflare_sso_connector", + "description": "Accepted Permissions\n\n- `SSO Connector Read`", + "example": "data \"cloudflare_sso_connector\" \"example_sso_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n sso_connector_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "sso_connector_id", + "type": "String", + "description": "SSO Connector identifier tag." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the SSO connector" + }, + { + "name": "email_domain", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "SSO Connector identifier tag." + }, + { + "name": "updated_on", + "type": "String", + "description": "Timestamp for the last update of the SSO connector" + }, + { + "name": "use_fedramp_language", + "type": "Boolean", + "description": "Controls the display of FedRAMP language to the user during SSO login" + }, + { + "name": "verification", + "type": "Attributes", + "children": [ + { + "name": "code", + "type": "String", + "description": "DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership." + }, + { + "name": "status", + "type": "String", + "description": "The status of the verification code from the verification process.\nAvailable values: \"awaiting\", \"pending\", \"failed\", \"verified\"." + } + ] + } + ] + }, + "resource:cloudflare_sso_connector": { + "kind": "resource", + "name": "cloudflare_sso_connector", + "description": "Accepted Permissions\n\n- `SSO Connector Read`\n- `SSO Connector Write`", + "example": "resource \"cloudflare_sso_connector\" \"example_sso_connector\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n email_domain = \"example.com\"\n begin_verification = true\n use_fedramp_language = false\n}", + "importExample": "$ terraform import cloudflare_sso_connector.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "email_domain", + "type": "String", + "description": "Email domain of the new SSO connector" + } + ], + "optional": [ + { + "name": "begin_verification", + "type": "Boolean", + "description": "Begin the verification process after creation" + }, + { + "name": "enabled", + "type": "Boolean", + "description": "SSO Connector enabled state" + }, + { + "name": "use_fedramp_language", + "type": "Boolean", + "description": "Controls the display of FedRAMP language to the user during SSO login" + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the SSO connector" + }, + { + "name": "id", + "type": "String", + "description": "SSO Connector identifier tag." + }, + { + "name": "updated_on", + "type": "String", + "description": "Timestamp for the last update of the SSO connector" + }, + { + "name": "verification", + "type": "Attributes", + "children": [ + { + "name": "code", + "type": "String", + "description": "DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership." + }, + { + "name": "status", + "type": "String", + "description": "The status of the verification code from the verification process.\nAvailable values: \"awaiting\", \"pending\", \"failed\", \"verified\"." + } + ] + } + ] + }, + "list-data-source:cloudflare_sso_connectors": { + "kind": "list-data-source", + "name": "cloudflare_sso_connectors", + "description": "Accepted Permissions\n\n- `SSO Connector Read`", + "example": "data \"cloudflare_sso_connectors\" \"example_sso_connectors\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the SSO connector" + }, + { + "name": "email_domain", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "SSO Connector identifier tag." + }, + { + "name": "updated_on", + "type": "String", + "description": "Timestamp for the last update of the SSO connector" + }, + { + "name": "use_fedramp_language", + "type": "Boolean", + "description": "Controls the display of FedRAMP language to the user during SSO login" + }, + { + "name": "verification", + "type": "Attributes", + "children": [ + { + "name": "code", + "type": "String", + "description": "DNS verification code. Add this entire string to the DNS TXT record of the email domain to validate ownership." + }, + { + "name": "status", + "type": "String", + "description": "The status of the verification code from the verification process.\nAvailable values: \"awaiting\", \"pending\", \"failed\", \"verified\"." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_stream": { + "kind": "data-source", + "name": "cloudflare_stream", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream\" \"example_stream\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ], + "optional": [], + "computed": [ + { + "name": "allowed_origins", + "type": "List of String", + "description": "Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin." + }, + { + "name": "clipped_from", + "type": "String", + "description": "The unique identifier of the source video this video was clipped from." + }, + { + "name": "created", + "type": "String", + "description": "The date and time the media item was created." + }, + { + "name": "creator", + "type": "String", + "description": "A user-defined identifier for the media creator." + }, + { + "name": "duration", + "type": "Number", + "description": "The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready." + }, + { + "name": "input", + "type": "Attributes", + "children": [ + { + "name": "height", + "type": "Number", + "description": "The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready." + }, + { + "name": "width", + "type": "Number", + "description": "The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready." + } + ] + }, + { + "name": "live_input", + "type": "String", + "description": "The live input ID used to upload a video with Stream Live." + }, + { + "name": "max_duration_seconds", + "type": "Number", + "description": "The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown." + }, + { + "name": "max_size_bytes", + "type": "Number", + "description": "The maximum size in bytes for the video upload." + }, + { + "name": "meta", + "type": "String", + "description": "A user modifiable key-value store used to reference other systems of record for managing videos." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the media item was last modified." + }, + { + "name": "playback", + "type": "Attributes", + "children": [ + { + "name": "dash", + "type": "String", + "description": "DASH Media Presentation Description for the video." + }, + { + "name": "hls", + "type": "String", + "description": "The HLS manifest for the video." + } + ] + }, + { + "name": "preview", + "type": "String", + "description": "The video's preview page URI. This field is omitted until encoding is complete." + }, + { + "name": "public_details", + "type": "Attributes", + "description": "Public details for the video including title, share link, channel link, and logo.", + "children": [ + { + "name": "channel_link", + "type": "String" + }, + { + "name": "logo", + "type": "String" + }, + { + "name": "media_id", + "type": "Number" + }, + { + "name": "share_link", + "type": "String" + }, + { + "name": "title", + "type": "String" + } + ] + }, + { + "name": "ready_to_stream", + "type": "Boolean", + "description": "Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress." + }, + { + "name": "ready_to_stream_at", + "type": "String", + "description": "Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress." + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video." + }, + { + "name": "scheduled_deletion", + "type": "String", + "description": "Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the media item in bytes." + }, + { + "name": "status", + "type": "Attributes", + "description": "Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.", + "children": [ + { + "name": "error_reason_code", + "type": "String", + "description": "Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use." + }, + { + "name": "error_reason_text", + "type": "String", + "description": "Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state." + }, + { + "name": "pct_complete", + "type": "String", + "description": "Indicates the size of the entire upload in bytes. The value must be a non-negative integer." + }, + { + "name": "state", + "type": "String", + "description": "Specifies the processing status for all quality levels for a video.\nAvailable values: \"pendingupload\", \"downloading\", \"queued\", \"inprogress\", \"ready\", \"error\", \"live-inprogress\"." + } + ] + }, + { + "name": "thumbnail", + "type": "String", + "description": "The media item's thumbnail URI. This field is omitted until encoding is complete." + }, + { + "name": "thumbnail_timestamp_pct", + "type": "Number", + "description": "The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + }, + { + "name": "upload_expiry", + "type": "String", + "description": "The date and time when the video upload URL is no longer valid for direct user uploads." + }, + { + "name": "uploaded", + "type": "String", + "description": "The date and time the media item was uploaded." + }, + { + "name": "watermark", + "type": "Attributes", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and a time a watermark profile was created." + }, + { + "name": "downloaded_from", + "type": "String", + "description": "The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null." + }, + { + "name": "height", + "type": "Number", + "description": "The height of the image in pixels." + }, + { + "name": "name", + "type": "String", + "description": "A short description of the watermark profile." + }, + { + "name": "opacity", + "type": "Number", + "description": "The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque." + }, + { + "name": "padding", + "type": "Number", + "description": "The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm." + }, + { + "name": "position", + "type": "String", + "description": "The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter." + }, + { + "name": "scale", + "type": "Number", + "description": "The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the image in bytes." + }, + { + "name": "uid", + "type": "String", + "description": "The unique identifier for a watermark profile." + }, + { + "name": "width", + "type": "Number", + "description": "The width of the image in pixels." + } + ] + } + ] + }, + "resource:cloudflare_stream": { + "kind": "resource", + "name": "cloudflare_stream", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream\" \"example_stream\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + } + ], + "optional": [ + { + "name": "allowed_origins", + "type": "List of String", + "description": "Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin." + }, + { + "name": "creator", + "type": "String", + "description": "A user-defined identifier for the media creator." + }, + { + "name": "direct_user", + "type": "Boolean", + "description": "Provisions a URL to let your end users upload videos directly to Cloudflare Stream without exposing your API token to clients." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + }, + { + "name": "max_duration_seconds", + "type": "Number", + "description": "The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown." + }, + { + "name": "meta", + "type": "String", + "description": "A user modifiable key-value store used to reference other systems of record for managing videos." + }, + { + "name": "public_details", + "type": "Attributes", + "description": "Public details for the video including title, share link, channel link, and logo.", + "children": [ + { + "name": "channel_link", + "type": "String" + }, + { + "name": "logo", + "type": "String" + }, + { + "name": "share_link", + "type": "String" + }, + { + "name": "title", + "type": "String" + } + ] + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video." + }, + { + "name": "scheduled_deletion", + "type": "String", + "description": "Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time." + }, + { + "name": "thumbnail_timestamp_pct", + "type": "Number", + "description": "The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video." + }, + { + "name": "uid", + "type": "String", + "description": "The unique identifier for the video. Can be used to verify the video being updated." + }, + { + "name": "upload_expiry", + "type": "String", + "description": "The date and time when the video upload URL is no longer valid for direct user uploads." + } + ], + "computed": [ + { + "name": "clipped_from", + "type": "String", + "description": "The unique identifier of the source video this video was clipped from." + }, + { + "name": "created", + "type": "String", + "description": "The date and time the media item was created." + }, + { + "name": "duration", + "type": "Number", + "description": "The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready." + }, + { + "name": "input", + "type": "Attributes", + "children": [ + { + "name": "height", + "type": "Number", + "description": "The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready." + }, + { + "name": "width", + "type": "Number", + "description": "The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready." + } + ] + }, + { + "name": "live_input", + "type": "String", + "description": "The live input ID used to upload a video with Stream Live." + }, + { + "name": "max_size_bytes", + "type": "Number", + "description": "The maximum size in bytes for the video upload." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the media item was last modified." + }, + { + "name": "playback", + "type": "Attributes", + "children": [ + { + "name": "dash", + "type": "String", + "description": "DASH Media Presentation Description for the video." + }, + { + "name": "hls", + "type": "String", + "description": "The HLS manifest for the video." + } + ] + }, + { + "name": "preview", + "type": "String", + "description": "The video's preview page URI. This field is omitted until encoding is complete." + }, + { + "name": "ready_to_stream", + "type": "Boolean", + "description": "Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress." + }, + { + "name": "ready_to_stream_at", + "type": "String", + "description": "Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the media item in bytes." + }, + { + "name": "status", + "type": "Attributes", + "description": "Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.", + "children": [ + { + "name": "error_reason_code", + "type": "String", + "description": "Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use." + }, + { + "name": "error_reason_text", + "type": "String", + "description": "Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state." + }, + { + "name": "pct_complete", + "type": "String", + "description": "Indicates the size of the entire upload in bytes. The value must be a non-negative integer." + }, + { + "name": "state", + "type": "String", + "description": "Specifies the processing status for all quality levels for a video.\nAvailable values: \"pendingupload\", \"downloading\", \"queued\", \"inprogress\", \"ready\", \"error\", \"live-inprogress\"." + } + ] + }, + { + "name": "thumbnail", + "type": "String", + "description": "The media item's thumbnail URI. This field is omitted until encoding is complete." + }, + { + "name": "uploaded", + "type": "String", + "description": "The date and time the media item was uploaded." + }, + { + "name": "watermark", + "type": "Attributes", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and a time a watermark profile was created." + }, + { + "name": "downloaded_from", + "type": "String", + "description": "The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null." + }, + { + "name": "height", + "type": "Number", + "description": "The height of the image in pixels." + }, + { + "name": "name", + "type": "String", + "description": "A short description of the watermark profile." + }, + { + "name": "opacity", + "type": "Number", + "description": "The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque." + }, + { + "name": "padding", + "type": "Number", + "description": "The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm." + }, + { + "name": "position", + "type": "String", + "description": "The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter." + }, + { + "name": "scale", + "type": "Number", + "description": "The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the image in bytes." + }, + { + "name": "uid", + "type": "String", + "description": "The unique identifier for a watermark profile." + }, + { + "name": "width", + "type": "Number", + "description": "The width of the image in pixels." + } + ] + } + ] + }, + "data-source:cloudflare_stream_audio_track": { + "kind": "data-source", + "name": "cloudflare_stream_audio_track", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_audio_track\" \"example_stream_audio_track\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ], + "optional": [], + "computed": [ + { + "name": "audio", + "type": "Attributes List", + "description": "Array of audio tracks for the video.", + "children": [ + { + "name": "default", + "type": "Boolean", + "description": "Denotes whether the audio track will be played by default in a player." + }, + { + "name": "label", + "type": "String", + "description": "A string to uniquely identify the track amongst other audio track labels for the specified video." + }, + { + "name": "status", + "type": "String", + "description": "Specifies the processing status of the video.\nAvailable values: \"queued\", \"ready\", \"error\"." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ] + } + ] + }, + "resource:cloudflare_stream_audio_track": { + "kind": "resource", + "name": "cloudflare_stream_audio_track", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream_audio_track\" \"example_stream_audio_track\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n audio_identifier = \"ea95132c15732412d22c1476fa83f27a\"\n default = true\n label = \"director commentary\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ], + "optional": [ + { + "name": "audio_identifier", + "type": "String", + "description": "The unique identifier for an additional audio track." + }, + { + "name": "default", + "type": "Boolean", + "description": "Denotes whether the audio track will be played by default in a player." + }, + { + "name": "label", + "type": "String", + "description": "A string to uniquely identify the track amongst other audio track labels for the specified video." + } + ], + "computed": [ + { + "name": "audio", + "type": "Attributes List", + "description": "Array of audio tracks for the video.", + "children": [ + { + "name": "default", + "type": "Boolean", + "description": "Denotes whether the audio track will be played by default in a player." + }, + { + "name": "label", + "type": "String", + "description": "A string to uniquely identify the track amongst other audio track labels for the specified video." + }, + { + "name": "status", + "type": "String", + "description": "Specifies the processing status of the video.\nAvailable values: \"queued\", \"ready\", \"error\"." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "Specifies the processing status of the video.\nAvailable values: \"queued\", \"ready\", \"error\"." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ] + }, + "data-source:cloudflare_stream_caption_language": { + "kind": "data-source", + "name": "cloudflare_stream_caption_language", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_caption_language\" \"example_stream_caption_language\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n language = \"tr\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + }, + { + "name": "language", + "type": "String", + "description": "The language tag in BCP 47 format." + } + ], + "optional": [], + "computed": [ + { + "name": "generated", + "type": "Boolean", + "description": "Whether the caption was generated via AI." + }, + { + "name": "label", + "type": "String", + "description": "The language label displayed in the native language to users." + }, + { + "name": "status", + "type": "String", + "description": "The status of a generated caption.\nAvailable values: \"ready\", \"inprogress\", \"error\"." + } + ] + }, + "resource:cloudflare_stream_caption_language": { + "kind": "resource", + "name": "cloudflare_stream_caption_language", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream_caption_language\" \"example_stream_caption_language\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n language = \"tr\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + }, + { + "name": "language", + "type": "String", + "description": "The language tag in BCP 47 format." + } + ], + "optional": [ + { + "name": "file", + "type": "String", + "description": "The WebVTT file containing the caption or subtitle content." + } + ], + "computed": [ + { + "name": "generated", + "type": "Boolean", + "description": "Whether the caption was generated via AI." + }, + { + "name": "label", + "type": "String", + "description": "The language label displayed in the native language to users." + }, + { + "name": "status", + "type": "String", + "description": "The status of a generated caption.\nAvailable values: \"ready\", \"inprogress\", \"error\"." + } + ] + }, + "data-source:cloudflare_stream_download": { + "kind": "data-source", + "name": "cloudflare_stream_download", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_download\" \"example_stream_download\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ], + "optional": [], + "computed": [] + }, + "resource:cloudflare_stream_download": { + "kind": "resource", + "name": "cloudflare_stream_download", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream_download\" \"example_stream_download\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "identifier", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + } + ], + "optional": [], + "computed": [ + { + "name": "audio", + "type": "Attributes", + "description": "The audio-only download. Only present if this download type has been created.", + "children": [ + { + "name": "percent_complete", + "type": "Number", + "description": "Indicates the progress as a percentage between 0 and 100." + }, + { + "name": "status", + "type": "String", + "description": "The status of a generated download.\nAvailable values: \"ready\", \"inprogress\", \"error\"." + }, + { + "name": "url", + "type": "String", + "description": "The URL to access the generated download." + } + ] + }, + { + "name": "default", + "type": "Attributes", + "description": "The default video download. Only present if this download type has been created.", + "children": [ + { + "name": "percent_complete", + "type": "Number", + "description": "Indicates the progress as a percentage between 0 and 100." + }, + { + "name": "status", + "type": "String", + "description": "The status of a generated download.\nAvailable values: \"ready\", \"inprogress\", \"error\"." + }, + { + "name": "url", + "type": "String", + "description": "The URL to access the generated download." + } + ] + } + ] + }, + "data-source:cloudflare_stream_key": { + "kind": "data-source", + "name": "cloudflare_stream_key", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_key\" \"example_stream_key\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time a signing key was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "key_id", + "type": "String", + "description": "The unique identifier for the signing key." + } + ] + }, + "resource:cloudflare_stream_key": { + "kind": "resource", + "name": "cloudflare_stream_key", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream_key\" \"example_stream_key\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "importExample": "$ terraform import cloudflare_stream_key.example ''", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time a signing key was created." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "jwk", + "type": "String", + "description": "The signing key in JWK format.", + "sensitive": true + }, + { + "name": "key_id", + "type": "String", + "description": "The unique identifier for the signing key." + }, + { + "name": "pem", + "type": "String", + "description": "The signing key in PEM format.", + "sensitive": true + } + ] + }, + "data-source:cloudflare_stream_live_input": { + "kind": "data-source", + "name": "cloudflare_stream_live_input", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_live_input\" \"example_stream_live_input\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n live_input_identifier = \"66be4bf738797e01e1fca35a7bdecdcd\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "live_input_identifier", + "type": "String", + "description": "A unique identifier for a live input." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the live input was created." + }, + { + "name": "delete_recording_after_days", + "type": "Number", + "description": "Indicates the number of days after which the live inputs recordings will be deleted. When a stream completes and the recording is ready, the value is used to calculate a scheduled deletion date for that recording. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether the live input is enabled and can accept streams." + }, + { + "name": "keys_rotated_at", + "type": "String", + "description": "The date and time the live input keys were last rotated. Omitted for live inputs that have never had their keys rotated." + }, + { + "name": "meta", + "type": "String", + "description": "A user modifiable key-value store used to reference other systems of record for managing live inputs." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the live input was last modified." + }, + { + "name": "playback", + "type": "Attributes", + "description": "Details for playing a live input's broadcast using the HLS or DASH manifests. URLs reference the live input ID.", + "children": [ + { + "name": "dash", + "type": "String", + "description": "The DASH manifest URL used to play live video, referencing the live input ID." + }, + { + "name": "hls", + "type": "String", + "description": "The HLS manifest URL used to play live video, referencing the live input ID." + } + ] + }, + { + "name": "prefer_low_latency", + "type": "Boolean", + "description": "When enabled, the live stream is delivered using Low-Latency HLS (LL-HLS), reducing glass-to-glass latency for viewers at the cost of reduced player compatibility." + }, + { + "name": "recording", + "type": "Attributes", + "description": "Records the input to a Cloudflare Stream video. Behavior depends on the mode. In most cases, the video will initially be viewable as a live video and transition to on-demand after a condition is satisfied.", + "children": [ + { + "name": "allowed_origins", + "type": "List of String", + "description": "Lists the origins allowed to display videos created with this input. Enter allowed origin domains in an array and use `*` for wildcard subdomains. An empty array allows videos to be viewed on any origin." + }, + { + "name": "hide_live_viewer_count", + "type": "Boolean", + "description": "Disables reporting the number of live viewers when this property is set to `true`." + }, + { + "name": "mode", + "type": "String", + "description": "Specifies the recording behavior for the live input. Set this value to `off` to prevent a recording. Set the value to `automatic` to begin a recording and transition to on-demand after Stream Live stops receiving input.\nAvailable values: \"off\", \"automatic\"." + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates if a video using the live input has the `requireSignedURLs` property set. Also enforces access controls on any video recording of the livestream with the live input." + }, + { + "name": "timeout_seconds", + "type": "Number", + "description": "Determines the amount of time a live input configured in `automatic` mode should wait before a recording transitions from live to on-demand. `0` is recommended for most use cases and indicates the platform default should be used." + } + ] + }, + { + "name": "rtmps", + "type": "Attributes", + "description": "Details for streaming to an live input using RTMPS.", + "children": [ + { + "name": "stream_key", + "type": "String", + "description": "The secret key to use when streaming via RTMPS to a live input.", + "sensitive": true + }, + { + "name": "url", + "type": "String", + "description": "The RTMPS URL you provide to the broadcaster, which they stream live video to.", + "sensitive": true + } + ] + }, + { + "name": "rtmps_playback", + "type": "Attributes", + "description": "Details for playback from an live input using RTMPS.", + "children": [ + { + "name": "stream_key", + "type": "String", + "description": "The secret key to use for playback via RTMPS.", + "sensitive": true + }, + { + "name": "url", + "type": "String", + "description": "The URL used to play live video over RTMPS.", + "sensitive": true + } + ] + }, + { + "name": "srt", + "type": "Attributes", + "description": "Details for streaming to a live input using SRT.", + "children": [ + { + "name": "passphrase", + "type": "String", + "description": "The secret key to use when streaming via SRT to a live input.", + "sensitive": true + }, + { + "name": "stream_id", + "type": "String", + "description": "The identifier of the live input to use when streaming via SRT." + }, + { + "name": "url", + "type": "String", + "description": "The SRT URL you provide to the broadcaster, which they stream live video to.", + "sensitive": true + } + ] + }, + { + "name": "srt_playback", + "type": "Attributes", + "description": "Details for playback from an live input using SRT.", + "children": [ + { + "name": "passphrase", + "type": "String", + "description": "The secret key to use for playback via SRT.", + "sensitive": true + }, + { + "name": "stream_id", + "type": "String", + "description": "The identifier of the live input to use for playback via SRT." + }, + { + "name": "url", + "type": "String", + "description": "The URL used to play live video over SRT.", + "sensitive": true + } + ] + }, + { + "name": "status", + "type": "String", + "description": "The connection status of a live input.\nAvailable values: \"connected\", \"reconnected\", \"reconnecting\", \"client_disconnect\", \"ttl_exceeded\", \"failed_to_connect\", \"failed_to_reconnect\", \"new_configuration_accepted\"." + }, + { + "name": "uid", + "type": "String", + "description": "A unique identifier for a live input." + }, + { + "name": "web_rtc", + "type": "Attributes", + "description": "Details for streaming to a live input using WebRTC.", + "children": [ + { + "name": "url", + "type": "String", + "description": "The WebRTC URL you provide to the broadcaster, which they stream live video to.", + "sensitive": true + } + ] + }, + { + "name": "web_rtc_playback", + "type": "Attributes", + "description": "Details for playback from a live input using WebRTC.", + "children": [ + { + "name": "url", + "type": "String", + "description": "The URL used to play live video over WebRTC.", + "sensitive": true + } + ] + } + ] + }, + "resource:cloudflare_stream_live_input": { + "kind": "resource", + "name": "cloudflare_stream_live_input", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream_live_input\" \"example_stream_live_input\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n default_creator = \"defaultCreator\"\n delete_recording_after_days = 45\n enabled = true\n meta = jsonencode({\n name = \"test stream 1\"\n })\n prefer_low_latency = true\n recording = {\n allowed_origins = [\"example.com\"]\n hide_live_viewer_count = false\n mode = \"off\"\n require_signed_urls = false\n timeout_seconds = 0\n }\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "default_creator", + "type": "String", + "description": "Sets the creator ID asssociated with this live input." + }, + { + "name": "delete_recording_after_days", + "type": "Number", + "description": "Indicates the number of days after which the live inputs recordings will be deleted. When a stream completes and the recording is ready, the value is used to calculate a scheduled deletion date for that recording. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Indicates whether the live input is enabled and can accept streams." + }, + { + "name": "live_input_identifier", + "type": "String", + "description": "A unique identifier for a live input." + }, + { + "name": "meta", + "type": "String", + "description": "A user modifiable key-value store used to reference other systems of record for managing live inputs." + }, + { + "name": "prefer_low_latency", + "type": "Boolean", + "description": "When enabled, the live stream is delivered using Low-Latency HLS (LL-HLS), reducing glass-to-glass latency for viewers at the cost of reduced player compatibility." + }, + { + "name": "recording", + "type": "Attributes", + "description": "Records the input to a Cloudflare Stream video. Behavior depends on the mode. In most cases, the video will initially be viewable as a live video and transition to on-demand after a condition is satisfied.", + "children": [ + { + "name": "allowed_origins", + "type": "List of String", + "description": "Lists the origins allowed to display videos created with this input. Enter allowed origin domains in an array and use `*` for wildcard subdomains. An empty array allows videos to be viewed on any origin." + }, + { + "name": "hide_live_viewer_count", + "type": "Boolean", + "description": "Disables reporting the number of live viewers when this property is set to `true`." + }, + { + "name": "mode", + "type": "String", + "description": "Specifies the recording behavior for the live input. Set this value to `off` to prevent a recording. Set the value to `automatic` to begin a recording and transition to on-demand after Stream Live stops receiving input.\nAvailable values: \"off\", \"automatic\"." + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates if a video using the live input has the `requireSignedURLs` property set. Also enforces access controls on any video recording of the livestream with the live input." + }, + { + "name": "timeout_seconds", + "type": "Number", + "description": "Determines the amount of time a live input configured in `automatic` mode should wait before a recording transitions from live to on-demand. `0` is recommended for most use cases and indicates the platform default should be used." + } + ] + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and time the live input was created." + }, + { + "name": "keys_rotated_at", + "type": "String", + "description": "The date and time the live input keys were last rotated. Omitted for live inputs that have never had their keys rotated." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the live input was last modified." + }, + { + "name": "playback", + "type": "Attributes", + "description": "Details for playing a live input's broadcast using the HLS or DASH manifests. URLs reference the live input ID.", + "children": [ + { + "name": "dash", + "type": "String", + "description": "The DASH manifest URL used to play live video, referencing the live input ID." + }, + { + "name": "hls", + "type": "String", + "description": "The HLS manifest URL used to play live video, referencing the live input ID." + } + ] + }, + { + "name": "rtmps", + "type": "Attributes", + "description": "Details for streaming to an live input using RTMPS.", + "children": [ + { + "name": "stream_key", + "type": "String", + "description": "The secret key to use when streaming via RTMPS to a live input.", + "sensitive": true + }, + { + "name": "url", + "type": "String", + "description": "The RTMPS URL you provide to the broadcaster, which they stream live video to.", + "sensitive": true + } + ] + }, + { + "name": "rtmps_playback", + "type": "Attributes", + "description": "Details for playback from an live input using RTMPS.", + "children": [ + { + "name": "stream_key", + "type": "String", + "description": "The secret key to use for playback via RTMPS.", + "sensitive": true + }, + { + "name": "url", + "type": "String", + "description": "The URL used to play live video over RTMPS.", + "sensitive": true + } + ] + }, + { + "name": "srt", + "type": "Attributes", + "description": "Details for streaming to a live input using SRT.", + "children": [ + { + "name": "passphrase", + "type": "String", + "description": "The secret key to use when streaming via SRT to a live input.", + "sensitive": true + }, + { + "name": "stream_id", + "type": "String", + "description": "The identifier of the live input to use when streaming via SRT." + }, + { + "name": "url", + "type": "String", + "description": "The SRT URL you provide to the broadcaster, which they stream live video to.", + "sensitive": true + } + ] + }, + { + "name": "srt_playback", + "type": "Attributes", + "description": "Details for playback from an live input using SRT.", + "children": [ + { + "name": "passphrase", + "type": "String", + "description": "The secret key to use for playback via SRT.", + "sensitive": true + }, + { + "name": "stream_id", + "type": "String", + "description": "The identifier of the live input to use for playback via SRT." + }, + { + "name": "url", + "type": "String", + "description": "The URL used to play live video over SRT.", + "sensitive": true + } + ] + }, + { + "name": "status", + "type": "String", + "description": "The connection status of a live input.\nAvailable values: \"connected\", \"reconnected\", \"reconnecting\", \"client_disconnect\", \"ttl_exceeded\", \"failed_to_connect\", \"failed_to_reconnect\", \"new_configuration_accepted\"." + }, + { + "name": "uid", + "type": "String", + "description": "A unique identifier for a live input." + }, + { + "name": "web_rtc", + "type": "Attributes", + "description": "Details for streaming to a live input using WebRTC.", + "children": [ + { + "name": "url", + "type": "String", + "description": "The WebRTC URL you provide to the broadcaster, which they stream live video to.", + "sensitive": true + } + ] + }, + { + "name": "web_rtc_playback", + "type": "Attributes", + "description": "Details for playback from a live input using WebRTC.", + "children": [ + { + "name": "url", + "type": "String", + "description": "The URL used to play live video over WebRTC.", + "sensitive": true + } + ] + } + ] + }, + "data-source:cloudflare_stream_watermark": { + "kind": "data-source", + "name": "cloudflare_stream_watermark", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_watermark\" \"example_stream_watermark\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"ea95132c15732412d22c1476fa83f27a\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "identifier", + "type": "String", + "description": "The unique identifier for a watermark profile." + } + ], + "optional": [], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and a time a watermark profile was created." + }, + { + "name": "downloaded_from", + "type": "String", + "description": "The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null." + }, + { + "name": "height", + "type": "Number", + "description": "The height of the image in pixels." + }, + { + "name": "name", + "type": "String", + "description": "A short description of the watermark profile." + }, + { + "name": "opacity", + "type": "Number", + "description": "The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque." + }, + { + "name": "padding", + "type": "Number", + "description": "The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm." + }, + { + "name": "position", + "type": "String", + "description": "The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter." + }, + { + "name": "scale", + "type": "Number", + "description": "The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the image in bytes." + }, + { + "name": "uid", + "type": "String", + "description": "The unique identifier for a watermark profile." + }, + { + "name": "width", + "type": "Number", + "description": "The width of the image in pixels." + } + ] + }, + "resource:cloudflare_stream_watermark": { + "kind": "resource", + "name": "cloudflare_stream_watermark", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream_watermark\" \"example_stream_watermark\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Marketing Videos\"\n opacity = 0.75\n padding = 0.1\n position = \"center\"\n scale = 0.1\n url = \"https://example.com\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + } + ], + "optional": [ + { + "name": "identifier", + "type": "String", + "description": "The unique identifier for a watermark profile." + }, + { + "name": "name", + "type": "String", + "description": "A short description of the watermark profile." + }, + { + "name": "opacity", + "type": "Number", + "description": "The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque." + }, + { + "name": "padding", + "type": "Number", + "description": "The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm." + }, + { + "name": "position", + "type": "String", + "description": "The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter." + }, + { + "name": "scale", + "type": "Number", + "description": "The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video." + }, + { + "name": "url", + "type": "String", + "description": "URL of the watermark image to copy." + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "The date and a time a watermark profile was created." + }, + { + "name": "downloaded_from", + "type": "String", + "description": "The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null." + }, + { + "name": "height", + "type": "Number", + "description": "The height of the image in pixels." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the image in bytes." + }, + { + "name": "uid", + "type": "String", + "description": "The unique identifier for a watermark profile." + }, + { + "name": "width", + "type": "Number", + "description": "The width of the image in pixels." + } + ] + }, + "list-data-source:cloudflare_stream_watermarks": { + "kind": "list-data-source", + "name": "cloudflare_stream_watermarks", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_watermarks\" \"example_stream_watermarks\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and a time a watermark profile was created." + }, + { + "name": "downloaded_from", + "type": "String", + "description": "The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null." + }, + { + "name": "height", + "type": "Number", + "description": "The height of the image in pixels." + }, + { + "name": "name", + "type": "String", + "description": "A short description of the watermark profile." + }, + { + "name": "opacity", + "type": "Number", + "description": "The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque." + }, + { + "name": "padding", + "type": "Number", + "description": "The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm." + }, + { + "name": "position", + "type": "String", + "description": "The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter." + }, + { + "name": "scale", + "type": "Number", + "description": "The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the image in bytes." + }, + { + "name": "uid", + "type": "String", + "description": "The unique identifier for a watermark profile." + }, + { + "name": "width", + "type": "Number", + "description": "The width of the image in pixels." + } + ] + } + ] + }, + "data-source:cloudflare_stream_webhook": { + "kind": "data-source", + "name": "cloudflare_stream_webhook", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_stream_webhook\" \"example_stream_webhook\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + } + ], + "computed": [ + { + "name": "modified", + "type": "String", + "description": "The date and time the webhook was last modified." + }, + { + "name": "notification_url", + "type": "String", + "description": "The URL where webhooks will be sent." + }, + { + "name": "secret", + "type": "String", + "description": "The secret used to verify webhook signatures.", + "sensitive": true + } + ] + }, + "resource:cloudflare_stream_webhook": { + "kind": "resource", + "name": "cloudflare_stream_webhook", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "resource \"cloudflare_stream_webhook\" \"example_stream_webhook\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n notification_url = \"https://example.com\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + } + ], + "optional": [ + { + "name": "notification_url", + "type": "String", + "description": "The URL where webhooks will be sent." + } + ], + "computed": [ + { + "name": "modified", + "type": "String", + "description": "The date and time the webhook was last modified." + }, + { + "name": "secret", + "type": "String", + "description": "The secret used to verify webhook signatures.", + "sensitive": true + } + ] + }, + "list-data-source:cloudflare_streams": { + "kind": "list-data-source", + "name": "cloudflare_streams", + "description": "Accepted Permissions\n\n- `Stream Read`\n- `Stream Write`", + "example": "data \"cloudflare_streams\" \"example_streams\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"ea95132c15732412d22c1476fa83f27a\"\n after = \"2019-12-27T18:11:19.117Z\"\n before = \"2019-12-27T18:11:19.117Z\"\n creator = \"creator-id_abcde12345\"\n end = \"2014-01-02T02:20:00Z\"\n limit = 1\n live_input_id = \"live_input_id\"\n name = \"name\"\n search = \"puppy.mp4\"\n start = \"2014-01-02T02:20:00Z\"\n status = \"inprogress\"\n type = \"live\"\n video_name = \"puppy.mp4\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The account identifier tag." + }, + { + "name": "after", + "type": "String", + "description": "Alias for 'start'. Returns videos created after this date/time (RFC 3339 format)." + }, + { + "name": "asc", + "type": "Boolean", + "description": "Lists videos in ascending order of creation." + }, + { + "name": "before", + "type": "String", + "description": "Alias for 'end'. Returns videos created before this date/time (RFC 3339 format)." + }, + { + "name": "creator", + "type": "String", + "description": "A user-defined identifier for the media creator." + }, + { + "name": "end", + "type": "String", + "description": "Lists videos created before the specified date." + }, + { + "name": "id", + "type": "String", + "description": "Filter by video ID(s). Can be a single ID or a comma-separated list of IDs." + }, + { + "name": "include_counts", + "type": "Boolean", + "description": "Includes the total number of videos associated with the submitted query parameters." + }, + { + "name": "limit", + "type": "Number", + "description": "Maximum number of videos to return (default 1000, max 1000)." + }, + { + "name": "live_input_id", + "type": "String", + "description": "Filter by live input ID to find videos associated with a specific live stream." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Filter by video name/UID(s). Can be a single name or a comma-separated list." + }, + { + "name": "search", + "type": "String", + "description": "Provides a partial word match of the `name` key in the `meta` field. Slow for medium to large video libraries. May be unavailable for very large libraries." + }, + { + "name": "start", + "type": "String", + "description": "Lists videos created after the specified date." + }, + { + "name": "status", + "type": "String", + "description": "Specifies the processing status for all quality levels for a video.\nAvailable values: \"pendingupload\", \"downloading\", \"queued\", \"inprogress\", \"ready\", \"error\", \"live-inprogress\"." + }, + { + "name": "type", + "type": "String", + "description": "Specifies whether the video is `vod` or `live`." + }, + { + "name": "video_name", + "type": "String", + "description": "Provides a fast, exact string match on the `name` key in the `meta` field." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allowed_origins", + "type": "List of String", + "description": "Lists the origins allowed to display the video. Enter allowed origin domains in an array and use `*` for wildcard subdomains. Empty arrays allow the video to be viewed on any origin." + }, + { + "name": "clipped_from", + "type": "String", + "description": "The unique identifier of the source video this video was clipped from." + }, + { + "name": "created", + "type": "String", + "description": "The date and time the media item was created." + }, + { + "name": "creator", + "type": "String", + "description": "A user-defined identifier for the media creator." + }, + { + "name": "duration", + "type": "Number", + "description": "The duration of the video in seconds. A value of `-1` means the duration is unknown. The duration becomes available after the upload and before the video is ready." + }, + { + "name": "input", + "type": "Attributes", + "children": [ + { + "name": "height", + "type": "Number", + "description": "The video height in pixels. A value of `-1` means the height is unknown. The value becomes available after the upload and before the video is ready." + }, + { + "name": "width", + "type": "Number", + "description": "The video width in pixels. A value of `-1` means the width is unknown. The value becomes available after the upload and before the video is ready." + } + ] + }, + { + "name": "live_input", + "type": "String", + "description": "The live input ID used to upload a video with Stream Live." + }, + { + "name": "max_duration_seconds", + "type": "Number", + "description": "The maximum duration in seconds for a video upload. Can be set for a video that is not yet uploaded to limit its duration. Uploads that exceed the specified duration will fail during processing. A value of `-1` means the value is unknown." + }, + { + "name": "max_size_bytes", + "type": "Number", + "description": "The maximum size in bytes for the video upload." + }, + { + "name": "meta", + "type": "String", + "description": "A user modifiable key-value store used to reference other systems of record for managing videos." + }, + { + "name": "modified", + "type": "String", + "description": "The date and time the media item was last modified." + }, + { + "name": "playback", + "type": "Attributes", + "children": [ + { + "name": "dash", + "type": "String", + "description": "DASH Media Presentation Description for the video." + }, + { + "name": "hls", + "type": "String", + "description": "The HLS manifest for the video." + } + ] + }, + { + "name": "preview", + "type": "String", + "description": "The video's preview page URI. This field is omitted until encoding is complete." + }, + { + "name": "public_details", + "type": "Attributes", + "description": "Public details for the video including title, share link, channel link, and logo.", + "children": [ + { + "name": "channel_link", + "type": "String" + }, + { + "name": "logo", + "type": "String" + }, + { + "name": "media_id", + "type": "Number" + }, + { + "name": "share_link", + "type": "String" + }, + { + "name": "title", + "type": "String" + } + ] + }, + { + "name": "ready_to_stream", + "type": "Boolean", + "description": "Indicates whether the video is playable. The field is empty if the video is not ready for viewing or the live stream is still in progress." + }, + { + "name": "ready_to_stream_at", + "type": "String", + "description": "Indicates the time at which the video became playable. The field is empty if the video is not ready for viewing or the live stream is still in progress." + }, + { + "name": "require_signed_urls", + "type": "Boolean", + "description": "Indicates whether the video can be a accessed using the UID. When set to `true`, a signed token must be generated with a signing key to view the video." + }, + { + "name": "scheduled_deletion", + "type": "String", + "description": "Indicates the date and time at which the video will be deleted. Omit the field to indicate no change, or include with a `null` value to remove an existing scheduled deletion. If specified, must be at least 30 days from upload time." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the media item in bytes." + }, + { + "name": "status", + "type": "Attributes", + "description": "Specifies a detailed status for a video. If the `state` is `inprogress` or `error`, the `step` field returns `encoding` or `manifest`. If the `state` is `inprogress`, `pctComplete` returns a number between 0 and 100 to indicate the approximate percent of completion. If the `state` is `error`, `errorReasonCode` and `errorReasonText` provide additional details.", + "children": [ + { + "name": "error_reason_code", + "type": "String", + "description": "Specifies why the video failed to encode. This field is empty if the video is not in an `error` state. Preferred for programmatic use." + }, + { + "name": "error_reason_text", + "type": "String", + "description": "Specifies why the video failed to encode using a human readable error message in English. This field is empty if the video is not in an `error` state." + }, + { + "name": "pct_complete", + "type": "String", + "description": "Indicates the size of the entire upload in bytes. The value must be a non-negative integer." + }, + { + "name": "state", + "type": "String", + "description": "Specifies the processing status for all quality levels for a video.\nAvailable values: \"pendingupload\", \"downloading\", \"queued\", \"inprogress\", \"ready\", \"error\", \"live-inprogress\"." + } + ] + }, + { + "name": "thumbnail", + "type": "String", + "description": "The media item's thumbnail URI. This field is omitted until encoding is complete." + }, + { + "name": "thumbnail_timestamp_pct", + "type": "Number", + "description": "The timestamp for a thumbnail image calculated as a percentage value of the video's duration. To convert from a second-wise timestamp to a percentage, divide the desired timestamp by the total duration of the video. If this value is not set, the default thumbnail image is taken from 0s of the video." + }, + { + "name": "uid", + "type": "String", + "description": "A Cloudflare-generated unique identifier for a media item." + }, + { + "name": "upload_expiry", + "type": "String", + "description": "The date and time when the video upload URL is no longer valid for direct user uploads." + }, + { + "name": "uploaded", + "type": "String", + "description": "The date and time the media item was uploaded." + }, + { + "name": "watermark", + "type": "Attributes", + "children": [ + { + "name": "created", + "type": "String", + "description": "The date and a time a watermark profile was created." + }, + { + "name": "downloaded_from", + "type": "String", + "description": "The source URL for a downloaded image. If the watermark profile was created via direct upload, this field is null." + }, + { + "name": "height", + "type": "Number", + "description": "The height of the image in pixels." + }, + { + "name": "name", + "type": "String", + "description": "A short description of the watermark profile." + }, + { + "name": "opacity", + "type": "Number", + "description": "The translucency of the image. A value of `0.0` makes the image completely transparent, and `1.0` makes the image completely opaque. Note that if the image is already semi-transparent, setting this to `1.0` will not make the image completely opaque." + }, + { + "name": "padding", + "type": "Number", + "description": "The whitespace between the adjacent edges (determined by position) of the video and the image. `0.0` indicates no padding, and `1.0` indicates a fully padded video width or length, as determined by the algorithm." + }, + { + "name": "position", + "type": "String", + "description": "The location of the image. Valid positions are: `upperRight`, `upperLeft`, `lowerLeft`, `lowerRight`, and `center`. Note that `center` ignores the `padding` parameter." + }, + { + "name": "scale", + "type": "Number", + "description": "The size of the image relative to the overall size of the video. This parameter will adapt to horizontal and vertical videos automatically. `0.0` indicates no scaling (use the size of the image as-is), and `1.0 `fills the entire video." + }, + { + "name": "size", + "type": "Number", + "description": "The size of the image in bytes." + }, + { + "name": "uid", + "type": "String", + "description": "The unique identifier for a watermark profile." + }, + { + "name": "width", + "type": "Number", + "description": "The width of the image in pixels." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_tiered_cache": { + "kind": "data-source", + "name": "cloudflare_tiered_cache", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_tiered_cache\" \"example_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + }, + { + "name": "value", + "type": "String", + "description": "Value of the Smart Tiered Cache zone setting.\nAvailable values: \"on\", \"off\"." + } + ] + }, + "resource:cloudflare_tiered_cache": { + "kind": "resource", + "name": "cloudflare_tiered_cache", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_tiered_cache\" \"example_tiered_cache\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}", + "importExample": "$ terraform import cloudflare_tiered_cache.example ''", + "required": [ + { + "name": "value", + "type": "String", + "description": "Enable or disable the Smart Tiered Cache.\nAvailable values: \"on\", \"off\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "data-source:cloudflare_token_validation_config": { + "kind": "data-source", + "name": "cloudflare_token_validation_config", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_token_validation_config\" \"example_token_validation_config\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n config_id = \"4a7ee8d3-dd63-4ceb-9d5f-c27831854ce7\"\n}", + "required": [ + { + "name": "config_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "credentials", + "type": "Attributes", + "children": [ + { + "name": "keys", + "type": "Attributes List", + "children": [ + { + "name": "alg", + "type": "String", + "description": "Algorithm\nAvailable values: \"RS256\", \"RS384\", \"RS512\", \"PS256\", \"PS384\", \"PS512\", \"ES256\", \"ES384\", \"HS256\", \"HS384\", \"HS512\"." + }, + { + "name": "crv", + "type": "String", + "description": "Curve\nAvailable values: \"P-256\", \"P-384\"." + }, + { + "name": "e", + "type": "String", + "description": "RSA exponent" + }, + { + "name": "kid", + "type": "String", + "description": "Key ID" + }, + { + "name": "kty", + "type": "String", + "description": "Key Type\nAvailable values: \"RSA\", \"EC\", \"oct\"." + }, + { + "name": "n", + "type": "String", + "description": "RSA modulus" + }, + { + "name": "x", + "type": "String", + "description": "X EC coordinate" + }, + { + "name": "y", + "type": "String", + "description": "Y EC coordinate" + } + ] + } + ] + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "title", + "type": "String" + }, + { + "name": "token_sources", + "type": "List of String" + }, + { + "name": "token_type", + "type": "String", + "description": "Available values: \"JWT\"." + } + ] + }, + "resource:cloudflare_token_validation_config": { + "kind": "resource", + "name": "cloudflare_token_validation_config", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "resource \"cloudflare_token_validation_config\" \"example_token_validation_config\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credentials = {\n keys = [{\n alg = \"RS256\"\n e = \"e\"\n kid = \"kid\"\n kty = \"RSA\"\n n = \"n\"\n }]\n }\n description = \"Long description for Token Validation Configuration\"\n title = \"Example Token Validation Configuration\"\n token_sources = [\"http.request.headers[\\\"x-auth\\\"][0]\", \"http.request.cookies[\\\"Authorization\\\"][0]\"]\n token_type = \"JWT\"\n}", + "importExample": "$ terraform import cloudflare_token_validation_config.example '/'", + "required": [ + { + "name": "credentials", + "type": "Attributes", + "description": "Request payload for create and PUT credentials operations. Provided keys define the complete stored key set. Key identities (`{alg,kid}`) must be unique.", + "children": [ + { + "name": "keys", + "type": "Attributes List", + "children": [ + { + "name": "alg", + "type": "String", + "description": "Algorithm\nAvailable values: \"RS256\", \"RS384\", \"RS512\", \"PS256\", \"PS384\", \"PS512\", \"ES256\", \"ES384\", \"HS256\", \"HS384\", \"HS512\"." + }, + { + "name": "crv", + "type": "String", + "description": "Curve\nAvailable values: \"P-256\", \"P-384\"." + }, + { + "name": "e", + "type": "String", + "description": "RSA exponent" + }, + { + "name": "k", + "type": "String", + "description": "Symmetric key material. Required for create and PUT update requests." + }, + { + "name": "kid", + "type": "String", + "description": "Key ID" + }, + { + "name": "kty", + "type": "String", + "description": "Key Type\nAvailable values: \"RSA\", \"EC\", \"oct\"." + }, + { + "name": "n", + "type": "String", + "description": "RSA modulus" + }, + { + "name": "x", + "type": "String", + "description": "X EC coordinate" + }, + { + "name": "y", + "type": "String", + "description": "Y EC coordinate" + } + ] + } + ] + }, + { + "name": "description", + "type": "String" + }, + { + "name": "title", + "type": "String" + }, + { + "name": "token_sources", + "type": "List of String" + }, + { + "name": "token_type", + "type": "String", + "description": "Available values: \"JWT\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_token_validation_configs": { + "kind": "list-data-source", + "name": "cloudflare_token_validation_configs", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_token_validation_configs\" \"example_token_validation_configs\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "credentials", + "type": "Attributes", + "children": [ + { + "name": "keys", + "type": "Attributes List", + "children": [ + { + "name": "alg", + "type": "String", + "description": "Algorithm\nAvailable values: \"RS256\", \"RS384\", \"RS512\", \"PS256\", \"PS384\", \"PS512\", \"ES256\", \"ES384\", \"HS256\", \"HS384\", \"HS512\"." + }, + { + "name": "crv", + "type": "String", + "description": "Curve\nAvailable values: \"P-256\", \"P-384\"." + }, + { + "name": "e", + "type": "String", + "description": "RSA exponent" + }, + { + "name": "kid", + "type": "String", + "description": "Key ID" + }, + { + "name": "kty", + "type": "String", + "description": "Key Type\nAvailable values: \"RSA\", \"EC\", \"oct\"." + }, + { + "name": "n", + "type": "String", + "description": "RSA modulus" + }, + { + "name": "x", + "type": "String", + "description": "X EC coordinate" + }, + { + "name": "y", + "type": "String", + "description": "Y EC coordinate" + } + ] + } + ] + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "title", + "type": "String" + }, + { + "name": "token_sources", + "type": "List of String" + }, + { + "name": "token_type", + "type": "String", + "description": "Available values: \"JWT\"." + } + ] + } + ] + }, + "data-source:cloudflare_token_validation_rules": { + "kind": "data-source", + "name": "cloudflare_token_validation_rules", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_token_validation_rules\" \"example_token_validation_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n rule_id = \"4a7ee8d3-dd63-4ceb-9d5f-c27831854ce7\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "action", + "type": "String", + "description": "Action to take on requests that match operations included in `selector` and fail `expression`.\nAvailable values: \"log\", \"block\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Toggle rule on or off." + }, + { + "name": "host", + "type": "String", + "description": "Select rules with this host in `include`." + }, + { + "name": "hostname", + "type": "String", + "description": "Select rules with this host in `include`." + }, + { + "name": "id", + "type": "String", + "description": "Select rules with these IDs." + }, + { + "name": "token_configuration", + "type": "List of String", + "description": "Select rules using any of these token configurations." + } + ] + }, + { + "name": "rule_id", + "type": "String", + "description": "UUID." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "action", + "type": "String", + "description": "Action to take on requests that match operations included in `selector` and fail `expression`.\nAvailable values: \"log\", \"block\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description that gives more details than `title`." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Toggle rule on or off." + }, + { + "name": "expression", + "type": "String", + "description": "Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/)." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "selector", + "type": "Attributes", + "description": "Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).", + "children": [ + { + "name": "exclude", + "type": "Attributes List", + "description": "Ignore operations that were otherwise included by `include`.", + "children": [ + { + "name": "operation_ids", + "type": "List of String", + "description": "Excluded operation IDs." + } + ] + }, + { + "name": "include", + "type": "Attributes List", + "description": "Select all matching operations.", + "children": [ + { + "name": "host", + "type": "List of String", + "description": "Included hostnames." + } + ] + } + ] + }, + { + "name": "title", + "type": "String", + "description": "A human-readable name for the rule." + } + ] + }, + "resource:cloudflare_token_validation_rules": { + "kind": "resource", + "name": "cloudflare_token_validation_rules", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "resource \"cloudflare_token_validation_rules\" \"example_token_validation_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n action = \"log\"\n description = \"Long description for Token Validation Rule\"\n enabled = true\n expression = \"is_jwt_valid(\\\"52973293-cb04-4a97-8f55-e7d2ad1107dd\\\") or is_jwt_valid(\\\"46eab8d1-6376-45e3-968f-2c649d77d423\\\")\"\n selector = {\n exclude = [{\n operation_ids = [\"f9c5615e-fe15-48ce-bec6-cfc1946f1bec\", \"56828eae-035a-4396-ba07-51c66d680a04\"]\n }]\n include = [{\n host = [\"v1.example.com\", \"v2.example.com\"]\n }]\n }\n title = \"Example Token Validation Rule\"\n}", + "importExample": "$ terraform import cloudflare_token_validation_rules.example '/'", + "required": [ + { + "name": "action", + "type": "String", + "description": "Action to take on requests that match operations included in `selector` and fail `expression`.\nAvailable values: \"log\", \"block\"." + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description that gives more details than `title`." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Toggle rule on or off." + }, + { + "name": "expression", + "type": "String", + "description": "Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/)." + }, + { + "name": "selector", + "type": "Attributes", + "description": "Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).", + "children": [ + { + "name": "exclude", + "type": "Attributes List", + "description": "Ignore operations that were otherwise included by `include`.", + "children": [ + { + "name": "operation_ids", + "type": "List of String", + "description": "Excluded operation IDs." + } + ] + }, + { + "name": "include", + "type": "Attributes List", + "description": "Select all matching operations.", + "children": [ + { + "name": "host", + "type": "List of String", + "description": "Included hostnames." + } + ] + } + ] + }, + { + "name": "title", + "type": "String", + "description": "A human-readable name for the rule." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "position", + "type": "Attributes", + "description": "Update rule order among zone rules.", + "children": [ + { + "name": "after", + "type": "String", + "description": "Move rule to after rule with this ID." + }, + { + "name": "before", + "type": "String", + "description": "Move rule to before rule with this ID." + }, + { + "name": "index", + "type": "Number", + "description": "Move rule to this position" + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_token_validation_rules_list": { + "kind": "list-data-source", + "name": "cloudflare_token_validation_rules_list", + "description": "Accepted Permissions\n\n- `Account API Gateway`\n- `Account API Gateway Read`\n- `Domain API Gateway`\n- `Domain API Gateway Read`", + "example": "data \"cloudflare_token_validation_rules_list\" \"example_token_validation_rules_list\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n action = \"log\"\n enabled = true\n host = \"www.example.com\"\n hostname = \"www.example.com\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n token_configuration = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n}", + "required": [], + "optional": [ + { + "name": "action", + "type": "String", + "description": "Action to take on requests that match operations included in `selector` and fail `expression`.\nAvailable values: \"log\", \"block\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Toggle rule on or off." + }, + { + "name": "host", + "type": "String", + "description": "Select rules with this host in `include`." + }, + { + "name": "hostname", + "type": "String", + "description": "Select rules with this host in `include`." + }, + { + "name": "id", + "type": "String", + "description": "Select rules with these IDs." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "rule_id", + "type": "String", + "description": "Select rules with these IDs." + }, + { + "name": "token_configuration", + "type": "List of String", + "description": "Select rules using any of these token configurations." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "action", + "type": "String", + "description": "Action to take on requests that match operations included in `selector` and fail `expression`.\nAvailable values: \"log\", \"block\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "A human-readable description that gives more details than `title`." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Toggle rule on or off." + }, + { + "name": "expression", + "type": "String", + "description": "Rule expression. Requests that fail to match this expression will be subject to `action`.\n\nFor details on expressions, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/)." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "selector", + "type": "Attributes", + "description": "Select operations covered by this rule.\n\nFor details on selectors, see the [Cloudflare Docs](https://developers.cloudflare.com/api-shield/security/jwt-validation/).", + "children": [ + { + "name": "exclude", + "type": "Attributes List", + "description": "Ignore operations that were otherwise included by `include`.", + "children": [ + { + "name": "operation_ids", + "type": "List of String", + "description": "Excluded operation IDs." + } + ] + }, + { + "name": "include", + "type": "Attributes List", + "description": "Select all matching operations.", + "children": [ + { + "name": "host", + "type": "List of String", + "description": "Included hostnames." + } + ] + } + ] + }, + { + "name": "title", + "type": "String", + "description": "A human-readable name for the rule." + } + ] + } + ] + }, + "data-source:cloudflare_total_tls": { + "kind": "data-source", + "name": "cloudflare_total_tls", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_total_tls\" \"example_total_tls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "certificate_authority", + "type": "String", + "description": "The Certificate Authority that Total TLS certificates will be issued through.\nAvailable values: \"google\", \"lets_encrypt\", \"ssl_com\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "If enabled, Total TLS will order a hostname specific TLS certificate for any proxied A, AAAA, or CNAME record in your zone." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "validity_period", + "type": "Number", + "description": "The validity period in days for the certificates ordered via Total TLS.\nAvailable values: 90." + } + ] + }, + "resource:cloudflare_total_tls": { + "kind": "resource", + "name": "cloudflare_total_tls", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_total_tls\" \"example_total_tls\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n certificate_authority = \"google\"\n}", + "importExample": "$ terraform import cloudflare_total_tls.example ''", + "required": [ + { + "name": "enabled", + "type": "Boolean", + "description": "If enabled, Total TLS will order a hostname specific TLS certificate for any proxied A, AAAA, or CNAME record in your zone." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "certificate_authority", + "type": "String", + "description": "The Certificate Authority that Total TLS certificates will be issued through.\nAvailable values: \"google\", \"lets_encrypt\", \"ssl_com\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "validity_period", + "type": "Number", + "description": "The validity period in days for the certificates ordered via Total TLS.\nAvailable values: 90." + } + ] + }, + "data-source:cloudflare_turnstile_widget": { + "kind": "data-source", + "name": "cloudflare_turnstile_widget", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Turnstile Sites Read`\n- `Turnstile Sites Write`", + "example": "data \"cloudflare_turnstile_widget\" \"example_turnstile_widget\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n sitekey = \"0x4AAF00AAAABn0R22HWm-YUc\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Direction to order widgets.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "String", + "description": "Filter widgets by field. The `name` field uses case-insensitive\nsubstring matching; `sitekey` uses exact matching.\nFormat: `field:value`\n\nSupported fields:\n- `name` - Filter by widget name (e.g., `filter=name:login-form`)\n- `sitekey` - Filter by sitekey (e.g., `filter=sitekey:0x4AAA`)\n\nReturns 400 Bad Request if the field is unsupported or format is invalid.\nAn empty filter value returns all results." + }, + { + "name": "order", + "type": "String", + "description": "Field to order widgets by.\nAvailable values: \"id\", \"sitekey\", \"name\", \"created_on\", \"modified_on\"." + } + ] + }, + { + "name": "sitekey", + "type": "String", + "description": "Unique identifier for a Turnstile widget." + } + ], + "computed": [ + { + "name": "bot_fight_mode", + "type": "Boolean", + "description": "If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only)." + }, + { + "name": "clearance_level", + "type": "String", + "description": "If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\nAvailable values: \"no_clearance\", \"jschallenge\", \"managed\", \"interactive\"." + }, + { + "name": "created_on", + "type": "String", + "description": "When the widget was created." + }, + { + "name": "deployed_via", + "type": "String", + "description": "Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\nAvailable values: \"wrangler\", \"dashboard\", \"spin\", \"api\", \"unknown\"." + }, + { + "name": "domains", + "type": "List of String" + }, + { + "name": "ephemeral_id", + "type": "Boolean", + "description": "Return the Ephemeral ID in /siteverify (ENT only)." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for a Turnstile widget." + }, + { + "name": "last_modified_via", + "type": "String", + "description": "Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\nAvailable values: \"wrangler\", \"dashboard\", \"spin\", \"api\", \"unknown\"." + }, + { + "name": "mode", + "type": "String", + "description": "Widget Mode\nAvailable values: \"non-interactive\", \"invisible\", \"managed\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the widget was modified." + }, + { + "name": "name", + "type": "String", + "description": "Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used." + }, + { + "name": "offlabel", + "type": "Boolean", + "description": "Do not show any Cloudflare branding on the widget (ENT only)." + }, + { + "name": "region", + "type": "String", + "description": "Region where this widget can be used. This cannot be changed after creation.\nAvailable values: \"world\", \"china\"." + }, + { + "name": "secret", + "type": "String", + "description": "Secret key for this widget.", + "sensitive": true + } + ] + }, + "resource:cloudflare_turnstile_widget": { + "kind": "resource", + "name": "cloudflare_turnstile_widget", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Turnstile Sites Read`\n- `Turnstile Sites Write`", + "example": "resource \"cloudflare_turnstile_widget\" \"example_turnstile_widget\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domains = [\"203.0.113.1\", \"cloudflare.com\", \"blog.example.com\"]\n mode = \"invisible\"\n name = \"blog.cloudflare.com login form\"\n bot_fight_mode = false\n clearance_level = \"interactive\"\n ephemeral_id = false\n offlabel = false\n region = \"world\"\n}", + "importExample": "$ terraform import cloudflare_turnstile_widget.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "domains", + "type": "List of String" + }, + { + "name": "mode", + "type": "String", + "description": "Widget Mode\nAvailable values: \"non-interactive\", \"invisible\", \"managed\"." + }, + { + "name": "name", + "type": "String", + "description": "Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used." + } + ], + "optional": [ + { + "name": "bot_fight_mode", + "type": "Boolean", + "description": "If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only)." + }, + { + "name": "clearance_level", + "type": "String", + "description": "If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\nAvailable values: \"no_clearance\", \"jschallenge\", \"managed\", \"interactive\"." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order widgets.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "ephemeral_id", + "type": "Boolean", + "description": "Return the Ephemeral ID in /siteverify (ENT only)." + }, + { + "name": "filter", + "type": "String", + "description": "Filter widgets by field using case-insensitive substring matching.\nFormat: `field:value`\n\nSupported fields:\n- `name` - Filter by widget name (e.g., `filter=name:login-form`)\n- `sitekey` - Filter by sitekey (e.g., `filter=sitekey:0x4AAA`)\n\nReturns 400 Bad Request if the field is unsupported or format is invalid.\nAn empty filter value returns all results." + }, + { + "name": "offlabel", + "type": "Boolean", + "description": "Do not show any Cloudflare branding on the widget (ENT only)." + }, + { + "name": "order", + "type": "String", + "description": "Field to order widgets by.\nAvailable values: \"id\", \"sitekey\", \"name\", \"created_on\", \"modified_on\"." + }, + { + "name": "page", + "type": "Number", + "description": "Page number of paginated results." + }, + { + "name": "per_page", + "type": "Number", + "description": "Number of items per page." + }, + { + "name": "region", + "type": "String", + "description": "Region where this widget can be used. This cannot be changed after creation.\nAvailable values: \"world\", \"china\"." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the widget was created." + }, + { + "name": "deployed_via", + "type": "String", + "description": "Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\nAvailable values: \"wrangler\", \"dashboard\", \"spin\", \"api\", \"unknown\"." + }, + { + "name": "id", + "type": "String", + "description": "Widget item identifier tag." + }, + { + "name": "last_modified_via", + "type": "String", + "description": "Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\nAvailable values: \"wrangler\", \"dashboard\", \"spin\", \"api\", \"unknown\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the widget was modified." + }, + { + "name": "secret", + "type": "String", + "description": "Secret key for this widget.", + "sensitive": true + }, + { + "name": "sitekey", + "type": "String", + "description": "Widget item identifier tag." + } + ] + }, + "list-data-source:cloudflare_turnstile_widgets": { + "kind": "list-data-source", + "name": "cloudflare_turnstile_widgets", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `Turnstile Sites Read`\n- `Turnstile Sites Write`", + "example": "data \"cloudflare_turnstile_widgets\" \"example_turnstile_widgets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n filter = \"name:my-widget\"\n order = \"id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier" + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order widgets.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "String", + "description": "Filter widgets by field. The `name` field uses case-insensitive\nsubstring matching; `sitekey` uses exact matching.\nFormat: `field:value`\n\nSupported fields:\n- `name` - Filter by widget name (e.g., `filter=name:login-form`)\n- `sitekey` - Filter by sitekey (e.g., `filter=sitekey:0x4AAA`)\n\nReturns 400 Bad Request if the field is unsupported or format is invalid.\nAn empty filter value returns all results." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to order widgets by.\nAvailable values: \"id\", \"sitekey\", \"name\", \"created_on\", \"modified_on\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "bot_fight_mode", + "type": "Boolean", + "description": "If bot_fight_mode is set to `true`, Cloudflare issues computationally\nexpensive challenges in response to malicious bots (ENT only)." + }, + { + "name": "clearance_level", + "type": "String", + "description": "If Turnstile is embedded on a Cloudflare site and the widget should grant challenge clearance,\nthis setting can determine the clearance level to be set\nAvailable values: \"no_clearance\", \"jschallenge\", \"managed\", \"interactive\"." + }, + { + "name": "created_on", + "type": "String", + "description": "When the widget was created." + }, + { + "name": "deployed_via", + "type": "String", + "description": "Origin that created this widget, recorded at creation time and\nimmutable afterward. Server-derived from the create request; not\nclient-settable. Omitted from the response for widgets created\nbefore this field existed.\nAvailable values: \"wrangler\", \"dashboard\", \"spin\", \"api\", \"unknown\"." + }, + { + "name": "domains", + "type": "List of String" + }, + { + "name": "ephemeral_id", + "type": "Boolean", + "description": "Return the Ephemeral ID in /siteverify (ENT only)." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for a Turnstile widget." + }, + { + "name": "last_modified_via", + "type": "String", + "description": "Origin of the most recent mutation (create, update, delete, or\nsecret rotation). Server-derived; not client-settable. Omitted for\nwidgets last mutated before this field existed.\nAvailable values: \"wrangler\", \"dashboard\", \"spin\", \"api\", \"unknown\"." + }, + { + "name": "mode", + "type": "String", + "description": "Widget Mode\nAvailable values: \"non-interactive\", \"invisible\", \"managed\"." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the widget was modified." + }, + { + "name": "name", + "type": "String", + "description": "Human readable widget name. Not unique. Cloudflare suggests that you\nset this to a meaningful string to make it easier to identify your\nwidget, and where it is used." + }, + { + "name": "offlabel", + "type": "Boolean", + "description": "Do not show any Cloudflare branding on the widget (ENT only)." + }, + { + "name": "region", + "type": "String", + "description": "Region where this widget can be used. This cannot be changed after creation.\nAvailable values: \"world\", \"china\"." + }, + { + "name": "sitekey", + "type": "String", + "description": "Unique identifier for a Turnstile widget." + } + ] + } + ] + }, + "data-source:cloudflare_universal_ssl_setting": { + "kind": "data-source", + "name": "cloudflare_universal_ssl_setting", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_universal_ssl_setting\" \"example_universal_ssl_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.\n\nBy disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.\n\n* HSTS\n* Always Use HTTPS\n* Opportunistic Encryption\n* Onion Routing\n* Any Page Rules redirecting traffic to HTTPS\n\nSimilarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare's edge.\n\nIf you do not have a valid custom or advanced certificate at Cloudflare's edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "resource:cloudflare_universal_ssl_setting": { + "kind": "resource", + "name": "cloudflare_universal_ssl_setting", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_universal_ssl_setting\" \"example_universal_ssl_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}", + "importExample": "$ terraform import cloudflare_universal_ssl_setting.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Disabling Universal SSL removes any currently active Universal SSL certificates for your zone from the edge and prevents any future Universal SSL certificates from being ordered. If there are no advanced certificates or custom certificates uploaded for the domain, visitors will be unable to access the domain over HTTPS.\n\nBy disabling Universal SSL, you understand that the following Cloudflare settings and preferences will result in visitors being unable to visit your domain unless you have uploaded a custom certificate or purchased an advanced certificate.\n\n* HSTS\n* Always Use HTTPS\n* Opportunistic Encryption\n* Onion Routing\n* Any Page Rules redirecting traffic to HTTPS\n\nSimilarly, any HTTP redirect to HTTPS at the origin while the Cloudflare proxy is enabled will result in users being unable to visit your site without a valid certificate at Cloudflare's edge.\n\nIf you do not have a valid custom or advanced certificate at Cloudflare's edge and are unsure if any of the above Cloudflare settings are enabled, or if any HTTP redirects exist at your origin, we advise leaving Universal SSL enabled for your domain." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_url_normalization_settings": { + "kind": "data-source", + "name": "cloudflare_url_normalization_settings", + "description": "Accepted Permissions\n\n- `Account Rulesets Read`\n- `Account Rulesets Write`\n- `Account WAF Read`\n- `Account WAF Write`\n- `Bot Management Read`\n- `Bot Management Write`\n- `Cache Settings Read`\n- `Cache Settings Write`\n- `Config Settings Read`\n- `Config Settings Write`\n- `Custom Errors Read`\n- `Custom Errors Write`\n- `Dynamic URL Redirects Read`\n- `Dynamic URL Redirects Write`\n- `HTTP DDoS Managed Ruleset Read`\n- `HTTP DDoS Managed Ruleset Write`\n- `L4 DDoS Managed Ruleset Read`\n- `L4 DDoS Managed Ruleset Write`\n- `Logs Read`\n- `Logs Write`\n- `Magic Firewall Read`\n- `Magic Firewall Write`\n- `Managed headers Read`\n- `Managed headers Write`\n- `Mass URL Redirects Read`\n- `Mass URL Redirects Write`\n- `Origin Read`\n- `Origin Write`\n- `Response Compression Read`\n- `Response Compression Write`\n- `Sanitize Read`\n- `Sanitize Write`\n- `Select Configuration Read`\n- `Select Configuration Write`\n- `Transform Rules Read`\n- `Transform Rules Write`\n- `Zone Transform Rules Read`\n- `Zone Transform Rules Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "data \"cloudflare_url_normalization_settings\" \"example_url_normalization_settings\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique ID of the zone." + }, + { + "name": "scope", + "type": "String", + "description": "The scope of the URL normalization.\nAvailable values: \"incoming\", \"both\", \"none\"." + }, + { + "name": "type", + "type": "String", + "description": "The type of URL normalization performed by Cloudflare.\nAvailable values: \"cloudflare\", \"rfc3986\"." + } + ] + }, + "resource:cloudflare_url_normalization_settings": { + "kind": "resource", + "name": "cloudflare_url_normalization_settings", + "description": "Accepted Permissions\n\n- `Account Rulesets Read`\n- `Account Rulesets Write`\n- `Account WAF Read`\n- `Account WAF Write`\n- `Bot Management Read`\n- `Bot Management Write`\n- `Cache Settings Read`\n- `Cache Settings Write`\n- `Config Settings Read`\n- `Config Settings Write`\n- `Custom Errors Read`\n- `Custom Errors Write`\n- `Dynamic URL Redirects Read`\n- `Dynamic URL Redirects Write`\n- `HTTP DDoS Managed Ruleset Read`\n- `HTTP DDoS Managed Ruleset Write`\n- `L4 DDoS Managed Ruleset Read`\n- `L4 DDoS Managed Ruleset Write`\n- `Logs Read`\n- `Logs Write`\n- `Magic Firewall Read`\n- `Magic Firewall Write`\n- `Managed headers Read`\n- `Managed headers Write`\n- `Mass URL Redirects Read`\n- `Mass URL Redirects Write`\n- `Origin Read`\n- `Origin Write`\n- `Response Compression Read`\n- `Response Compression Write`\n- `Sanitize Read`\n- `Sanitize Write`\n- `Select Configuration Read`\n- `Select Configuration Write`\n- `Transform Rules Read`\n- `Transform Rules Write`\n- `Zone Transform Rules Read`\n- `Zone Transform Rules Write`\n- `Zone WAF Read`\n- `Zone WAF Write`", + "example": "resource \"cloudflare_url_normalization_settings\" \"example_url_normalization_settings\" {\n zone_id = \"9f1839b6152d298aca64c4e906b6d074\"\n scope = \"incoming\"\n type = \"cloudflare\"\n}", + "importExample": "$ terraform import cloudflare_url_normalization_settings.example ''", + "required": [ + { + "name": "scope", + "type": "String", + "description": "The scope of the URL normalization.\nAvailable values: \"incoming\", \"both\", \"none\"." + }, + { + "name": "type", + "type": "String", + "description": "The type of URL normalization performed by Cloudflare.\nAvailable values: \"cloudflare\", \"rfc3986\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "The unique ID of the zone." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique ID of the zone." + } + ] + }, + "data-source:cloudflare_user": { + "kind": "data-source", + "name": "cloudflare_user", + "description": "Accepted Permissions\n\n- `User Details Read`\n- `User Details Write`", + "example": "data \"cloudflare_user\" \"example_user\" {\n\n}", + "required": [], + "optional": [], + "computed": [ + { + "name": "betas", + "type": "List of String", + "description": "Lists the betas that the user is participating in." + }, + { + "name": "country", + "type": "String", + "description": "The country in which the user lives." + }, + { + "name": "email", + "type": "String", + "description": "Current email address of the user." + }, + { + "name": "first_name", + "type": "String", + "description": "User's first name" + }, + { + "name": "has_business_zones", + "type": "Boolean", + "description": "Indicates whether user has any business zones" + }, + { + "name": "has_enterprise_zones", + "type": "Boolean", + "description": "Indicates whether user has any enterprise zones" + }, + { + "name": "has_pro_zones", + "type": "Boolean", + "description": "Indicates whether user has any pro zones" + }, + { + "name": "id", + "type": "String", + "description": "Identifier of the user." + }, + { + "name": "last_name", + "type": "String", + "description": "User's last name" + }, + { + "name": "organizations", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "Organization name." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Access permissions for this User." + }, + { + "name": "roles", + "type": "List of String", + "description": "List of roles that a user has within an organization." + }, + { + "name": "status", + "type": "String", + "description": "Whether the user is a member of the organization or has an invitation pending.\nAvailable values: \"member\", \"invited\"." + } + ] + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Indicates whether user has been suspended" + }, + { + "name": "telephone", + "type": "String", + "description": "User's telephone number" + }, + { + "name": "two_factor_authentication_enabled", + "type": "Boolean", + "description": "Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication." + }, + { + "name": "two_factor_authentication_locked", + "type": "Boolean", + "description": "Indicates whether two-factor authentication is required by one of the accounts that the user is a member of." + }, + { + "name": "zipcode", + "type": "String", + "description": "The zipcode or postal code where the user lives." + } + ] + }, + "resource:cloudflare_user": { + "kind": "resource", + "name": "cloudflare_user", + "description": "Accepted Permissions\n\n- `User Details Read`\n- `User Details Write`", + "example": "resource \"cloudflare_user\" \"example_user\" {\n country = \"US\"\n first_name = \"John\"\n last_name = \"Appleseed\"\n telephone = \"+1 123-123-1234\"\n zipcode = \"12345\"\n}", + "required": [], + "optional": [ + { + "name": "country", + "type": "String", + "description": "The country in which the user lives." + }, + { + "name": "first_name", + "type": "String", + "description": "User's first name" + }, + { + "name": "last_name", + "type": "String", + "description": "User's last name" + }, + { + "name": "telephone", + "type": "String", + "description": "User's telephone number" + }, + { + "name": "zipcode", + "type": "String", + "description": "The zipcode or postal code where the user lives." + } + ], + "computed": [ + { + "name": "betas", + "type": "List of String", + "description": "Lists the betas that the user is participating in." + }, + { + "name": "email", + "type": "String", + "description": "Current email address of the user." + }, + { + "name": "has_business_zones", + "type": "Boolean", + "description": "Indicates whether user has any business zones" + }, + { + "name": "has_enterprise_zones", + "type": "Boolean", + "description": "Indicates whether user has any enterprise zones" + }, + { + "name": "has_pro_zones", + "type": "Boolean", + "description": "Indicates whether user has any pro zones" + }, + { + "name": "id", + "type": "String", + "description": "Identifier of the user." + }, + { + "name": "organizations", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "Organization name." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Access permissions for this User." + }, + { + "name": "roles", + "type": "List of String", + "description": "List of roles that a user has within an organization." + }, + { + "name": "status", + "type": "String", + "description": "Whether the user is a member of the organization or has an invitation pending.\nAvailable values: \"member\", \"invited\"." + } + ] + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Indicates whether user has been suspended" + }, + { + "name": "two_factor_authentication_enabled", + "type": "Boolean", + "description": "Indicates whether two-factor authentication is enabled for the user account. Does not apply to API authentication." + }, + { + "name": "two_factor_authentication_locked", + "type": "Boolean", + "description": "Indicates whether two-factor authentication is required by one of the accounts that the user is a member of." + } + ] + }, + "data-source:cloudflare_user_agent_blocking_rule": { + "kind": "data-source", + "name": "cloudflare_user_agent_blocking_rule", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_user_agent_blocking_rule\" \"example_user_agent_blocking_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ua_rule_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "description", + "type": "String", + "description": "A string to search for in the description of existing rules." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + }, + { + "name": "user_agent", + "type": "String", + "description": "A string to search for in the user agent values of existing rules." + } + ] + }, + { + "name": "ua_rule_id", + "type": "String", + "description": "The unique identifier of the User Agent Blocking rule." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "configuration", + "type": "Attributes", + "description": "The configuration object for the current rule.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target for this rule. You must set the target to `ua` for User Agent Blocking rules." + }, + { + "name": "value", + "type": "String", + "description": "The exact user agent string to match. This value will be compared to the received `User-Agent` HTTP header value." + } + ] + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the User Agent Blocking rule." + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + } + ] + }, + "resource:cloudflare_user_agent_blocking_rule": { + "kind": "resource", + "name": "cloudflare_user_agent_blocking_rule", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "resource \"cloudflare_user_agent_blocking_rule\" \"example_user_agent_blocking_rule\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n configuration = {\n target = \"ua\"\n value = \"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)\"\n }\n mode = \"challenge\"\n description = \"Prevent multiple login failures to mitigate brute force attacks\"\n paused = false\n}", + "importExample": "$ terraform import cloudflare_user_agent_blocking_rule.example '/'", + "required": [ + { + "name": "configuration", + "type": "Attributes", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target. You must set the target to `ua` when specifying a user agent in the rule.\nAvailable values: \"ua\"." + }, + { + "name": "value", + "type": "String", + "description": "the user agent to exactly match" + } + ] + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"whitelist\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the rule. This value is sanitized and any tags will be removed." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique identifier of the User Agent Blocking rule." + } + ] + }, + "list-data-source:cloudflare_user_agent_blocking_rules": { + "kind": "list-data-source", + "name": "cloudflare_user_agent_blocking_rules", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_user_agent_blocking_rules\" \"example_user_agent_blocking_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n description = \"abusive\"\n paused = false\n user_agent = \"Safari\"\n}", + "required": [], + "optional": [ + { + "name": "description", + "type": "String", + "description": "A string to search for in the description of existing rules." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + }, + { + "name": "user_agent", + "type": "String", + "description": "A string to search for in the user agent values of existing rules." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "configuration", + "type": "Attributes", + "description": "The configuration object for the current rule.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target for this rule. You must set the target to `ua` for User Agent Blocking rules." + }, + { + "name": "value", + "type": "String", + "description": "The exact user agent string to match. This value will be compared to the received `User-Agent` HTTP header value." + } + ] + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the User Agent Blocking rule." + }, + { + "name": "mode", + "type": "String", + "description": "The action to apply to a matched request.\nAvailable values: \"block\", \"challenge\", \"js_challenge\", \"managed_challenge\"." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + } + ] + } + ] + }, + "data-source:cloudflare_user_group": { + "kind": "data-source", + "name": "cloudflare_user_group", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_user_group\" \"example_user_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "The sort order of returned user groups by name (ascending or descending).\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "fuzzy_name", + "type": "String", + "description": "A string used for searching for user groups containing that substring." + }, + { + "name": "id", + "type": "String", + "description": "ID of the user group to be fetched." + }, + { + "name": "name", + "type": "String", + "description": "Name of the user group to be fetched." + } + ] + }, + { + "name": "user_group_id", + "type": "String", + "description": "User Group identifier tag." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the user group" + }, + { + "name": "id", + "type": "String", + "description": "User Group identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the user group was modified." + }, + { + "name": "name", + "type": "String", + "description": "Name of the user group." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "Policies attached to the User group", + "children": [ + { + "name": "access", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resource_groups", + "type": "Attributes List", + "description": "A list of resource groups that the policy applies to.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the resource group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the resource group.", + "children": [ + { + "name": "key", + "type": "String" + }, + { + "name": "value", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the resource group." + }, + { + "name": "scope", + "type": "Attributes List", + "description": "The scope associated to the resource group", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Account ID etc.)" + }, + { + "name": "objects", + "type": "Attributes List", + "description": "A list of scope objects for additional context.", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Zone ID etc.)" + } + ] + } + ] + } + ] + } + ] + } + ] + }, + "resource:cloudflare_user_group": { + "kind": "resource", + "name": "cloudflare_user_group", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "resource \"cloudflare_user_group\" \"example_user_group\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My New User Group\"\n policies = [{\n access = \"allow\"\n permission_groups = [{\n id = \"c8fed203ed3043cba015a93ad1616f1f\"\n }, {\n id = \"82e64a83756745bbbb1c9c2701bf816b\"\n }]\n resource_groups = [{\n id = \"6d7f2f5f5b1d4a0e9081fdc98d432fd1\"\n }]\n }]\n}", + "importExample": "$ terraform import cloudflare_user_group.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "name", + "type": "String", + "description": "Name of the User group." + } + ], + "optional": [ + { + "name": "policies", + "type": "Attributes List", + "description": "Policies attached to the User group", + "children": [ + { + "name": "access", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Permission Group identifier tag." + } + ] + }, + { + "name": "resource_groups", + "type": "Attributes List", + "description": "A set of resource groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Resource Group identifier tag." + } + ] + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the user group" + }, + { + "name": "id", + "type": "String", + "description": "User Group identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the user group was modified." + } + ] + }, + "data-source:cloudflare_user_group_members": { + "kind": "data-source", + "name": "cloudflare_user_group_members", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_user_group_members\" \"example_user_group_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n fuzzy_email = \"user@\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "user_group_id", + "type": "String", + "description": "User Group identifier tag." + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The sort order of returned user group members by email.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "fuzzy_email", + "type": "String", + "description": "A string used for filtering members by partial email match." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "User Group identifier tag." + }, + { + "name": "members", + "type": "Attributes List", + "description": "List of members in the user group.", + "children": [ + { + "name": "email", + "type": "String", + "description": "The contact email address of the user." + }, + { + "name": "id", + "type": "String", + "description": "Account member identifier." + }, + { + "name": "status", + "type": "String", + "description": "The member's status in the account.\nAvailable values: \"accepted\", \"pending\"." + } + ] + } + ] + }, + "resource:cloudflare_user_group_members": { + "kind": "resource", + "name": "cloudflare_user_group_members", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "resource \"cloudflare_user_group_members\" \"example_user_group_members\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n user_group_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n members = [{\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n }]\n}", + "importExample": "$ terraform import cloudflare_user_group_members.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + }, + { + "name": "members", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "The identifier of an existing account Member." + } + ] + }, + { + "name": "user_group_id", + "type": "String", + "description": "User Group identifier tag." + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The sort order of returned user group members by email.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "fuzzy_email", + "type": "String", + "description": "A string used for filtering members by partial email match." + }, + { + "name": "page", + "type": "Number", + "description": "Page number of paginated results." + }, + { + "name": "per_page", + "type": "Number", + "description": "Maximum number of results per page." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "User Group identifier tag." + } + ] + }, + "list-data-source:cloudflare_user_groups": { + "kind": "list-data-source", + "name": "cloudflare_user_groups", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`\n- `SCIM Provisioning`", + "example": "data \"cloudflare_user_groups\" \"example_user_groups\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n fuzzy_name = \"Foo\"\n name = \"NameOfTheUserGroup\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier tag." + } + ], + "optional": [ + { + "name": "direction", + "type": "String", + "description": "The sort order of returned user groups by name (ascending or descending).\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "fuzzy_name", + "type": "String", + "description": "A string used for searching for user groups containing that substring." + }, + { + "name": "id", + "type": "String", + "description": "ID of the user group to be fetched." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Name of the user group to be fetched." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "Timestamp for the creation of the user group" + }, + { + "name": "id", + "type": "String", + "description": "User Group identifier tag." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time the user group was modified." + }, + { + "name": "name", + "type": "String", + "description": "Name of the user group." + }, + { + "name": "policies", + "type": "Attributes List", + "description": "Policies attached to the User group", + "children": [ + { + "name": "access", + "type": "String", + "description": "Allow or deny operations against the resources.\nAvailable values: \"allow\", \"deny\"." + }, + { + "name": "id", + "type": "String", + "description": "Policy identifier." + }, + { + "name": "permission_groups", + "type": "Attributes List", + "description": "A set of permission groups that are specified to the policy.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the permission group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the permission group.", + "children": [ + { + "name": "category", + "type": "String", + "description": "A category used to group permission groups." + }, + { + "name": "deprecated", + "type": "String", + "description": "Indicates whether the permission group is deprecated." + }, + { + "name": "description", + "type": "String", + "description": "Additional information about the permission group." + }, + { + "name": "editable", + "type": "String", + "description": "Indicates whether the permission group can be edited." + }, + { + "name": "eol_at", + "type": "String", + "description": "The planned end-of-life date and time, when provided." + }, + { + "name": "label", + "type": "String", + "description": "A label identifying the permission group." + }, + { + "name": "scopes", + "type": "String", + "description": "The scope associated with the permission group." + }, + { + "name": "visibility", + "type": "String", + "description": "Indicates the permission group's availability or visibility." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the permission group." + } + ] + }, + { + "name": "resource_groups", + "type": "Attributes List", + "description": "A list of resource groups that the policy applies to.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier of the resource group." + }, + { + "name": "meta", + "type": "Attributes", + "description": "Attributes associated to the resource group.", + "children": [ + { + "name": "key", + "type": "String" + }, + { + "name": "value", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Name of the resource group." + }, + { + "name": "scope", + "type": "Attributes List", + "description": "The scope associated to the resource group", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Account ID etc.)" + }, + { + "name": "objects", + "type": "Attributes List", + "description": "A list of scope objects for additional context.", + "children": [ + { + "name": "key", + "type": "String", + "description": "This is a combination of pre-defined resource name and identifier (like Zone ID etc.)" + } + ] + } + ] + } + ] + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_vulnerability_scanner_credential": { + "kind": "data-source", + "name": "cloudflare_vulnerability_scanner_credential", + "example": "data \"cloudflare_vulnerability_scanner_credential\" \"example_vulnerability_scanner_credential\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n credential_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "credential_id", + "type": "String" + }, + { + "name": "credential_set_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "location", + "type": "String", + "description": "Where the credential is attached in outgoing requests.\nAvailable values: \"header\", \"cookie\"." + }, + { + "name": "location_name", + "type": "String", + "description": "Name of the header or cookie where the credential is attached." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + } + ] + }, + "resource:cloudflare_vulnerability_scanner_credential": { + "kind": "resource", + "name": "cloudflare_vulnerability_scanner_credential", + "example": "resource \"cloudflare_vulnerability_scanner_credential\" \"example_vulnerability_scanner_credential\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n location = \"header\"\n location_name = \"Authorization\"\n name = \"Admin API key\"\n value = \"Bearer EXAMPLE_TOKEN\"\n}", + "importExample": "$ terraform import cloudflare_vulnerability_scanner_credential.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "credential_set_id", + "type": "String" + }, + { + "name": "location", + "type": "String", + "description": "Where the credential is attached in outgoing requests.\nAvailable values: \"header\", \"cookie\"." + }, + { + "name": "location_name", + "type": "String", + "description": "Name of the header or cookie where the credential is attached." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + }, + { + "name": "value", + "type": "String", + "description": "The credential value (e.g. API key, session token). Write-only.\nNever returned in responses.", + "sensitive": true + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Credential identifier." + } + ] + }, + "data-source:cloudflare_vulnerability_scanner_credential_set": { + "kind": "data-source", + "name": "cloudflare_vulnerability_scanner_credential_set", + "example": "data \"cloudflare_vulnerability_scanner_credential_set\" \"example_vulnerability_scanner_credential_set\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "credential_set_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + } + ] + }, + "resource:cloudflare_vulnerability_scanner_credential_set": { + "kind": "resource", + "name": "cloudflare_vulnerability_scanner_credential_set", + "example": "resource \"cloudflare_vulnerability_scanner_credential_set\" \"example_vulnerability_scanner_credential_set\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production API credentials\"\n}", + "importExample": "$ terraform import cloudflare_vulnerability_scanner_credential_set.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Credential set identifier." + } + ] + }, + "list-data-source:cloudflare_vulnerability_scanner_credential_sets": { + "kind": "list-data-source", + "name": "cloudflare_vulnerability_scanner_credential_sets", + "example": "data \"cloudflare_vulnerability_scanner_credential_sets\" \"example_vulnerability_scanner_credential_sets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "Credential set identifier." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + } + ] + } + ] + }, + "list-data-source:cloudflare_vulnerability_scanner_credentials": { + "kind": "list-data-source", + "name": "cloudflare_vulnerability_scanner_credentials", + "example": "data \"cloudflare_vulnerability_scanner_credentials\" \"example_vulnerability_scanner_credentials\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n credential_set_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "credential_set_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "credential_set_id", + "type": "String", + "description": "Parent credential set identifier." + }, + { + "name": "id", + "type": "String", + "description": "Credential identifier." + }, + { + "name": "location", + "type": "String", + "description": "Where the credential is attached in outgoing requests.\nAvailable values: \"header\", \"cookie\"." + }, + { + "name": "location_name", + "type": "String", + "description": "Name of the header or cookie where the credential is attached." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + } + ] + } + ] + }, + "data-source:cloudflare_vulnerability_scanner_target_environment": { + "kind": "data-source", + "name": "cloudflare_vulnerability_scanner_target_environment", + "example": "data \"cloudflare_vulnerability_scanner_target_environment\" \"example_vulnerability_scanner_target_environment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n target_environment_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "target_environment_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "description", + "type": "String", + "description": "Optional description providing additional context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + }, + { + "name": "target", + "type": "Attributes", + "description": "Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"zone\"." + }, + { + "name": "zone_tag", + "type": "String", + "description": "Cloudflare zone tag. The zone must belong to the account." + } + ] + } + ] + }, + "resource:cloudflare_vulnerability_scanner_target_environment": { + "kind": "resource", + "name": "cloudflare_vulnerability_scanner_target_environment", + "example": "resource \"cloudflare_vulnerability_scanner_target_environment\" \"example_vulnerability_scanner_target_environment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"Production Zone\"\n target = {\n type = \"zone\"\n zone_tag = \"d8e8fca2dc0f896fd7cb4cb0031ba249\"\n }\n description = \"Main production environment\"\n}", + "importExample": "$ terraform import cloudflare_vulnerability_scanner_target_environment.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + }, + { + "name": "target", + "type": "Attributes", + "description": "Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"zone\"." + }, + { + "name": "zone_tag", + "type": "String", + "description": "Cloudflare zone tag. The zone must belong to the account." + } + ] + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Optional description." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Target environment identifier." + } + ] + }, + "list-data-source:cloudflare_vulnerability_scanner_target_environments": { + "kind": "list-data-source", + "name": "cloudflare_vulnerability_scanner_target_environments", + "example": "data \"cloudflare_vulnerability_scanner_target_environments\" \"example_vulnerability_scanner_target_environments\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "Optional description providing additional context." + }, + { + "name": "id", + "type": "String", + "description": "Target environment identifier." + }, + { + "name": "name", + "type": "String", + "description": "Human-readable name." + }, + { + "name": "target", + "type": "Attributes", + "description": "Identifies the Cloudflare asset to scan. Uses a `type` discriminator.\nCurrently the service supports only `zone` targets.", + "children": [ + { + "name": "type", + "type": "String", + "description": "Available values: \"zone\"." + }, + { + "name": "zone_tag", + "type": "String", + "description": "Cloudflare zone tag. The zone must belong to the account." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_waiting_room": { + "kind": "data-source", + "name": "cloudflare_waiting_room", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "data \"cloudflare_waiting_room\" \"example_waiting_room\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [ + { + "name": "waiting_room_id", + "type": "String" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "additional_routes", + "type": "Attributes List", + "description": "Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an implied wildcard at the end of the path. The hostname and path combination must be unique to this and all other waiting rooms.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The hostname to which this waiting room will be applied (no wildcards). The hostname must be the primary domain, subdomain, or custom hostname (if using SSL for SaaS) of this zone. Please do not include the scheme (http:// or https://)." + }, + { + "name": "path", + "type": "String", + "description": "Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported." + } + ] + }, + { + "name": "cookie_attributes", + "type": "Attributes", + "description": "Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.", + "children": [ + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on the waiting room cookie. Value `auto` will be translated to `lax` or `none` depending if **Always Use HTTPS** is enabled. Note that when using value `none`, the secure attribute cannot be set to `never`.\nAvailable values: \"auto\", \"lax\", \"none\", \"strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on the waiting room cookie. Value `always` indicates that the Secure attribute will be set in the Set-Cookie header, `never` indicates that the Secure attribute will not be set, and `auto` will set the Secure attribute depending if **Always Use HTTPS** is enabled.\nAvailable values: \"auto\", \"always\", \"never\"." + } + ] + }, + { + "name": "cookie_suffix", + "type": "String", + "description": "Appends a '_' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(__cf_waitingroom). If `cookie_suffix` is \"abcd\", the cookie name will be `__cf_waitingroom_abcd`. This field is required if using `additional_routes`." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "custom_page_html", + "type": "String", + "description": "Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custom_page_html is provided, the default waiting room will be used. The template is based on mustache ( https://mustache.github.io/ ). There are several variables that are evaluated by the Cloudflare edge:\n1. {{`waitTimeKnown`}} Acts like a boolean value that indicates the behavior to take when wait time is not available, for instance when queue_all is **true**.\n2. {{`waitTimeFormatted`}} Estimated wait time for the user. For example, five minutes. Alternatively, you can use:\n3. {{`waitTime`}} Number of minutes of estimated wait for a user.\n4. {{`waitTimeHours`}} Number of hours of estimated wait for a user (`Math.floor(waitTime/60)`).\n5. {{`waitTimeHourMinutes`}} Number of minutes above the `waitTimeHours` value (`waitTime%60`).\n6. {{`queueIsFull`}} Changes to **true** when no more people can be added to the queue.\n\nTo view the full list of variables, look at the `cfWaitingRoom` object described under the `json_response_enabled` property in other Waiting Room API calls." + }, + { + "name": "default_template_language", + "type": "String", + "description": "The language of the default page template. If no default_template_language is provided, then `en-US` (English) will be used.\nAvailable values: \"en-US\", \"es-ES\", \"de-DE\", \"fr-FR\", \"it-IT\", \"ja-JP\", \"ko-KR\", \"pt-BR\", \"zh-CN\", \"zh-TW\", \"nl-NL\", \"pl-PL\", \"id-ID\", \"tr-TR\", \"ar-EG\", \"ru-RU\", \"fa-IR\", \"bg-BG\", \"hr-HR\", \"cs-CZ\", \"da-DK\", \"fi-FI\", \"lt-LT\", \"lv-LV\", \"ms-MY\", \"nb-NO\", \"ro-RO\", \"el-GR\", \"he-IL\", \"hi-IN\", \"hu-HU\", \"sr-BA\", \"sk-SK\", \"sl-SI\", \"sv-SE\", \"tl-PH\", \"th-TH\", \"uk-UA\", \"vi-VN\"." + }, + { + "name": "description", + "type": "String", + "description": "A note that you can use to add more details about the waiting room." + }, + { + "name": "disable_session_renewal", + "type": "Boolean", + "description": "Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If `true`, an accepted user will have session_duration minutes to browse the site. After that, they will have to go through the waiting room again. If `false`, a user's session cookie will be automatically renewed on every request." + }, + { + "name": "enabled_origin_commands", + "type": "List of String", + "description": "A list of enabled origin commands." + }, + { + "name": "host", + "type": "String", + "description": "The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination must be unique." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "json_response_enabled", + "type": "Boolean", + "description": "Only available for the Waiting Room Advanced subscription. If `true`, requests to the waiting room with the header `Accept: application/json` will receive a JSON response object with information on the user's status in the waiting room as opposed to the configured static HTML page. This JSON response object has one property `cfWaitingRoom` which is an object containing the following fields:\n1. `inWaitingRoom`: Boolean indicating if the user is in the waiting room (always **true**).\n2. `waitTimeKnown`: Boolean indicating if the current estimated wait times are accurate. If **false**, they are not available.\n3. `waitTime`: Valid only when `waitTimeKnown` is **true**. Integer indicating the current estimated time in minutes the user will wait in the waiting room. When `queueingMethod` is **random**, this is set to `waitTime50Percentile`.\n4. `waitTime25Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 25% of users that gain entry the fastest (25th percentile).\n5. `waitTime50Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 50% of users that gain entry the fastest (50th percentile). In other words, half of the queued users are expected to let into the origin website before `waitTime50Percentile` and half are expected to be let in after it.\n6. `waitTime75Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 75% of users that gain entry the fastest (75th percentile).\n7. `waitTimeFormatted`: String displaying the `waitTime` formatted in English for users. If `waitTimeKnown` is **false**, `waitTimeFormatted` will display **unavailable**.\n8. `queueIsFull`: Boolean indicating if the waiting room's queue is currently full and not accepting new users at the moment.\n9. `queueAll`: Boolean indicating if all users will be queued in the waiting room and no one will be let into the origin website.\n10. `lastUpdated`: String displaying the timestamp as an ISO 8601 string of the user's last attempt to leave the waiting room and be let into the origin website. The user is able to make another attempt after `refreshIntervalSeconds` past this time. If the user makes a request too soon, it will be ignored and `lastUpdated` will not change.\n11. `refreshIntervalSeconds`: Integer indicating the number of seconds after `lastUpdated` until the user is able to make another attempt to leave the waiting room and be let into the origin website. When the `queueingMethod` is `reject`, there is no specified refresh time —\\_it will always be **zero**.\n12. `queueingMethod`: The queueing method currently used by the waiting room. It is either **fifo**, **random**, **passthrough**, or **reject**.\n13. `isFIFOQueue`: Boolean indicating if the waiting room uses a FIFO (First-In-First-Out) queue.\n14. `isRandomQueue`: Boolean indicating if the waiting room uses a Random queue where users gain access randomly.\n15. `isPassthroughQueue`: Boolean indicating if the waiting room uses a passthrough queue. Keep in mind that when passthrough is enabled, this JSON response will only exist when `queueAll` is **true** or `isEventPrequeueing` is **true** because in all other cases requests will go directly to the origin.\n16. `isRejectQueue`: Boolean indicating if the waiting room uses a reject queue.\n17. `isEventActive`: Boolean indicating if an event is currently occurring. Events are able to change a waiting room's behavior during a specified period of time. For additional information, look at the event properties `prequeue_start_time`, `event_start_time`, and `event_end_time` in the documentation for creating waiting room events. Events are considered active between these start and end times, as well as during the prequeueing period if it exists.\n18. `isEventPrequeueing`: Valid only when `isEventActive` is **true**. Boolean indicating if an event is currently prequeueing users before it starts.\n19. `timeUntilEventStart`: Valid only when `isEventPrequeueing` is **true**. Integer indicating the number of minutes until the event starts.\n20. `timeUntilEventStartFormatted`: String displaying the `timeUntilEventStart` formatted in English for users. If `isEventPrequeueing` is **false**, `timeUntilEventStartFormatted` will display **unavailable**.\n21. `timeUntilEventEnd`: Valid only when `isEventActive` is **true**. Integer indicating the number of minutes until the event ends.\n22. `timeUntilEventEndFormatted`: String displaying the `timeUntilEventEnd` formatted in English for users. If `isEventActive` is **false**, `timeUntilEventEndFormatted` will display **unavailable**.\n23. `shuffleAtEventStart`: Valid only when `isEventActive` is **true**. Boolean indicating if the users in the prequeue are shuffled randomly when the event starts.\n24. `turnstile`: Empty when turnstile isn't enabled. String displaying an html tag to display the Turnstile widget. Please add the `{{{turnstile}}}` tag to the `custom_html` template to ensure the Turnstile widget appears.\n25. `infiniteQueue`: Boolean indicating whether the response is for a user in the infinite queue.\n\nAn example cURL to a waiting room could be:\n\n\tcurl -X GET \"https://example.com/waitingroom\" \\\n\t\t-H \"Accept: application/json\"\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **fifo** and no event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 0,\n\t\t\t\"waitTime50Percentile\": 0,\n\t\t\t\"waitTime75Percentile\": 0,\n\t\t\t\"waitTimeFormatted\": \"10 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"fifo\",\n\t\t\t\"isFIFOQueue\": true,\n\t\t\t\"isRandomQueue\": false,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": false,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 0,\n\t\t\t\"timeUntilEventEndFormatted\": \"unavailable\",\n\t\t\t\"shuffleAtEventStart\": false\n\t\t}\n\t}\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **random** and an event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 5,\n\t\t\t\"waitTime50Percentile\": 10,\n\t\t\t\"waitTime75Percentile\": 15,\n\t\t\t\"waitTimeFormatted\": \"5 minutes to 15 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"random\",\n\t\t\t\"isFIFOQueue\": false,\n\t\t\t\"isRandomQueue\": true,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": true,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 15,\n\t\t\t\"timeUntilEventEndFormatted\": \"15 minutes\",\n\t\t\t\"shuffleAtEventStart\": true\n\t\t}\n\t}" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "new_users_per_minute", + "type": "Number", + "description": "Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. So it is possible that there is a little more or little less traffic coming to the route based on the traffic patterns at that time around the world." + }, + { + "name": "next_event_prequeue_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when the next event will begin queueing." + }, + { + "name": "next_event_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when the next event will start." + }, + { + "name": "path", + "type": "String", + "description": "Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported." + }, + { + "name": "queue_all", + "type": "Boolean", + "description": "If queue_all is `true`, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and estimated time will become unavailable." + }, + { + "name": "queueing_method", + "type": "String", + "description": "Sets the queueing method used by the waiting room. Changing this parameter from the **default** queueing method is only available for the Waiting Room Advanced subscription. Regardless of the queueing method, if `queue_all` is enabled or an event is prequeueing, users in the waiting room will not be accepted to the origin. These users will always see a waiting room page that refreshes automatically. The valid queueing methods are:\n1. `fifo` **(default)**: First-In-First-Out queue where customers gain access in the order they arrived.\n2. `random`: Random queue where customers gain access randomly, regardless of arrival time.\n3. `passthrough`: Users will pass directly through the waiting room and into the origin website. As a result, any configured limits will not be respected while this is enabled. This method can be used as an alternative to disabling a waiting room (with `suspended`) so that analytics are still reported. This can be used if you wish to allow all traffic normally, but want to restrict traffic during a waiting room event, or vice versa.\n4. `reject`: Users will be immediately rejected from the waiting room. As a result, no users will reach the origin website while this is enabled. This can be used if you wish to reject all traffic while performing maintenance, block traffic during a specified period of time (an event), or block traffic while events are not occurring. Consider a waiting room used for vaccine distribution that only allows traffic during sign-up events, and otherwise blocks all traffic. For this case, the waiting room uses `reject`, and its events override this with `fifo`, `random`, or `passthrough`. When this queueing method is enabled and neither `queueAll` is enabled nor an event is prequeueing, the waiting room page **will not refresh automatically**.\nAvailable values: \"fifo\", \"random\", \"passthrough\", \"reject\"." + }, + { + "name": "queueing_status_code", + "type": "Number", + "description": "HTTP status code returned to a user while in the queue.\nAvailable values: 200, 202, 429." + }, + { + "name": "session_duration", + "type": "Number", + "description": "Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they will be treated as a new user that visits the route." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Suspends or allows traffic going to the waiting room. If set to `true`, the traffic will not go to the waiting room." + }, + { + "name": "total_active_users", + "type": "Number", + "description": "Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available. This value is used as a baseline for the total number of active user sessions on the route. It is possible to have a situation where there are more or less active users sessions on the route based on the traffic patterns at that time around the world." + }, + { + "name": "turnstile_action", + "type": "String", + "description": "Which action to take when a bot is detected using Turnstile. `log` will\nhave no impact on queueing behavior, simply keeping track of how many\nbots are detected in Waiting Room Analytics. `infinite_queue` will send\nbots to a false queueing state, where they will never reach your\norigin. `infinite_queue` requires Advanced Waiting Room.\nAvailable values: \"log\", \"infinite_queue\"." + }, + { + "name": "turnstile_mode", + "type": "String", + "description": "Which Turnstile widget type to use for detecting bot traffic. See\n[the Turnstile documentation](https://developers.cloudflare.com/turnstile/concepts/widget/#widget-types)\nfor the definitions of these widget types. Set to `off` to disable the\nTurnstile integration entirely. Setting this to anything other than\n`off` or `invisible` requires Advanced Waiting Room.\nAvailable values: \"off\", \"invisible\", \"visible_non_interactive\", \"visible_managed\"." + } + ] + }, + "resource:cloudflare_waiting_room": { + "kind": "resource", + "name": "cloudflare_waiting_room", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "resource \"cloudflare_waiting_room\" \"example_waiting_room\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n host = \"shop.example.com\"\n name = \"production_webinar\"\n new_users_per_minute = 200\n total_active_users = 200\n additional_routes = [{\n host = \"shop2.example.com\"\n path = \"/shop2/checkout\"\n }]\n cookie_attributes = {\n samesite = \"auto\"\n secure = \"auto\"\n }\n cookie_suffix = \"abcd\"\n custom_page_html = \"{{#waitTimeKnown}} {{waitTime}} mins {{/waitTimeKnown}} {{^waitTimeKnown}} Queue all enabled {{/waitTimeKnown}}\"\n default_template_language = \"es-ES\"\n description = \"Production - DO NOT MODIFY\"\n disable_session_renewal = false\n enabled_origin_commands = [\"revoke\"]\n json_response_enabled = false\n path = \"/shop/checkout\"\n queue_all = true\n queueing_method = \"fifo\"\n queueing_status_code = 202\n session_duration = 1\n suspended = true\n turnstile_action = \"log\"\n turnstile_mode = \"off\"\n}", + "importExample": "$ terraform import cloudflare_waiting_room.example '/'", + "required": [ + { + "name": "host", + "type": "String", + "description": "The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination must be unique." + }, + { + "name": "name", + "type": "String", + "description": "A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "new_users_per_minute", + "type": "Number", + "description": "Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. So it is possible that there is a little more or little less traffic coming to the route based on the traffic patterns at that time around the world." + }, + { + "name": "total_active_users", + "type": "Number", + "description": "Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available. This value is used as a baseline for the total number of active user sessions on the route. It is possible to have a situation where there are more or less active users sessions on the route based on the traffic patterns at that time around the world." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "additional_routes", + "type": "Attributes List", + "description": "Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an implied wildcard at the end of the path. The hostname and path combination must be unique to this and all other waiting rooms.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The hostname to which this waiting room will be applied (no wildcards). The hostname must be the primary domain, subdomain, or custom hostname (if using SSL for SaaS) of this zone. Please do not include the scheme (http:// or https://)." + }, + { + "name": "path", + "type": "String", + "description": "Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported." + } + ] + }, + { + "name": "cookie_attributes", + "type": "Attributes", + "description": "Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.", + "children": [ + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on the waiting room cookie. Value `auto` will be translated to `lax` or `none` depending if **Always Use HTTPS** is enabled. Note that when using value `none`, the secure attribute cannot be set to `never`.\nAvailable values: \"auto\", \"lax\", \"none\", \"strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on the waiting room cookie. Value `always` indicates that the Secure attribute will be set in the Set-Cookie header, `never` indicates that the Secure attribute will not be set, and `auto` will set the Secure attribute depending if **Always Use HTTPS** is enabled.\nAvailable values: \"auto\", \"always\", \"never\"." + } + ] + }, + { + "name": "cookie_suffix", + "type": "String", + "description": "Appends a '_' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(__cf_waitingroom). If `cookie_suffix` is \"abcd\", the cookie name will be `__cf_waitingroom_abcd`. This field is required if using `additional_routes`." + }, + { + "name": "custom_page_html", + "type": "String", + "description": "Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custom_page_html is provided, the default waiting room will be used. The template is based on mustache ( https://mustache.github.io/ ). There are several variables that are evaluated by the Cloudflare edge:\n1. {{`waitTimeKnown`}} Acts like a boolean value that indicates the behavior to take when wait time is not available, for instance when queue_all is **true**.\n2. {{`waitTimeFormatted`}} Estimated wait time for the user. For example, five minutes. Alternatively, you can use:\n3. {{`waitTime`}} Number of minutes of estimated wait for a user.\n4. {{`waitTimeHours`}} Number of hours of estimated wait for a user (`Math.floor(waitTime/60)`).\n5. {{`waitTimeHourMinutes`}} Number of minutes above the `waitTimeHours` value (`waitTime%60`).\n6. {{`queueIsFull`}} Changes to **true** when no more people can be added to the queue.\n\nTo view the full list of variables, look at the `cfWaitingRoom` object described under the `json_response_enabled` property in other Waiting Room API calls." + }, + { + "name": "default_template_language", + "type": "String", + "description": "The language of the default page template. If no default_template_language is provided, then `en-US` (English) will be used.\nAvailable values: \"en-US\", \"es-ES\", \"de-DE\", \"fr-FR\", \"it-IT\", \"ja-JP\", \"ko-KR\", \"pt-BR\", \"zh-CN\", \"zh-TW\", \"nl-NL\", \"pl-PL\", \"id-ID\", \"tr-TR\", \"ar-EG\", \"ru-RU\", \"fa-IR\", \"bg-BG\", \"hr-HR\", \"cs-CZ\", \"da-DK\", \"fi-FI\", \"lt-LT\", \"lv-LV\", \"ms-MY\", \"nb-NO\", \"ro-RO\", \"el-GR\", \"he-IL\", \"hi-IN\", \"hu-HU\", \"sr-BA\", \"sk-SK\", \"sl-SI\", \"sv-SE\", \"tl-PH\", \"th-TH\", \"uk-UA\", \"vi-VN\"." + }, + { + "name": "description", + "type": "String", + "description": "A note that you can use to add more details about the waiting room." + }, + { + "name": "disable_session_renewal", + "type": "Boolean", + "description": "Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If `true`, an accepted user will have session_duration minutes to browse the site. After that, they will have to go through the waiting room again. If `false`, a user's session cookie will be automatically renewed on every request." + }, + { + "name": "enabled_origin_commands", + "type": "List of String", + "description": "A list of enabled origin commands." + }, + { + "name": "json_response_enabled", + "type": "Boolean", + "description": "Only available for the Waiting Room Advanced subscription. If `true`, requests to the waiting room with the header `Accept: application/json` will receive a JSON response object with information on the user's status in the waiting room as opposed to the configured static HTML page. This JSON response object has one property `cfWaitingRoom` which is an object containing the following fields:\n1. `inWaitingRoom`: Boolean indicating if the user is in the waiting room (always **true**).\n2. `waitTimeKnown`: Boolean indicating if the current estimated wait times are accurate. If **false**, they are not available.\n3. `waitTime`: Valid only when `waitTimeKnown` is **true**. Integer indicating the current estimated time in minutes the user will wait in the waiting room. When `queueingMethod` is **random**, this is set to `waitTime50Percentile`.\n4. `waitTime25Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 25% of users that gain entry the fastest (25th percentile).\n5. `waitTime50Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 50% of users that gain entry the fastest (50th percentile). In other words, half of the queued users are expected to let into the origin website before `waitTime50Percentile` and half are expected to be let in after it.\n6. `waitTime75Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 75% of users that gain entry the fastest (75th percentile).\n7. `waitTimeFormatted`: String displaying the `waitTime` formatted in English for users. If `waitTimeKnown` is **false**, `waitTimeFormatted` will display **unavailable**.\n8. `queueIsFull`: Boolean indicating if the waiting room's queue is currently full and not accepting new users at the moment.\n9. `queueAll`: Boolean indicating if all users will be queued in the waiting room and no one will be let into the origin website.\n10. `lastUpdated`: String displaying the timestamp as an ISO 8601 string of the user's last attempt to leave the waiting room and be let into the origin website. The user is able to make another attempt after `refreshIntervalSeconds` past this time. If the user makes a request too soon, it will be ignored and `lastUpdated` will not change.\n11. `refreshIntervalSeconds`: Integer indicating the number of seconds after `lastUpdated` until the user is able to make another attempt to leave the waiting room and be let into the origin website. When the `queueingMethod` is `reject`, there is no specified refresh time —\\_it will always be **zero**.\n12. `queueingMethod`: The queueing method currently used by the waiting room. It is either **fifo**, **random**, **passthrough**, or **reject**.\n13. `isFIFOQueue`: Boolean indicating if the waiting room uses a FIFO (First-In-First-Out) queue.\n14. `isRandomQueue`: Boolean indicating if the waiting room uses a Random queue where users gain access randomly.\n15. `isPassthroughQueue`: Boolean indicating if the waiting room uses a passthrough queue. Keep in mind that when passthrough is enabled, this JSON response will only exist when `queueAll` is **true** or `isEventPrequeueing` is **true** because in all other cases requests will go directly to the origin.\n16. `isRejectQueue`: Boolean indicating if the waiting room uses a reject queue.\n17. `isEventActive`: Boolean indicating if an event is currently occurring. Events are able to change a waiting room's behavior during a specified period of time. For additional information, look at the event properties `prequeue_start_time`, `event_start_time`, and `event_end_time` in the documentation for creating waiting room events. Events are considered active between these start and end times, as well as during the prequeueing period if it exists.\n18. `isEventPrequeueing`: Valid only when `isEventActive` is **true**. Boolean indicating if an event is currently prequeueing users before it starts.\n19. `timeUntilEventStart`: Valid only when `isEventPrequeueing` is **true**. Integer indicating the number of minutes until the event starts.\n20. `timeUntilEventStartFormatted`: String displaying the `timeUntilEventStart` formatted in English for users. If `isEventPrequeueing` is **false**, `timeUntilEventStartFormatted` will display **unavailable**.\n21. `timeUntilEventEnd`: Valid only when `isEventActive` is **true**. Integer indicating the number of minutes until the event ends.\n22. `timeUntilEventEndFormatted`: String displaying the `timeUntilEventEnd` formatted in English for users. If `isEventActive` is **false**, `timeUntilEventEndFormatted` will display **unavailable**.\n23. `shuffleAtEventStart`: Valid only when `isEventActive` is **true**. Boolean indicating if the users in the prequeue are shuffled randomly when the event starts.\n24. `turnstile`: Empty when turnstile isn't enabled. String displaying an html tag to display the Turnstile widget. Please add the `{{{turnstile}}}` tag to the `custom_html` template to ensure the Turnstile widget appears.\n25. `infiniteQueue`: Boolean indicating whether the response is for a user in the infinite queue.\n\nAn example cURL to a waiting room could be:\n\n\tcurl -X GET \"https://example.com/waitingroom\" \\\n\t\t-H \"Accept: application/json\"\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **fifo** and no event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 0,\n\t\t\t\"waitTime50Percentile\": 0,\n\t\t\t\"waitTime75Percentile\": 0,\n\t\t\t\"waitTimeFormatted\": \"10 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"fifo\",\n\t\t\t\"isFIFOQueue\": true,\n\t\t\t\"isRandomQueue\": false,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": false,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 0,\n\t\t\t\"timeUntilEventEndFormatted\": \"unavailable\",\n\t\t\t\"shuffleAtEventStart\": false\n\t\t}\n\t}\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **random** and an event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 5,\n\t\t\t\"waitTime50Percentile\": 10,\n\t\t\t\"waitTime75Percentile\": 15,\n\t\t\t\"waitTimeFormatted\": \"5 minutes to 15 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"random\",\n\t\t\t\"isFIFOQueue\": false,\n\t\t\t\"isRandomQueue\": true,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": true,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 15,\n\t\t\t\"timeUntilEventEndFormatted\": \"15 minutes\",\n\t\t\t\"shuffleAtEventStart\": true\n\t\t}\n\t}" + }, + { + "name": "path", + "type": "String", + "description": "Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported." + }, + { + "name": "queue_all", + "type": "Boolean", + "description": "If queue_all is `true`, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and estimated time will become unavailable." + }, + { + "name": "queueing_method", + "type": "String", + "description": "Sets the queueing method used by the waiting room. Changing this parameter from the **default** queueing method is only available for the Waiting Room Advanced subscription. Regardless of the queueing method, if `queue_all` is enabled or an event is prequeueing, users in the waiting room will not be accepted to the origin. These users will always see a waiting room page that refreshes automatically. The valid queueing methods are:\n1. `fifo` **(default)**: First-In-First-Out queue where customers gain access in the order they arrived.\n2. `random`: Random queue where customers gain access randomly, regardless of arrival time.\n3. `passthrough`: Users will pass directly through the waiting room and into the origin website. As a result, any configured limits will not be respected while this is enabled. This method can be used as an alternative to disabling a waiting room (with `suspended`) so that analytics are still reported. This can be used if you wish to allow all traffic normally, but want to restrict traffic during a waiting room event, or vice versa.\n4. `reject`: Users will be immediately rejected from the waiting room. As a result, no users will reach the origin website while this is enabled. This can be used if you wish to reject all traffic while performing maintenance, block traffic during a specified period of time (an event), or block traffic while events are not occurring. Consider a waiting room used for vaccine distribution that only allows traffic during sign-up events, and otherwise blocks all traffic. For this case, the waiting room uses `reject`, and its events override this with `fifo`, `random`, or `passthrough`. When this queueing method is enabled and neither `queueAll` is enabled nor an event is prequeueing, the waiting room page **will not refresh automatically**.\nAvailable values: \"fifo\", \"random\", \"passthrough\", \"reject\"." + }, + { + "name": "queueing_status_code", + "type": "Number", + "description": "HTTP status code returned to a user while in the queue.\nAvailable values: 200, 202, 429." + }, + { + "name": "session_duration", + "type": "Number", + "description": "Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they will be treated as a new user that visits the route." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Suspends or allows traffic going to the waiting room. If set to `true`, the traffic will not go to the waiting room." + }, + { + "name": "turnstile_action", + "type": "String", + "description": "Which action to take when a bot is detected using Turnstile. `log` will\nhave no impact on queueing behavior, simply keeping track of how many\nbots are detected in Waiting Room Analytics. `infinite_queue` will send\nbots to a false queueing state, where they will never reach your\norigin. `infinite_queue` requires Advanced Waiting Room.\nAvailable values: \"log\", \"infinite_queue\"." + }, + { + "name": "turnstile_mode", + "type": "String", + "description": "Which Turnstile widget type to use for detecting bot traffic. See\n[the Turnstile documentation](https://developers.cloudflare.com/turnstile/concepts/widget/#widget-types)\nfor the definitions of these widget types. Set to `off` to disable the\nTurnstile integration entirely. Setting this to anything other than\n`off` or `invisible` requires Advanced Waiting Room.\nAvailable values: \"off\", \"invisible\", \"visible_non_interactive\", \"visible_managed\"." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "next_event_prequeue_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when the next event will begin queueing." + }, + { + "name": "next_event_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when the next event will start." + } + ] + }, + "data-source:cloudflare_waiting_room_event": { + "kind": "data-source", + "name": "cloudflare_waiting_room_event", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "data \"cloudflare_waiting_room_event\" \"example_waiting_room_event\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n event_id = \"25756b2dfe6e378a06b033b670413757\"\n}", + "required": [ + { + "name": "event_id", + "type": "String" + }, + { + "name": "waiting_room_id", + "type": "String" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "custom_page_html", + "type": "String", + "description": "If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it." + }, + { + "name": "description", + "type": "String", + "description": "A note that you can use to add more details about the event." + }, + { + "name": "disable_session_renewal", + "type": "Boolean", + "description": "If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it." + }, + { + "name": "event_end_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks the end of the event." + }, + { + "name": "event_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "new_users_per_minute", + "type": "Number", + "description": "If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set." + }, + { + "name": "prequeue_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`." + }, + { + "name": "queueing_method", + "type": "String", + "description": "If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it." + }, + { + "name": "session_duration", + "type": "Number", + "description": "If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it." + }, + { + "name": "shuffle_at_event_start", + "type": "Boolean", + "description": "If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration." + }, + { + "name": "total_active_users", + "type": "Number", + "description": "If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set." + }, + { + "name": "turnstile_action", + "type": "String", + "description": "If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it.\nAvailable values: \"log\", \"infinite_queue\"." + }, + { + "name": "turnstile_mode", + "type": "String", + "description": "If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it.\nAvailable values: \"off\", \"invisible\", \"visible_non_interactive\", \"visible_managed\"." + } + ] + }, + "resource:cloudflare_waiting_room_event": { + "kind": "resource", + "name": "cloudflare_waiting_room_event", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "resource \"cloudflare_waiting_room_event\" \"example_waiting_room_event\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n event_end_time = \"2021-09-28T17:00:00Z\"\n event_start_time = \"2021-09-28T15:30:00Z\"\n name = \"production_webinar_event\"\n custom_page_html = \"{{#waitTimeKnown}} {{waitTime}} mins {{/waitTimeKnown}} {{^waitTimeKnown}} Event is prequeueing / Queue all enabled {{/waitTimeKnown}}\"\n description = \"Production event - DO NOT MODIFY\"\n disable_session_renewal = true\n new_users_per_minute = 200\n prequeue_start_time = \"2021-09-28T15:00:00Z\"\n queueing_method = \"random\"\n session_duration = 1\n shuffle_at_event_start = true\n suspended = true\n total_active_users = 200\n turnstile_action = \"log\"\n turnstile_mode = \"off\"\n}", + "importExample": "$ terraform import cloudflare_waiting_room_event.example '//'", + "required": [ + { + "name": "event_end_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks the end of the event." + }, + { + "name": "event_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`." + }, + { + "name": "name", + "type": "String", + "description": "A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "waiting_room_id", + "type": "String" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "custom_page_html", + "type": "String", + "description": "If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it." + }, + { + "name": "description", + "type": "String", + "description": "A note that you can use to add more details about the event." + }, + { + "name": "disable_session_renewal", + "type": "Boolean", + "description": "If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it." + }, + { + "name": "new_users_per_minute", + "type": "Number", + "description": "If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set." + }, + { + "name": "prequeue_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`." + }, + { + "name": "queueing_method", + "type": "String", + "description": "If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it." + }, + { + "name": "session_duration", + "type": "Number", + "description": "If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it." + }, + { + "name": "shuffle_at_event_start", + "type": "Boolean", + "description": "If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration." + }, + { + "name": "total_active_users", + "type": "Number", + "description": "If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set." + }, + { + "name": "turnstile_action", + "type": "String", + "description": "If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it.\nAvailable values: \"log\", \"infinite_queue\"." + }, + { + "name": "turnstile_mode", + "type": "String", + "description": "If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it.\nAvailable values: \"off\", \"invisible\", \"visible_non_interactive\", \"visible_managed\"." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_waiting_room_events": { + "kind": "list-data-source", + "name": "cloudflare_waiting_room_events", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "data \"cloudflare_waiting_room_events\" \"example_waiting_room_events\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [ + { + "name": "waiting_room_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "custom_page_html", + "type": "String", + "description": "If set, the event will override the waiting room's `custom_page_html` property while it is active. If null, the event will inherit it." + }, + { + "name": "description", + "type": "String", + "description": "A note that you can use to add more details about the event." + }, + { + "name": "disable_session_renewal", + "type": "Boolean", + "description": "If set, the event will override the waiting room's `disable_session_renewal` property while it is active. If null, the event will inherit it." + }, + { + "name": "event_end_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks the end of the event." + }, + { + "name": "event_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks the start of the event. At this time, queued users will be processed with the event's configuration. The start time must be at least one minute before `event_end_time`." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A unique name to identify the event. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "new_users_per_minute", + "type": "Number", + "description": "If set, the event will override the waiting room's `new_users_per_minute` property while it is active. If null, the event will inherit it. This can only be set if the event's `total_active_users` property is also set." + }, + { + "name": "prequeue_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when to begin queueing all users before the event starts. The prequeue must start at least five minutes before `event_start_time`." + }, + { + "name": "queueing_method", + "type": "String", + "description": "If set, the event will override the waiting room's `queueing_method` property while it is active. If null, the event will inherit it." + }, + { + "name": "session_duration", + "type": "Number", + "description": "If set, the event will override the waiting room's `session_duration` property while it is active. If null, the event will inherit it." + }, + { + "name": "shuffle_at_event_start", + "type": "Boolean", + "description": "If enabled, users in the prequeue will be shuffled randomly at the `event_start_time`. Requires that `prequeue_start_time` is not null. This is useful for situations when many users will join the event prequeue at the same time and you want to shuffle them to ensure fairness. Naturally, it makes the most sense to enable this feature when the `queueing_method` during the event respects ordering such as **fifo**, or else the shuffling may be unnecessary." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Suspends or allows an event. If set to `true`, the event is ignored and traffic will be handled based on the waiting room configuration." + }, + { + "name": "total_active_users", + "type": "Number", + "description": "If set, the event will override the waiting room's `total_active_users` property while it is active. If null, the event will inherit it. This can only be set if the event's `new_users_per_minute` property is also set." + }, + { + "name": "turnstile_action", + "type": "String", + "description": "If set, the event will override the waiting room's `turnstile_action` property while it is active. If null, the event will inherit it.\nAvailable values: \"log\", \"infinite_queue\"." + }, + { + "name": "turnstile_mode", + "type": "String", + "description": "If set, the event will override the waiting room's `turnstile_mode` property while it is active. If null, the event will inherit it.\nAvailable values: \"off\", \"invisible\", \"visible_non_interactive\", \"visible_managed\"." + } + ] + } + ] + }, + "data-source:cloudflare_waiting_room_rules": { + "kind": "data-source", + "name": "cloudflare_waiting_room_rules", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "data \"cloudflare_waiting_room_rules\" \"example_waiting_room_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [ + { + "name": "waiting_room_id", + "type": "String" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "action", + "type": "String", + "description": "The action to take when the expression matches.\nAvailable values: \"bypass_waiting_room\"." + }, + { + "name": "description", + "type": "String", + "description": "The description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "When set to true, the rule is enabled." + }, + { + "name": "expression", + "type": "String", + "description": "Criteria defining when there is a match for the current rule." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "last_updated", + "type": "String" + }, + { + "name": "version", + "type": "String", + "description": "The version of the rule." + } + ] + }, + "resource:cloudflare_waiting_room_rules": { + "kind": "resource", + "name": "cloudflare_waiting_room_rules", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "resource \"cloudflare_waiting_room_rules\" \"example_waiting_room_rules\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n waiting_room_id = \"699d98642c564d2e855e9661899b7252\"\n rules = [{\n action = \"bypass_waiting_room\"\n expression = \"ip.src in {10.20.30.40}\"\n description = \"allow all traffic from 10.20.30.40\"\n enabled = true\n }]\n}", + "importExample": "$ terraform import cloudflare_waiting_room_rules.example '/'", + "required": [ + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action to take when the expression matches.\nAvailable values: \"bypass_waiting_room\"." + }, + { + "name": "description", + "type": "String", + "description": "The description of the rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "When set to true, the rule is enabled." + }, + { + "name": "expression", + "type": "String", + "description": "Criteria defining when there is a match for the current rule." + } + ] + }, + { + "name": "waiting_room_id", + "type": "String" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of the rule." + } + ] + }, + "data-source:cloudflare_waiting_room_settings": { + "kind": "data-source", + "name": "cloudflare_waiting_room_settings", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "data \"cloudflare_waiting_room_settings\" \"example_waiting_room_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "search_engine_crawler_bypass", + "type": "Boolean", + "description": "Whether to allow verified search engine crawlers to bypass all waiting rooms on this zone.\nVerified search engine crawlers will not be tracked or counted by the waiting room system,\nand will not appear in waiting room analytics." + } + ] + }, + "resource:cloudflare_waiting_room_settings": { + "kind": "resource", + "name": "cloudflare_waiting_room_settings", + "description": "Accepted Permissions\n\n- `Waiting Rooms Read`\n- `Waiting Rooms Write`", + "example": "resource \"cloudflare_waiting_room_settings\" \"example_waiting_room_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n search_engine_crawler_bypass = true\n}", + "importExample": "$ terraform import cloudflare_waiting_room_settings.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "search_engine_crawler_bypass", + "type": "Boolean", + "description": "Whether to allow verified search engine crawlers to bypass all waiting rooms on this zone.\nVerified search engine crawlers will not be tracked or counted by the waiting room system,\nand will not appear in waiting room analytics." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "list-data-source:cloudflare_waiting_rooms": { + "kind": "list-data-source", + "name": "cloudflare_waiting_rooms", + "description": "Accepted Permissions\n\n- `Account Waiting Rooms Read`", + "example": "data \"cloudflare_waiting_rooms\" \"example_waiting_rooms\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "additional_routes", + "type": "Attributes List", + "description": "Only available for the Waiting Room Advanced subscription. Additional hostname and path combinations to which this waiting room will be applied. There is an implied wildcard at the end of the path. The hostname and path combination must be unique to this and all other waiting rooms.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The hostname to which this waiting room will be applied (no wildcards). The hostname must be the primary domain, subdomain, or custom hostname (if using SSL for SaaS) of this zone. Please do not include the scheme (http:// or https://)." + }, + { + "name": "path", + "type": "String", + "description": "Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported." + } + ] + }, + { + "name": "cookie_attributes", + "type": "Attributes", + "description": "Configures cookie attributes for the waiting room cookie. This encrypted cookie stores a user's status in the waiting room, such as queue position.", + "children": [ + { + "name": "samesite", + "type": "String", + "description": "Configures the SameSite attribute on the waiting room cookie. Value `auto` will be translated to `lax` or `none` depending if **Always Use HTTPS** is enabled. Note that when using value `none`, the secure attribute cannot be set to `never`.\nAvailable values: \"auto\", \"lax\", \"none\", \"strict\"." + }, + { + "name": "secure", + "type": "String", + "description": "Configures the Secure attribute on the waiting room cookie. Value `always` indicates that the Secure attribute will be set in the Set-Cookie header, `never` indicates that the Secure attribute will not be set, and `auto` will set the Secure attribute depending if **Always Use HTTPS** is enabled.\nAvailable values: \"auto\", \"always\", \"never\"." + } + ] + }, + { + "name": "cookie_suffix", + "type": "String", + "description": "Appends a '_' + a custom suffix to the end of Cloudflare Waiting Room's cookie name(__cf_waitingroom). If `cookie_suffix` is \"abcd\", the cookie name will be `__cf_waitingroom_abcd`. This field is required if using `additional_routes`." + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "custom_page_html", + "type": "String", + "description": "Only available for the Waiting Room Advanced subscription. This is a template html file that will be rendered at the edge. If no custom_page_html is provided, the default waiting room will be used. The template is based on mustache ( https://mustache.github.io/ ). There are several variables that are evaluated by the Cloudflare edge:\n1. {{`waitTimeKnown`}} Acts like a boolean value that indicates the behavior to take when wait time is not available, for instance when queue_all is **true**.\n2. {{`waitTimeFormatted`}} Estimated wait time for the user. For example, five minutes. Alternatively, you can use:\n3. {{`waitTime`}} Number of minutes of estimated wait for a user.\n4. {{`waitTimeHours`}} Number of hours of estimated wait for a user (`Math.floor(waitTime/60)`).\n5. {{`waitTimeHourMinutes`}} Number of minutes above the `waitTimeHours` value (`waitTime%60`).\n6. {{`queueIsFull`}} Changes to **true** when no more people can be added to the queue.\n\nTo view the full list of variables, look at the `cfWaitingRoom` object described under the `json_response_enabled` property in other Waiting Room API calls." + }, + { + "name": "default_template_language", + "type": "String", + "description": "The language of the default page template. If no default_template_language is provided, then `en-US` (English) will be used.\nAvailable values: \"en-US\", \"es-ES\", \"de-DE\", \"fr-FR\", \"it-IT\", \"ja-JP\", \"ko-KR\", \"pt-BR\", \"zh-CN\", \"zh-TW\", \"nl-NL\", \"pl-PL\", \"id-ID\", \"tr-TR\", \"ar-EG\", \"ru-RU\", \"fa-IR\", \"bg-BG\", \"hr-HR\", \"cs-CZ\", \"da-DK\", \"fi-FI\", \"lt-LT\", \"lv-LV\", \"ms-MY\", \"nb-NO\", \"ro-RO\", \"el-GR\", \"he-IL\", \"hi-IN\", \"hu-HU\", \"sr-BA\", \"sk-SK\", \"sl-SI\", \"sv-SE\", \"tl-PH\", \"th-TH\", \"uk-UA\", \"vi-VN\"." + }, + { + "name": "description", + "type": "String", + "description": "A note that you can use to add more details about the waiting room." + }, + { + "name": "disable_session_renewal", + "type": "Boolean", + "description": "Only available for the Waiting Room Advanced subscription. Disables automatic renewal of session cookies. If `true`, an accepted user will have session_duration minutes to browse the site. After that, they will have to go through the waiting room again. If `false`, a user's session cookie will be automatically renewed on every request." + }, + { + "name": "enabled_origin_commands", + "type": "List of String", + "description": "A list of enabled origin commands." + }, + { + "name": "host", + "type": "String", + "description": "The host name to which the waiting room will be applied (no wildcards). Please do not include the scheme (http:// or https://). The host and path combination must be unique." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "json_response_enabled", + "type": "Boolean", + "description": "Only available for the Waiting Room Advanced subscription. If `true`, requests to the waiting room with the header `Accept: application/json` will receive a JSON response object with information on the user's status in the waiting room as opposed to the configured static HTML page. This JSON response object has one property `cfWaitingRoom` which is an object containing the following fields:\n1. `inWaitingRoom`: Boolean indicating if the user is in the waiting room (always **true**).\n2. `waitTimeKnown`: Boolean indicating if the current estimated wait times are accurate. If **false**, they are not available.\n3. `waitTime`: Valid only when `waitTimeKnown` is **true**. Integer indicating the current estimated time in minutes the user will wait in the waiting room. When `queueingMethod` is **random**, this is set to `waitTime50Percentile`.\n4. `waitTime25Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 25% of users that gain entry the fastest (25th percentile).\n5. `waitTime50Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 50% of users that gain entry the fastest (50th percentile). In other words, half of the queued users are expected to let into the origin website before `waitTime50Percentile` and half are expected to be let in after it.\n6. `waitTime75Percentile`: Valid only when `queueingMethod` is **random** and `waitTimeKnown` is **true**. Integer indicating the current estimated maximum wait time for the 75% of users that gain entry the fastest (75th percentile).\n7. `waitTimeFormatted`: String displaying the `waitTime` formatted in English for users. If `waitTimeKnown` is **false**, `waitTimeFormatted` will display **unavailable**.\n8. `queueIsFull`: Boolean indicating if the waiting room's queue is currently full and not accepting new users at the moment.\n9. `queueAll`: Boolean indicating if all users will be queued in the waiting room and no one will be let into the origin website.\n10. `lastUpdated`: String displaying the timestamp as an ISO 8601 string of the user's last attempt to leave the waiting room and be let into the origin website. The user is able to make another attempt after `refreshIntervalSeconds` past this time. If the user makes a request too soon, it will be ignored and `lastUpdated` will not change.\n11. `refreshIntervalSeconds`: Integer indicating the number of seconds after `lastUpdated` until the user is able to make another attempt to leave the waiting room and be let into the origin website. When the `queueingMethod` is `reject`, there is no specified refresh time —\\_it will always be **zero**.\n12. `queueingMethod`: The queueing method currently used by the waiting room. It is either **fifo**, **random**, **passthrough**, or **reject**.\n13. `isFIFOQueue`: Boolean indicating if the waiting room uses a FIFO (First-In-First-Out) queue.\n14. `isRandomQueue`: Boolean indicating if the waiting room uses a Random queue where users gain access randomly.\n15. `isPassthroughQueue`: Boolean indicating if the waiting room uses a passthrough queue. Keep in mind that when passthrough is enabled, this JSON response will only exist when `queueAll` is **true** or `isEventPrequeueing` is **true** because in all other cases requests will go directly to the origin.\n16. `isRejectQueue`: Boolean indicating if the waiting room uses a reject queue.\n17. `isEventActive`: Boolean indicating if an event is currently occurring. Events are able to change a waiting room's behavior during a specified period of time. For additional information, look at the event properties `prequeue_start_time`, `event_start_time`, and `event_end_time` in the documentation for creating waiting room events. Events are considered active between these start and end times, as well as during the prequeueing period if it exists.\n18. `isEventPrequeueing`: Valid only when `isEventActive` is **true**. Boolean indicating if an event is currently prequeueing users before it starts.\n19. `timeUntilEventStart`: Valid only when `isEventPrequeueing` is **true**. Integer indicating the number of minutes until the event starts.\n20. `timeUntilEventStartFormatted`: String displaying the `timeUntilEventStart` formatted in English for users. If `isEventPrequeueing` is **false**, `timeUntilEventStartFormatted` will display **unavailable**.\n21. `timeUntilEventEnd`: Valid only when `isEventActive` is **true**. Integer indicating the number of minutes until the event ends.\n22. `timeUntilEventEndFormatted`: String displaying the `timeUntilEventEnd` formatted in English for users. If `isEventActive` is **false**, `timeUntilEventEndFormatted` will display **unavailable**.\n23. `shuffleAtEventStart`: Valid only when `isEventActive` is **true**. Boolean indicating if the users in the prequeue are shuffled randomly when the event starts.\n24. `turnstile`: Empty when turnstile isn't enabled. String displaying an html tag to display the Turnstile widget. Please add the `{{{turnstile}}}` tag to the `custom_html` template to ensure the Turnstile widget appears.\n25. `infiniteQueue`: Boolean indicating whether the response is for a user in the infinite queue.\n\nAn example cURL to a waiting room could be:\n\n\tcurl -X GET \"https://example.com/waitingroom\" \\\n\t\t-H \"Accept: application/json\"\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **fifo** and no event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 0,\n\t\t\t\"waitTime50Percentile\": 0,\n\t\t\t\"waitTime75Percentile\": 0,\n\t\t\t\"waitTimeFormatted\": \"10 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"fifo\",\n\t\t\t\"isFIFOQueue\": true,\n\t\t\t\"isRandomQueue\": false,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": false,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 0,\n\t\t\t\"timeUntilEventEndFormatted\": \"unavailable\",\n\t\t\t\"shuffleAtEventStart\": false\n\t\t}\n\t}\n\nIf `json_response_enabled` is **true** and the request hits the waiting room, an example JSON response when `queueingMethod` is **random** and an event is active could be:\n\n\t{\n\t\t\"cfWaitingRoom\": {\n\t\t\t\"inWaitingRoom\": true,\n\t\t\t\"waitTimeKnown\": true,\n\t\t\t\"waitTime\": 10,\n\t\t\t\"waitTime25Percentile\": 5,\n\t\t\t\"waitTime50Percentile\": 10,\n\t\t\t\"waitTime75Percentile\": 15,\n\t\t\t\"waitTimeFormatted\": \"5 minutes to 15 minutes\",\n\t\t\t\"queueIsFull\": false,\n\t\t\t\"queueAll\": false,\n\t\t\t\"lastUpdated\": \"2020-08-03T23:46:00.000Z\",\n\t\t\t\"refreshIntervalSeconds\": 20,\n\t\t\t\"queueingMethod\": \"random\",\n\t\t\t\"isFIFOQueue\": false,\n\t\t\t\"isRandomQueue\": true,\n\t\t\t\"isPassthroughQueue\": false,\n\t\t\t\"isRejectQueue\": false,\n\t\t\t\"isEventActive\": true,\n\t\t\t\"isEventPrequeueing\": false,\n\t\t\t\"timeUntilEventStart\": 0,\n\t\t\t\"timeUntilEventStartFormatted\": \"unavailable\",\n\t\t\t\"timeUntilEventEnd\": 15,\n\t\t\t\"timeUntilEventEndFormatted\": \"15 minutes\",\n\t\t\t\"shuffleAtEventStart\": true\n\t\t}\n\t}" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A unique name to identify the waiting room. Only alphanumeric characters, hyphens and underscores are allowed." + }, + { + "name": "new_users_per_minute", + "type": "Number", + "description": "Sets the number of new users that will be let into the route every minute. This value is used as baseline for the number of users that are let in per minute. So it is possible that there is a little more or little less traffic coming to the route based on the traffic patterns at that time around the world." + }, + { + "name": "next_event_prequeue_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when the next event will begin queueing." + }, + { + "name": "next_event_start_time", + "type": "String", + "description": "An ISO 8601 timestamp that marks when the next event will start." + }, + { + "name": "path", + "type": "String", + "description": "Sets the path within the host to enable the waiting room on. The waiting room will be enabled for all subpaths as well. If there are two waiting rooms on the same subpath, the waiting room for the most specific path will be chosen. Wildcards and query parameters are not supported." + }, + { + "name": "queue_all", + "type": "Boolean", + "description": "If queue_all is `true`, all the traffic that is coming to a route will be sent to the waiting room. No new traffic can get to the route once this field is set and estimated time will become unavailable." + }, + { + "name": "queueing_method", + "type": "String", + "description": "Sets the queueing method used by the waiting room. Changing this parameter from the **default** queueing method is only available for the Waiting Room Advanced subscription. Regardless of the queueing method, if `queue_all` is enabled or an event is prequeueing, users in the waiting room will not be accepted to the origin. These users will always see a waiting room page that refreshes automatically. The valid queueing methods are:\n1. `fifo` **(default)**: First-In-First-Out queue where customers gain access in the order they arrived.\n2. `random`: Random queue where customers gain access randomly, regardless of arrival time.\n3. `passthrough`: Users will pass directly through the waiting room and into the origin website. As a result, any configured limits will not be respected while this is enabled. This method can be used as an alternative to disabling a waiting room (with `suspended`) so that analytics are still reported. This can be used if you wish to allow all traffic normally, but want to restrict traffic during a waiting room event, or vice versa.\n4. `reject`: Users will be immediately rejected from the waiting room. As a result, no users will reach the origin website while this is enabled. This can be used if you wish to reject all traffic while performing maintenance, block traffic during a specified period of time (an event), or block traffic while events are not occurring. Consider a waiting room used for vaccine distribution that only allows traffic during sign-up events, and otherwise blocks all traffic. For this case, the waiting room uses `reject`, and its events override this with `fifo`, `random`, or `passthrough`. When this queueing method is enabled and neither `queueAll` is enabled nor an event is prequeueing, the waiting room page **will not refresh automatically**.\nAvailable values: \"fifo\", \"random\", \"passthrough\", \"reject\"." + }, + { + "name": "queueing_status_code", + "type": "Number", + "description": "HTTP status code returned to a user while in the queue.\nAvailable values: 200, 202, 429." + }, + { + "name": "session_duration", + "type": "Number", + "description": "Lifetime of a cookie (in minutes) set by Cloudflare for users who get access to the route. If a user is not seen by Cloudflare again in that time period, they will be treated as a new user that visits the route." + }, + { + "name": "suspended", + "type": "Boolean", + "description": "Suspends or allows traffic going to the waiting room. If set to `true`, the traffic will not go to the waiting room." + }, + { + "name": "total_active_users", + "type": "Number", + "description": "Sets the total number of active user sessions on the route at a point in time. A route is a combination of host and path on which a waiting room is available. This value is used as a baseline for the total number of active user sessions on the route. It is possible to have a situation where there are more or less active users sessions on the route based on the traffic patterns at that time around the world." + }, + { + "name": "turnstile_action", + "type": "String", + "description": "Which action to take when a bot is detected using Turnstile. `log` will\nhave no impact on queueing behavior, simply keeping track of how many\nbots are detected in Waiting Room Analytics. `infinite_queue` will send\nbots to a false queueing state, where they will never reach your\norigin. `infinite_queue` requires Advanced Waiting Room.\nAvailable values: \"log\", \"infinite_queue\"." + }, + { + "name": "turnstile_mode", + "type": "String", + "description": "Which Turnstile widget type to use for detecting bot traffic. See\n[the Turnstile documentation](https://developers.cloudflare.com/turnstile/concepts/widget/#widget-types)\nfor the definitions of these widget types. Set to `off` to disable the\nTurnstile integration entirely. Setting this to anything other than\n`off` or `invisible` requires Advanced Waiting Room.\nAvailable values: \"off\", \"invisible\", \"visible_non_interactive\", \"visible_managed\"." + } + ] + } + ] + }, + "resource:cloudflare_web_analytics_rule": { + "kind": "resource", + "name": "cloudflare_web_analytics_rule", + "example": "resource \"cloudflare_web_analytics_rule\" \"example_web_analytics_rule\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n ruleset_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n host = \"example.com\"\n inclusive = true\n is_paused = false\n paths = [\"*\"]\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "ruleset_id", + "type": "String", + "description": "The Web Analytics ruleset identifier." + } + ], + "optional": [ + { + "name": "host", + "type": "String" + }, + { + "name": "inclusive", + "type": "Boolean", + "description": "Whether the rule includes or excludes traffic from being measured." + }, + { + "name": "is_paused", + "type": "Boolean", + "description": "Whether the rule is paused or not." + }, + { + "name": "paths", + "type": "List of String" + } + ], + "computed": [ + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics rule identifier." + }, + { + "name": "priority", + "type": "Number" + } + ] + }, + "data-source:cloudflare_web_analytics_site": { + "kind": "data-source", + "name": "cloudflare_web_analytics_site", + "description": "Accepted Permissions\n\n- `Account Settings Read`", + "example": "data \"cloudflare_web_analytics_site\" \"example_web_analytics_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n site_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "order_by", + "type": "String", + "description": "The property used to sort the list of results.\nAvailable values: \"host\", \"created\"." + } + ] + }, + { + "name": "site_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "auto_install", + "type": "Boolean", + "description": "If enabled, the JavaScript snippet is automatically injected for orange-clouded sites." + }, + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "A list of rules.", + "children": [ + { + "name": "created", + "type": "String" + }, + { + "name": "host", + "type": "String", + "description": "The hostname the rule will be applied to." + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics rule identifier." + }, + { + "name": "inclusive", + "type": "Boolean", + "description": "Whether the rule includes or excludes traffic from being measured." + }, + { + "name": "is_paused", + "type": "Boolean", + "description": "Whether the rule is paused or not." + }, + { + "name": "paths", + "type": "List of String", + "description": "The paths the rule will be applied to." + }, + { + "name": "priority", + "type": "Number" + } + ] + }, + { + "name": "ruleset", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the ruleset is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics ruleset identifier." + }, + { + "name": "zone_name", + "type": "String" + }, + { + "name": "zone_tag", + "type": "String", + "description": "The zone identifier." + } + ] + }, + { + "name": "site_tag", + "type": "String", + "description": "The Web Analytics site identifier." + }, + { + "name": "site_token", + "type": "String", + "description": "The Web Analytics site token." + }, + { + "name": "snippet", + "type": "String", + "description": "Encoded JavaScript snippet." + } + ] + }, + "resource:cloudflare_web_analytics_site": { + "kind": "resource", + "name": "cloudflare_web_analytics_site", + "description": "Accepted Permissions\n\n- `Account Settings Read`\n- `Account Settings Write`", + "example": "resource \"cloudflare_web_analytics_site\" \"example_web_analytics_site\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n auto_install = true\n host = \"example.com\"\n zone_tag = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "importExample": "$ terraform import cloudflare_web_analytics_site.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "auto_install", + "type": "Boolean", + "description": "If enabled, the JavaScript snippet is automatically injected for orange-clouded sites." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Enables or disables RUM. This option can be used only when auto_install is set to true." + }, + { + "name": "host", + "type": "String", + "description": "The hostname to use for gray-clouded sites." + }, + { + "name": "lite", + "type": "Boolean", + "description": "If enabled, the JavaScript snippet will not be injected for visitors from the EU." + }, + { + "name": "zone_tag", + "type": "String", + "description": "The zone identifier." + } + ], + "computed": [ + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics site identifier." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "A list of rules.", + "children": [ + { + "name": "created", + "type": "String" + }, + { + "name": "host", + "type": "String", + "description": "The hostname the rule will be applied to." + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics rule identifier." + }, + { + "name": "inclusive", + "type": "Boolean", + "description": "Whether the rule includes or excludes traffic from being measured." + }, + { + "name": "is_paused", + "type": "Boolean", + "description": "Whether the rule is paused or not." + }, + { + "name": "paths", + "type": "List of String", + "description": "The paths the rule will be applied to." + }, + { + "name": "priority", + "type": "Number" + } + ] + }, + { + "name": "ruleset", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the ruleset is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics ruleset identifier." + }, + { + "name": "zone_name", + "type": "String" + }, + { + "name": "zone_tag", + "type": "String", + "description": "The zone identifier." + } + ] + }, + { + "name": "site_tag", + "type": "String", + "description": "The Web Analytics site identifier." + }, + { + "name": "site_token", + "type": "String", + "description": "The Web Analytics site token." + }, + { + "name": "snippet", + "type": "String", + "description": "Encoded JavaScript snippet." + } + ] + }, + "list-data-source:cloudflare_web_analytics_sites": { + "kind": "list-data-source", + "name": "cloudflare_web_analytics_sites", + "description": "Accepted Permissions\n\n- `Account Settings Read`", + "example": "data \"cloudflare_web_analytics_sites\" \"example_web_analytics_sites\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n order_by = \"host\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order_by", + "type": "String", + "description": "The property used to sort the list of results.\nAvailable values: \"host\", \"created\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "auto_install", + "type": "Boolean", + "description": "If enabled, the JavaScript snippet is automatically injected for orange-clouded sites." + }, + { + "name": "created", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics site identifier." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "A list of rules.", + "children": [ + { + "name": "created", + "type": "String" + }, + { + "name": "host", + "type": "String", + "description": "The hostname the rule will be applied to." + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics rule identifier." + }, + { + "name": "inclusive", + "type": "Boolean", + "description": "Whether the rule includes or excludes traffic from being measured." + }, + { + "name": "is_paused", + "type": "Boolean", + "description": "Whether the rule is paused or not." + }, + { + "name": "paths", + "type": "List of String", + "description": "The paths the rule will be applied to." + }, + { + "name": "priority", + "type": "Number" + } + ] + }, + { + "name": "ruleset", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the ruleset is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The Web Analytics ruleset identifier." + }, + { + "name": "zone_name", + "type": "String" + }, + { + "name": "zone_tag", + "type": "String", + "description": "The zone identifier." + } + ] + }, + { + "name": "site_tag", + "type": "String", + "description": "The Web Analytics site identifier." + }, + { + "name": "site_token", + "type": "String", + "description": "The Web Analytics site token." + }, + { + "name": "snippet", + "type": "String", + "description": "Encoded JavaScript snippet." + } + ] + } + ] + }, + "data-source:cloudflare_web3_hostname": { + "kind": "data-source", + "name": "cloudflare_web3_hostname", + "description": "Accepted Permissions\n\n- `Web3 Hostnames Read`\n- `Web3 Hostnames Write`", + "example": "data \"cloudflare_web3_hostname\" \"example_web3_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n identifier = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "identifier", + "type": "String", + "description": "Specify the identifier of the hostname." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Specify the identifier of the hostname." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Specify an optional description of the hostname." + }, + { + "name": "dnslink", + "type": "String", + "description": "Specify the DNSLink value used if the target is ipfs." + }, + { + "name": "id", + "type": "String", + "description": "Specify the identifier of the hostname." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Specify the hostname that points to the target gateway via CNAME." + }, + { + "name": "status", + "type": "String", + "description": "Specifies the status of the hostname's activation.\nAvailable values: \"active\", \"pending\", \"deleting\", \"error\"." + }, + { + "name": "target", + "type": "String", + "description": "Specify the target gateway of the hostname.\nAvailable values: \"ethereum\", \"ipfs\", \"ipfs_universal_path\"." + } + ] + }, + "resource:cloudflare_web3_hostname": { + "kind": "resource", + "name": "cloudflare_web3_hostname", + "description": "Accepted Permissions\n\n- `Web3 Hostnames Read`\n- `Web3 Hostnames Write`", + "example": "resource \"cloudflare_web3_hostname\" \"example_web3_hostname\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"gateway.example.com\"\n target = \"ipfs\"\n description = \"This is my IPFS gateway.\"\n dnslink = \"/ipns/onboarding.ipfs.cloudflare.com\"\n}", + "importExample": "$ terraform import cloudflare_web3_hostname.example '/'", + "required": [ + { + "name": "name", + "type": "String", + "description": "Specify the hostname that points to the target gateway via CNAME." + }, + { + "name": "target", + "type": "String", + "description": "Specify the target gateway of the hostname.\nAvailable values: \"ethereum\", \"ipfs\", \"ipfs_universal_path\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "Specify the identifier of the hostname." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Specify an optional description of the hostname." + }, + { + "name": "dnslink", + "type": "String", + "description": "Specify the DNSLink value used if the target is ipfs." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Specify the identifier of the hostname." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "status", + "type": "String", + "description": "Specifies the status of the hostname's activation.\nAvailable values: \"active\", \"pending\", \"deleting\", \"error\"." + } + ] + }, + "list-data-source:cloudflare_web3_hostnames": { + "kind": "list-data-source", + "name": "cloudflare_web3_hostnames", + "description": "Accepted Permissions\n\n- `Web3 Hostnames Read`\n- `Web3 Hostnames Write`", + "example": "data \"cloudflare_web3_hostnames\" \"example_web3_hostnames\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Specify the identifier of the hostname." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Specify an optional description of the hostname." + }, + { + "name": "dnslink", + "type": "String", + "description": "Specify the DNSLink value used if the target is ipfs." + }, + { + "name": "id", + "type": "String", + "description": "Specify the identifier of the hostname." + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Specify the hostname that points to the target gateway via CNAME." + }, + { + "name": "status", + "type": "String", + "description": "Specifies the status of the hostname's activation.\nAvailable values: \"active\", \"pending\", \"deleting\", \"error\"." + }, + { + "name": "target", + "type": "String", + "description": "Specify the target gateway of the hostname.\nAvailable values: \"ethereum\", \"ipfs\", \"ipfs_universal_path\"." + } + ] + } + ] + }, + "data-source:cloudflare_worker": { + "kind": "data-source", + "name": "cloudflare_worker", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_worker\" \"example_worker\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "order", + "type": "String", + "description": "Sort direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order_by", + "type": "String", + "description": "Property to sort results by.\nAvailable values: \"deployed_on\", \"updated_on\", \"created_on\", \"name\"." + } + ] + }, + { + "name": "worker_id", + "type": "String", + "description": "Identifier for the Worker, which can be ID or name." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the Worker was created." + }, + { + "name": "deployed_on", + "type": "String", + "description": "When the Worker's most recent deployment was created. `null` if the Worker has never been deployed." + }, + { + "name": "id", + "type": "String", + "description": "Identifier for the Worker, which can be ID or name." + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether logpush is enabled for the Worker." + }, + { + "name": "name", + "type": "String", + "description": "Name of the Worker." + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "redact_query_string", + "type": "Boolean", + "description": "Whether query strings are removed from request URLs in logs and traces." + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "previews_base_config", + "type": "Attributes", + "description": "Template configuration used when creating new Previews for this Worker.", + "children": [ + { + "name": "cache_options", + "type": "Attributes", + "description": "Cache options used when creating new Previews.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "env", + "type": "Attributes Map", + "description": "Bindings used when creating new Previews, keyed by binding name.", + "children": [ + { + "name": "type", + "type": "String", + "description": "The kind of resource that the binding provides." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Resource limits enforced at runtime for newly created Previews.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "The amount of CPU time this Worker can use in milliseconds." + }, + { + "name": "subrequests", + "type": "Number", + "description": "The number of subrequests this Worker can make per request." + } + ] + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether logpush is enabled when creating new Previews." + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings used when creating new Previews.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "redact_query_string", + "type": "Boolean", + "description": "Whether query strings are removed from request URLs in logs and traces." + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement configuration used when creating new Previews.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "Other Workers that should consume logs from newly created Previews.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the consumer Worker." + } + ] + } + ] + }, + { + "name": "references", + "type": "Attributes", + "description": "Other resources that reference the Worker and depend on it existing.", + "children": [ + { + "name": "dispatch_namespace_outbounds", + "type": "Attributes List", + "description": "Other Workers that reference the Worker as an outbound for a dispatch namespace.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the dispatch namespace." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the dispatch namespace." + }, + { + "name": "worker_id", + "type": "String", + "description": "ID of the Worker using the dispatch namespace." + }, + { + "name": "worker_name", + "type": "String", + "description": "Name of the Worker using the dispatch namespace." + } + ] + }, + { + "name": "domains", + "type": "Attributes List", + "description": "Custom domains connected to the Worker.", + "children": [ + { + "name": "certificate_id", + "type": "String", + "description": "ID of the TLS certificate issued for the custom domain." + }, + { + "name": "hostname", + "type": "String", + "description": "Full hostname of the custom domain, including the zone name." + }, + { + "name": "id", + "type": "String", + "description": "ID of the custom domain." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone." + } + ] + }, + { + "name": "durable_objects", + "type": "Attributes List", + "description": "Other Workers that reference Durable Object classes implemented by the Worker.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace being used." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the Durable Object namespace being used." + }, + { + "name": "worker_id", + "type": "String", + "description": "ID of the Worker using the Durable Object implementation." + }, + { + "name": "worker_name", + "type": "String", + "description": "Name of the Worker using the Durable Object implementation." + } + ] + }, + { + "name": "queues", + "type": "Attributes List", + "description": "Queues that send messages to the Worker.", + "children": [ + { + "name": "queue_consumer_id", + "type": "String", + "description": "ID of the queue consumer configuration." + }, + { + "name": "queue_id", + "type": "String", + "description": "ID of the queue." + }, + { + "name": "queue_name", + "type": "String", + "description": "Name of the queue." + } + ] + }, + { + "name": "workers", + "type": "Attributes List", + "description": "Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).", + "children": [ + { + "name": "id", + "type": "String", + "description": "ID of the referencing Worker." + }, + { + "name": "name", + "type": "String", + "description": "Name of the referencing Worker." + } + ] + } + ] + }, + { + "name": "subdomain", + "type": "Attributes", + "description": "Subdomain settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the *.workers.dev subdomain is enabled for the Worker." + }, + { + "name": "preview_url_suffix", + "type": "String", + "description": "Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain." + }, + { + "name": "previews_enabled", + "type": "Boolean", + "description": "Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker." + }, + { + "name": "url", + "type": "String", + "description": "The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain." + } + ] + }, + { + "name": "tags", + "type": "Set of String", + "description": "Tags associated with the Worker." + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "Other Workers that should consume logs from the Worker.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the consumer Worker." + } + ] + }, + { + "name": "updated_on", + "type": "String", + "description": "When the Worker was most recently updated." + } + ] + }, + "resource:cloudflare_worker": { + "kind": "resource", + "name": "cloudflare_worker", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "resource \"cloudflare_worker\" \"example_worker\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-worker\"\n logpush = true\n observability = {\n enabled = true\n head_sampling_rate = 1\n issues = {\n enabled = true\n }\n logs = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n invocation_logs = true\n persist = true\n }\n redact_query_string = true\n traces = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n persist = true\n propagation_policy = \"authenticated\"\n }\n }\n previews_base_config = {\n cache_options = {\n enabled = true\n cross_version_cache = true\n }\n env = {\n MY_ENV_VAR = {\n type = \"plain_text\"\n }\n }\n limits = {\n cpu_ms = 50\n subrequests = 1000\n }\n logpush = true\n observability = {\n enabled = true\n head_sampling_rate = 1\n issues = {\n enabled = true\n }\n logs = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n invocation_logs = true\n persist = true\n }\n redact_query_string = true\n traces = {\n destinations = [\"string\"]\n enabled = true\n head_sampling_rate = 1\n persist = true\n propagation_policy = \"authenticated\"\n }\n }\n placement = {\n mode = \"smart\"\n }\n tail_consumers = [{\n name = \"my-tail-consumer\"\n }]\n }\n subdomain = {\n enabled = true\n previews_enabled = true\n }\n tags = [\"my-team\", \"my-public-api\"]\n tail_consumers = [{\n name = \"my-tail-consumer\"\n }]\n}", + "importExample": "$ terraform import cloudflare_worker.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "Name of the Worker." + } + ], + "optional": [ + { + "name": "force", + "type": "Boolean", + "description": "If true, delete the Worker even when other Workers still reference it. Service bindings in those Workers may be left broken. Durable Object namespaces implemented by the deleted Worker are deleted even if other Workers reference them." + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether logpush is enabled for the Worker." + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" (default) honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "previews_base_config", + "type": "Attributes", + "description": "Template configuration used when creating new Previews for this Worker.", + "children": [ + { + "name": "cache_options", + "type": "Attributes", + "description": "Cache options used when creating new Previews.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "env", + "type": "Attributes Map", + "description": "Bindings used when creating new Previews, keyed by binding name.", + "children": [ + { + "name": "type", + "type": "String", + "description": "The kind of resource that the binding provides." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Resource limits enforced at runtime for newly created Previews.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "The amount of CPU time this Worker can use in milliseconds." + }, + { + "name": "subrequests", + "type": "Number", + "description": "The number of subrequests this Worker can make per request." + } + ] + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether logpush is enabled when creating new Previews." + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings used when creating new Previews.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "redact_query_string", + "type": "Boolean", + "description": "Whether query strings are removed from request URLs in logs and traces." + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement configuration used when creating new Previews.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "Other Workers that should consume logs from newly created Previews.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the consumer Worker." + } + ] + } + ] + }, + { + "name": "subdomain", + "type": "Attributes", + "description": "Subdomain settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the *.workers.dev subdomain is enabled for the Worker." + }, + { + "name": "preview_url_suffix", + "type": "String", + "description": "Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain." + }, + { + "name": "previews_enabled", + "type": "Boolean", + "description": "Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker." + }, + { + "name": "url", + "type": "String", + "description": "The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain." + } + ] + }, + { + "name": "tags", + "type": "Set of String", + "description": "Tags associated with the Worker." + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "Other Workers that should consume logs from the Worker.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the consumer Worker." + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the Worker was created." + }, + { + "name": "deployed_on", + "type": "String", + "description": "When the Worker's most recent deployment was created. `null` if the Worker has never been deployed." + }, + { + "name": "id", + "type": "String", + "description": "Immutable ID of the Worker." + }, + { + "name": "references", + "type": "Attributes", + "description": "Other resources that reference the Worker and depend on it existing.", + "children": [ + { + "name": "dispatch_namespace_outbounds", + "type": "Attributes List", + "description": "Other Workers that reference the Worker as an outbound for a dispatch namespace.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the dispatch namespace." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the dispatch namespace." + }, + { + "name": "worker_id", + "type": "String", + "description": "ID of the Worker using the dispatch namespace." + }, + { + "name": "worker_name", + "type": "String", + "description": "Name of the Worker using the dispatch namespace." + } + ] + }, + { + "name": "domains", + "type": "Attributes List", + "description": "Custom domains connected to the Worker.", + "children": [ + { + "name": "certificate_id", + "type": "String", + "description": "ID of the TLS certificate issued for the custom domain." + }, + { + "name": "hostname", + "type": "String", + "description": "Full hostname of the custom domain, including the zone name." + }, + { + "name": "id", + "type": "String", + "description": "ID of the custom domain." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone." + } + ] + }, + { + "name": "durable_objects", + "type": "Attributes List", + "description": "Other Workers that reference Durable Object classes implemented by the Worker.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace being used." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the Durable Object namespace being used." + }, + { + "name": "worker_id", + "type": "String", + "description": "ID of the Worker using the Durable Object implementation." + }, + { + "name": "worker_name", + "type": "String", + "description": "Name of the Worker using the Durable Object implementation." + } + ] + }, + { + "name": "queues", + "type": "Attributes List", + "description": "Queues that send messages to the Worker.", + "children": [ + { + "name": "queue_consumer_id", + "type": "String", + "description": "ID of the queue consumer configuration." + }, + { + "name": "queue_id", + "type": "String", + "description": "ID of the queue." + }, + { + "name": "queue_name", + "type": "String", + "description": "Name of the queue." + } + ] + }, + { + "name": "workers", + "type": "Attributes List", + "description": "Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).", + "children": [ + { + "name": "id", + "type": "String", + "description": "ID of the referencing Worker." + }, + { + "name": "name", + "type": "String", + "description": "Name of the referencing Worker." + } + ] + } + ] + }, + { + "name": "updated_on", + "type": "String", + "description": "When the Worker was most recently updated." + } + ] + }, + "data-source:cloudflare_worker_version": { + "kind": "data-source", + "name": "cloudflare_worker_version", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_worker_version\" \"example_worker_version\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n version_id = \"version_id\"\n include = \"modules\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier for the version, which can be a UUID, a UUID prefix (minimum length 8), or the literal \"latest\" to operate on the most recently created version." + }, + { + "name": "worker_id", + "type": "String", + "description": "Identifier for the Worker, which can be ID or name." + } + ], + "optional": [ + { + "name": "include", + "type": "String", + "description": "Whether to include the `modules` property of the version in the response, which contains code and sourcemap content and may add several megabytes to the response size.\nAvailable values: \"modules\"." + } + ], + "computed": [ + { + "name": "annotations", + "type": "Attributes", + "description": "Metadata about the version.", + "children": [ + { + "name": "workers_message", + "type": "String", + "description": "Human-readable message about the version. Truncated to 1000 bytes if longer." + }, + { + "name": "workers_tag", + "type": "String", + "description": "User-provided identifier for the version. Maximum 100 bytes." + }, + { + "name": "workers_triggered_by", + "type": "String", + "description": "Operation that triggered the creation of the version." + } + ] + }, + { + "name": "assets", + "type": "Attributes", + "description": "Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.", + "children": [ + { + "name": "config", + "type": "Attributes", + "description": "Configuration for assets within a Worker.", + "children": [ + { + "name": "base_path", + "type": "String", + "description": "The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%." + }, + { + "name": "html_handling", + "type": "String", + "description": "Determines the redirects and rewrites of requests for HTML content.\nAvailable values: \"auto-trailing-slash\", \"force-trailing-slash\", \"drop-trailing-slash\", \"none\"." + }, + { + "name": "not_found_handling", + "type": "String", + "description": "Determines the response when a request does not match a static asset, and there is no Worker script.\nAvailable values: \"none\", \"404-page\", \"single-page-application\"." + }, + { + "name": "run_worker_first", + "type": "List of String", + "description": "Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules." + } + ] + }, + { + "name": "jwt", + "type": "String", + "description": "Token provided upon successful upload of all files from a registered manifest.", + "sensitive": true + } + ] + }, + { + "name": "author_email", + "type": "String", + "description": "Email of the user who created the version." + }, + { + "name": "author_id", + "type": "String", + "description": "Identifier of the user who created the version." + }, + { + "name": "bindings", + "type": "Attributes List", + "description": "List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.", + "children": [ + { + "name": "algorithm", + "type": "String", + "description": "Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)." + }, + { + "name": "allowed_destination_addresses", + "type": "List of String", + "description": "List of allowed destination addresses." + }, + { + "name": "allowed_sender_addresses", + "type": "List of String", + "description": "List of allowed sender addresses." + }, + { + "name": "app_id", + "type": "String", + "description": "ID of the Flagship app to bind to for feature flag evaluation." + }, + { + "name": "bucket_name", + "type": "String", + "description": "R2 bucket to bind to." + }, + { + "name": "certificate_id", + "type": "String", + "description": "Identifier of the certificate to bind to." + }, + { + "name": "class_name", + "type": "String", + "description": "The exported class name of the Durable Object." + }, + { + "name": "database_id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "dataset", + "type": "String", + "description": "The name of the dataset to bind to." + }, + { + "name": "destination_address", + "type": "String", + "description": "Destination address for the email." + }, + { + "name": "dispatch_namespace", + "type": "String", + "description": "The dispatch namespace the Durable Object script belongs to." + }, + { + "name": "entrypoint", + "type": "String", + "description": "Entrypoint to invoke on the target Worker." + }, + { + "name": "environment", + "type": "String", + "description": "The environment of the script_name to bind to." + }, + { + "name": "format", + "type": "String", + "description": "Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format).\nAvailable values: \"raw\", \"pkcs8\", \"spki\", \"jwk\"." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "identity", + "type": "String", + "description": "Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\nAvailable values: \"runtime-email-alpha\"." + }, + { + "name": "index_name", + "type": "String", + "description": "Name of the Vectorize index to bind to." + }, + { + "name": "instance_name", + "type": "String", + "description": "The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance." + }, + { + "name": "json", + "type": "String", + "description": "JSON data to use." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket.\nAvailable values: \"eu\", \"fedramp\", \"fedramp-high\", \"us\"." + }, + { + "name": "key_base64", + "type": "String", + "description": "Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".", + "sensitive": true + }, + { + "name": "key_jwk", + "type": "String", + "description": "Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".", + "sensitive": true + }, + { + "name": "name", + "type": "String", + "description": "A JavaScript variable name for the binding." + }, + { + "name": "namespace", + "type": "String", + "description": "The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field." + }, + { + "name": "namespace_id", + "type": "String", + "description": "Namespace identifier tag." + }, + { + "name": "network_id", + "type": "String", + "description": "Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id." + }, + { + "name": "old_name", + "type": "String", + "description": "The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions." + }, + { + "name": "outbound", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "params", + "type": "Attributes List", + "description": "Pass information from the Dispatch Worker to the Outbound Worker through the parameters.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the parameter." + } + ] + }, + { + "name": "worker", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "Entrypoint to invoke on the outbound worker." + }, + { + "name": "environment", + "type": "String", + "description": "Environment of the outbound worker." + }, + { + "name": "service", + "type": "String", + "description": "Name of the outbound worker." + } + ] + } + ] + }, + { + "name": "part", + "type": "String", + "description": "The name of the file containing the data content. Only accepted for `service worker syntax` Workers." + }, + { + "name": "pipeline", + "type": "String", + "description": "Name of the Pipeline to bind to." + }, + { + "name": "queue_name", + "type": "String", + "description": "Name of the Queue to bind to." + }, + { + "name": "script_name", + "type": "String", + "description": "The script where the Durable Object is defined, if it is external to this Worker." + }, + { + "name": "secret_name", + "type": "String", + "description": "Name of the secret in the store." + }, + { + "name": "service", + "type": "String", + "description": "Name of Worker to bind to." + }, + { + "name": "service_id", + "type": "String", + "description": "Identifier of the VPC service to bind to." + }, + { + "name": "simple", + "type": "Attributes", + "description": "The rate limit configuration.", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "The limit (requests per period)." + }, + { + "name": "mitigation_timeout", + "type": "Number", + "description": "Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero." + }, + { + "name": "period", + "type": "Number", + "description": "The period in seconds." + } + ] + }, + { + "name": "store_id", + "type": "String", + "description": "ID of the store containing the secret." + }, + { + "name": "stream", + "type": "String", + "description": "ID of a K2 stream owned by the account deploying the Worker." + }, + { + "name": "text", + "type": "String", + "description": "The text value to use.", + "sensitive": true + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id." + }, + { + "name": "type", + "type": "String", + "description": "The kind of resource that the binding provides.\nAvailable values: \"ai\", \"ai_search\", \"ai_search_namespace\", \"messaging\", \"analytics_engine\", \"artifacts\", \"assets\", \"browser\", \"d1\", \"data_blob\", \"dispatch_namespace\", \"durable_object_namespace\", \"hyperdrive\", \"inherit\", \"images\", \"json\", \"kv_namespace\", \"media\", \"mtls_certificate\", \"plain_text\", \"pipelines\", \"k2\", \"queue\", \"ratelimit\", \"r2_bucket\", \"secret_text\", \"send_email\", \"service\", \"text_blob\", \"vectorize\", \"version_metadata\", \"secrets_store_secret\", \"flagship\", \"secret_key\", \"workflow\", \"wasm_module\", \"vpc_service\", \"vpc_network\"." + }, + { + "name": "usages", + "type": "Set of String", + "description": "Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version." + }, + { + "name": "workflow_name", + "type": "String", + "description": "Name of the Workflow to bind to." + } + ] + }, + { + "name": "cache_options", + "type": "Attributes", + "description": "Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker." + }, + { + "name": "compatibility_flags", + "type": "Set of String", + "description": "Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`." + }, + { + "name": "containers", + "type": "Attributes Set", + "description": "List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.", + "children": [ + { + "name": "class_name", + "type": "String", + "description": "Select which Durable Object class should get this container attached." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the version was created." + }, + { + "name": "exports", + "type": "Attributes Map", + "description": "Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.", + "children": [ + { + "name": "cache", + "type": "Attributes", + "description": "Cache override for this entrypoint. It applies only to\n`type: worker` entries and overrides the Worker's global\n`cache_options.enabled` for that entrypoint.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this entrypoint." + } + ] + }, + { + "name": "renamed_to", + "type": "String", + "description": "Destination class name for a `state: renamed` tombstone. The\ntarget must appear as a live (`created`) entry in the same\n`exports` map. Write-only: never present in GET responses." + }, + { + "name": "state", + "type": "String", + "description": "Lifecycle state of the export entry. Defaults to `created`\n(a normal, live export) when omitted.\n\n`deleted`, `renamed`, and `transferred` are tombstones:\nwrite-only lifecycle operations that retire, rename, or hand\noff a provisioned Durable Object namespace. They are applied\nat upload and are filtered out of GET responses, so a read\nonly ever returns `created` or `expecting-transfer`.\n\n`expecting-transfer` is a live export whose data is being\nreceived from another script via the two-phase transfer flow;\nit carries `storage` and `transfer_from`.\nAvailable values: \"created\", \"deleted\", \"renamed\", \"transferred\", \"expecting-transfer\"." + }, + { + "name": "storage", + "type": "String", + "description": "Storage backend for a `type: durable-object` export. Required\nfor live Durable Object entries (`created` and\n`expecting-transfer`). `sqlite` selects SQLite-backed storage;\n`legacy-kv` selects the legacy key-value storage.\nAvailable values: \"sqlite\", \"legacy-kv\"." + }, + { + "name": "transfer_from", + "type": "String", + "description": "Source script for a `state: expecting-transfer` entry. The\nnamespace on this script is materialised from the source\nscript's data via the pending-transfer flow. Present on reads\nfor `expecting-transfer` entries." + }, + { + "name": "transferred_to", + "type": "String", + "description": "Destination script for a `state: transferred` tombstone. Must\nreference a script in the same account; cross-dispatch-namespace\ntransfers are rejected. Write-only: never present in GET\nresponses." + }, + { + "name": "type", + "type": "String", + "description": "The kind of export.\nAvailable values: \"worker\", \"durable-object\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Identifier for the version, which can be a UUID, a UUID prefix (minimum length 8), or the literal \"latest\" to operate on the most recently created version." + }, + { + "name": "limits", + "type": "Attributes", + "description": "Resource limits enforced at runtime.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + }, + { + "name": "subrequests", + "type": "Number", + "description": "Subrequest limit per request." + } + ] + }, + { + "name": "main_module", + "type": "String", + "description": "The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler)." + }, + { + "name": "main_script_base64", + "type": "String", + "description": "The base64-encoded main script content. This is only returned for service worker syntax workers (not ES modules)." + }, + { + "name": "migration_tag", + "type": "String", + "description": "Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects." + }, + { + "name": "migrations", + "type": "Attributes", + "description": "Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "new_tag", + "type": "String", + "description": "Tag to set as the latest migration tag." + }, + { + "name": "old_tag", + "type": "String", + "description": "Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "steps", + "type": "Attributes List", + "description": "Migrations to apply in order.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "modules", + "type": "Attributes Set", + "description": "Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.", + "children": [ + { + "name": "content_base64", + "type": "String", + "description": "The base64-encoded module content." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type of the module." + }, + { + "name": "name", + "type": "String", + "description": "The name of the module." + } + ] + }, + { + "name": "number", + "type": "Number", + "description": "The integer version number, starting from one." + }, + { + "name": "package_dependencies", + "type": "Attributes List", + "description": "The list of npm packages that were installed and used when this Worker\nversion was built.", + "children": [ + { + "name": "installed_version", + "type": "String", + "description": "The exact version that was resolved and installed by the package manager." + }, + { + "name": "name", + "type": "String", + "description": "The npm package name." + }, + { + "name": "package_json_version", + "type": "String", + "description": "The version constraint as written in package.json." + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "source", + "type": "String", + "description": "The client used to create the version." + }, + { + "name": "startup_time_ms", + "type": "Number", + "description": "Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)." + }, + { + "name": "urls", + "type": "List of String", + "description": "All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version." + }, + { + "name": "usage_model", + "type": "String", + "description": "Usage model for the version.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + } + ] + }, + "resource:cloudflare_worker_version": { + "kind": "resource", + "name": "cloudflare_worker_version", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "resource \"cloudflare_worker_version\" \"example_worker_version\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n annotations = {\n workers_message = \"Fixed bug.\"\n workers_tag = \"v1.0.1\"\n }\n assets = {\n config = {\n base_path = \"/docs/\"\n html_handling = \"auto-trailing-slash\"\n not_found_handling = \"404-page\"\n run_worker_first = []\n }\n jwt = \"jwt\"\n }\n bindings = [{\n name = \"MY_ENV_VAR\"\n text = \"my_data\"\n type = \"plain_text\"\n }]\n cache_options = {\n enabled = true\n cross_version_cache = true\n }\n compatibility_date = \"2021-01-01T00:00:00Z\"\n compatibility_flags = [\"nodejs_compat\"]\n containers = [{\n class_name = \"MyDurableObject\"\n }]\n exports = {\n Admin = {\n type = \"worker\"\n cache = {\n enabled = true\n }\n state = \"created\"\n }\n Counter = {\n storage = \"sqlite\"\n type = \"durable-object\"\n container = \"my-container\"\n state = \"created\"\n }\n OldCounter = {\n renamed_to = \"Counter\"\n state = \"renamed\"\n type = \"durable-object\"\n }\n default = {\n type = \"worker\"\n cache = {\n enabled = false\n }\n state = \"created\"\n }\n }\n limits = {\n cpu_ms = 50\n subrequests = 1000\n }\n main_module = \"index.js\"\n migrations = {\n deleted_classes = [\"string\"]\n new_classes = [\"string\"]\n new_sqlite_classes = [\"string\"]\n new_tag = \"v2\"\n old_tag = \"v1\"\n renamed_classes = [{\n from = \"from\"\n to = \"to\"\n }]\n transferred_classes = [{\n from = \"from\"\n from_script = \"from_script\"\n to = \"to\"\n }]\n }\n modules = [{\n content_base64 = \"ZXhwb3J0IGRlZmF1bHQgewogIGFzeW5jIGZldGNoKHJlcXVlc3QsIGVudiwgY3R4KSB7CiAgICByZXR1cm4gbmV3IFJlc3BvbnNlKCdIZWxsbyBXb3JsZCEnKQogIH0KfQ==\"\n content_type = \"application/javascript+module\"\n name = \"index.js\"\n }]\n package_dependencies = [{\n installed_version = \"4.17.22\"\n name = \"lodash\"\n package_json_version = \"^4.17.21\"\n }]\n placement = {\n mode = \"smart\"\n }\n usage_model = \"standard\"\n}", + "importExample": "$ terraform import cloudflare_worker_version.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "worker_id", + "type": "String", + "description": "Identifier for the Worker, which can be ID or name." + } + ], + "optional": [ + { + "name": "annotations", + "type": "Attributes", + "description": "Metadata about the version.", + "children": [ + { + "name": "workers_message", + "type": "String", + "description": "Human-readable message about the version. Truncated to 1000 bytes if longer." + }, + { + "name": "workers_tag", + "type": "String", + "description": "User-provided identifier for the version. Maximum 100 bytes." + }, + { + "name": "workers_triggered_by", + "type": "String", + "description": "Operation that triggered the creation of the version." + } + ] + }, + { + "name": "assets", + "type": "Attributes", + "description": "Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.", + "children": [ + { + "name": "asset_manifest_sha256", + "type": "String", + "description": "The SHA-256 hash of the asset manifest of files to upload." + }, + { + "name": "config", + "type": "Attributes", + "description": "Configuration for assets within a Worker.", + "children": [ + { + "name": "base_path", + "type": "String", + "description": "The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%." + }, + { + "name": "html_handling", + "type": "String", + "description": "Determines the redirects and rewrites of requests for HTML content.\nAvailable values: \"auto-trailing-slash\", \"force-trailing-slash\", \"drop-trailing-slash\", \"none\"." + }, + { + "name": "not_found_handling", + "type": "String", + "description": "Determines the response when a request does not match a static asset, and there is no Worker script.\nAvailable values: \"none\", \"404-page\", \"single-page-application\"." + }, + { + "name": "run_worker_first", + "type": "Dynamic", + "description": "When a boolean true, requests will always invoke the Worker script. Otherwise, attempt to serve an asset matching the request, falling back to the Worker script. When a list of strings, contains path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules." + } + ] + }, + { + "name": "directory", + "type": "String", + "description": "Path to the directory containing asset files to upload." + }, + { + "name": "jwt", + "type": "String", + "description": "Token provided upon successful upload of all files from a registered manifest.", + "sensitive": true + } + ] + }, + { + "name": "bindings", + "type": "Attributes List", + "description": "List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.", + "children": [ + { + "name": "algorithm", + "type": "String", + "description": "Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)." + }, + { + "name": "allowed_destination_addresses", + "type": "List of String", + "description": "List of allowed destination addresses." + }, + { + "name": "allowed_sender_addresses", + "type": "List of String", + "description": "List of allowed sender addresses." + }, + { + "name": "app_id", + "type": "String", + "description": "ID of the Flagship app to bind to for feature flag evaluation." + }, + { + "name": "bucket_name", + "type": "String", + "description": "R2 bucket to bind to." + }, + { + "name": "certificate_id", + "type": "String", + "description": "Identifier of the certificate to bind to." + }, + { + "name": "class_name", + "type": "String", + "description": "The exported class name of the Durable Object." + }, + { + "name": "database_id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "dataset", + "type": "String", + "description": "The name of the dataset to bind to." + }, + { + "name": "destination_address", + "type": "String", + "description": "Destination address for the email." + }, + { + "name": "dispatch_namespace", + "type": "String", + "description": "The dispatch namespace the Durable Object script belongs to." + }, + { + "name": "entrypoint", + "type": "String", + "description": "Entrypoint to invoke on the target Worker." + }, + { + "name": "environment", + "type": "String", + "description": "The environment of the script_name to bind to." + }, + { + "name": "format", + "type": "String", + "description": "Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format).\nAvailable values: \"raw\", \"pkcs8\", \"spki\", \"jwk\"." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "identity", + "type": "String", + "description": "Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\nAvailable values: \"runtime-email-alpha\"." + }, + { + "name": "index_name", + "type": "String", + "description": "Name of the Vectorize index to bind to." + }, + { + "name": "instance_name", + "type": "String", + "description": "The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance." + }, + { + "name": "json", + "type": "String", + "description": "JSON data to use." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket.\nAvailable values: \"eu\", \"fedramp\", \"fedramp-high\", \"us\"." + }, + { + "name": "key_base64", + "type": "String", + "description": "Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".", + "sensitive": true + }, + { + "name": "key_jwk", + "type": "String", + "description": "Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".", + "sensitive": true + }, + { + "name": "name", + "type": "String", + "description": "A JavaScript variable name for the binding." + }, + { + "name": "namespace", + "type": "String", + "description": "The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field." + }, + { + "name": "namespace_id", + "type": "String", + "description": "Namespace identifier tag." + }, + { + "name": "network_id", + "type": "String", + "description": "Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id." + }, + { + "name": "old_name", + "type": "String", + "description": "The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions." + }, + { + "name": "outbound", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "params", + "type": "Attributes List", + "description": "Pass information from the Dispatch Worker to the Outbound Worker through the parameters.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the parameter." + } + ] + }, + { + "name": "worker", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "Entrypoint to invoke on the outbound worker." + }, + { + "name": "environment", + "type": "String", + "description": "Environment of the outbound worker." + }, + { + "name": "service", + "type": "String", + "description": "Name of the outbound worker." + } + ] + } + ] + }, + { + "name": "part", + "type": "String", + "description": "The name of the file containing the data content. Only accepted for `service worker syntax` Workers." + }, + { + "name": "pipeline", + "type": "String", + "description": "Name of the Pipeline to bind to." + }, + { + "name": "queue_name", + "type": "String", + "description": "Name of the Queue to bind to." + }, + { + "name": "script_name", + "type": "String", + "description": "The script where the Durable Object is defined, if it is external to this Worker." + }, + { + "name": "secret_name", + "type": "String", + "description": "Name of the secret in the store." + }, + { + "name": "service", + "type": "String", + "description": "Name of Worker to bind to." + }, + { + "name": "service_id", + "type": "String", + "description": "Identifier of the VPC service to bind to." + }, + { + "name": "simple", + "type": "Attributes", + "description": "The rate limit configuration.", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "The limit (requests per period)." + }, + { + "name": "mitigation_timeout", + "type": "Number", + "description": "Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero." + }, + { + "name": "period", + "type": "Number", + "description": "The period in seconds." + } + ] + }, + { + "name": "store_id", + "type": "String", + "description": "ID of the store containing the secret." + }, + { + "name": "stream", + "type": "String", + "description": "ID of a K2 stream owned by the account deploying the Worker." + }, + { + "name": "text", + "type": "String", + "description": "The text value to use.", + "sensitive": true + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id." + }, + { + "name": "type", + "type": "String", + "description": "The kind of resource that the binding provides.\nAvailable values: \"ai\", \"ai_search\", \"ai_search_namespace\", \"messaging\", \"analytics_engine\", \"artifacts\", \"assets\", \"browser\", \"d1\", \"data_blob\", \"dispatch_namespace\", \"durable_object_namespace\", \"hyperdrive\", \"inherit\", \"images\", \"json\", \"kv_namespace\", \"media\", \"mtls_certificate\", \"plain_text\", \"pipelines\", \"k2\", \"queue\", \"ratelimit\", \"r2_bucket\", \"secret_text\", \"send_email\", \"service\", \"text_blob\", \"vectorize\", \"version_metadata\", \"secrets_store_secret\", \"flagship\", \"secret_key\", \"workflow\", \"wasm_module\", \"vpc_service\", \"vpc_network\"." + }, + { + "name": "usages", + "type": "Set of String", + "description": "Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version." + }, + { + "name": "workflow_name", + "type": "String", + "description": "Name of the Workflow to bind to." + } + ] + }, + { + "name": "cache_options", + "type": "Attributes", + "description": "Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker." + }, + { + "name": "compatibility_flags", + "type": "Set of String", + "description": "Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`." + }, + { + "name": "containers", + "type": "Attributes Set", + "description": "List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.", + "children": [ + { + "name": "class_name", + "type": "String", + "description": "Select which Durable Object class should get this container attached." + } + ] + }, + { + "name": "deploy", + "type": "Boolean", + "description": "If true, a deployment will be created that sends 100% of traffic to the new version." + }, + { + "name": "exports", + "type": "Attributes Map", + "description": "Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.", + "children": [ + { + "name": "cache", + "type": "Attributes", + "description": "Cache override for this entrypoint. It applies only to\n`type: worker` entries and overrides the Worker's global\n`cache_options.enabled` for that entrypoint.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this entrypoint." + } + ] + }, + { + "name": "renamed_to", + "type": "String", + "description": "Destination class name for a `state: renamed` tombstone. The\ntarget must appear as a live (`created`) entry in the same\n`exports` map. Write-only: never present in GET responses." + }, + { + "name": "state", + "type": "String", + "description": "Lifecycle state of the export entry. Defaults to `created`\n(a normal, live export) when omitted.\n\n`deleted`, `renamed`, and `transferred` are tombstones:\nwrite-only lifecycle operations that retire, rename, or hand\noff a provisioned Durable Object namespace. They are applied\nat upload and are filtered out of GET responses, so a read\nonly ever returns `created` or `expecting-transfer`.\n\n`expecting-transfer` is a live export whose data is being\nreceived from another script via the two-phase transfer flow;\nit carries `storage` and `transfer_from`.\nAvailable values: \"created\", \"deleted\", \"renamed\", \"transferred\", \"expecting-transfer\"." + }, + { + "name": "storage", + "type": "String", + "description": "Storage backend for a `type: durable-object` export. Required\nfor live Durable Object entries (`created` and\n`expecting-transfer`). `sqlite` selects SQLite-backed storage;\n`legacy-kv` selects the legacy key-value storage.\nAvailable values: \"sqlite\", \"legacy-kv\"." + }, + { + "name": "transfer_from", + "type": "String", + "description": "Source script for a `state: expecting-transfer` entry. The\nnamespace on this script is materialised from the source\nscript's data via the pending-transfer flow. Present on reads\nfor `expecting-transfer` entries." + }, + { + "name": "transferred_to", + "type": "String", + "description": "Destination script for a `state: transferred` tombstone. Must\nreference a script in the same account; cross-dispatch-namespace\ntransfers are rejected. Write-only: never present in GET\nresponses." + }, + { + "name": "type", + "type": "String", + "description": "The kind of export.\nAvailable values: \"worker\", \"durable-object\"." + } + ] + }, + { + "name": "include", + "type": "String", + "description": "Whether to include the `modules` property of the version in the response, which contains code and sourcemap content and may add several megabytes to the response size.\nAvailable values: \"modules\"." + }, + { + "name": "limits", + "type": "Attributes", + "description": "Resource limits enforced at runtime.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + }, + { + "name": "subrequests", + "type": "Number", + "description": "Subrequest limit per request." + } + ] + }, + { + "name": "main_module", + "type": "String", + "description": "The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler)." + }, + { + "name": "migrations", + "type": "Attributes", + "description": "Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "new_tag", + "type": "String", + "description": "Tag to set as the latest migration tag." + }, + { + "name": "old_tag", + "type": "String", + "description": "Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "steps", + "type": "Attributes List", + "description": "Migrations to apply in order.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "modules", + "type": "Attributes Set", + "description": "Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.", + "children": [ + { + "name": "content_base64", + "type": "String", + "description": "The base64-encoded module content." + }, + { + "name": "content_file", + "type": "String", + "description": "The file path of the module content." + }, + { + "name": "content_sha256", + "type": "String", + "description": "The SHA-256 hash of the module content." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type of the module." + }, + { + "name": "name", + "type": "String", + "description": "The name of the module." + } + ] + }, + { + "name": "package_dependencies", + "type": "Attributes List", + "description": "The list of npm packages that were installed and used when this Worker\nversion was built.", + "children": [ + { + "name": "installed_version", + "type": "String", + "description": "The exact version that was resolved and installed by the package manager." + }, + { + "name": "name", + "type": "String", + "description": "The npm package name." + }, + { + "name": "package_json_version", + "type": "String", + "description": "The version constraint as written in package.json." + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "Usage model for the version.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + } + ], + "computed": [ + { + "name": "author_email", + "type": "String", + "description": "Email of the user who created the version." + }, + { + "name": "author_id", + "type": "String", + "description": "Identifier of the user who created the version." + }, + { + "name": "created_on", + "type": "String", + "description": "When the version was created." + }, + { + "name": "exports_reconciliation", + "type": "Attributes", + "description": "Summary of the declarative exports reconciliation that ran on this upload. Populated only when the uploaded metadata included an `exports` block. Durable Object entries drive reconciliation; `type: worker` entries do not contribute to this summary.", + "children": [ + { + "name": "created", + "type": "List of String", + "description": "Class names for which a new namespace was provisioned." + }, + { + "name": "deleted", + "type": "List of String", + "description": "Class names whose namespace was deleted by a `deleted` tombstone." + }, + { + "name": "info", + "type": "Attributes List", + "description": "Non-blocking info entries (stale tombstones, tombstone applied with class still in code). See `exports_reconciliation_info`.", + "children": [ + { + "name": "class", + "type": "String", + "description": "The class name the info entry is about." + }, + { + "name": "message", + "type": "String", + "description": "Human-readable explanation." + }, + { + "name": "namespace_id", + "type": "String", + "description": "The provisioned namespace the entry relates to, when applicable." + }, + { + "name": "referencing_scripts", + "type": "List of String", + "description": "Other Workers in the account that still bind to the affected class. Advisory: while non-empty the tombstone is not yet safe to remove — redeploy these Workers with bindings re-pointed first." + }, + { + "name": "scenario", + "type": "String", + "description": "Stable, machine-readable tag identifying which reconciliation scenario produced an error, warning, or info entry. Clients may branch on this value instead of parsing `message`." + } + ] + }, + { + "name": "removable_entries", + "type": "List of String", + "description": "Source class names whose tombstone entry is now stale and safe to delete from `exports` (no remaining referencing scripts)." + }, + { + "name": "renamed", + "type": "Attributes List", + "description": "Applied `renamed` tombstones.", + "children": [ + { + "name": "from", + "type": "String", + "description": "The original (source) class name." + }, + { + "name": "to", + "type": "String", + "description": "The new class name (`renamed_to`)." + } + ] + }, + { + "name": "transfer_pending", + "type": "Attributes List", + "description": "Phase-1 transfer hints recorded on the target side.", + "children": [ + { + "name": "class", + "type": "String", + "description": "The target-side class name awaiting transfer." + }, + { + "name": "from", + "type": "String", + "description": "The source script the namespace will be transferred from." + } + ] + }, + { + "name": "transferred", + "type": "Attributes List", + "description": "Committed `transferred` tombstones (phase-2).", + "children": [ + { + "name": "class", + "type": "String", + "description": "The source class name that was transferred." + }, + { + "name": "phase", + "type": "String", + "description": "The transfer phase. Currently always `committed`." + }, + { + "name": "to", + "type": "String", + "description": "The destination script that now owns the namespace." + } + ] + }, + { + "name": "updated", + "type": "List of String", + "description": "Class names whose provisioned namespace was mutated in place." + }, + { + "name": "warnings", + "type": "Attributes List", + "description": "Non-blocking warnings. See `exports_reconciliation_warning`.", + "children": [ + { + "name": "class", + "type": "String", + "description": "The class name the warning is about." + }, + { + "name": "message", + "type": "String", + "description": "Human-readable explanation of the warning." + }, + { + "name": "namespace_id", + "type": "String", + "description": "The provisioned namespace the warning relates to, when applicable." + }, + { + "name": "scenario", + "type": "String", + "description": "Stable, machine-readable tag identifying which reconciliation scenario produced an error, warning, or info entry. Clients may branch on this value instead of parsing `message`." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Version identifier." + }, + { + "name": "main_script_base64", + "type": "String", + "description": "The base64-encoded main script content. This is only returned for service worker syntax workers (not ES modules). Used when importing existing workers that use the older service worker syntax." + }, + { + "name": "migration_tag", + "type": "String", + "description": "Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects." + }, + { + "name": "number", + "type": "Number", + "description": "The integer version number, starting from one." + }, + { + "name": "source", + "type": "String", + "description": "The client used to create the version." + }, + { + "name": "startup_time_ms", + "type": "Number", + "description": "Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)." + }, + { + "name": "urls", + "type": "List of String", + "description": "All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version." + } + ] + }, + "list-data-source:cloudflare_worker_versions": { + "kind": "list-data-source", + "name": "cloudflare_worker_versions", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_worker_versions\" \"example_worker_versions\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n worker_id = \"worker_id\"\n}", + "required": [ + { + "name": "worker_id", + "type": "String", + "description": "Identifier for the Worker, which can be ID or name." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "annotations", + "type": "Attributes", + "description": "Metadata about the version.", + "children": [ + { + "name": "workers_message", + "type": "String", + "description": "Human-readable message about the version. Truncated to 1000 bytes if longer." + }, + { + "name": "workers_tag", + "type": "String", + "description": "User-provided identifier for the version. Maximum 100 bytes." + }, + { + "name": "workers_triggered_by", + "type": "String", + "description": "Operation that triggered the creation of the version." + } + ] + }, + { + "name": "assets", + "type": "Attributes", + "description": "Configuration for assets within a Worker.\n\n[`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.", + "children": [ + { + "name": "config", + "type": "Attributes", + "description": "Configuration for assets within a Worker.", + "children": [ + { + "name": "base_path", + "type": "String", + "description": "The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%." + }, + { + "name": "html_handling", + "type": "String", + "description": "Determines the redirects and rewrites of requests for HTML content.\nAvailable values: \"auto-trailing-slash\", \"force-trailing-slash\", \"drop-trailing-slash\", \"none\"." + }, + { + "name": "not_found_handling", + "type": "String", + "description": "Determines the response when a request does not match a static asset, and there is no Worker script.\nAvailable values: \"none\", \"404-page\", \"single-page-application\"." + }, + { + "name": "run_worker_first", + "type": "List of String", + "description": "Contains a list path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules." + } + ] + }, + { + "name": "jwt", + "type": "String", + "description": "Token provided upon successful upload of all files from a registered manifest.", + "sensitive": true + } + ] + }, + { + "name": "author_email", + "type": "String", + "description": "Email of the user who created the version." + }, + { + "name": "author_id", + "type": "String", + "description": "Identifier of the user who created the version." + }, + { + "name": "bindings", + "type": "Attributes List", + "description": "List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.", + "children": [ + { + "name": "algorithm", + "type": "String", + "description": "Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)." + }, + { + "name": "allowed_destination_addresses", + "type": "List of String", + "description": "List of allowed destination addresses." + }, + { + "name": "allowed_sender_addresses", + "type": "List of String", + "description": "List of allowed sender addresses." + }, + { + "name": "app_id", + "type": "String", + "description": "ID of the Flagship app to bind to for feature flag evaluation." + }, + { + "name": "bucket_name", + "type": "String", + "description": "R2 bucket to bind to." + }, + { + "name": "certificate_id", + "type": "String", + "description": "Identifier of the certificate to bind to." + }, + { + "name": "class_name", + "type": "String", + "description": "The exported class name of the Durable Object." + }, + { + "name": "database_id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "dataset", + "type": "String", + "description": "The name of the dataset to bind to." + }, + { + "name": "destination_address", + "type": "String", + "description": "Destination address for the email." + }, + { + "name": "dispatch_namespace", + "type": "String", + "description": "The dispatch namespace the Durable Object script belongs to." + }, + { + "name": "entrypoint", + "type": "String", + "description": "Entrypoint to invoke on the target Worker." + }, + { + "name": "environment", + "type": "String", + "description": "The environment of the script_name to bind to." + }, + { + "name": "format", + "type": "String", + "description": "Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format).\nAvailable values: \"raw\", \"pkcs8\", \"spki\", \"jwk\"." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "identity", + "type": "String", + "description": "Enables Gateway identity for the binding. Requires network_id to be \"cf1:network\" and cannot be combined with tunnel_id.\nAvailable values: \"runtime-email-alpha\"." + }, + { + "name": "index_name", + "type": "String", + "description": "Name of the Vectorize index to bind to." + }, + { + "name": "instance_name", + "type": "String", + "description": "The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance." + }, + { + "name": "json", + "type": "String", + "description": "JSON data to use." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket.\nAvailable values: \"eu\", \"fedramp\", \"fedramp-high\", \"us\"." + }, + { + "name": "key_base64", + "type": "String", + "description": "Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".", + "sensitive": true + }, + { + "name": "key_jwk", + "type": "String", + "description": "Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".", + "sensitive": true + }, + { + "name": "name", + "type": "String", + "description": "A JavaScript variable name for the binding." + }, + { + "name": "namespace", + "type": "String", + "description": "The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field." + }, + { + "name": "namespace_id", + "type": "String", + "description": "Namespace identifier tag." + }, + { + "name": "network_id", + "type": "String", + "description": "Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id." + }, + { + "name": "old_name", + "type": "String", + "description": "The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions." + }, + { + "name": "outbound", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "params", + "type": "Attributes List", + "description": "Pass information from the Dispatch Worker to the Outbound Worker through the parameters.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the parameter." + } + ] + }, + { + "name": "worker", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "entrypoint", + "type": "String", + "description": "Entrypoint to invoke on the outbound worker." + }, + { + "name": "environment", + "type": "String", + "description": "Environment of the outbound worker." + }, + { + "name": "service", + "type": "String", + "description": "Name of the outbound worker." + } + ] + } + ] + }, + { + "name": "part", + "type": "String", + "description": "The name of the file containing the data content. Only accepted for `service worker syntax` Workers." + }, + { + "name": "pipeline", + "type": "String", + "description": "Name of the Pipeline to bind to." + }, + { + "name": "queue_name", + "type": "String", + "description": "Name of the Queue to bind to." + }, + { + "name": "script_name", + "type": "String", + "description": "The script where the Durable Object is defined, if it is external to this Worker." + }, + { + "name": "secret_name", + "type": "String", + "description": "Name of the secret in the store." + }, + { + "name": "service", + "type": "String", + "description": "Name of Worker to bind to." + }, + { + "name": "service_id", + "type": "String", + "description": "Identifier of the VPC service to bind to." + }, + { + "name": "simple", + "type": "Attributes", + "description": "The rate limit configuration.", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "The limit (requests per period)." + }, + { + "name": "mitigation_timeout", + "type": "Number", + "description": "Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero." + }, + { + "name": "period", + "type": "Number", + "description": "The period in seconds." + } + ] + }, + { + "name": "store_id", + "type": "String", + "description": "ID of the store containing the secret." + }, + { + "name": "stream", + "type": "String", + "description": "ID of a K2 stream owned by the account deploying the Worker." + }, + { + "name": "text", + "type": "String", + "description": "The text value to use.", + "sensitive": true + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id." + }, + { + "name": "type", + "type": "String", + "description": "The kind of resource that the binding provides.\nAvailable values: \"ai\", \"ai_search\", \"ai_search_namespace\", \"messaging\", \"analytics_engine\", \"artifacts\", \"assets\", \"browser\", \"d1\", \"data_blob\", \"dispatch_namespace\", \"durable_object_namespace\", \"hyperdrive\", \"inherit\", \"images\", \"json\", \"kv_namespace\", \"media\", \"mtls_certificate\", \"plain_text\", \"pipelines\", \"k2\", \"queue\", \"ratelimit\", \"r2_bucket\", \"secret_text\", \"send_email\", \"service\", \"text_blob\", \"vectorize\", \"version_metadata\", \"secrets_store_secret\", \"flagship\", \"secret_key\", \"workflow\", \"wasm_module\", \"vpc_service\", \"vpc_network\"." + }, + { + "name": "usages", + "type": "Set of String", + "description": "Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version." + }, + { + "name": "workflow_name", + "type": "String", + "description": "Name of the Workflow to bind to." + } + ] + }, + { + "name": "cache_options", + "type": "Attributes", + "description": "Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker." + }, + { + "name": "compatibility_flags", + "type": "Set of String", + "description": "Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`." + }, + { + "name": "containers", + "type": "Attributes Set", + "description": "List of containers attached to a Worker. Containers can only be attached to Durable Object classes of this Worker script.", + "children": [ + { + "name": "class_name", + "type": "String", + "description": "Select which Durable Object class should get this container attached." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "When the version was created." + }, + { + "name": "exports", + "type": "Attributes Map", + "description": "Declarative exports for the version, including Durable Object\nclasses (with their `storage` backend) and named Worker\nentrypoints. On reads, tombstoned lifecycle entries are\nomitted, so only live exports (`created` and\n`expecting-transfer`) are returned. `exports` and `migrations`\nare mutually exclusive on upload.", + "children": [ + { + "name": "cache", + "type": "Attributes", + "description": "Cache override for this entrypoint. It applies only to\n`type: worker` entries and overrides the Worker's global\n`cache_options.enabled` for that entrypoint.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this entrypoint." + } + ] + }, + { + "name": "renamed_to", + "type": "String", + "description": "Destination class name for a `state: renamed` tombstone. The\ntarget must appear as a live (`created`) entry in the same\n`exports` map. Write-only: never present in GET responses." + }, + { + "name": "state", + "type": "String", + "description": "Lifecycle state of the export entry. Defaults to `created`\n(a normal, live export) when omitted.\n\n`deleted`, `renamed`, and `transferred` are tombstones:\nwrite-only lifecycle operations that retire, rename, or hand\noff a provisioned Durable Object namespace. They are applied\nat upload and are filtered out of GET responses, so a read\nonly ever returns `created` or `expecting-transfer`.\n\n`expecting-transfer` is a live export whose data is being\nreceived from another script via the two-phase transfer flow;\nit carries `storage` and `transfer_from`.\nAvailable values: \"created\", \"deleted\", \"renamed\", \"transferred\", \"expecting-transfer\"." + }, + { + "name": "storage", + "type": "String", + "description": "Storage backend for a `type: durable-object` export. Required\nfor live Durable Object entries (`created` and\n`expecting-transfer`). `sqlite` selects SQLite-backed storage;\n`legacy-kv` selects the legacy key-value storage.\nAvailable values: \"sqlite\", \"legacy-kv\"." + }, + { + "name": "transfer_from", + "type": "String", + "description": "Source script for a `state: expecting-transfer` entry. The\nnamespace on this script is materialised from the source\nscript's data via the pending-transfer flow. Present on reads\nfor `expecting-transfer` entries." + }, + { + "name": "transferred_to", + "type": "String", + "description": "Destination script for a `state: transferred` tombstone. Must\nreference a script in the same account; cross-dispatch-namespace\ntransfers are rejected. Write-only: never present in GET\nresponses." + }, + { + "name": "type", + "type": "String", + "description": "The kind of export.\nAvailable values: \"worker\", \"durable-object\"." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Version identifier." + }, + { + "name": "limits", + "type": "Attributes", + "description": "Resource limits enforced at runtime.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "CPU time limit in milliseconds." + }, + { + "name": "subrequests", + "type": "Number", + "description": "Subrequest limit per request." + } + ] + }, + { + "name": "main_module", + "type": "String", + "description": "The name of the main module in the `modules` array (e.g. the name of the module that exports a `fetch` handler)." + }, + { + "name": "main_script_base64", + "type": "String", + "description": "The base64-encoded main script content. This is only returned for service worker syntax workers (not ES modules)." + }, + { + "name": "migration_tag", + "type": "String", + "description": "Durable Object migration tag. Set when the version is deployed. Omitted if the version has not been deployed or the Worker does not use Durable Objects." + }, + { + "name": "migrations", + "type": "Attributes", + "description": "Migrations for Durable Objects associated with the version. Migrations are applied when the version is deployed.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "new_tag", + "type": "String", + "description": "Tag to set as the latest migration tag." + }, + { + "name": "old_tag", + "type": "String", + "description": "Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "steps", + "type": "Attributes List", + "description": "Migrations to apply in order.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "modules", + "type": "Attributes Set", + "description": "Code, sourcemaps, and other content used at runtime.\n\nThis includes [`_headers`](https://developers.cloudflare.com/workers/static-assets/headers/#custom-headers) and\n[`_redirects`](https://developers.cloudflare.com/workers/static-assets/redirects/) files used to configure\n[Static Assets](https://developers.cloudflare.com/workers/static-assets/). `_headers` and `_redirects` files should be\nincluded as modules named `_headers` and `_redirects` with content type `text/plain`.", + "children": [ + { + "name": "content_base64", + "type": "String", + "description": "The base64-encoded module content." + }, + { + "name": "content_type", + "type": "String", + "description": "The content type of the module." + }, + { + "name": "name", + "type": "String", + "description": "The name of the module." + } + ] + }, + { + "name": "number", + "type": "Number", + "description": "The integer version number, starting from one." + }, + { + "name": "package_dependencies", + "type": "Attributes List", + "description": "The list of npm packages that were installed and used when this Worker\nversion was built.", + "children": [ + { + "name": "installed_version", + "type": "String", + "description": "The exact version that was resolved and installed by the package manager." + }, + { + "name": "name", + "type": "String", + "description": "The npm package name." + }, + { + "name": "package_json_version", + "type": "String", + "description": "The version constraint as written in package.json." + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "source", + "type": "String", + "description": "The client used to create the version." + }, + { + "name": "startup_time_ms", + "type": "Number", + "description": "Time in milliseconds spent on [Worker startup](https://developers.cloudflare.com/workers/platform/limits/#worker-startup-time)." + }, + { + "name": "urls", + "type": "List of String", + "description": "All routable URLs that always point to this version. Does not include alias URLs, since aliases can be updated to point to a different version." + }, + { + "name": "usage_model", + "type": "String", + "description": "Usage model for the version.\nAvailable values: \"standard\", \"bundled\", \"unbound\".", + "deprecated": "Deprecated." + } + ] + } + ] + }, + "list-data-source:cloudflare_workers": { + "kind": "list-data-source", + "name": "cloudflare_workers", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers\" \"example_workers\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Sort direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order_by", + "type": "String", + "description": "Property to sort results by.\nAvailable values: \"deployed_on\", \"updated_on\", \"created_on\", \"name\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "When the Worker was created." + }, + { + "name": "deployed_on", + "type": "String", + "description": "When the Worker's most recent deployment was created. `null` if the Worker has never been deployed." + }, + { + "name": "id", + "type": "String", + "description": "Immutable ID of the Worker." + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether logpush is enabled for the Worker." + }, + { + "name": "name", + "type": "String", + "description": "Name of the Worker." + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "redact_query_string", + "type": "Boolean", + "description": "Whether query strings are removed from request URLs in logs and traces." + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "previews_base_config", + "type": "Attributes", + "description": "Template configuration used when creating new Previews for this Worker.", + "children": [ + { + "name": "cache_options", + "type": "Attributes", + "description": "Cache options used when creating new Previews.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "env", + "type": "Attributes Map", + "description": "Bindings used when creating new Previews, keyed by binding name.", + "children": [ + { + "name": "type", + "type": "String", + "description": "The kind of resource that the binding provides." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "description": "Resource limits enforced at runtime for newly created Previews.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "The amount of CPU time this Worker can use in milliseconds." + }, + { + "name": "subrequests", + "type": "Number", + "description": "The number of subrequests this Worker can make per request." + } + ] + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether logpush is enabled when creating new Previews." + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings used when creating new Previews.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for observability. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "redact_query_string", + "type": "Boolean", + "description": "Whether query strings are removed from request URLs in logs and traces." + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%)." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Placement configuration used when creating new Previews.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "Other Workers that should consume logs from newly created Previews.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the consumer Worker." + } + ] + } + ] + }, + { + "name": "references", + "type": "Attributes", + "description": "Other resources that reference the Worker and depend on it existing.", + "children": [ + { + "name": "dispatch_namespace_outbounds", + "type": "Attributes List", + "description": "Other Workers that reference the Worker as an outbound for a dispatch namespace.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the dispatch namespace." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the dispatch namespace." + }, + { + "name": "worker_id", + "type": "String", + "description": "ID of the Worker using the dispatch namespace." + }, + { + "name": "worker_name", + "type": "String", + "description": "Name of the Worker using the dispatch namespace." + } + ] + }, + { + "name": "domains", + "type": "Attributes List", + "description": "Custom domains connected to the Worker.", + "children": [ + { + "name": "certificate_id", + "type": "String", + "description": "ID of the TLS certificate issued for the custom domain." + }, + { + "name": "hostname", + "type": "String", + "description": "Full hostname of the custom domain, including the zone name." + }, + { + "name": "id", + "type": "String", + "description": "ID of the custom domain." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone." + } + ] + }, + { + "name": "durable_objects", + "type": "Attributes List", + "description": "Other Workers that reference Durable Object classes implemented by the Worker.", + "children": [ + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Durable Object namespace being used." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the Durable Object namespace being used." + }, + { + "name": "worker_id", + "type": "String", + "description": "ID of the Worker using the Durable Object implementation." + }, + { + "name": "worker_name", + "type": "String", + "description": "Name of the Worker using the Durable Object implementation." + } + ] + }, + { + "name": "queues", + "type": "Attributes List", + "description": "Queues that send messages to the Worker.", + "children": [ + { + "name": "queue_consumer_id", + "type": "String", + "description": "ID of the queue consumer configuration." + }, + { + "name": "queue_id", + "type": "String", + "description": "ID of the queue." + }, + { + "name": "queue_name", + "type": "String", + "description": "Name of the queue." + } + ] + }, + { + "name": "workers", + "type": "Attributes List", + "description": "Other Workers that reference the Worker using [service bindings](https://developers.cloudflare.com/workers/runtime-apis/bindings/service-bindings/).", + "children": [ + { + "name": "id", + "type": "String", + "description": "ID of the referencing Worker." + }, + { + "name": "name", + "type": "String", + "description": "Name of the referencing Worker." + } + ] + } + ] + }, + { + "name": "subdomain", + "type": "Attributes", + "description": "Subdomain settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the *.workers.dev subdomain is enabled for the Worker." + }, + { + "name": "preview_url_suffix", + "type": "String", + "description": "Prepend a version or preview prefix to this host suffix to form the *.workers.dev [preview URL](https://developers.cloudflare.com/workers/configuration/previews/) the Worker would serve on once previews are enabled, e.g. `https://-my-worker.my-subdomain.workers.dev`. Present whenever the account owns a workers.dev subdomain, regardless of whether `previews_enabled` is true, so presence does not imply preview URLs are currently live. Absent only when the account owns no workers.dev subdomain." + }, + { + "name": "previews_enabled", + "type": "Boolean", + "description": "Whether [preview URLs](https://developers.cloudflare.com/workers/configuration/previews/) are enabled for the Worker." + }, + { + "name": "url", + "type": "String", + "description": "The address the Worker would serve on once its *.workers.dev subdomain is enabled. Present whenever the account owns a workers.dev subdomain, regardless of whether `enabled` is true, so presence does not imply the Worker is currently live at this URL. Absent only when the account owns no workers.dev subdomain." + } + ] + }, + { + "name": "tags", + "type": "Set of String", + "description": "Tags associated with the Worker." + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "Other Workers that should consume logs from the Worker.", + "children": [ + { + "name": "name", + "type": "String", + "description": "Name of the consumer Worker." + } + ] + }, + { + "name": "updated_on", + "type": "String", + "description": "When the Worker was most recently updated." + } + ] + } + ] + }, + "data-source:cloudflare_workers_cron_trigger": { + "kind": "data-source", + "name": "cloudflare_workers_cron_trigger", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "data \"cloudflare_workers_cron_trigger\" \"example_workers_cron_trigger\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}", + "required": [ + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Name of the script." + }, + { + "name": "schedules", + "type": "Attributes List", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "cron", + "type": "String" + }, + { + "name": "modified_on", + "type": "String" + } + ] + } + ] + }, + "resource:cloudflare_workers_cron_trigger": { + "kind": "resource", + "name": "cloudflare_workers_cron_trigger", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "resource \"cloudflare_workers_cron_trigger\" \"example_workers_cron_trigger\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n schedules = [{\n cron = \"*/30 * * * *\"\n }]\n}", + "importExample": "$ terraform import cloudflare_workers_cron_trigger.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "schedules", + "type": "Attributes List", + "children": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "cron", + "type": "String" + }, + { + "name": "modified_on", + "type": "String" + } + ] + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Name of the script." + } + ] + }, + "data-source:cloudflare_workers_custom_domain": { + "kind": "data-source", + "name": "cloudflare_workers_custom_domain", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "data \"cloudflare_workers_custom_domain\" \"example_workers_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n domain_id = \"dbe10b4bc17c295377eabd600e1787fd\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "domain_id", + "type": "String", + "description": "ID of the domain." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "environment", + "type": "String", + "description": "Worker environment associated with the domain." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname of the domain." + }, + { + "name": "service", + "type": "String", + "description": "Name of the Worker associated with the domain." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone containing the domain hostname." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone containing the domain hostname." + } + ] + } + ], + "computed": [ + { + "name": "cert_id", + "type": "String", + "description": "ID of the TLS certificate issued for the domain." + }, + { + "name": "environment", + "type": "String", + "description": "Worker environment associated with the domain.", + "deprecated": "Deprecated." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker." + }, + { + "name": "id", + "type": "String", + "description": "ID of the domain." + }, + { + "name": "service", + "type": "String", + "description": "Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone containing the domain hostname." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone containing the domain hostname." + } + ] + }, + "resource:cloudflare_workers_custom_domain": { + "kind": "resource", + "name": "cloudflare_workers_custom_domain", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "resource \"cloudflare_workers_custom_domain\" \"example_workers_custom_domain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"app.example.com\"\n service = \"my-worker\"\n zone_id = \"593c9c94de529bbbfaac7c53ced0447d\"\n zone_name = \"example.com\"\n}", + "importExample": "$ terraform import cloudflare_workers_custom_domain.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker." + }, + { + "name": "service", + "type": "String", + "description": "Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker." + } + ], + "optional": [ + { + "name": "environment", + "type": "String", + "description": "Worker environment associated with the domain.", + "deprecated": "Deprecated." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone containing the domain hostname." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone containing the domain hostname." + } + ], + "computed": [ + { + "name": "cert_id", + "type": "String", + "description": "ID of the TLS certificate issued for the domain." + }, + { + "name": "id", + "type": "String", + "description": "Immutable ID of the domain." + } + ] + }, + "list-data-source:cloudflare_workers_custom_domains": { + "kind": "list-data-source", + "name": "cloudflare_workers_custom_domains", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`", + "example": "data \"cloudflare_workers_custom_domains\" \"example_workers_custom_domains\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n environment = \"production\"\n hostname = \"app.example.com\"\n service = \"my-worker\"\n zone_id = \"593c9c94de529bbbfaac7c53ced0447d\"\n zone_name = \"example.com\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "environment", + "type": "String", + "description": "Worker environment associated with the domain." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname of the domain." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "service", + "type": "String", + "description": "Name of the Worker associated with the domain." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone containing the domain hostname." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone containing the domain hostname." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "cert_id", + "type": "String", + "description": "ID of the TLS certificate issued for the domain." + }, + { + "name": "environment", + "type": "String", + "description": "Worker environment associated with the domain.", + "deprecated": "Deprecated." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname of the domain. Can be either the zone apex or a subdomain of the zone. Requests to this hostname will be routed to the configured Worker." + }, + { + "name": "id", + "type": "String", + "description": "Immutable ID of the domain." + }, + { + "name": "service", + "type": "String", + "description": "Name of the Worker associated with the domain. Requests to the configured hostname will be routed to this Worker." + }, + { + "name": "zone_id", + "type": "String", + "description": "ID of the zone containing the domain hostname." + }, + { + "name": "zone_name", + "type": "String", + "description": "Name of the zone containing the domain hostname." + } + ] + } + ] + }, + "data-source:cloudflare_workers_deployment": { + "kind": "data-source", + "name": "cloudflare_workers_deployment", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers_deployment\" \"example_workers_deployment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n deployment_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "deployment_id", + "type": "String" + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + } + ], + "optional": [], + "computed": [ + { + "name": "annotations", + "type": "Attributes", + "children": [ + { + "name": "workers_message", + "type": "String", + "description": "Human-readable message about the deployment. Truncated to 1000 bytes if longer." + }, + { + "name": "workers_triggered_by", + "type": "String", + "description": "Operation that triggered the creation of the deployment." + } + ] + }, + { + "name": "author_email", + "type": "String" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "source", + "type": "String" + }, + { + "name": "strategy", + "type": "String", + "description": "Available values: \"percentage\"." + }, + { + "name": "versions", + "type": "Attributes List", + "description": "Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.", + "children": [ + { + "name": "percentage", + "type": "Number", + "description": "Percentage of traffic served by this version." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier of the Worker Version." + } + ] + } + ] + }, + "resource:cloudflare_workers_deployment": { + "kind": "resource", + "name": "cloudflare_workers_deployment", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "resource \"cloudflare_workers_deployment\" \"example_workers_deployment\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n strategy = \"percentage\"\n versions = [{\n percentage = 100\n version_id = \"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\"\n }]\n annotations = {\n workers_message = \"Deploy bug fix.\"\n }\n}", + "importExample": "$ terraform import cloudflare_workers_deployment.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + }, + { + "name": "strategy", + "type": "String", + "description": "Available values: \"percentage\"." + }, + { + "name": "versions", + "type": "Attributes List", + "description": "Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.", + "children": [ + { + "name": "percentage", + "type": "Number", + "description": "Percentage of traffic served by this version." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier of the Worker Version." + } + ] + } + ], + "optional": [ + { + "name": "annotations", + "type": "Attributes", + "children": [ + { + "name": "workers_message", + "type": "String", + "description": "Human-readable message about the deployment. Truncated to 1000 bytes if longer." + }, + { + "name": "workers_triggered_by", + "type": "String", + "description": "Operation that triggered the creation of the deployment." + } + ] + }, + { + "name": "force", + "type": "Boolean", + "description": "If set to true, the deployment will be created even if normally blocked by something such rolling back to an older version when a secret has changed." + } + ], + "computed": [ + { + "name": "author_email", + "type": "String" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "source", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_workers_deployments": { + "kind": "list-data-source", + "name": "cloudflare_workers_deployments", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers_deployments\" \"example_workers_deployments\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n since = \"2019-12-27T18:11:19.117Z\"\n until = \"2019-12-27T18:11:19.117Z\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "since", + "type": "String", + "description": "Start of the deployment creation time range, inclusive." + }, + { + "name": "until", + "type": "String", + "description": "End of the deployment creation time range, inclusive." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "deployments", + "type": "Attributes List", + "children": [ + { + "name": "annotations", + "type": "Attributes", + "children": [ + { + "name": "workers_message", + "type": "String", + "description": "Human-readable message about the deployment. Truncated to 1000 bytes if longer." + }, + { + "name": "workers_triggered_by", + "type": "String", + "description": "Operation that triggered the creation of the deployment." + } + ] + }, + { + "name": "author_email", + "type": "String" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "source", + "type": "String" + }, + { + "name": "strategy", + "type": "String", + "description": "Available values: \"percentage\"." + }, + { + "name": "versions", + "type": "Attributes List", + "description": "Worker versions included in this deployment. Each object must contain a `version_id` UUID and a `percentage`; percentages across all objects must total 100. In the `cf` CLI, pass the entire array as one JSON value to `--versions`, either inline, for example `--versions '[{\"version_id\":\"023e105f-2a42-4f8b-a1c1-73f6a2a30c0f\",\"percentage\":100}]'`, or from a JSON file with `--versions @versions.json`.", + "children": [ + { + "name": "percentage", + "type": "Number", + "description": "Percentage of traffic served by this version." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier of the Worker Version." + } + ] + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_workers_for_platforms_dispatch_namespace": { + "kind": "data-source", + "name": "cloudflare_workers_for_platforms_dispatch_namespace", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers_for_platforms_dispatch_namespace\" \"example_workers_for_platforms_dispatch_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dispatch_namespace = \"my-dispatch-namespace\"\n}", + "required": [ + { + "name": "dispatch_namespace", + "type": "String", + "description": "Name of the Workers for Platforms dispatch namespace." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "created_by", + "type": "String", + "description": "Identifier." + }, + { + "name": "created_on", + "type": "String", + "description": "When the script was created." + }, + { + "name": "id", + "type": "String", + "description": "Name of the Workers for Platforms dispatch namespace." + }, + { + "name": "modified_by", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the script was last modified." + }, + { + "name": "namespace_id", + "type": "String", + "description": "API Resource UUID tag." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the Workers for Platforms dispatch namespace." + }, + { + "name": "script_count", + "type": "Number", + "description": "The current number of scripts in this Dispatch Namespace." + }, + { + "name": "trusted_workers", + "type": "Boolean", + "description": "Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"." + } + ] + }, + "resource:cloudflare_workers_for_platforms_dispatch_namespace": { + "kind": "resource", + "name": "cloudflare_workers_for_platforms_dispatch_namespace", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "resource \"cloudflare_workers_for_platforms_dispatch_namespace\" \"example_workers_for_platforms_dispatch_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"my-dispatch-namespace\"\n}", + "importExample": "$ terraform import cloudflare_workers_for_platforms_dispatch_namespace.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "name", + "type": "String", + "description": "The name of the dispatch namespace." + } + ], + "computed": [ + { + "name": "created_by", + "type": "String", + "description": "Identifier." + }, + { + "name": "created_on", + "type": "String", + "description": "When the script was created." + }, + { + "name": "id", + "type": "String", + "description": "Name of the Workers for Platforms dispatch namespace." + }, + { + "name": "modified_by", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the script was last modified." + }, + { + "name": "namespace_id", + "type": "String", + "description": "API Resource UUID tag." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the Workers for Platforms dispatch namespace." + }, + { + "name": "script_count", + "type": "Number", + "description": "The current number of scripts in this Dispatch Namespace." + }, + { + "name": "trusted_workers", + "type": "Boolean", + "description": "Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"." + } + ] + }, + "list-data-source:cloudflare_workers_for_platforms_dispatch_namespaces": { + "kind": "list-data-source", + "name": "cloudflare_workers_for_platforms_dispatch_namespaces", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers_for_platforms_dispatch_namespaces\" \"example_workers_for_platforms_dispatch_namespaces\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_by", + "type": "String", + "description": "Identifier." + }, + { + "name": "created_on", + "type": "String", + "description": "When the script was created." + }, + { + "name": "id", + "type": "String", + "description": "Name of the Workers for Platforms dispatch namespace." + }, + { + "name": "modified_by", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the script was last modified." + }, + { + "name": "namespace_id", + "type": "String", + "description": "API Resource UUID tag." + }, + { + "name": "namespace_name", + "type": "String", + "description": "Name of the Workers for Platforms dispatch namespace." + }, + { + "name": "script_count", + "type": "Number", + "description": "The current number of scripts in this Dispatch Namespace." + }, + { + "name": "trusted_workers", + "type": "Boolean", + "description": "Whether the Workers in the namespace are executed in a \"trusted\" manner. When a Worker is trusted, it has access to the shared caches for the zone in the Cache API, and has access to the `request.cf` object on incoming Requests. When a Worker is untrusted, caches are not shared across the zone, and `request.cf` is undefined. By default, Workers in a namespace are \"untrusted\"." + } + ] + } + ] + }, + "data-source:cloudflare_workers_kv": { + "kind": "data-source", + "name": "cloudflare_workers_kv", + "description": "Accepted Permissions\n\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`", + "example": "data \"cloudflare_workers_kv\" \"example_workers_kv\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n key_name = \"My-Key\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "ID of the Cloudflare account that owns the Workers KV namespaces." + }, + { + "name": "key_name", + "type": "String", + "description": "A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL." + }, + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Workers KV namespace." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL." + }, + { + "name": "value", + "type": "String" + } + ] + }, + "resource:cloudflare_workers_kv": { + "kind": "resource", + "name": "cloudflare_workers_kv", + "description": "Accepted Permissions\n\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`", + "example": "resource \"cloudflare_workers_kv\" \"example_workers_kv\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n key_name = \"My-Key\"\n value = \"Some Value\"\n metadata = jsonencode({})\n}", + "importExample": "$ terraform import cloudflare_workers_kv.example '//'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "ID of the Cloudflare account that owns the Workers KV namespaces." + }, + { + "name": "key_name", + "type": "String", + "description": "A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL." + }, + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Workers KV namespace." + }, + { + "name": "value", + "type": "String", + "description": "A byte sequence to be stored, up to 25 MiB in length." + } + ], + "optional": [ + { + "name": "expiration", + "type": "Number", + "description": "Expires the key at a certain time, measured in number of seconds since the UNIX epoch." + }, + { + "name": "expiration_ttl", + "type": "Number", + "description": "Expires the key after a number of seconds. Must be at least 60." + }, + { + "name": "metadata", + "type": "String", + "description": "Associates arbitrary JSON data with a key/value pair." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "A key's name. The name may be at most 512 bytes. All printable, non-whitespace characters are valid. Use percent-encoding to define key names as part of a URL." + } + ] + }, + "data-source:cloudflare_workers_kv_namespace": { + "kind": "data-source", + "name": "cloudflare_workers_kv_namespace", + "description": "Accepted Permissions\n\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`", + "example": "data \"cloudflare_workers_kv_namespace\" \"example_workers_kv_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n namespace_id = \"0f2ac74b498b48028cb68387c421e279\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "ID of the Cloudflare account that owns the Workers KV namespaces." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Sort namespaces in ascending (`asc`) or descending (`desc`) order.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "order", + "type": "String", + "description": "Namespace field to sort by (`id` or `title`).\nAvailable values: \"id\", \"title\"." + } + ] + }, + { + "name": "namespace_id", + "type": "String", + "description": "ID of the Workers KV namespace." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "ID of the Workers KV namespace." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time.\nAvailable values: \"eu\", \"fedramp\", \"us\"." + }, + { + "name": "supports_url_encoding", + "type": "Boolean", + "description": "True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"." + }, + { + "name": "title", + "type": "String", + "description": "Human-readable string name for a Workers KV namespace." + } + ] + }, + "resource:cloudflare_workers_kv_namespace": { + "kind": "resource", + "name": "cloudflare_workers_kv_namespace", + "description": "Accepted Permissions\n\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`", + "example": "resource \"cloudflare_workers_kv_namespace\" \"example_workers_kv_namespace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n title = \"My Own Namespace\"\n jurisdiction = \"eu\"\n}", + "importExample": "$ terraform import cloudflare_workers_kv_namespace.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "ID of the Cloudflare account that owns the Workers KV namespaces." + }, + { + "name": "title", + "type": "String", + "description": "Human-readable string name for a Workers KV namespace." + } + ], + "optional": [ + { + "name": "jurisdiction", + "type": "String", + "description": "Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time.\nAvailable values: \"eu\", \"fedramp\", \"us\"." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "ID of the Workers KV namespace." + }, + { + "name": "supports_url_encoding", + "type": "Boolean", + "description": "True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"." + } + ] + }, + "list-data-source:cloudflare_workers_kv_namespaces": { + "kind": "list-data-source", + "name": "cloudflare_workers_kv_namespaces", + "description": "Accepted Permissions\n\n- `Workers KV Storage Read`\n- `Workers KV Storage Write`", + "example": "data \"cloudflare_workers_kv_namespaces\" \"example_workers_kv_namespaces\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n direction = \"asc\"\n order = \"id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "ID of the Cloudflare account that owns the Workers KV namespaces." + }, + { + "name": "direction", + "type": "String", + "description": "Sort namespaces in ascending (`asc`) or descending (`desc`) order.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Namespace field to sort by (`id` or `title`).\nAvailable values: \"id\", \"title\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "ID of the Workers KV namespace." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "Specify the jurisdiction to restrict the KV namespace to durably store data within. Can only be set at namespace creation time.\nAvailable values: \"eu\", \"fedramp\", \"us\"." + }, + { + "name": "supports_url_encoding", + "type": "Boolean", + "description": "True if keys written on the URL will be URL-decoded before storing. For example, if set to \"true\", a key written on the URL as \"%3F\" will be stored as \"?\"." + }, + { + "name": "title", + "type": "String", + "description": "Human-readable string name for a Workers KV namespace." + } + ] + } + ] + }, + "data-source:cloudflare_workers_route": { + "kind": "data-source", + "name": "cloudflare_workers_route", + "description": "Accepted Permissions\n\n- `Workers Routes Read`\n- `Workers Routes Write`", + "example": "data \"cloudflare_workers_route\" \"example_workers_route\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n route_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "route_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "pattern", + "type": "String", + "description": "Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)." + }, + { + "name": "script", + "type": "String", + "description": "Name of the script to run if the route matches." + } + ] + }, + "resource:cloudflare_workers_route": { + "kind": "resource", + "name": "cloudflare_workers_route", + "description": "Accepted Permissions\n\n- `Workers Routes Read`\n- `Workers Routes Write`", + "example": "resource \"cloudflare_workers_route\" \"example_workers_route\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n pattern = \"example.com/*\"\n script = \"my-workers-script\"\n}", + "importExample": "$ terraform import cloudflare_workers_route.example '/'", + "required": [ + { + "name": "pattern", + "type": "String", + "description": "Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "script", + "type": "String", + "description": "Name of the script to run if the route matches." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "list-data-source:cloudflare_workers_routes": { + "kind": "list-data-source", + "name": "cloudflare_workers_routes", + "description": "Accepted Permissions\n\n- `Workers Routes Read`\n- `Workers Routes Write`", + "example": "data \"cloudflare_workers_routes\" \"example_workers_routes\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "pattern", + "type": "String", + "description": "Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)." + }, + { + "name": "script", + "type": "String", + "description": "Name of the script to run if the route matches." + } + ] + } + ] + }, + "data-source:cloudflare_workers_script": { + "kind": "data-source", + "name": "cloudflare_workers_script", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers_script\" \"example_workers_script\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "tags", + "type": "String", + "description": "Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'." + } + ] + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Name of the script." + }, + { + "name": "script", + "type": "String" + } + ] + }, + "resource:cloudflare_workers_script": { + "kind": "resource", + "name": "cloudflare_workers_script", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`\n\n-> For more direct control over Workers resources, we recommend the beta `cloudflare_worker`, `cloudflare_worker_version`, and `cloudflare_workers_deployment` resources. See how to use them in the [developer documentation](https://developers.cloudflare.com/workers/platform/infrastructure-as-code/).", + "example": "resource \"cloudflare_workers_script\" \"example_workers_script\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n assets = {\n config = {\n headers = </'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script, used in URLs and route configuration." + } + ], + "optional": [ + { + "name": "annotations", + "type": "Attributes", + "description": "Annotations for the version created by this upload.", + "children": [ + { + "name": "workers_message", + "type": "String", + "description": "Human-readable message about the version. Truncated to 1000 bytes if longer." + }, + { + "name": "workers_tag", + "type": "String", + "description": "User-provided identifier for the version. Maximum 100 bytes." + }, + { + "name": "workers_triggered_by", + "type": "String", + "description": "Indicates the trigger that created this version. Server-set value." + } + ] + }, + { + "name": "assets", + "type": "Attributes", + "description": "Configuration for assets within a Worker.", + "children": [ + { + "name": "asset_manifest_sha256", + "type": "String", + "description": "The SHA-256 hash of the asset manifest of files to upload." + }, + { + "name": "config", + "type": "Attributes", + "description": "Configuration for assets within a Worker.", + "children": [ + { + "name": "base_path", + "type": "String", + "description": "The public URL path prefix under which assets are served. A null request value resets it to `/`; responses represent the root as `/`. All versions in a gradual deployment must use the same canonical value. To change it, first deploy the version containing the change at 100%." + }, + { + "name": "headers", + "type": "String", + "description": "The contents of a _headers file (used to attach custom headers on asset responses)." + }, + { + "name": "html_handling", + "type": "String", + "description": "Determines the redirects and rewrites of requests for HTML content.\nAvailable values: \"auto-trailing-slash\", \"force-trailing-slash\", \"drop-trailing-slash\", \"none\"." + }, + { + "name": "not_found_handling", + "type": "String", + "description": "Determines the response when a request does not match a static asset, and there is no Worker script.\nAvailable values: \"none\", \"404-page\", \"single-page-application\"." + }, + { + "name": "redirects", + "type": "String", + "description": "The contents of a _redirects file (used to apply redirects or proxy paths ahead of asset serving)." + }, + { + "name": "run_worker_first", + "type": "Dynamic", + "description": "When a boolean true, requests will always invoke the Worker script. Otherwise, attempt to serve an asset matching the request, falling back to the Worker script. When a list of strings, contains path rules to control routing to either the Worker or assets. Glob (*) and negative (!) rules are supported. Rules must start with either '/' or '!/'. At least one non-negative rule must be provided, and negative rules have higher precedence than non-negative rules." + }, + { + "name": "serve_directly", + "type": "Boolean", + "description": "When true and the incoming request matches an asset, that will be served instead of invoking the Worker script. When false, requests will always invoke the Worker script.", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "directory", + "type": "String", + "description": "Path to the directory containing asset files to upload." + }, + { + "name": "jwt", + "type": "String", + "description": "Token provided upon successful upload of all files from a registered manifest.", + "sensitive": true + } + ] + }, + { + "name": "bindings", + "type": "Attributes List", + "description": "List of bindings attached to a Worker. You can find more about bindings on our docs: https://developers.cloudflare.com/workers/configuration/multipart-upload-metadata/#bindings.", + "children": [ + { + "name": "algorithm", + "type": "String", + "description": "Algorithm-specific key parameters. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#algorithm)." + }, + { + "name": "allowed_destination_addresses", + "type": "List of String", + "description": "List of allowed destination addresses." + }, + { + "name": "allowed_sender_addresses", + "type": "List of String", + "description": "List of allowed sender addresses." + }, + { + "name": "app_id", + "type": "String", + "description": "ID of the Flagship app to bind to for feature flag evaluation." + }, + { + "name": "bucket_name", + "type": "String", + "description": "R2 bucket to bind to." + }, + { + "name": "certificate_id", + "type": "String", + "description": "Identifier of the certificate to bind to." + }, + { + "name": "class_name", + "type": "String", + "description": "The exported class name of the Durable Object." + }, + { + "name": "database_id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "dataset", + "type": "String", + "description": "The name of the dataset to bind to." + }, + { + "name": "destination_address", + "type": "String", + "description": "Destination address for the email." + }, + { + "name": "dispatch_namespace", + "type": "String", + "description": "The dispatch namespace the Durable Object script belongs to." + }, + { + "name": "entrypoint", + "type": "String", + "description": "Entrypoint to invoke on the target Worker." + }, + { + "name": "environment", + "type": "String", + "description": "The environment of the script_name to bind to." + }, + { + "name": "format", + "type": "String", + "description": "Data format of the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#format).\nAvailable values: \"raw\", \"pkcs8\", \"spki\", \"jwk\"." + }, + { + "name": "id", + "type": "String", + "description": "Identifier of the D1 database to bind to." + }, + { + "name": "index_name", + "type": "String", + "description": "Name of the Vectorize index to bind to." + }, + { + "name": "instance_name", + "type": "String", + "description": "The user-chosen instance name. Must exist at deploy time. The worker can search, chat, update, and manage items/jobs on this instance." + }, + { + "name": "json", + "type": "String", + "description": "JSON data to use." + }, + { + "name": "jurisdiction", + "type": "String", + "description": "The [jurisdiction](https://developers.cloudflare.com/r2/reference/data-location/#jurisdictional-restrictions) of the R2 bucket.\nAvailable values: \"eu\", \"fedramp\", \"fedramp-high\"." + }, + { + "name": "key_base64", + "type": "String", + "description": "Base64-encoded key data. Required if `format` is \"raw\", \"pkcs8\", or \"spki\".", + "sensitive": true + }, + { + "name": "key_jwk", + "type": "String", + "description": "Key data in [JSON Web Key](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#json_web_key) format. Required if `format` is \"jwk\".", + "sensitive": true + }, + { + "name": "name", + "type": "String", + "description": "A JavaScript variable name for the binding." + }, + { + "name": "namespace", + "type": "String", + "description": "The namespace the instance belongs to. Defaults to \"default\" if omitted. Customers who don't use namespaces can simply omit this field." + }, + { + "name": "namespace_id", + "type": "String", + "description": "Namespace identifier tag." + }, + { + "name": "network_id", + "type": "String", + "description": "Identifier of the network to bind to. Only \"cf1:network\" is currently supported. Mutually exclusive with tunnel_id." + }, + { + "name": "old_name", + "type": "String", + "description": "The old name of the inherited binding. If set, the binding will be renamed from `old_name` to `name` in the new version. If not set, the binding will keep the same name between versions." + }, + { + "name": "outbound", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "params", + "type": "List of String", + "description": "Pass information from the Dispatch Worker to the Outbound Worker through the parameters." + }, + { + "name": "worker", + "type": "Attributes", + "description": "Outbound worker.", + "children": [ + { + "name": "environment", + "type": "String", + "description": "Environment of the outbound worker." + }, + { + "name": "service", + "type": "String", + "description": "Name of the outbound worker." + } + ] + } + ] + }, + { + "name": "part", + "type": "String", + "description": "The name of the file containing the data content. Only accepted for `service worker syntax` Workers." + }, + { + "name": "pipeline", + "type": "String", + "description": "Name of the Pipeline to bind to." + }, + { + "name": "queue_name", + "type": "String", + "description": "Name of the Queue to bind to." + }, + { + "name": "script_name", + "type": "String", + "description": "The script where the Durable Object is defined, if it is external to this Worker." + }, + { + "name": "secret_name", + "type": "String", + "description": "Name of the secret in the store." + }, + { + "name": "service", + "type": "String", + "description": "Name of Worker to bind to." + }, + { + "name": "service_id", + "type": "String", + "description": "Identifier of the VPC service to bind to." + }, + { + "name": "simple", + "type": "Attributes", + "description": "A simple rate limit.", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "The rate limit value." + }, + { + "name": "mitigation_timeout", + "type": "Number", + "description": "Duration in seconds to apply the mitigation action after the rate limit is exceeded. Valid values are 0 (disabled), 10, or multiples of 60 up to 86400. Must be greater than or equal to the period when non-zero." + }, + { + "name": "period", + "type": "Number", + "description": "The rate limit period in seconds." + } + ] + }, + { + "name": "store_id", + "type": "String", + "description": "ID of the store containing the secret." + }, + { + "name": "stream", + "type": "String", + "description": "ID of a K2 stream owned by the account deploying the Worker." + }, + { + "name": "text", + "type": "String", + "description": "The text value to use.", + "sensitive": true + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel to bind to. Mutually exclusive with network_id." + }, + { + "name": "type", + "type": "String", + "description": "The kind of resource that the binding provides.\nAvailable values: \"ai\", \"ai_search\", \"ai_search_namespace\", \"messaging\", \"analytics_engine\", \"artifacts\", \"assets\", \"browser\", \"d1\", \"data_blob\", \"dispatch_namespace\", \"durable_object_namespace\", \"hyperdrive\", \"inherit\", \"images\", \"json\", \"kv_namespace\", \"media\", \"mtls_certificate\", \"plain_text\", \"pipelines\", \"k2\", \"queue\", \"ratelimit\", \"r2_bucket\", \"secret_text\", \"send_email\", \"service\", \"text_blob\", \"vectorize\", \"version_metadata\", \"secrets_store_secret\", \"flagship\", \"secret_key\", \"workflow\", \"wasm_module\", \"vpc_service\", \"vpc_network\"." + }, + { + "name": "usages", + "type": "Set of String", + "description": "Allowed operations with the key. [Learn more](https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/importKey#keyUsages)." + }, + { + "name": "version_id", + "type": "String", + "description": "Identifier for the version to inherit the binding from, which can be the version ID or the literal \"latest\" to inherit from the latest version. Defaults to inheriting the binding from the latest version." + }, + { + "name": "workflow_name", + "type": "String", + "description": "Name of the Workflow to bind to." + } + ] + }, + { + "name": "body_part", + "type": "String", + "description": "Name of the uploaded file that contains the script (e.g. the file adding a listener to the `fetch` event). Indicates a `service worker syntax` Worker." + }, + { + "name": "cache_options", + "type": "Attributes", + "description": "Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker." + }, + { + "name": "compatibility_flags", + "type": "Set of String", + "description": "Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`." + }, + { + "name": "content", + "type": "String", + "description": "Module or Service Worker contents of the Worker. Conflicts with `content_file`." + }, + { + "name": "content_file", + "type": "String", + "description": "Path to a file containing the Module or Service Worker contents of the Worker. Conflicts with `content`. Must be paired with `content_sha256`." + }, + { + "name": "content_sha256", + "type": "String", + "description": "SHA-256 hash of the Worker contents. Used to trigger updates when source code changes. Must be provided when `content_file` is specified." + }, + { + "name": "content_type", + "type": "String", + "description": "Content-Type of the Worker. Required if uploading a non-JavaScript Worker (e.g. \"text/x-python\")." + }, + { + "name": "exports", + "type": "Attributes Map", + "description": "Per-entrypoint export configuration. Keys are the export names; values describe the entrypoint's kind and per-entrypoint cache behavior.", + "children": [ + { + "name": "cache", + "type": "Attributes", + "description": "Per-entrypoint cache override. When present, this overrides the top-level `cache_options` for this specific entrypoint.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this entrypoint." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The kind of entrypoint. A `type: worker` entry overrides the top-level `cache_options` for this specific entrypoint." + } + ] + }, + { + "name": "files", + "type": "Attributes Map", + "description": "Additional modules and data files to include in the multipart Worker upload. Map keys are multipart part names referenced by binding `part` values and module imports.", + "children": [ + { + "name": "content_base64", + "type": "String", + "description": "Base64-encoded file content." + }, + { + "name": "content_file", + "type": "String", + "description": "Path to the file content." + }, + { + "name": "content_sha256", + "type": "String", + "description": "SHA-256 hash of the file content, used to detect changes and remote drift." + }, + { + "name": "content_type", + "type": "String", + "description": "Content type of the file, such as `application/wasm`, `text/plain`, or `application/octet-stream`." + } + ] + }, + { + "name": "force", + "type": "Boolean", + "description": "If true, delete the Worker even when other Workers still reference it. Service bindings in those Workers may be left broken. Durable Object namespaces implemented by the deleted Worker are deleted even if other Workers reference them." + }, + { + "name": "keep_assets", + "type": "Boolean", + "description": "Retain assets which exist for a previously uploaded Worker version; used in lieu of providing a completion token. An explicit `assets` upload takes precedence over `keep_assets`." + }, + { + "name": "keep_bindings", + "type": "Set of String", + "description": "List of binding types to keep from previous_upload." + }, + { + "name": "limits", + "type": "Attributes", + "description": "Limits to apply for this Worker.", + "children": [ + { + "name": "cpu_ms", + "type": "Number", + "description": "The amount of CPU time this Worker can use in milliseconds." + }, + { + "name": "subrequests", + "type": "Number", + "description": "The number of subrequests this Worker can make per request." + } + ] + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether Logpush is turned on for the Worker." + }, + { + "name": "main_module", + "type": "String", + "description": "Name of the uploaded file that contains the main module (e.g. the file exporting a `fetch` handler). Indicates a `module syntax` Worker." + }, + { + "name": "migrations", + "type": "Attributes", + "description": "Migrations to apply for Durable Objects associated with this Worker.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "new_tag", + "type": "String", + "description": "Tag to set as the latest migration tag." + }, + { + "name": "old_tag", + "type": "String", + "description": "Tag used to verify against the latest migration tag for this Worker. If they don't match, the upload is rejected." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "steps", + "type": "Attributes List", + "description": "Migrations to apply in order.", + "children": [ + { + "name": "deleted_classes", + "type": "List of String", + "description": "A list of classes to delete Durable Object namespaces from." + }, + { + "name": "new_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces from." + }, + { + "name": "new_sqlite_classes", + "type": "List of String", + "description": "A list of classes to create Durable Object namespaces with SQLite from." + }, + { + "name": "renamed_classes", + "type": "Attributes List", + "description": "A list of classes with Durable Object namespaces that were renamed.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "transferred_classes", + "type": "Attributes List", + "description": "A list of transfers for Durable Object namespaces from a different Worker and class to a class defined in this Worker.", + "children": [ + { + "name": "from", + "type": "String" + }, + { + "name": "from_script", + "type": "String" + }, + { + "name": "to", + "type": "String" + } + ] + } + ] + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for incoming requests. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" (default) honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "package_dependencies", + "type": "Attributes List", + "description": "The list of npm packages that were installed and used when this Worker was built.", + "children": [ + { + "name": "installed_version", + "type": "String", + "description": "The exact version that was resolved and installed by the package manager." + }, + { + "name": "name", + "type": "String", + "description": "The npm package name." + }, + { + "name": "package_json_version", + "type": "String", + "description": "The version constraint as written in package.json." + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "last_analyzed_at", + "type": "String", + "description": "The last time the script was analyzed for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "status", + "type": "String", + "description": "Status of [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"SUCCESS\", \"UNSUPPORTED_APPLICATION\", \"INSUFFICIENT_INVOCATIONS\"." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "List of Workers that will consume logs from the attached Worker.", + "children": [ + { + "name": "environment", + "type": "String", + "description": "Optional environment if the Worker utilizes one." + }, + { + "name": "namespace", + "type": "String", + "description": "Optional dispatch namespace the script belongs to." + }, + { + "name": "service", + "type": "String", + "description": "Name of Worker that is to be the consumer." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "Usage model for the Worker invocations.\nAvailable values: \"standard\", \"bundled\", \"unbound\"." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "When the script was created." + }, + { + "name": "etag", + "type": "String", + "description": "Hashed script content, can be used in a If-None-Match header when updating." + }, + { + "name": "handlers", + "type": "List of String", + "description": "The names of handlers exported as part of the default export." + }, + { + "name": "has_assets", + "type": "Boolean", + "description": "Whether a Worker contains assets." + }, + { + "name": "has_modules", + "type": "Boolean", + "description": "Whether a Worker contains modules." + }, + { + "name": "id", + "type": "String", + "description": "Name of the script, used in URLs and route configuration." + }, + { + "name": "last_deployed_from", + "type": "String", + "description": "The client most recently used to deploy this Worker." + }, + { + "name": "migration_tag", + "type": "String", + "description": "The tag of the Durable Object migration that was most recently applied for this Worker." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the script was last modified." + }, + { + "name": "named_handlers", + "type": "Attributes List", + "description": "Named exports, such as Durable Object class implementations and named entrypoints.", + "children": [ + { + "name": "handlers", + "type": "List of String", + "description": "The names of handlers exported as part of the named export." + }, + { + "name": "name", + "type": "String", + "description": "The name of the export." + } + ] + }, + { + "name": "placement_mode", + "type": "String", + "description": "Available values: \"smart\", \"targeted\".", + "deprecated": "Deprecated." + }, + { + "name": "placement_status", + "type": "String", + "description": "Available values: \"SUCCESS\", \"UNSUPPORTED_APPLICATION\", \"INSUFFICIENT_INVOCATIONS\".", + "deprecated": "Deprecated." + }, + { + "name": "startup_time_ms", + "type": "Number" + } + ] + }, + "data-source:cloudflare_workers_script_subdomain": { + "kind": "data-source", + "name": "cloudflare_workers_script_subdomain", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers_script_subdomain\" \"example_workers_script_subdomain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + } + ], + "optional": [], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Worker is available on the workers.dev subdomain." + }, + { + "name": "previews_enabled", + "type": "Boolean", + "description": "Whether the Worker's Preview URLs are available on the workers.dev subdomain." + } + ] + }, + "resource:cloudflare_workers_script_subdomain": { + "kind": "resource", + "name": "cloudflare_workers_script_subdomain", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`\n\n-> This resource is redundant with `cloudflare_worker` and should not be used together. When using the `cloudflare_worker` resource, use the nested `subdomain` attribute to control subdomain settings instead.", + "example": "resource \"cloudflare_workers_script_subdomain\" \"example_workers_script_subdomain\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n script_name = \"this-is_my_script-01\"\n enabled = true\n previews_enabled = false\n}", + "importExample": "$ terraform import cloudflare_workers_script_subdomain.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Worker should be available on the workers.dev subdomain." + }, + { + "name": "script_name", + "type": "String", + "description": "Name of the script." + } + ], + "optional": [ + { + "name": "previews_enabled", + "type": "Boolean", + "description": "Whether the Worker's Preview URLs should be available on the workers.dev subdomain." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Identifier for the resource." + } + ] + }, + "list-data-source:cloudflare_workers_scripts": { + "kind": "list-data-source", + "name": "cloudflare_workers_scripts", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workers_scripts\" \"example_workers_scripts\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tags = \"production:yes,staging:no\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "tags", + "type": "String", + "description": "Filter scripts by tags. Format: comma-separated list of tag:allowed pairs where allowed is 'yes' or 'no'." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "cache_options", + "type": "Attributes", + "description": "Global CacheW configuration for the Worker. When caching is on,\nthe platform provisions a `cloudflare.app` zone for the Worker.\nA `type: worker` entry in the `exports` map can override this\nvalue for a single entrypoint.", + "children": [ + { + "name": "cross_version_cache", + "type": "Boolean", + "description": "Whether cached responses are shared across Worker version\nuploads. This is independent of `enabled`. It can stay true\nwhile caching is off, so the preference survives turning\ncaching off and back on." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this Worker." + } + ] + }, + { + "name": "compatibility_date", + "type": "String", + "description": "Date indicating targeted support in the Workers runtime. Backwards incompatible fixes to the runtime following this date will not affect this Worker." + }, + { + "name": "compatibility_flags", + "type": "Set of String", + "description": "Flags that enable or disable certain features in the Workers runtime. Used to enable upcoming features or opt in or out of specific changes not included in a `compatibility_date`." + }, + { + "name": "created_on", + "type": "String", + "description": "When the script was created." + }, + { + "name": "etag", + "type": "String", + "description": "Hashed script content, can be used in a If-None-Match header when updating." + }, + { + "name": "exports", + "type": "Attributes Map", + "description": "Declarative exports for the Worker's most recent version,\nincluding Durable Object classes (with their `storage`\nbackend) and named Worker entrypoints. Tombstoned lifecycle\nentries are omitted, so only live exports (`created` and\n`expecting-transfer`) are returned.", + "children": [ + { + "name": "cache", + "type": "Attributes", + "description": "Cache override for this entrypoint. It applies only to\n`type: worker` entries and overrides the Worker's global\n`cache_options.enabled` for that entrypoint.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether caching is enabled for this entrypoint." + } + ] + }, + { + "name": "renamed_to", + "type": "String", + "description": "Destination class name for a `state: renamed` tombstone. The\ntarget must appear as a live (`created`) entry in the same\n`exports` map. Write-only: never present in GET responses." + }, + { + "name": "state", + "type": "String", + "description": "Lifecycle state of the export entry. Defaults to `created`\n(a normal, live export) when omitted.\n\n`deleted`, `renamed`, and `transferred` are tombstones:\nwrite-only lifecycle operations that retire, rename, or hand\noff a provisioned Durable Object namespace. They are applied\nat upload and are filtered out of GET responses, so a read\nonly ever returns `created` or `expecting-transfer`.\n\n`expecting-transfer` is a live export whose data is being\nreceived from another script via the two-phase transfer flow;\nit carries `storage` and `transfer_from`.\nAvailable values: \"created\", \"deleted\", \"renamed\", \"transferred\", \"expecting-transfer\"." + }, + { + "name": "storage", + "type": "String", + "description": "Storage backend for a `type: durable-object` export. Required\nfor live Durable Object entries (`created` and\n`expecting-transfer`). `sqlite` selects SQLite-backed storage;\n`legacy-kv` selects the legacy key-value storage.\nAvailable values: \"sqlite\", \"legacy-kv\"." + }, + { + "name": "transfer_from", + "type": "String", + "description": "Source script for a `state: expecting-transfer` entry. The\nnamespace on this script is materialised from the source\nscript's data via the pending-transfer flow. Present on reads\nfor `expecting-transfer` entries." + }, + { + "name": "transferred_to", + "type": "String", + "description": "Destination script for a `state: transferred` tombstone. Must\nreference a script in the same account; cross-dispatch-namespace\ntransfers are rejected. Write-only: never present in GET\nresponses." + }, + { + "name": "type", + "type": "String", + "description": "The kind of export.\nAvailable values: \"worker\", \"durable-object\"." + } + ] + }, + { + "name": "handlers", + "type": "List of String", + "description": "The names of handlers exported as part of the default export." + }, + { + "name": "has_assets", + "type": "Boolean", + "description": "Whether a Worker contains assets." + }, + { + "name": "has_modules", + "type": "Boolean", + "description": "Whether a Worker contains modules." + }, + { + "name": "id", + "type": "String", + "description": "The name used to identify the script." + }, + { + "name": "last_deployed_from", + "type": "String", + "description": "The client most recently used to deploy this Worker." + }, + { + "name": "logpush", + "type": "Boolean", + "description": "Whether Logpush is turned on for the Worker." + }, + { + "name": "migration_tag", + "type": "String", + "description": "The tag of the Durable Object migration that was most recently applied for this Worker." + }, + { + "name": "modified_on", + "type": "String", + "description": "When the script was last modified." + }, + { + "name": "named_handlers", + "type": "Attributes List", + "description": "Named exports, such as Durable Object class implementations and named entrypoints.", + "children": [ + { + "name": "handlers", + "type": "List of String", + "description": "The names of handlers exported as part of the named export." + }, + { + "name": "name", + "type": "String", + "description": "The name of the export." + } + ] + }, + { + "name": "observability", + "type": "Attributes", + "description": "Observability settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether observability is enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for incoming requests. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1." + }, + { + "name": "issues", + "type": "Attributes", + "description": "Real-time Issues settings for the Worker.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether real-time Issues are enabled for the Worker." + } + ] + }, + { + "name": "logs", + "type": "Attributes", + "description": "Log settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where logs will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether logs are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for logs. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1." + }, + { + "name": "invocation_logs", + "type": "Boolean", + "description": "Whether [invocation logs](https://developers.cloudflare.com/workers/observability/logs/workers-logs/#invocation-logs) are enabled for the Worker." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether log persistence is enabled for the Worker." + } + ] + }, + { + "name": "redact_query_string", + "type": "Boolean", + "description": "Whether query strings are removed from request URLs in logs and traces." + }, + { + "name": "traces", + "type": "Attributes", + "description": "Trace settings for the Worker.", + "children": [ + { + "name": "destinations", + "type": "List of String", + "description": "A list of destinations where traces will be exported to." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether traces are enabled for the Worker." + }, + { + "name": "head_sampling_rate", + "type": "Number", + "description": "The sampling rate for traces. From 0 to 1 (1 = 100%, 0.1 = 10%). Default is 1." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether trace persistence is enabled for the Worker." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "Controls how inbound trace context (traceparent/tracestate) headers on incoming requests are handled. \"authenticated\" honors inbound trace context only when accompanied by a valid trace auth token. \"accept\" unconditionally accepts inbound trace context. Requires the trace propagation feature to be enabled. Returns null when the trace propagation feature is not enabled for the account.\nAvailable values: \"authenticated\", \"accept\"." + } + ] + } + ] + }, + { + "name": "placement", + "type": "Attributes", + "description": "Configuration for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement). Specify mode='smart' for Smart Placement, or one of region/hostname/host.", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host and port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "last_analyzed_at", + "type": "String", + "description": "The last time the script was analyzed for [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement)." + }, + { + "name": "mode", + "type": "String", + "description": "Enables [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"smart\", \"targeted\"." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region for targeted placement in format 'provider:region'." + }, + { + "name": "status", + "type": "String", + "description": "Status of [Smart Placement](https://developers.cloudflare.com/workers/configuration/smart-placement).\nAvailable values: \"SUCCESS\", \"UNSUPPORTED_APPLICATION\", \"INSUFFICIENT_INVOCATIONS\"." + }, + { + "name": "target", + "type": "Attributes List", + "description": "Array of placement targets (currently limited to single target).", + "children": [ + { + "name": "host", + "type": "String", + "description": "TCP host:port for targeted placement." + }, + { + "name": "hostname", + "type": "String", + "description": "HTTP hostname for targeted placement." + }, + { + "name": "region", + "type": "String", + "description": "Cloud region in format 'provider:region'." + } + ] + } + ] + }, + { + "name": "placement_mode", + "type": "String", + "description": "Available values: \"smart\", \"targeted\".", + "deprecated": "Deprecated." + }, + { + "name": "placement_status", + "type": "String", + "description": "Available values: \"SUCCESS\", \"UNSUPPORTED_APPLICATION\", \"INSUFFICIENT_INVOCATIONS\".", + "deprecated": "Deprecated." + }, + { + "name": "routes", + "type": "Attributes List", + "description": "Routes associated with the Worker.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "pattern", + "type": "String", + "description": "Pattern to match incoming requests against. [Learn more](https://developers.cloudflare.com/workers/configuration/routing/routes/#matching-behavior)." + }, + { + "name": "script", + "type": "String", + "description": "Name of the script to run if the route matches." + } + ] + }, + { + "name": "tag", + "type": "String", + "description": "The immutable ID of the script." + }, + { + "name": "tags", + "type": "Set of String", + "description": "Tags associated with the Worker." + }, + { + "name": "tail_consumers", + "type": "Attributes Set", + "description": "List of Workers that will consume logs from the attached Worker.", + "children": [ + { + "name": "environment", + "type": "String", + "description": "Optional environment if the Worker utilizes one." + }, + { + "name": "namespace", + "type": "String", + "description": "Optional dispatch namespace the script belongs to." + }, + { + "name": "service", + "type": "String", + "description": "Name of Worker that is to be the consumer." + } + ] + }, + { + "name": "usage_model", + "type": "String", + "description": "Usage model for the Worker invocations.\nAvailable values: \"standard\", \"bundled\", \"unbound\"." + } + ] + } + ] + }, + "data-source:cloudflare_workflow": { + "kind": "data-source", + "name": "cloudflare_workflow", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workflow\" \"example_workflow\" {\n account_id = \"account_id\"\n workflow_name = \"x\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "search", + "type": "String", + "description": "Allows filtering workflows` name." + } + ] + }, + { + "name": "workflow_name", + "type": "String" + } + ], + "computed": [ + { + "name": "class_name", + "type": "String" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "instances", + "type": "Map of Number" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "schedules", + "type": "Attributes List", + "children": [ + { + "name": "cron", + "type": "String" + }, + { + "name": "next_instance", + "type": "String" + } + ] + }, + { + "name": "script_deleted", + "type": "Boolean", + "description": "Whether the bound Worker was deleted, leaving this Workflow inactive." + }, + { + "name": "script_name", + "type": "String" + }, + { + "name": "triggered_on", + "type": "String" + } + ] + }, + "resource:cloudflare_workflow": { + "kind": "resource", + "name": "cloudflare_workflow", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "resource \"cloudflare_workflow\" \"example_workflow\" {\n account_id = \"account_id\"\n workflow_name = \"x\"\n class_name = \"x\"\n script_name = \"x\"\n concurrency = {\n limit = 1\n }\n default_retention = {\n error_retention = \"5 minutes\"\n success_retention = \"5 minutes\"\n }\n limits = {\n steps = 1\n }\n schedules = [{\n cron = \"x\"\n }]\n}", + "importExample": "$ terraform import cloudflare_workflow.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "class_name", + "type": "String" + }, + { + "name": "script_name", + "type": "String" + }, + { + "name": "workflow_name", + "type": "String" + } + ], + "optional": [ + { + "name": "concurrency", + "type": "Attributes", + "children": [ + { + "name": "limit", + "type": "Number", + "description": "Maximum number of instances of this workflow that can run concurrently. Additional instances are queued and started as running instances complete. Must not exceed the account concurrency limit." + } + ] + }, + { + "name": "default_retention", + "type": "Attributes", + "description": "Default retention applied to instances of this version when they do not set their own retention.", + "children": [ + { + "name": "error_retention", + "type": "Dynamic", + "description": "Specifies the duration in milliseconds or as a string like '5 minutes'." + }, + { + "name": "success_retention", + "type": "Dynamic", + "description": "Specifies the duration in milliseconds or as a string like '5 minutes'." + } + ] + }, + { + "name": "limits", + "type": "Attributes", + "children": [ + { + "name": "steps", + "type": "Number" + } + ] + }, + { + "name": "schedules", + "type": "Attributes List", + "children": [ + { + "name": "cron", + "type": "String" + } + ] + } + ], + "computed": [ + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "instances", + "type": "Map of Number" + }, + { + "name": "is_deleted", + "type": "Number" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "script_deleted", + "type": "Boolean", + "description": "Whether the bound Worker was deleted, leaving this Workflow inactive." + }, + { + "name": "terminator_running", + "type": "Number" + }, + { + "name": "triggered_on", + "type": "String" + }, + { + "name": "version_id", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_workflows": { + "kind": "list-data-source", + "name": "cloudflare_workflows", + "description": "Accepted Permissions\n\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Workers Tail Read`", + "example": "data \"cloudflare_workflows\" \"example_workflows\" {\n account_id = \"account_id\"\n search = \"x\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "search", + "type": "String", + "description": "Allows filtering workflows` name." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "class_name", + "type": "String" + }, + { + "name": "created_on", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "instances", + "type": "Map of Number" + }, + { + "name": "modified_on", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "schedules", + "type": "Attributes List", + "children": [ + { + "name": "cron", + "type": "String" + }, + { + "name": "next_instance", + "type": "String" + } + ] + }, + { + "name": "script_deleted", + "type": "Boolean", + "description": "Whether the bound Worker was deleted, leaving this Workflow inactive." + }, + { + "name": "script_name", + "type": "String" + }, + { + "name": "triggered_on", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_ai_controls_mcp_portal": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_ai_controls_mcp_portal", + "description": "Accepted Permissions\n\n- `MCP Portals Read`\n- `MCP Portals Write`", + "example": "data \"cloudflare_zero_trust_access_ai_controls_mcp_portal\" \"example_zero_trust_access_ai_controls_mcp_portal\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-portal\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "search", + "type": "String", + "description": "Search by id, name, hostname" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP portal." + } + ], + "computed": [ + { + "name": "allow_code_mode", + "type": "Boolean", + "description": "Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.", + "deprecated": "Deprecated." + }, + { + "name": "code_mode", + "type": "String", + "description": "Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400.\nAvailable values: \"off\", \"opt_in\", \"default_on\", \"enforced\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP portal." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname where the MCP portal is available." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP portal." + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound MCP traffic through Zero Trust Secure Web Gateway." + }, + { + "name": "servers", + "type": "Attributes Set", + "children": [ + { + "name": "auth_config_summary", + "type": "Attributes", + "description": "Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.", + "children": [ + { + "name": "auth_mode", + "type": "String", + "description": "Available values: \"dcr\", \"manual\"." + }, + { + "name": "client_secret_version", + "type": "Number" + }, + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "authorization_endpoint", + "type": "String" + }, + { + "name": "issuer", + "type": "String" + }, + { + "name": "resource", + "type": "String" + }, + { + "name": "revocation_endpoint", + "type": "String" + }, + { + "name": "token_endpoint", + "type": "String" + } + ] + }, + { + "name": "has_client_secret", + "type": "Boolean" + }, + { + "name": "registration_info", + "type": "Attributes", + "children": [ + { + "name": "client_id", + "type": "String" + }, + { + "name": "redirect_uris", + "type": "List of String" + }, + { + "name": "scope", + "type": "String" + }, + { + "name": "token_endpoint_auth_method", + "type": "String" + } + ] + } + ] + }, + { + "name": "auth_type", + "type": "String", + "description": "Authentication method used to connect to the upstream MCP server.\nAvailable values: \"oauth\", \"bearer\", \"unauthenticated\"." + }, + { + "name": "authentication_status", + "type": "String", + "description": "Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.\nAvailable values: \"not_required\", \"required\", \"connected\", \"stale\", \"manual\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "default_disabled", + "type": "Boolean", + "description": "Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated_tools or updated_prompts." + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP server." + }, + { + "name": "error", + "type": "String" + }, + { + "name": "error_details", + "type": "Attributes", + "children": [ + { + "name": "cause", + "type": "String", + "description": "Underlying error message" + }, + { + "name": "is_upstream", + "type": "Boolean", + "description": "True = MCP server returned an error. False = couldn't reach the server" + }, + { + "name": "mcp_code", + "type": "Number", + "description": "MCP protocol error code" + }, + { + "name": "retryable", + "type": "Boolean", + "description": "Whether the error is transient and worth retrying" + }, + { + "name": "status_code", + "type": "Number", + "description": "HTTP status code from the server" + } + ] + }, + { + "name": "hostname", + "type": "String", + "description": "URL of the upstream MCP endpoint." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP server." + }, + { + "name": "is_shared_oauth_callback_enabled", + "type": "Boolean", + "description": "When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. New public server creates default to true; existing servers default to false from migration until explicitly updated. Effective behavior is gated by the gateway worker's per-env rollout mode KV key." + }, + { + "name": "last_successful_sync", + "type": "String" + }, + { + "name": "last_synced", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP server." + }, + { + "name": "on_behalf", + "type": "Boolean" + }, + { + "name": "prompts", + "type": "List of Map of String" + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway." + }, + { + "name": "server_id", + "type": "String", + "description": "Unique identifier for the MCP server." + }, + { + "name": "status", + "type": "String", + "description": "Current sync state of the server\nAvailable values: \"waiting\", \"ready\", \"stale\", \"error\"." + }, + { + "name": "tools", + "type": "List of Map of String" + }, + { + "name": "updated_prompts", + "type": "Attributes List", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "portal_alias", + "type": "String" + }, + { + "name": "portal_description", + "type": "String" + }, + { + "name": "server_alias", + "type": "String" + }, + { + "name": "server_description", + "type": "String" + } + ] + }, + { + "name": "updated_tools", + "type": "Attributes List", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "portal_alias", + "type": "String" + }, + { + "name": "portal_description", + "type": "String" + }, + { + "name": "server_alias", + "type": "String" + }, + { + "name": "server_description", + "type": "String" + } + ] + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_access_ai_controls_mcp_portal": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_ai_controls_mcp_portal", + "description": "Accepted Permissions\n\n- `MCP Portals Read`\n- `MCP Portals Write`", + "example": "resource \"cloudflare_zero_trust_access_ai_controls_mcp_portal\" \"example_zero_trust_access_ai_controls_mcp_portal\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-portal\"\n hostname = \"example.com\"\n name = \"My MCP Portal\"\n allow_code_mode = true\n code_mode = \"opt_in\"\n description = \"This is my custom MCP Portal\"\n secure_web_gateway = false\n servers = [{\n server_id = \"my-mcp-server\"\n default_disabled = true\n on_behalf = true\n updated_prompts = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n updated_tools = [{\n name = \"name\"\n alias = \"my-custom-alias\"\n description = \"description\"\n enabled = true\n }]\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_ai_controls_mcp_portal.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname where the MCP portal is available." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP portal." + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP portal." + } + ], + "optional": [ + { + "name": "allow_code_mode", + "type": "Boolean", + "description": "Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.", + "deprecated": "Deprecated." + }, + { + "name": "code_mode", + "type": "String", + "description": "Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400.\nAvailable values: \"off\", \"opt_in\", \"default_on\", \"enforced\"." + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP portal." + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound MCP traffic through Zero Trust Secure Web Gateway." + }, + { + "name": "servers", + "type": "Attributes Set", + "description": "MCP servers attached to the portal and their portal-specific settings.", + "children": [ + { + "name": "default_disabled", + "type": "Boolean", + "description": "Disable this server by default for clients connecting through the portal." + }, + { + "name": "on_behalf", + "type": "Boolean", + "description": "Use end-user OAuth credentials when connecting this server to the portal." + }, + { + "name": "server_id", + "type": "String", + "description": "Unique identifier for the MCP server." + }, + { + "name": "updated_prompts", + "type": "Attributes List", + "description": "Portal-specific prompt overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + }, + { + "name": "updated_tools", + "type": "Attributes List", + "description": "Portal-specific tool overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_ai_controls_mcp_portals": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_ai_controls_mcp_portals", + "description": "Accepted Permissions\n\n- `MCP Portals Read`\n- `MCP Portals Write`", + "example": "data \"cloudflare_zero_trust_access_ai_controls_mcp_portals\" \"example_zero_trust_access_ai_controls_mcp_portals\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "search", + "type": "String", + "description": "Search by id, name, hostname" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allow_code_mode", + "type": "Boolean", + "description": "Deprecated: use `code_mode` for new integrations. `true` maps to any non-off Code Mode policy; `false` maps to `code_mode: off`. If both fields are sent, they must be consistent or the request returns a 400.", + "deprecated": "Deprecated." + }, + { + "name": "code_mode", + "type": "String", + "description": "Code Mode policy for this portal. `off`: Code Mode is unavailable; query parameters are ignored. `opt_in`: Code Mode is off by default; clients turn it on with `?codemode=search_and_execute`. `default_on`: Code Mode is on by default; clients can opt out with `?codemode=off`. `enforced`: Code Mode is always on; query parameters are ignored. Defaults to `opt_in` when omitted on create. If both `code_mode` and `allow_code_mode` are sent, they must be consistent or the request returns a 400.\nAvailable values: \"off\", \"opt_in\", \"default_on\", \"enforced\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP portal." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname where the MCP portal is available." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP portal." + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP portal." + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound MCP traffic through Zero Trust Secure Web Gateway." + }, + { + "name": "servers", + "type": "Attributes Set", + "children": [ + { + "name": "auth_config_summary", + "type": "Attributes", + "description": "Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.", + "children": [ + { + "name": "auth_mode", + "type": "String", + "description": "Available values: \"dcr\", \"manual\"." + }, + { + "name": "client_secret_version", + "type": "Number" + }, + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "authorization_endpoint", + "type": "String" + }, + { + "name": "issuer", + "type": "String" + }, + { + "name": "resource", + "type": "String" + }, + { + "name": "revocation_endpoint", + "type": "String" + }, + { + "name": "token_endpoint", + "type": "String" + } + ] + }, + { + "name": "has_client_secret", + "type": "Boolean" + }, + { + "name": "registration_info", + "type": "Attributes", + "children": [ + { + "name": "client_id", + "type": "String" + }, + { + "name": "redirect_uris", + "type": "List of String" + }, + { + "name": "scope", + "type": "String" + }, + { + "name": "token_endpoint_auth_method", + "type": "String" + } + ] + } + ] + }, + { + "name": "auth_type", + "type": "String", + "description": "Authentication method used to connect to the upstream MCP server.\nAvailable values: \"oauth\", \"bearer\", \"unauthenticated\"." + }, + { + "name": "authentication_status", + "type": "String", + "description": "Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.\nAvailable values: \"not_required\", \"required\", \"connected\", \"stale\", \"manual\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "default_disabled", + "type": "Boolean", + "description": "Hide this server's tools and prompts by default. To expose specific capabilities, set enabled: true for them in updated_tools or updated_prompts." + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP server." + }, + { + "name": "error", + "type": "String" + }, + { + "name": "error_details", + "type": "Attributes", + "children": [ + { + "name": "cause", + "type": "String", + "description": "Underlying error message" + }, + { + "name": "is_upstream", + "type": "Boolean", + "description": "True = MCP server returned an error. False = couldn't reach the server" + }, + { + "name": "mcp_code", + "type": "Number", + "description": "MCP protocol error code" + }, + { + "name": "retryable", + "type": "Boolean", + "description": "Whether the error is transient and worth retrying" + }, + { + "name": "status_code", + "type": "Number", + "description": "HTTP status code from the server" + } + ] + }, + { + "name": "hostname", + "type": "String", + "description": "URL of the upstream MCP endpoint." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP server." + }, + { + "name": "is_shared_oauth_callback_enabled", + "type": "Boolean", + "description": "When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. New public server creates default to true; existing servers default to false from migration until explicitly updated. Effective behavior is gated by the gateway worker's per-env rollout mode KV key." + }, + { + "name": "last_successful_sync", + "type": "String" + }, + { + "name": "last_synced", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP server." + }, + { + "name": "on_behalf", + "type": "Boolean" + }, + { + "name": "prompts", + "type": "List of Map of String" + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway." + }, + { + "name": "server_id", + "type": "String", + "description": "Unique identifier for the MCP server." + }, + { + "name": "status", + "type": "String", + "description": "Current sync state of the server\nAvailable values: \"waiting\", \"ready\", \"stale\", \"error\"." + }, + { + "name": "tools", + "type": "List of Map of String" + }, + { + "name": "updated_prompts", + "type": "Attributes List", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "portal_alias", + "type": "String" + }, + { + "name": "portal_description", + "type": "String" + }, + { + "name": "server_alias", + "type": "String" + }, + { + "name": "server_description", + "type": "String" + } + ] + }, + { + "name": "updated_tools", + "type": "Attributes List", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "portal_alias", + "type": "String" + }, + { + "name": "portal_description", + "type": "String" + }, + { + "name": "server_alias", + "type": "String" + }, + { + "name": "server_description", + "type": "String" + } + ] + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_ai_controls_mcp_server": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_ai_controls_mcp_server", + "description": "Accepted Permissions\n\n- `MCP Portals Read`\n- `MCP Portals Write`", + "example": "data \"cloudflare_zero_trust_access_ai_controls_mcp_server\" \"example_zero_trust_access_ai_controls_mcp_server\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n id = \"my-mcp-server\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "search", + "type": "String", + "description": "Search by id, name" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP server." + } + ], + "computed": [ + { + "name": "auth_config_summary", + "type": "Attributes", + "description": "Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.", + "children": [ + { + "name": "auth_mode", + "type": "String", + "description": "Available values: \"dcr\", \"manual\"." + }, + { + "name": "client_secret_version", + "type": "Number" + }, + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "authorization_endpoint", + "type": "String" + }, + { + "name": "issuer", + "type": "String" + }, + { + "name": "resource", + "type": "String" + }, + { + "name": "revocation_endpoint", + "type": "String" + }, + { + "name": "token_endpoint", + "type": "String" + } + ] + }, + { + "name": "has_client_secret", + "type": "Boolean" + }, + { + "name": "registration_info", + "type": "Attributes", + "children": [ + { + "name": "client_id", + "type": "String" + }, + { + "name": "redirect_uris", + "type": "List of String" + }, + { + "name": "scope", + "type": "String" + }, + { + "name": "token_endpoint_auth_method", + "type": "String" + } + ] + } + ] + }, + { + "name": "auth_type", + "type": "String", + "description": "Authentication method used to connect to the upstream MCP server.\nAvailable values: \"oauth\", \"bearer\", \"unauthenticated\"." + }, + { + "name": "authentication_status", + "type": "String", + "description": "Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.\nAvailable values: \"not_required\", \"required\", \"connected\", \"stale\", \"manual\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP server." + }, + { + "name": "error", + "type": "String" + }, + { + "name": "error_details", + "type": "Attributes", + "children": [ + { + "name": "cause", + "type": "String", + "description": "Underlying error message" + }, + { + "name": "is_upstream", + "type": "Boolean", + "description": "True = MCP server returned an error. False = couldn't reach the server" + }, + { + "name": "mcp_code", + "type": "Number", + "description": "MCP protocol error code" + }, + { + "name": "retryable", + "type": "Boolean", + "description": "Whether the error is transient and worth retrying" + }, + { + "name": "status_code", + "type": "Number", + "description": "HTTP status code from the server" + } + ] + }, + { + "name": "hostname", + "type": "String", + "description": "URL of the upstream MCP endpoint." + }, + { + "name": "is_shared_oauth_callback_enabled", + "type": "Boolean", + "description": "When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. New public server creates default to true; existing servers default to false from migration until explicitly updated. Effective behavior is gated by the gateway worker's per-env rollout mode KV key." + }, + { + "name": "last_successful_sync", + "type": "String" + }, + { + "name": "last_synced", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP server." + }, + { + "name": "prompts", + "type": "List of Map of String" + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway." + }, + { + "name": "status", + "type": "String", + "description": "Current sync state of the server\nAvailable values: \"waiting\", \"ready\", \"stale\", \"error\"." + }, + { + "name": "tools", + "type": "List of Map of String" + }, + { + "name": "updated_prompts", + "type": "Attributes List", + "description": "Server-wide prompt capability overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + }, + { + "name": "updated_tools", + "type": "Attributes List", + "description": "Server-wide tool capability overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_access_ai_controls_mcp_server": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_ai_controls_mcp_server", + "description": "Accepted Permissions\n\n- `MCP Portals Read`\n- `MCP Portals Write`", + "example": "resource \"cloudflare_zero_trust_access_ai_controls_mcp_server\" \"example_zero_trust_access_ai_controls_mcp_server\" {\n account_id = var.cloudflare_account_id\n id = \"github\"\n auth_type = \"oauth\"\n hostname = \"https://github-mcp.example.com/mcp\"\n name = \"GitHub MCP Server\"\n\n auth_credentials = jsonencode({\n auth_mode = \"manual\"\n config = {\n authorization_endpoint = \"https://github.com/login/oauth/authorize\"\n token_endpoint = \"https://github.com/login/oauth/access_token\"\n }\n registration_info = {\n client_id = var.mcp_oauth_client_id\n token_endpoint_auth_method = \"client_secret_basic\"\n scope = \"repo read:user\"\n }\n })\n client_secret = var.mcp_oauth_client_secret\n\n # This lets the API fill in Cloudflare's shared callback URL.\n is_shared_oauth_callback_enabled = true\n}\n\nvariable \"cloudflare_account_id\" {\n type = string\n}\n\nvariable \"mcp_oauth_client_id\" {\n type = string\n}\n\nvariable \"mcp_oauth_client_secret\" {\n type = string\n sensitive = true\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_ai_controls_mcp_server.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "auth_type", + "type": "String", + "description": "Authentication method used to connect to the upstream MCP server.\nAvailable values: \"oauth\", \"bearer\", \"unauthenticated\"." + }, + { + "name": "hostname", + "type": "String", + "description": "URL of the upstream MCP endpoint." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP server." + } + ], + "optional": [ + { + "name": "auth_credentials", + "type": "String", + "description": "Static credential for the upstream MCP server. For auth_type \"bearer\", either a raw token string (e.g. \"sk-abc123\"), which is wrapped server-side as `Authorization: Bearer `, or a JSON-encoded object of the form `{\"headers\":{\"Header-Name\":\"value\",...}}` for custom or multiple static headers (e.g. Cloudflare Access service tokens: `{\"headers\":{\"cf-access-client-id\":\"...\",\"cf-access-client-secret\":\"...\"}}`).", + "sensitive": true + }, + { + "name": "client_secret", + "type": "String", + "description": "Pre-registered OAuth client_secret. Write-only - accepted on create/update when auth_credentials.auth_mode is 'manual'. Stored AES-GCM-encrypted in server_oauth_secrets; never returned by read endpoints.", + "sensitive": true + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP server." + }, + { + "name": "is_shared_oauth_callback_enabled", + "type": "Boolean", + "description": "When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. Defaults to false (off); opt in per server by setting true." + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway." + }, + { + "name": "updated_prompts", + "type": "Attributes List", + "description": "Server-wide prompt capability overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + }, + { + "name": "updated_tools", + "type": "Attributes List", + "description": "Server-wide tool capability overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + } + ], + "computed": [ + { + "name": "auth_config_summary", + "type": "Attributes", + "description": "Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.", + "children": [ + { + "name": "auth_mode", + "type": "String", + "description": "Available values: \"dcr\", \"manual\"." + }, + { + "name": "client_secret_version", + "type": "Number" + }, + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "authorization_endpoint", + "type": "String" + }, + { + "name": "issuer", + "type": "String" + }, + { + "name": "resource", + "type": "String" + }, + { + "name": "revocation_endpoint", + "type": "String" + }, + { + "name": "token_endpoint", + "type": "String" + } + ] + }, + { + "name": "has_client_secret", + "type": "Boolean" + }, + { + "name": "registration_info", + "type": "Attributes", + "children": [ + { + "name": "client_id", + "type": "String" + }, + { + "name": "redirect_uris", + "type": "List of String" + }, + { + "name": "scope", + "type": "String" + }, + { + "name": "token_endpoint_auth_method", + "type": "String" + } + ] + } + ] + }, + { + "name": "authentication_status", + "type": "String", + "description": "Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.\nAvailable values: \"not_required\", \"required\", \"connected\", \"stale\", \"manual\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "error", + "type": "String" + }, + { + "name": "error_details", + "type": "Attributes", + "children": [ + { + "name": "cause", + "type": "String", + "description": "Underlying error message" + }, + { + "name": "is_upstream", + "type": "Boolean", + "description": "True = MCP server returned an error. False = couldn't reach the server" + }, + { + "name": "mcp_code", + "type": "Number", + "description": "MCP protocol error code" + }, + { + "name": "retryable", + "type": "Boolean", + "description": "Whether the error is transient and worth retrying" + }, + { + "name": "status_code", + "type": "Number", + "description": "HTTP status code from the server" + } + ] + }, + { + "name": "last_successful_sync", + "type": "String" + }, + { + "name": "last_synced", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "prompts", + "type": "List of Map of String" + }, + { + "name": "status", + "type": "String" + }, + { + "name": "tools", + "type": "List of Map of String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_ai_controls_mcp_servers": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_ai_controls_mcp_servers", + "description": "Accepted Permissions\n\n- `MCP Portals Read`\n- `MCP Portals Write`", + "example": "data \"cloudflare_zero_trust_access_ai_controls_mcp_servers\" \"example_zero_trust_access_ai_controls_mcp_servers\" {\n account_id = \"a86a8f5c339544d7bdc89926de14fb8c\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "search", + "type": "String", + "description": "Search by id, name" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "auth_config_summary", + "type": "Attributes", + "description": "Safe subset of auth_credentials surfaced to the dashboard. Includes auth_mode (dcr|manual), has_client_secret, client_secret_version, and the OAuth endpoints + client_id for manual servers. Never includes the secret value.", + "children": [ + { + "name": "auth_mode", + "type": "String", + "description": "Available values: \"dcr\", \"manual\"." + }, + { + "name": "client_secret_version", + "type": "Number" + }, + { + "name": "config", + "type": "Attributes", + "children": [ + { + "name": "authorization_endpoint", + "type": "String" + }, + { + "name": "issuer", + "type": "String" + }, + { + "name": "resource", + "type": "String" + }, + { + "name": "revocation_endpoint", + "type": "String" + }, + { + "name": "token_endpoint", + "type": "String" + } + ] + }, + { + "name": "has_client_secret", + "type": "Boolean" + }, + { + "name": "registration_info", + "type": "Attributes", + "children": [ + { + "name": "client_id", + "type": "String" + }, + { + "name": "redirect_uris", + "type": "List of String" + }, + { + "name": "scope", + "type": "String" + }, + { + "name": "token_endpoint_auth_method", + "type": "String" + } + ] + } + ] + }, + { + "name": "auth_type", + "type": "String", + "description": "Authentication method used to connect to the upstream MCP server.\nAvailable values: \"oauth\", \"bearer\", \"unauthenticated\"." + }, + { + "name": "authentication_status", + "type": "String", + "description": "Whether administrative authentication is required before capabilities can be synced. Manual OAuth is user-managed and has no administrative authentication flow.\nAvailable values: \"not_required\", \"required\", \"connected\", \"stale\", \"manual\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "created_by", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Optional description of the MCP server." + }, + { + "name": "error", + "type": "String" + }, + { + "name": "error_details", + "type": "Attributes", + "children": [ + { + "name": "cause", + "type": "String", + "description": "Underlying error message" + }, + { + "name": "is_upstream", + "type": "Boolean", + "description": "True = MCP server returned an error. False = couldn't reach the server" + }, + { + "name": "mcp_code", + "type": "Number", + "description": "MCP protocol error code" + }, + { + "name": "retryable", + "type": "Boolean", + "description": "Whether the error is transient and worth retrying" + }, + { + "name": "status_code", + "type": "Number", + "description": "HTTP status code from the server" + } + ] + }, + { + "name": "hostname", + "type": "String", + "description": "URL of the upstream MCP endpoint." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the MCP server." + }, + { + "name": "is_shared_oauth_callback_enabled", + "type": "Boolean", + "description": "When true, the gateway worker uses the shared Cloudflare-owned OAuth callback endpoint as the redirect_uri for upstream on-behalf OAuth, instead of the customer portal hostname. New public server creates default to true; existing servers default to false from migration until explicitly updated. Effective behavior is gated by the gateway worker's per-env rollout mode KV key." + }, + { + "name": "last_successful_sync", + "type": "String" + }, + { + "name": "last_synced", + "type": "String" + }, + { + "name": "modified_at", + "type": "String" + }, + { + "name": "modified_by", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Display name for the MCP server." + }, + { + "name": "prompts", + "type": "List of Map of String" + }, + { + "name": "secure_web_gateway", + "type": "Boolean", + "description": "Route outbound traffic to this MCP server through Zero Trust Secure Web Gateway." + }, + { + "name": "status", + "type": "String", + "description": "Current sync state of the server\nAvailable values: \"waiting\", \"ready\", \"stale\", \"error\"." + }, + { + "name": "tools", + "type": "List of Map of String" + }, + { + "name": "updated_prompts", + "type": "Attributes List", + "description": "Server-wide prompt capability overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + }, + { + "name": "updated_tools", + "type": "Attributes List", + "description": "Server-wide tool capability overrides.", + "children": [ + { + "name": "alias", + "type": "String", + "description": "Custom name exposed for the capability." + }, + { + "name": "description", + "type": "String", + "description": "Custom description exposed for the capability." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the capability is available through the MCP server." + }, + { + "name": "name", + "type": "String", + "description": "Name of the tool or prompt capability to override." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_application": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_application", + "example": "data \"cloudflare_zero_trust_access_application\" \"example_zero_trust_access_application\" {\n app_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "app_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "aud", + "type": "String", + "description": "The aud of the app." + }, + { + "name": "domain", + "type": "String", + "description": "The domain of the app." + }, + { + "name": "exact", + "type": "Boolean", + "description": "True for only exact string matches against passed name/domain query parameters." + }, + { + "name": "name", + "type": "String", + "description": "The name of the app." + }, + { + "name": "search", + "type": "String", + "description": "Search for apps by other listed query parameters." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "allow_authenticate_via_warp", + "type": "Boolean", + "description": "When set to true, users can authenticate to this application using their WARP session. When set to false this application will always require direct IdP authentication. This setting always overrides the organization setting for WARP authentication." + }, + { + "name": "allow_iframe", + "type": "Boolean", + "description": "Enables loading application content in an iFrame." + }, + { + "name": "allowed_idps", + "type": "List of String", + "description": "The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account." + }, + { + "name": "app_launcher_logo_url", + "type": "String", + "description": "The image URL of the logo shown in the App Launcher header." + }, + { + "name": "app_launcher_visible", + "type": "Boolean", + "description": "Displays the application in the App Launcher." + }, + { + "name": "aud", + "type": "String", + "description": "Audience tag." + }, + { + "name": "auto_redirect_to_identity", + "type": "Boolean", + "description": "When set to `true`, users skip the identity provider selection step during login. You must specify only one identity provider in allowed_idps." + }, + { + "name": "bg_color", + "type": "String", + "description": "The background color of the App Launcher page." + }, + { + "name": "cors_headers", + "type": "Attributes", + "children": [ + { + "name": "allow_all_headers", + "type": "Boolean", + "description": "Allows all HTTP request headers." + }, + { + "name": "allow_all_methods", + "type": "Boolean", + "description": "Allows all HTTP request methods." + }, + { + "name": "allow_all_origins", + "type": "Boolean", + "description": "Allows all origins." + }, + { + "name": "allow_credentials", + "type": "Boolean", + "description": "When set to `true`, includes credentials (cookies, authorization headers, or TLS client certificates) with requests." + }, + { + "name": "allowed_headers", + "type": "List of String", + "description": "Allowed HTTP request headers." + }, + { + "name": "allowed_methods", + "type": "List of String", + "description": "Allowed HTTP request methods." + }, + { + "name": "allowed_origins", + "type": "List of String", + "description": "Allowed origins." + }, + { + "name": "max_age", + "type": "Number", + "description": "The maximum number of seconds the results of a preflight request can be cached." + } + ] + }, + { + "name": "custom_deny_message", + "type": "String", + "description": "The custom error message shown to a user when they are denied access to the application." + }, + { + "name": "custom_deny_url", + "type": "String", + "description": "The custom URL a user is redirected to when they are denied access to the application when failing identity-based rules." + }, + { + "name": "custom_non_identity_deny_url", + "type": "String", + "description": "The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules." + }, + { + "name": "custom_pages", + "type": "List of String", + "description": "The custom pages that will be displayed when applicable for this application" + }, + { + "name": "destinations", + "type": "Attributes List", + "description": "List of destinations secured by Access. This supersedes `self_hosted_domains` to allow for more flexibility in defining different types of domains. If `destinations` are provided, then `self_hosted_domains` will be ignored.", + "children": [ + { + "name": "cidr", + "type": "String", + "description": "The CIDR range of the destination. Single IPs will be computed as /32." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname of the destination. Matches a valid SNI served by an HTTPS origin." + }, + { + "name": "l4_protocol", + "type": "String", + "description": "The L4 protocol of the destination. When omitted, both UDP and TCP traffic will match.\nAvailable values: \"tcp\", \"udp\"." + }, + { + "name": "mcp_server_id", + "type": "String", + "description": "A MCP server id configured in ai-controls. Access will secure the MCP server if accessed through a MCP portal." + }, + { + "name": "port_range", + "type": "String", + "description": "The port range of the destination. Can be a single port or a range of ports. When omitted, all ports will match." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"public\", \"private\", \"via_mcp_server_portal\", \"worker\", \"preview_worker\", \"all_workers\", \"all_preview_workers\"." + }, + { + "name": "uri", + "type": "String", + "description": "The URI of the destination. Public destinations' URIs can include a domain and path with [wildcards](https://developers.cloudflare.com/cloudflare-one/policies/access/app-paths/)." + }, + { + "name": "vnet_id", + "type": "String", + "description": "The VNET ID to match the destination. When omitted, all VNETs will match." + }, + { + "name": "worker_id", + "type": "String", + "description": "The ID of the Cloudflare Worker to protect with Access. Required when type is `worker` or `preview_worker`." + } + ] + }, + { + "name": "domain", + "type": "String", + "description": "The primary hostname and path secured by Access. This domain will be displayed if the app is visible in the App Launcher." + }, + { + "name": "enable_binding_cookie", + "type": "Boolean", + "description": "Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks." + }, + { + "name": "footer_links", + "type": "Attributes List", + "description": "The links in the App Launcher footer.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The hypertext in the footer link." + }, + { + "name": "url", + "type": "String", + "description": "the hyperlink in the footer link." + } + ] + }, + { + "name": "header_bg_color", + "type": "String", + "description": "The background color of the App Launcher header." + }, + { + "name": "http_only_cookie_attribute", + "type": "Boolean", + "description": "Enables the HttpOnly cookie attribute, which increases security against XSS attacks." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "landing_page_design", + "type": "Attributes", + "description": "The design of the App Launcher landing page shown to users when they log in.", + "children": [ + { + "name": "button_color", + "type": "String", + "description": "The background color of the log in button on the landing page." + }, + { + "name": "button_text_color", + "type": "String", + "description": "The color of the text in the log in button on the landing page." + }, + { + "name": "image_url", + "type": "String", + "description": "The URL of the image shown on the landing page." + }, + { + "name": "message", + "type": "String", + "description": "The message shown on the landing page." + }, + { + "name": "title", + "type": "String", + "description": "The title shown on the landing page." + } + ] + }, + { + "name": "logo_url", + "type": "String", + "description": "The image URL for the logo shown in the App Launcher dashboard." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for the application. Only valid for self_hosted, ssh, vnc, and rdp application types.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "The authenticators allowed for MFA.\nAvailable values: \"totp\", \"biometrics\", \"security_key\"." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Whether MFA is disabled for this application." + }, + { + "name": "session_duration", + "type": "String", + "description": "How often a user will be forced to re-authenticate with MFA." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the application." + }, + { + "name": "options_preflight_bypass", + "type": "Boolean", + "description": "Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors_headers is set." + }, + { + "name": "path_cookie_attribute", + "type": "Boolean", + "description": "Enables cookie paths to scope an application's JWT to the application path. If disabled, the JWT will scope to the hostname by default" + }, + { + "name": "policies", + "type": "Attributes List", + "children": [ + { + "name": "approval_groups", + "type": "Attributes Set", + "description": "Administrators who can approve a temporary authentication request.", + "children": [ + { + "name": "approvals_needed", + "type": "Number", + "description": "The number of approvals needed to obtain access." + }, + { + "name": "email_addresses", + "type": "List of String", + "description": "A list of emails that can approve the access request." + }, + { + "name": "email_list_uuid", + "type": "String", + "description": "The UUID of an re-usable email list." + } + ] + }, + { + "name": "approval_required", + "type": "Boolean", + "description": "Requires the user to request access from an administrator at the start of each session." + }, + { + "name": "connection_rules", + "type": "Attributes", + "description": "The rules that define how users may connect to the targets secured by your application.", + "children": [ + { + "name": "ssh", + "type": "Attributes", + "description": "The SSH-specific rules that define how users may connect to the targets secured by your application.", + "children": [ + { + "name": "allow_email_alias", + "type": "Boolean", + "description": "Enables using Identity Provider email alias as SSH username." + }, + { + "name": "usernames", + "type": "List of String", + "description": "Contains the Unix usernames that may be used when connecting over SSH." + } + ] + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "decision", + "type": "String", + "description": "The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.\nAvailable values: \"allow\", \"deny\", \"non_identity\", \"bypass\"." + }, + { + "name": "exclude", + "type": "Attributes Set", + "description": "Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the policy" + }, + { + "name": "include", + "type": "Attributes Set", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "isolation_required", + "type": "Boolean", + "description": "Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for this policy.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "The authenticators allowed for MFA.\nAvailable values: \"totp\", \"biometrics\", \"security_key\", \"ssh_piv_key\"." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Whether MFA is disabled for this policy." + }, + { + "name": "session_duration", + "type": "String", + "description": "How often a user will be forced to re-authenticate with MFA." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access policy." + }, + { + "name": "precedence", + "type": "Number", + "description": "The order of execution for this policy. Must be unique for each policy within an app." + }, + { + "name": "purpose_justification_prompt", + "type": "String", + "description": "A custom message that will appear on the purpose justification screen." + }, + { + "name": "purpose_justification_required", + "type": "Boolean", + "description": "Require users to enter a justification when they log in to the application." + }, + { + "name": "require", + "type": "Attributes Set", + "description": "Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "read_service_tokens_from_header", + "type": "String", + "description": "Allows matching Access Service Tokens passed HTTP in a single header with this name.\nThis works as an alternative to the (CF-Access-Client-Id, CF-Access-Client-Secret) pair of headers.\nThe header value will be interpreted as a json object similar to: \n {\n \"cf-access-client-id\": \"88bf3b6d86161464f6509f7219099e57.access.example.com\",\n \"cf-access-client-secret\": \"bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5\"\n }" + }, + { + "name": "saas_app", + "type": "Attributes", + "children": [ + { + "name": "access_token_lifetime", + "type": "String", + "description": "The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h." + }, + { + "name": "allow_pkce_without_client_secret", + "type": "Boolean", + "description": "If client secret should be required on the token endpoint when authorization_code_with_pkce grant is used." + }, + { + "name": "app_launcher_url", + "type": "String", + "description": "The URL where this applications tile redirects users" + }, + { + "name": "auth_type", + "type": "String", + "description": "Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is \"saml\"\nAvailable values: \"saml\", \"oidc\"." + }, + { + "name": "client_id", + "type": "String", + "description": "The application client id" + }, + { + "name": "client_secret", + "type": "String", + "description": "The application client secret, only returned on POST request.", + "sensitive": true + }, + { + "name": "consumer_service_url", + "type": "String", + "description": "The service provider's endpoint that is responsible for receiving and parsing a SAML assertion." + }, + { + "name": "custom_attributes", + "type": "Attributes List", + "children": [ + { + "name": "friendly_name", + "type": "String", + "description": "The SAML FriendlyName of the attribute." + }, + { + "name": "name", + "type": "String", + "description": "The name of the attribute." + }, + { + "name": "name_format", + "type": "String", + "description": "A globally unique name for an identity or service provider.\nAvailable values: \"urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified\", \"urn:oasis:names:tc:SAML:2.0:attrname-format:basic\", \"urn:oasis:names:tc:SAML:2.0:attrname-format:uri\"." + }, + { + "name": "required", + "type": "Boolean", + "description": "If the attribute is required when building a SAML assertion." + }, + { + "name": "source", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the IdP attribute." + }, + { + "name": "name_by_idp", + "type": "Attributes List", + "description": "A mapping from IdP ID to attribute name.", + "children": [ + { + "name": "idp_id", + "type": "String", + "description": "The UID of the IdP." + }, + { + "name": "source_name", + "type": "String", + "description": "The name of the IdP provided attribute." + } + ] + } + ] + } + ] + }, + { + "name": "custom_claims", + "type": "Attributes List", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the claim." + }, + { + "name": "required", + "type": "Boolean", + "description": "If the claim is required when building an OIDC token." + }, + { + "name": "scope", + "type": "String", + "description": "The scope of the claim.\nAvailable values: \"groups\", \"profile\", \"email\", \"openid\"." + }, + { + "name": "source", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the IdP claim." + }, + { + "name": "name_by_idp", + "type": "Map of String", + "description": "A mapping from IdP ID to claim name." + } + ] + } + ] + }, + { + "name": "default_relay_state", + "type": "String", + "description": "The URL that the user will be redirected to after a successful login for IDP initiated logins." + }, + { + "name": "grant_types", + "type": "List of String", + "description": "The OIDC flows supported by this application" + }, + { + "name": "group_filter_regex", + "type": "String", + "description": "A regex to filter Cloudflare groups returned in ID token and userinfo endpoint" + }, + { + "name": "hybrid_and_implicit_options", + "type": "Attributes", + "children": [ + { + "name": "return_access_token_from_authorization_endpoint", + "type": "Boolean", + "description": "If an Access Token should be returned from the OIDC Authorization endpoint" + }, + { + "name": "return_id_token_from_authorization_endpoint", + "type": "Boolean", + "description": "If an ID Token should be returned from the OIDC Authorization endpoint" + } + ] + }, + { + "name": "idp_entity_id", + "type": "String", + "description": "The unique identifier for your SaaS application." + }, + { + "name": "name_id_format", + "type": "String", + "description": "The format of the name identifier sent to the SaaS application.\nAvailable values: \"id\", \"email\"." + }, + { + "name": "name_id_transform_jsonata", + "type": "String", + "description": "A [JSONata](https://jsonata.org/) expression that transforms an application's user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the `name_id_format` setting." + }, + { + "name": "public_key", + "type": "String", + "description": "The Access public certificate that will be used to verify your identity." + }, + { + "name": "redirect_uris", + "type": "List of String", + "description": "The permitted URL's for Cloudflare to return Authorization codes and Access/ID tokens" + }, + { + "name": "refresh_token_options", + "type": "Attributes", + "children": [ + { + "name": "lifetime", + "type": "String", + "description": "How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m." + } + ] + }, + { + "name": "saml_attribute_transform_jsonata", + "type": "String", + "description": "A [JSONata] (https://jsonata.org/) expression that transforms an application's user identities into attribute assertions in the SAML response. The expression can transform id, email, name, and groups values. It can also transform fields listed in the saml_attributes or oidc_fields of the identity provider used to authenticate. The output of this expression must be a JSON object." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Define the user information shared with access, \"offline_access\" scope will be automatically enabled if refresh tokens are enabled" + }, + { + "name": "sp_entity_id", + "type": "String", + "description": "A globally unique name for an identity or service provider." + }, + { + "name": "sso_endpoint", + "type": "String", + "description": "The endpoint where your SaaS application will send login requests." + } + ] + }, + { + "name": "same_site_cookie_attribute", + "type": "String", + "description": "Sets the SameSite cookie setting, which provides increased security against CSRF attacks." + }, + { + "name": "scim_config", + "type": "Attributes", + "description": "Configuration for provisioning to this application via SCIM. This is currently in closed beta.", + "children": [ + { + "name": "authentication", + "type": "Attributes", + "description": "Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.", + "children": [ + { + "name": "authorization_url", + "type": "String", + "description": "URL used to generate the auth code used during token generation." + }, + { + "name": "client_id", + "type": "String", + "description": "Client ID used to authenticate when generating a token for authenticating with the remote SCIM service." + }, + { + "name": "client_secret", + "type": "String", + "description": "Secret used to authenticate when generating a token for authenticating with the remove SCIM service.", + "sensitive": true + }, + { + "name": "password", + "type": "String", + "description": "Password used to authenticate with the remote SCIM service." + }, + { + "name": "scheme", + "type": "String", + "description": "The authentication scheme to use when making SCIM requests to this application.\nAvailable values: \"httpbasic\", \"oauthbearertoken\", \"oauth2\", \"access_service_token\"." + }, + { + "name": "scopes", + "type": "List of String", + "description": "The authorization scopes to request when generating the token used to authenticate with the remove SCIM service." + }, + { + "name": "token", + "type": "String", + "description": "Token used to authenticate with the remote SCIM service.", + "sensitive": true + }, + { + "name": "token_url", + "type": "String", + "description": "URL used to generate the token used to authenticate with the remote SCIM service." + }, + { + "name": "user", + "type": "String", + "description": "User name used to authenticate with the remote SCIM service." + } + ] + }, + { + "name": "deactivate_on_delete", + "type": "Boolean", + "description": "If false, propagates DELETE requests to the target application for SCIM resources. If true, sets 'active' to false on the SCIM resource. Note: Some targets do not support DELETE operations." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether SCIM provisioning is turned on for this application." + }, + { + "name": "idp_uid", + "type": "String", + "description": "The UID of the IdP to use as the source for SCIM resources to provision to this application." + }, + { + "name": "mappings", + "type": "Attributes List", + "description": "A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not this mapping is enabled." + }, + { + "name": "filter", + "type": "String", + "description": "A [SCIM filter expression](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2) that matches resources that should be provisioned to this application." + }, + { + "name": "operations", + "type": "Attributes", + "description": "Whether or not this mapping applies to creates, updates, or deletes.", + "children": [ + { + "name": "create", + "type": "Boolean", + "description": "Whether or not this mapping applies to create (POST) operations." + }, + { + "name": "delete", + "type": "Boolean", + "description": "Whether or not this mapping applies to DELETE operations." + }, + { + "name": "update", + "type": "Boolean", + "description": "Whether or not this mapping applies to update (PATCH/PUT) operations." + } + ] + }, + { + "name": "schema", + "type": "String", + "description": "Which SCIM resource type this mapping applies to." + }, + { + "name": "strictness", + "type": "String", + "description": "The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.\nAvailable values: \"strict\", \"passthrough\"." + }, + { + "name": "transform_jsonata", + "type": "String", + "description": "A [JSONata](https://jsonata.org/) expression that transforms the resource before provisioning it in the application." + } + ] + }, + { + "name": "remote_uri", + "type": "String", + "description": "The base URI for the application's SCIM-compatible API." + } + ] + }, + { + "name": "self_hosted_domains", + "type": "List of String", + "description": "List of public domains that Access will secure. This field is deprecated in favor of `destinations` and will be supported until **November 21, 2025.** If `destinations` are provided, then `self_hosted_domains` will be ignored.", + "deprecated": "Deprecated." + }, + { + "name": "service_auth_401_redirect", + "type": "Boolean", + "description": "Returns a 401 status code when the request is blocked by a Service Auth policy." + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for this application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h. Note: unsupported for infrastructure type applications." + }, + { + "name": "skip_app_launcher_login_page", + "type": "Boolean", + "description": "Determines when to skip the App Launcher landing page." + }, + { + "name": "skip_interstitial", + "type": "Boolean", + "description": "Enables automatic authentication through cloudflared." + }, + { + "name": "tags", + "type": "Set of String", + "description": "The tags you want assigned to an application. Tags are used to filter applications in the App Launcher dashboard." + }, + { + "name": "target_criteria", + "type": "Attributes List", + "children": [ + { + "name": "port", + "type": "Number", + "description": "The port that the targets use for the chosen communication protocol. A port cannot be assigned to multiple protocols." + }, + { + "name": "protocol", + "type": "String", + "description": "The communication protocol your application secures.\nAvailable values: \"SSH\", \"RDP\"." + }, + { + "name": "target_attributes", + "type": "Map of List of String", + "description": "Contains a map of target attribute keys to target attribute values." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The application type.\nAvailable values: \"self_hosted\", \"saas\", \"ssh\", \"vnc\", \"app_launcher\", \"warp\", \"biso\", \"bookmark\", \"dash_sso\", \"infrastructure\", \"rdp\", \"mcp\", \"mcp_portal\"." + } + ] + }, + "resource:cloudflare_zero_trust_access_application": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_application", + "example": "resource \"cloudflare_zero_trust_access_application\" \"example_zero_trust_access_application\" {\n domain = \"test.example.com/admin\"\n type = \"self_hosted\"\n zone_id = \"zone_id\"\n allow_authenticate_via_warp = true\n allow_iframe = true\n allowed_idps = [\"699d98642c564d2e855e9661899b7252\"]\n app_launcher_visible = true\n auto_redirect_to_identity = true\n cors_headers = {\n allow_all_headers = true\n allow_all_methods = true\n allow_all_origins = true\n allow_credentials = true\n allowed_headers = [\"string\"]\n allowed_methods = [\"GET\"]\n allowed_origins = [\"https://example.com\"]\n max_age = -1\n }\n custom_deny_message = \"custom_deny_message\"\n custom_deny_url = \"custom_deny_url\"\n custom_non_identity_deny_url = \"custom_non_identity_deny_url\"\n custom_pages = [\"699d98642c564d2e855e9661899b7252\"]\n destinations = [{\n type = \"public\"\n uri = \"test.example.com/admin\"\n }, {\n type = \"public\"\n uri = \"test.anotherexample.com/staff\"\n }, {\n cidr = \"10.5.0.0/24\"\n hostname = \"hostname\"\n l4_protocol = \"tcp\"\n port_range = \"80-90\"\n type = \"private\"\n vnet_id = \"vnet_id\"\n }, {\n cidr = \"10.5.0.3/32\"\n hostname = \"hostname\"\n l4_protocol = \"tcp\"\n port_range = \"80\"\n type = \"private\"\n vnet_id = \"vnet_id\"\n }, {\n cidr = \"cidr\"\n hostname = \"hostname\"\n l4_protocol = \"tcp\"\n port_range = \"port_range\"\n type = \"private\"\n vnet_id = \"vnet_id\"\n }]\n enable_binding_cookie = true\n http_only_cookie_attribute = true\n logo_url = \"https://www.cloudflare.com/img/logo-web-badges/cf-logo-on-white-bg.svg\"\n name = \"Admin Site\"\n options_preflight_bypass = true\n path_cookie_attribute = true\n policies = [{\n id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n precedence = 0\n }]\n read_service_tokens_from_header = \"Authorization\"\n same_site_cookie_attribute = \"strict\"\n scim_config = {\n idp_uid = \"idp_uid\"\n remote_uri = \"remote_uri\"\n authentication = {\n password = \"password\"\n scheme = \"httpbasic\"\n user = \"user\"\n }\n deactivate_on_delete = true\n enabled = true\n mappings = [{\n schema = \"urn:ietf:params:scim:schemas:core:2.0:User\"\n enabled = true\n filter = \"title pr or userType eq \\\"Intern\\\"\"\n operations = {\n create = true\n delete = true\n update = true\n }\n strictness = \"strict\"\n transform_jsonata = \"$merge([$, {\\'userName\\': $substringBefore($.userName, \\'@\\') & \\'+test@\\' & $substringAfter($.userName, \\'@\\')}])\"\n }]\n }\n self_hosted_domains = [\"test.example.com/admin\", \"test.anotherexample.com/staff\"]\n service_auth_401_redirect = true\n session_duration = \"24h\"\n skip_interstitial = true\n tags = [\"engineers\"]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_application.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "allow_authenticate_via_warp", + "type": "Boolean", + "description": "When set to true, users can authenticate to this application using their WARP session. When set to false this application will always require direct IdP authentication. This setting always overrides the organization setting for WARP authentication." + }, + { + "name": "allow_iframe", + "type": "Boolean", + "description": "Enables loading application content in an iFrame." + }, + { + "name": "allowed_idps", + "type": "Set of String", + "description": "The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account." + }, + { + "name": "app_launcher_logo_url", + "type": "String", + "description": "The image URL of the logo shown in the App Launcher header." + }, + { + "name": "app_launcher_visible", + "type": "Boolean", + "description": "Displays the application in the App Launcher." + }, + { + "name": "auto_redirect_to_identity", + "type": "Boolean", + "description": "When set to `true`, users skip the identity provider selection step during login. You must specify only one identity provider in allowed_idps." + }, + { + "name": "bg_color", + "type": "String", + "description": "The background color of the App Launcher page." + }, + { + "name": "cors_headers", + "type": "Attributes", + "children": [ + { + "name": "allow_all_headers", + "type": "Boolean", + "description": "Allows all HTTP request headers." + }, + { + "name": "allow_all_methods", + "type": "Boolean", + "description": "Allows all HTTP request methods." + }, + { + "name": "allow_all_origins", + "type": "Boolean", + "description": "Allows all origins." + }, + { + "name": "allow_credentials", + "type": "Boolean", + "description": "When set to `true`, includes credentials (cookies, authorization headers, or TLS client certificates) with requests." + }, + { + "name": "allowed_headers", + "type": "Set of String", + "description": "Allowed HTTP request headers." + }, + { + "name": "allowed_methods", + "type": "Set of String", + "description": "Allowed HTTP request methods." + }, + { + "name": "allowed_origins", + "type": "Set of String", + "description": "Allowed origins." + }, + { + "name": "max_age", + "type": "Number", + "description": "The maximum number of seconds the results of a preflight request can be cached." + } + ] + }, + { + "name": "custom_deny_message", + "type": "String", + "description": "The custom error message shown to a user when they are denied access to the application." + }, + { + "name": "custom_deny_url", + "type": "String", + "description": "The custom URL a user is redirected to when they are denied access to the application when failing identity-based rules." + }, + { + "name": "custom_non_identity_deny_url", + "type": "String", + "description": "The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules." + }, + { + "name": "custom_pages", + "type": "List of String", + "description": "The custom pages that will be displayed when applicable for this application" + }, + { + "name": "destinations", + "type": "Attributes List", + "description": "List of destinations secured by Access. This supersedes `self_hosted_domains` to allow for more flexibility in defining different types of domains. If `destinations` are provided, then `self_hosted_domains` will be ignored.", + "children": [ + { + "name": "cidr", + "type": "String", + "description": "The CIDR range of the destination. Single IPs will be computed as /32." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname of the destination. Matches a valid SNI served by an HTTPS origin." + }, + { + "name": "l4_protocol", + "type": "String", + "description": "The L4 protocol of the destination. When omitted, both UDP and TCP traffic will match.\nAvailable values: \"tcp\", \"udp\"." + }, + { + "name": "mcp_server_id", + "type": "String", + "description": "A MCP server id configured in ai-controls. Access will secure the MCP server if accessed through a MCP portal." + }, + { + "name": "port_range", + "type": "String", + "description": "The port range of the destination. Can be a single port or a range of ports. When omitted, all ports will match." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"public\", \"private\", \"via_mcp_server_portal\", \"worker\", \"preview_worker\", \"all_workers\", \"all_preview_workers\"." + }, + { + "name": "uri", + "type": "String", + "description": "The URI of the destination. Public destinations' URIs can include a domain and path with [wildcards](https://developers.cloudflare.com/cloudflare-one/policies/access/app-paths/)." + }, + { + "name": "vnet_id", + "type": "String", + "description": "The VNET ID to match the destination. When omitted, all VNETs will match." + }, + { + "name": "worker_id", + "type": "String", + "description": "The ID of the Cloudflare Worker to protect with Access. Required when type is `worker` or `preview_worker`." + } + ] + }, + { + "name": "domain", + "type": "String", + "description": "The primary hostname and path secured by Access. This domain will be displayed if the app is visible in the App Launcher." + }, + { + "name": "enable_binding_cookie", + "type": "Boolean", + "description": "Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks." + }, + { + "name": "footer_links", + "type": "Attributes List", + "description": "The links in the App Launcher footer.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The hypertext in the footer link." + }, + { + "name": "url", + "type": "String", + "description": "the hyperlink in the footer link." + } + ] + }, + { + "name": "header_bg_color", + "type": "String", + "description": "The background color of the App Launcher header." + }, + { + "name": "http_only_cookie_attribute", + "type": "Boolean", + "description": "Enables the HttpOnly cookie attribute, which increases security against XSS attacks." + }, + { + "name": "landing_page_design", + "type": "Attributes", + "description": "The design of the App Launcher landing page shown to users when they log in.", + "children": [ + { + "name": "button_color", + "type": "String", + "description": "The background color of the log in button on the landing page." + }, + { + "name": "button_text_color", + "type": "String", + "description": "The color of the text in the log in button on the landing page." + }, + { + "name": "image_url", + "type": "String", + "description": "The URL of the image shown on the landing page." + }, + { + "name": "message", + "type": "String", + "description": "The message shown on the landing page." + }, + { + "name": "title", + "type": "String", + "description": "The title shown on the landing page." + } + ] + }, + { + "name": "logo_url", + "type": "String", + "description": "The image URL for the logo shown in the App Launcher dashboard." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for the application. Only valid for self_hosted, ssh, vnc, and rdp application types.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "The authenticators allowed for MFA.\nAvailable values: \"totp\", \"biometrics\", \"security_key\"." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Whether MFA is disabled for this application." + }, + { + "name": "session_duration", + "type": "String", + "description": "How often a user will be forced to re-authenticate with MFA." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the application." + }, + { + "name": "oauth_configuration", + "type": "Attributes", + "description": "Optional configuration for managing an OAuth authorization flow controlled by Access. When set, Access will act as the OAuth authorization server for this application. This feature is currently in beta.", + "children": [ + { + "name": "dynamic_client_registration", + "type": "Attributes", + "description": "Settings for OAuth dynamic client registration.", + "children": [ + { + "name": "allow_any_on_localhost", + "type": "Boolean", + "description": "Allows any client with redirect URIs on localhost." + }, + { + "name": "allow_any_on_loopback", + "type": "Boolean", + "description": "Allows any client with redirect URIs on 127.0.0.1." + }, + { + "name": "allowed_uris", + "type": "List of String", + "description": "The URIs that are allowed as redirect URIs for dynamically registered clients. Must use the `https` protocol. Paths may end in `/*` to match all sub-paths." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether dynamic client registration is enabled." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the OAuth configuration is enabled for this application. When set to `false`, Access will not handle OAuth for this application. Defaults to `true` if omitted." + }, + { + "name": "grant", + "type": "Attributes", + "description": "Settings for OAuth grant behavior.", + "children": [ + { + "name": "access_token_lifetime", + "type": "String", + "description": "The lifetime of the access token. Must be in the format `300ms` or `2h45m`. Valid time units are ns, us (or µs), ms, s, m, h." + }, + { + "name": "session_duration", + "type": "String", + "description": "The duration of the OAuth session. Must be in the format `300ms` or `2h45m`. Valid time units are ns, us (or µs), ms, s, m, h." + } + ] + } + ] + }, + { + "name": "options_preflight_bypass", + "type": "Boolean", + "description": "Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors_headers is set." + }, + { + "name": "path_cookie_attribute", + "type": "Boolean", + "description": "Enables cookie paths to scope an application's JWT to the application path. If disabled, the JWT will scope to the hostname by default" + }, + { + "name": "policies", + "type": "Attributes List", + "description": "The policies that Access applies to the application, in ascending order of precedence. Items can reference existing policies or create new policies exclusive to the application.", + "children": [ + { + "name": "connection_rules", + "type": "Attributes", + "description": "The rules that define how users may connect to the targets secured by your application.", + "children": [ + { + "name": "rdp", + "type": "Attributes", + "description": "The RDP-specific rules that define clipboard behavior for RDP connections.", + "children": [ + { + "name": "allowed_clipboard_local_to_remote_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from local machine to remote RDP session." + }, + { + "name": "allowed_clipboard_remote_to_local_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from remote RDP session to local machine." + } + ] + }, + { + "name": "ssh", + "type": "Attributes", + "description": "The SSH-specific rules that define how users may connect to the targets secured by your application.", + "children": [ + { + "name": "allow_email_alias", + "type": "Boolean", + "description": "Enables using Identity Provider email alias as SSH username." + }, + { + "name": "usernames", + "type": "List of String", + "description": "Contains the Unix usernames that may be used when connecting over SSH." + } + ] + } + ] + }, + { + "name": "decision", + "type": "String", + "description": "The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.\nAvailable values: \"allow\", \"deny\", \"non_identity\", \"bypass\"." + }, + { + "name": "exclude", + "type": "Attributes Set", + "description": "Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the policy" + }, + { + "name": "include", + "type": "Attributes Set", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for this policy. For infrastructure applications only `ssh_piv_key` is a supported authenticator; for other application types use `totp`, `biometrics`, or `security_key`.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "The authenticators allowed for MFA.\nAvailable values: \"totp\", \"biometrics\", \"security_key\", \"ssh_piv_key\"." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Whether MFA is disabled for this policy." + }, + { + "name": "session_duration", + "type": "String", + "description": "How often a user will be forced to re-authenticate with MFA." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access policy." + }, + { + "name": "precedence", + "type": "Number", + "description": "The order of execution for this policy. Must be unique for each policy within an app." + }, + { + "name": "require", + "type": "Attributes Set", + "description": "Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + } + ] + }, + { + "name": "read_service_tokens_from_header", + "type": "String", + "description": "Allows matching Access Service Tokens passed HTTP in a single header with this name.\nThis works as an alternative to the (CF-Access-Client-Id, CF-Access-Client-Secret) pair of headers.\nThe header value will be interpreted as a json object similar to: \n {\n \"cf-access-client-id\": \"88bf3b6d86161464f6509f7219099e57.access.example.com\",\n \"cf-access-client-secret\": \"bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5\"\n }" + }, + { + "name": "saas_app", + "type": "Attributes", + "children": [ + { + "name": "access_token_lifetime", + "type": "String", + "description": "The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h." + }, + { + "name": "allow_pkce_without_client_secret", + "type": "Boolean", + "description": "If client secret should be required on the token endpoint when authorization_code_with_pkce grant is used." + }, + { + "name": "app_launcher_url", + "type": "String", + "description": "The URL where this applications tile redirects users" + }, + { + "name": "auth_type", + "type": "String", + "description": "Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is \"saml\"\nAvailable values: \"saml\", \"oidc\"." + }, + { + "name": "client_id", + "type": "String", + "description": "The application client id" + }, + { + "name": "client_secret", + "type": "String", + "description": "The application client secret, only returned on POST request.", + "sensitive": true + }, + { + "name": "consumer_service_url", + "type": "String", + "description": "The service provider's endpoint that is responsible for receiving and parsing a SAML assertion." + }, + { + "name": "custom_attributes", + "type": "Attributes List", + "children": [ + { + "name": "friendly_name", + "type": "String", + "description": "The SAML FriendlyName of the attribute." + }, + { + "name": "name", + "type": "String", + "description": "The name of the attribute." + }, + { + "name": "name_format", + "type": "String", + "description": "A globally unique name for an identity or service provider.\nAvailable values: \"urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified\", \"urn:oasis:names:tc:SAML:2.0:attrname-format:basic\", \"urn:oasis:names:tc:SAML:2.0:attrname-format:uri\"." + }, + { + "name": "required", + "type": "Boolean", + "description": "If the attribute is required when building a SAML assertion." + }, + { + "name": "source", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the IdP attribute." + }, + { + "name": "name_by_idp", + "type": "Attributes List", + "description": "A mapping from IdP ID to attribute name.", + "children": [ + { + "name": "idp_id", + "type": "String", + "description": "The UID of the IdP." + }, + { + "name": "source_name", + "type": "String", + "description": "The name of the IdP provided attribute." + } + ] + } + ] + } + ] + }, + { + "name": "custom_claims", + "type": "Attributes List", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the claim." + }, + { + "name": "required", + "type": "Boolean", + "description": "If the claim is required when building an OIDC token." + }, + { + "name": "scope", + "type": "String", + "description": "The scope of the claim.\nAvailable values: \"groups\", \"profile\", \"email\", \"openid\"." + }, + { + "name": "source", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the IdP claim." + }, + { + "name": "name_by_idp", + "type": "Map of String", + "description": "A mapping from IdP ID to claim name." + } + ] + } + ] + }, + { + "name": "default_relay_state", + "type": "String", + "description": "The URL that the user will be redirected to after a successful login for IDP initiated logins." + }, + { + "name": "grant_types", + "type": "List of String", + "description": "The OIDC flows supported by this application" + }, + { + "name": "group_filter_regex", + "type": "String", + "description": "A regex to filter Cloudflare groups returned in ID token and userinfo endpoint" + }, + { + "name": "hybrid_and_implicit_options", + "type": "Attributes", + "children": [ + { + "name": "return_access_token_from_authorization_endpoint", + "type": "Boolean", + "description": "If an Access Token should be returned from the OIDC Authorization endpoint" + }, + { + "name": "return_id_token_from_authorization_endpoint", + "type": "Boolean", + "description": "If an ID Token should be returned from the OIDC Authorization endpoint" + } + ] + }, + { + "name": "idp_entity_id", + "type": "String", + "description": "The unique identifier for your SaaS application." + }, + { + "name": "name_id_format", + "type": "String", + "description": "The format of the name identifier sent to the SaaS application.\nAvailable values: \"id\", \"email\"." + }, + { + "name": "name_id_transform_jsonata", + "type": "String", + "description": "A [JSONata](https://jsonata.org/) expression that transforms an application's user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the `name_id_format` setting." + }, + { + "name": "public_key", + "type": "String", + "description": "The Access public certificate that will be used to verify your identity." + }, + { + "name": "redirect_uris", + "type": "List of String", + "description": "The permitted URL's for Cloudflare to return Authorization codes and Access/ID tokens" + }, + { + "name": "refresh_token_options", + "type": "Attributes", + "children": [ + { + "name": "lifetime", + "type": "String", + "description": "How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m." + } + ] + }, + { + "name": "saml_attribute_transform_jsonata", + "type": "String", + "description": "A [JSONata] (https://jsonata.org/) expression that transforms an application's user identities into attribute assertions in the SAML response. The expression can transform id, email, name, and groups values. It can also transform fields listed in the saml_attributes or oidc_fields of the identity provider used to authenticate. The output of this expression must be a JSON object." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Define the user information shared with access, \"offline_access\" scope will be automatically enabled if refresh tokens are enabled" + }, + { + "name": "sp_entity_id", + "type": "String", + "description": "A globally unique name for an identity or service provider." + }, + { + "name": "sso_endpoint", + "type": "String", + "description": "The endpoint where your SaaS application will send login requests." + } + ] + }, + { + "name": "same_site_cookie_attribute", + "type": "String", + "description": "Sets the SameSite cookie setting, which provides increased security against CSRF attacks." + }, + { + "name": "scim_config", + "type": "Attributes", + "description": "Configuration for provisioning to this application via SCIM. This is currently in closed beta.", + "children": [ + { + "name": "authentication", + "type": "Attributes", + "description": "Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.", + "children": [ + { + "name": "authorization_url", + "type": "String", + "description": "URL used to generate the auth code used during token generation." + }, + { + "name": "client_id", + "type": "String", + "description": "Client ID used to authenticate when generating a token for authenticating with the remote SCIM service." + }, + { + "name": "client_secret", + "type": "String", + "description": "Secret used to authenticate when generating a token for authenticating with the remove SCIM service.", + "sensitive": true + }, + { + "name": "password", + "type": "String", + "description": "Password used to authenticate with the remote SCIM service.", + "sensitive": true + }, + { + "name": "scheme", + "type": "String", + "description": "The authentication scheme to use when making SCIM requests to this application.\nAvailable values: \"httpbasic\", \"oauthbearertoken\", \"oauth2\", \"access_service_token\"." + }, + { + "name": "scopes", + "type": "List of String", + "description": "The authorization scopes to request when generating the token used to authenticate with the remove SCIM service." + }, + { + "name": "token", + "type": "String", + "description": "Token used to authenticate with the remote SCIM service.", + "sensitive": true + }, + { + "name": "token_url", + "type": "String", + "description": "URL used to generate the token used to authenticate with the remote SCIM service." + }, + { + "name": "user", + "type": "String", + "description": "User name used to authenticate with the remote SCIM service." + } + ] + }, + { + "name": "deactivate_on_delete", + "type": "Boolean", + "description": "If false, propagates DELETE requests to the target application for SCIM resources. If true, sets 'active' to false on the SCIM resource. Note: Some targets do not support DELETE operations." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether SCIM provisioning is turned on for this application." + }, + { + "name": "idp_uid", + "type": "String", + "description": "The UID of the IdP to use as the source for SCIM resources to provision to this application." + }, + { + "name": "mappings", + "type": "Attributes List", + "description": "A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not this mapping is enabled." + }, + { + "name": "filter", + "type": "String", + "description": "A [SCIM filter expression](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2) that matches resources that should be provisioned to this application." + }, + { + "name": "operations", + "type": "Attributes", + "description": "Whether or not this mapping applies to creates, updates, or deletes.", + "children": [ + { + "name": "create", + "type": "Boolean", + "description": "Whether or not this mapping applies to create (POST) operations." + }, + { + "name": "delete", + "type": "Boolean", + "description": "Whether or not this mapping applies to DELETE operations." + }, + { + "name": "update", + "type": "Boolean", + "description": "Whether or not this mapping applies to update (PATCH/PUT) operations." + } + ] + }, + { + "name": "schema", + "type": "String", + "description": "Which SCIM resource type this mapping applies to." + }, + { + "name": "strictness", + "type": "String", + "description": "The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.\nAvailable values: \"strict\", \"passthrough\"." + }, + { + "name": "transform_jsonata", + "type": "String", + "description": "A [JSONata](https://jsonata.org/) expression that transforms the resource before provisioning it in the application." + } + ] + }, + { + "name": "remote_uri", + "type": "String", + "description": "The base URI for the application's SCIM-compatible API." + } + ] + }, + { + "name": "self_hosted_domains", + "type": "Set of String", + "description": "List of public domains that Access will secure. This field is deprecated in favor of `destinations` and will be supported until **November 21, 2025.** If `destinations` are provided, then `self_hosted_domains` will be ignored.", + "deprecated": "Deprecated." + }, + { + "name": "service_auth_401_redirect", + "type": "Boolean", + "description": "Returns a 401 status code when the request is blocked by a Service Auth policy." + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for this application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h. Note: unsupported for infrastructure type applications." + }, + { + "name": "skip_app_launcher_login_page", + "type": "Boolean", + "description": "Determines when to skip the App Launcher landing page." + }, + { + "name": "skip_interstitial", + "type": "Boolean", + "description": "Enables automatic authentication through cloudflared." + }, + { + "name": "tags", + "type": "Set of String", + "description": "The tags you want assigned to an application. Tags are used to filter applications in the App Launcher dashboard." + }, + { + "name": "target_criteria", + "type": "Attributes List", + "children": [ + { + "name": "port", + "type": "Number", + "description": "The port that the targets use for the chosen communication protocol. A port cannot be assigned to multiple protocols." + }, + { + "name": "protocol", + "type": "String", + "description": "The communication protocol your application secures.\nAvailable values: \"SSH\", \"RDP\"." + }, + { + "name": "target_attributes", + "type": "Map of List of String", + "description": "Contains a map of target attribute keys to target attribute values." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The application type.\nAvailable values: \"self_hosted\", \"saas\", \"ssh\", \"vnc\", \"app_launcher\", \"warp\", \"biso\", \"bookmark\", \"dash_sso\", \"infrastructure\", \"rdp\", \"mcp\", \"mcp_portal\", \"proxy_endpoint\"." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "aud", + "type": "String", + "description": "Audience tag." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_applications": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_applications", + "example": "data \"cloudflare_zero_trust_access_applications\" \"example_zero_trust_access_applications\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n aud = \"aud\"\n domain = \"domain\"\n exact = true\n name = \"name\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "aud", + "type": "String", + "description": "The aud of the app." + }, + { + "name": "domain", + "type": "String", + "description": "The domain of the app." + }, + { + "name": "exact", + "type": "Boolean", + "description": "True for only exact string matches against passed name/domain query parameters." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "The name of the app." + }, + { + "name": "search", + "type": "String", + "description": "Search for apps by other listed query parameters." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allow_authenticate_via_warp", + "type": "Boolean", + "description": "When set to true, users can authenticate to this application using their WARP session. When set to false this application will always require direct IdP authentication. This setting always overrides the organization setting for WARP authentication." + }, + { + "name": "allow_iframe", + "type": "Boolean", + "description": "Enables loading application content in an iFrame." + }, + { + "name": "allowed_idps", + "type": "List of String", + "description": "The identity providers your users can select when connecting to this application. Defaults to all IdPs configured in your account." + }, + { + "name": "app_launcher_logo_url", + "type": "String", + "description": "The image URL of the logo shown in the App Launcher header." + }, + { + "name": "app_launcher_visible", + "type": "Boolean", + "description": "Displays the application in the App Launcher." + }, + { + "name": "aud", + "type": "String", + "description": "Audience tag." + }, + { + "name": "auto_redirect_to_identity", + "type": "Boolean", + "description": "When set to `true`, users skip the identity provider selection step during login. You must specify only one identity provider in allowed_idps." + }, + { + "name": "bg_color", + "type": "String", + "description": "The background color of the App Launcher page." + }, + { + "name": "cors_headers", + "type": "Attributes", + "children": [ + { + "name": "allow_all_headers", + "type": "Boolean", + "description": "Allows all HTTP request headers." + }, + { + "name": "allow_all_methods", + "type": "Boolean", + "description": "Allows all HTTP request methods." + }, + { + "name": "allow_all_origins", + "type": "Boolean", + "description": "Allows all origins." + }, + { + "name": "allow_credentials", + "type": "Boolean", + "description": "When set to `true`, includes credentials (cookies, authorization headers, or TLS client certificates) with requests." + }, + { + "name": "allowed_headers", + "type": "List of String", + "description": "Allowed HTTP request headers." + }, + { + "name": "allowed_methods", + "type": "List of String", + "description": "Allowed HTTP request methods." + }, + { + "name": "allowed_origins", + "type": "List of String", + "description": "Allowed origins." + }, + { + "name": "max_age", + "type": "Number", + "description": "The maximum number of seconds the results of a preflight request can be cached." + } + ] + }, + { + "name": "custom_deny_message", + "type": "String", + "description": "The custom error message shown to a user when they are denied access to the application." + }, + { + "name": "custom_deny_url", + "type": "String", + "description": "The custom URL a user is redirected to when they are denied access to the application when failing identity-based rules." + }, + { + "name": "custom_non_identity_deny_url", + "type": "String", + "description": "The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules." + }, + { + "name": "custom_pages", + "type": "List of String", + "description": "The custom pages that will be displayed when applicable for this application" + }, + { + "name": "destinations", + "type": "Attributes List", + "description": "List of destinations secured by Access. This supersedes `self_hosted_domains` to allow for more flexibility in defining different types of domains. If `destinations` are provided, then `self_hosted_domains` will be ignored.", + "children": [ + { + "name": "cidr", + "type": "String", + "description": "The CIDR range of the destination. Single IPs will be computed as /32." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname of the destination. Matches a valid SNI served by an HTTPS origin." + }, + { + "name": "l4_protocol", + "type": "String", + "description": "The L4 protocol of the destination. When omitted, both UDP and TCP traffic will match.\nAvailable values: \"tcp\", \"udp\"." + }, + { + "name": "mcp_server_id", + "type": "String", + "description": "A MCP server id configured in ai-controls. Access will secure the MCP server if accessed through a MCP portal." + }, + { + "name": "port_range", + "type": "String", + "description": "The port range of the destination. Can be a single port or a range of ports. When omitted, all ports will match." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"public\", \"private\", \"via_mcp_server_portal\", \"worker\", \"preview_worker\", \"all_workers\", \"all_preview_workers\"." + }, + { + "name": "uri", + "type": "String", + "description": "The URI of the destination. Public destinations' URIs can include a domain and path with [wildcards](https://developers.cloudflare.com/cloudflare-one/policies/access/app-paths/)." + }, + { + "name": "vnet_id", + "type": "String", + "description": "The VNET ID to match the destination. When omitted, all VNETs will match." + }, + { + "name": "worker_id", + "type": "String", + "description": "The ID of the Cloudflare Worker to protect with Access. Required when type is `worker` or `preview_worker`." + } + ] + }, + { + "name": "domain", + "type": "String", + "description": "The primary hostname and path secured by Access. This domain will be displayed if the app is visible in the App Launcher." + }, + { + "name": "enable_binding_cookie", + "type": "Boolean", + "description": "Enables the binding cookie, which increases security against compromised authorization tokens and CSRF attacks." + }, + { + "name": "footer_links", + "type": "Attributes List", + "description": "The links in the App Launcher footer.", + "children": [ + { + "name": "name", + "type": "String", + "description": "The hypertext in the footer link." + }, + { + "name": "url", + "type": "String", + "description": "the hyperlink in the footer link." + } + ] + }, + { + "name": "header_bg_color", + "type": "String", + "description": "The background color of the App Launcher header." + }, + { + "name": "http_only_cookie_attribute", + "type": "Boolean", + "description": "Enables the HttpOnly cookie attribute, which increases security against XSS attacks." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "landing_page_design", + "type": "Attributes", + "description": "The design of the App Launcher landing page shown to users when they log in.", + "children": [ + { + "name": "button_color", + "type": "String", + "description": "The background color of the log in button on the landing page." + }, + { + "name": "button_text_color", + "type": "String", + "description": "The color of the text in the log in button on the landing page." + }, + { + "name": "image_url", + "type": "String", + "description": "The URL of the image shown on the landing page." + }, + { + "name": "message", + "type": "String", + "description": "The message shown on the landing page." + }, + { + "name": "title", + "type": "String", + "description": "The title shown on the landing page." + } + ] + }, + { + "name": "logo_url", + "type": "String", + "description": "The image URL for the logo shown in the App Launcher dashboard." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for the application. Only valid for self_hosted, ssh, vnc, and rdp application types.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "The authenticators allowed for MFA.\nAvailable values: \"totp\", \"biometrics\", \"security_key\"." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Whether MFA is disabled for this application." + }, + { + "name": "session_duration", + "type": "String", + "description": "How often a user will be forced to re-authenticate with MFA." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the application." + }, + { + "name": "options_preflight_bypass", + "type": "Boolean", + "description": "Allows options preflight requests to bypass Access authentication and go directly to the origin. Cannot turn on if cors_headers is set." + }, + { + "name": "path_cookie_attribute", + "type": "Boolean", + "description": "Enables cookie paths to scope an application's JWT to the application path. If disabled, the JWT will scope to the hostname by default" + }, + { + "name": "policies", + "type": "Attributes List", + "children": [ + { + "name": "approval_groups", + "type": "Attributes Set", + "description": "Administrators who can approve a temporary authentication request.", + "children": [ + { + "name": "approvals_needed", + "type": "Number", + "description": "The number of approvals needed to obtain access." + }, + { + "name": "email_addresses", + "type": "List of String", + "description": "A list of emails that can approve the access request." + }, + { + "name": "email_list_uuid", + "type": "String", + "description": "The UUID of an re-usable email list." + } + ] + }, + { + "name": "approval_required", + "type": "Boolean", + "description": "Requires the user to request access from an administrator at the start of each session." + }, + { + "name": "connection_rules", + "type": "Attributes", + "description": "The rules that define how users may connect to the targets secured by your application.", + "children": [ + { + "name": "ssh", + "type": "Attributes", + "description": "The SSH-specific rules that define how users may connect to the targets secured by your application.", + "children": [ + { + "name": "allow_email_alias", + "type": "Boolean", + "description": "Enables using Identity Provider email alias as SSH username." + }, + { + "name": "usernames", + "type": "List of String", + "description": "Contains the Unix usernames that may be used when connecting over SSH." + } + ] + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "decision", + "type": "String", + "description": "The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.\nAvailable values: \"allow\", \"deny\", \"non_identity\", \"bypass\"." + }, + { + "name": "exclude", + "type": "Attributes Set", + "description": "Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the policy" + }, + { + "name": "include", + "type": "Attributes Set", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "isolation_required", + "type": "Boolean", + "description": "Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for this policy.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "The authenticators allowed for MFA.\nAvailable values: \"totp\", \"biometrics\", \"security_key\", \"ssh_piv_key\"." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Whether MFA is disabled for this policy." + }, + { + "name": "session_duration", + "type": "String", + "description": "How often a user will be forced to re-authenticate with MFA." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access policy." + }, + { + "name": "precedence", + "type": "Number", + "description": "The order of execution for this policy. Must be unique for each policy within an app." + }, + { + "name": "purpose_justification_prompt", + "type": "String", + "description": "A custom message that will appear on the purpose justification screen." + }, + { + "name": "purpose_justification_required", + "type": "Boolean", + "description": "Require users to enter a justification when they log in to the application." + }, + { + "name": "require", + "type": "Attributes Set", + "description": "Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + } + ] + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "read_service_tokens_from_header", + "type": "String", + "description": "Allows matching Access Service Tokens passed HTTP in a single header with this name.\nThis works as an alternative to the (CF-Access-Client-Id, CF-Access-Client-Secret) pair of headers.\nThe header value will be interpreted as a json object similar to: \n {\n \"cf-access-client-id\": \"88bf3b6d86161464f6509f7219099e57.access.example.com\",\n \"cf-access-client-secret\": \"bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5\"\n }" + }, + { + "name": "saas_app", + "type": "Attributes", + "children": [ + { + "name": "access_token_lifetime", + "type": "String", + "description": "The lifetime of the OIDC Access Token after creation. Valid units are m,h. Must be greater than or equal to 1m and less than or equal to 24h." + }, + { + "name": "allow_pkce_without_client_secret", + "type": "Boolean", + "description": "If client secret should be required on the token endpoint when authorization_code_with_pkce grant is used." + }, + { + "name": "app_launcher_url", + "type": "String", + "description": "The URL where this applications tile redirects users" + }, + { + "name": "auth_type", + "type": "String", + "description": "Optional identifier indicating the authentication protocol used for the saas app. Required for OIDC. Default if unset is \"saml\"\nAvailable values: \"saml\", \"oidc\"." + }, + { + "name": "client_id", + "type": "String", + "description": "The application client id" + }, + { + "name": "client_secret", + "type": "String", + "description": "The application client secret, only returned on POST request.", + "sensitive": true + }, + { + "name": "consumer_service_url", + "type": "String", + "description": "The service provider's endpoint that is responsible for receiving and parsing a SAML assertion." + }, + { + "name": "custom_attributes", + "type": "Attributes List", + "children": [ + { + "name": "friendly_name", + "type": "String", + "description": "The SAML FriendlyName of the attribute." + }, + { + "name": "name", + "type": "String", + "description": "The name of the attribute." + }, + { + "name": "name_format", + "type": "String", + "description": "A globally unique name for an identity or service provider.\nAvailable values: \"urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified\", \"urn:oasis:names:tc:SAML:2.0:attrname-format:basic\", \"urn:oasis:names:tc:SAML:2.0:attrname-format:uri\"." + }, + { + "name": "required", + "type": "Boolean", + "description": "If the attribute is required when building a SAML assertion." + }, + { + "name": "source", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the IdP attribute." + }, + { + "name": "name_by_idp", + "type": "Attributes List", + "description": "A mapping from IdP ID to attribute name.", + "children": [ + { + "name": "idp_id", + "type": "String", + "description": "The UID of the IdP." + }, + { + "name": "source_name", + "type": "String", + "description": "The name of the IdP provided attribute." + } + ] + } + ] + } + ] + }, + { + "name": "custom_claims", + "type": "Attributes List", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the claim." + }, + { + "name": "required", + "type": "Boolean", + "description": "If the claim is required when building an OIDC token." + }, + { + "name": "scope", + "type": "String", + "description": "The scope of the claim.\nAvailable values: \"groups\", \"profile\", \"email\", \"openid\"." + }, + { + "name": "source", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the IdP claim." + }, + { + "name": "name_by_idp", + "type": "Map of String", + "description": "A mapping from IdP ID to claim name." + } + ] + } + ] + }, + { + "name": "default_relay_state", + "type": "String", + "description": "The URL that the user will be redirected to after a successful login for IDP initiated logins." + }, + { + "name": "grant_types", + "type": "List of String", + "description": "The OIDC flows supported by this application" + }, + { + "name": "group_filter_regex", + "type": "String", + "description": "A regex to filter Cloudflare groups returned in ID token and userinfo endpoint" + }, + { + "name": "hybrid_and_implicit_options", + "type": "Attributes", + "children": [ + { + "name": "return_access_token_from_authorization_endpoint", + "type": "Boolean", + "description": "If an Access Token should be returned from the OIDC Authorization endpoint" + }, + { + "name": "return_id_token_from_authorization_endpoint", + "type": "Boolean", + "description": "If an ID Token should be returned from the OIDC Authorization endpoint" + } + ] + }, + { + "name": "idp_entity_id", + "type": "String", + "description": "The unique identifier for your SaaS application." + }, + { + "name": "name_id_format", + "type": "String", + "description": "The format of the name identifier sent to the SaaS application.\nAvailable values: \"id\", \"email\"." + }, + { + "name": "name_id_transform_jsonata", + "type": "String", + "description": "A [JSONata](https://jsonata.org/) expression that transforms an application's user identities into a NameID value for its SAML assertion. This expression should evaluate to a singular string. The output of this expression can override the `name_id_format` setting." + }, + { + "name": "public_key", + "type": "String", + "description": "The Access public certificate that will be used to verify your identity." + }, + { + "name": "redirect_uris", + "type": "List of String", + "description": "The permitted URL's for Cloudflare to return Authorization codes and Access/ID tokens" + }, + { + "name": "refresh_token_options", + "type": "Attributes", + "children": [ + { + "name": "lifetime", + "type": "String", + "description": "How long a refresh token will be valid for after creation. Valid units are m,h,d. Must be longer than 1m." + } + ] + }, + { + "name": "saml_attribute_transform_jsonata", + "type": "String", + "description": "A [JSONata] (https://jsonata.org/) expression that transforms an application's user identities into attribute assertions in the SAML response. The expression can transform id, email, name, and groups values. It can also transform fields listed in the saml_attributes or oidc_fields of the identity provider used to authenticate. The output of this expression must be a JSON object." + }, + { + "name": "scopes", + "type": "List of String", + "description": "Define the user information shared with access, \"offline_access\" scope will be automatically enabled if refresh tokens are enabled" + }, + { + "name": "sp_entity_id", + "type": "String", + "description": "A globally unique name for an identity or service provider." + }, + { + "name": "sso_endpoint", + "type": "String", + "description": "The endpoint where your SaaS application will send login requests." + } + ] + }, + { + "name": "same_site_cookie_attribute", + "type": "String", + "description": "Sets the SameSite cookie setting, which provides increased security against CSRF attacks." + }, + { + "name": "scim_config", + "type": "Attributes", + "description": "Configuration for provisioning to this application via SCIM. This is currently in closed beta.", + "children": [ + { + "name": "authentication", + "type": "Attributes", + "description": "Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.", + "children": [ + { + "name": "authorization_url", + "type": "String", + "description": "URL used to generate the auth code used during token generation." + }, + { + "name": "client_id", + "type": "String", + "description": "Client ID used to authenticate when generating a token for authenticating with the remote SCIM service." + }, + { + "name": "client_secret", + "type": "String", + "description": "Secret used to authenticate when generating a token for authenticating with the remove SCIM service.", + "sensitive": true + }, + { + "name": "password", + "type": "String", + "description": "Password used to authenticate with the remote SCIM service." + }, + { + "name": "scheme", + "type": "String", + "description": "The authentication scheme to use when making SCIM requests to this application.\nAvailable values: \"httpbasic\", \"oauthbearertoken\", \"oauth2\", \"access_service_token\"." + }, + { + "name": "scopes", + "type": "List of String", + "description": "The authorization scopes to request when generating the token used to authenticate with the remove SCIM service." + }, + { + "name": "token", + "type": "String", + "description": "Token used to authenticate with the remote SCIM service.", + "sensitive": true + }, + { + "name": "token_url", + "type": "String", + "description": "URL used to generate the token used to authenticate with the remote SCIM service." + }, + { + "name": "user", + "type": "String", + "description": "User name used to authenticate with the remote SCIM service." + } + ] + }, + { + "name": "deactivate_on_delete", + "type": "Boolean", + "description": "If false, propagates DELETE requests to the target application for SCIM resources. If true, sets 'active' to false on the SCIM resource. Note: Some targets do not support DELETE operations." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether SCIM provisioning is turned on for this application." + }, + { + "name": "idp_uid", + "type": "String", + "description": "The UID of the IdP to use as the source for SCIM resources to provision to this application." + }, + { + "name": "mappings", + "type": "Attributes List", + "description": "A list of mappings to apply to SCIM resources before provisioning them in this application. These can transform or filter the resources to be provisioned.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether or not this mapping is enabled." + }, + { + "name": "filter", + "type": "String", + "description": "A [SCIM filter expression](https://datatracker.ietf.org/doc/html/rfc7644#section-3.4.2.2) that matches resources that should be provisioned to this application." + }, + { + "name": "operations", + "type": "Attributes", + "description": "Whether or not this mapping applies to creates, updates, or deletes.", + "children": [ + { + "name": "create", + "type": "Boolean", + "description": "Whether or not this mapping applies to create (POST) operations." + }, + { + "name": "delete", + "type": "Boolean", + "description": "Whether or not this mapping applies to DELETE operations." + }, + { + "name": "update", + "type": "Boolean", + "description": "Whether or not this mapping applies to update (PATCH/PUT) operations." + } + ] + }, + { + "name": "schema", + "type": "String", + "description": "Which SCIM resource type this mapping applies to." + }, + { + "name": "strictness", + "type": "String", + "description": "The level of adherence to outbound resource schemas when provisioning to this mapping. ‘Strict’ removes unknown values, while ‘passthrough’ passes unknown values to the target.\nAvailable values: \"strict\", \"passthrough\"." + }, + { + "name": "transform_jsonata", + "type": "String", + "description": "A [JSONata](https://jsonata.org/) expression that transforms the resource before provisioning it in the application." + } + ] + }, + { + "name": "remote_uri", + "type": "String", + "description": "The base URI for the application's SCIM-compatible API." + } + ] + }, + { + "name": "self_hosted_domains", + "type": "List of String", + "description": "List of public domains that Access will secure. This field is deprecated in favor of `destinations` and will be supported until **November 21, 2025.** If `destinations` are provided, then `self_hosted_domains` will be ignored.", + "deprecated": "Deprecated." + }, + { + "name": "service_auth_401_redirect", + "type": "Boolean", + "description": "Returns a 401 status code when the request is blocked by a Service Auth policy." + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for this application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h. Note: unsupported for infrastructure type applications." + }, + { + "name": "skip_app_launcher_login_page", + "type": "Boolean", + "description": "Determines when to skip the App Launcher landing page." + }, + { + "name": "skip_interstitial", + "type": "Boolean", + "description": "Enables automatic authentication through cloudflared." + }, + { + "name": "tags", + "type": "Set of String", + "description": "The tags you want assigned to an application. Tags are used to filter applications in the App Launcher dashboard." + }, + { + "name": "target_criteria", + "type": "Attributes List", + "children": [ + { + "name": "port", + "type": "Number", + "description": "The port that the targets use for the chosen communication protocol. A port cannot be assigned to multiple protocols." + }, + { + "name": "protocol", + "type": "String", + "description": "The communication protocol your application secures.\nAvailable values: \"SSH\", \"RDP\"." + }, + { + "name": "target_attributes", + "type": "Map of List of String", + "description": "Contains a map of target attribute keys to target attribute values." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The application type.\nAvailable values: \"self_hosted\", \"saas\", \"ssh\", \"vnc\", \"app_launcher\", \"warp\", \"biso\", \"bookmark\", \"dash_sso\", \"infrastructure\", \"rdp\", \"mcp\", \"mcp_portal\"." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_custom_page": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_custom_page", + "description": "Accepted Permissions\n\n- `Access: Custom Pages Read`\n- `Access: Custom Pages Write`", + "example": "data \"cloudflare_zero_trust_access_custom_page\" \"example_zero_trust_access_custom_page\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_page_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "custom_page_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "contract_version", + "type": "Number", + "description": "Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim." + }, + { + "name": "custom_html", + "type": "String", + "description": "Custom page HTML." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "Custom page name." + }, + { + "name": "type", + "type": "String", + "description": "Custom page type.\nAvailable values: \"identity_denied\", \"forbidden\", \"login\", \"interstitial\"." + }, + { + "name": "uid", + "type": "String", + "description": "UUID." + } + ] + }, + "resource:cloudflare_zero_trust_access_custom_page": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_custom_page", + "description": "Accepted Permissions\n\n- `Access: Custom Pages Read`\n- `Access: Custom Pages Write`", + "example": "resource \"cloudflare_zero_trust_access_custom_page\" \"example_zero_trust_access_custom_page\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n custom_html = \"

Access Denied

\"\n name = \"name\"\n type = \"identity_denied\"\n contract_version = 0\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_custom_page.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "custom_html", + "type": "String", + "description": "Custom page HTML." + }, + { + "name": "name", + "type": "String", + "description": "Custom page name." + }, + { + "name": "type", + "type": "String", + "description": "Custom page type.\nAvailable values: \"identity_denied\", \"forbidden\", \"login\", \"interstitial\"." + } + ], + "optional": [ + { + "name": "contract_version", + "type": "Number", + "description": "Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "uid", + "type": "String", + "description": "UUID." + }, + { + "name": "warnings", + "type": "Attributes List", + "description": "Advisory validation findings returned when creating or updating a template. Omitted when empty.", + "children": [ + { + "name": "message", + "type": "String", + "description": "Human-readable description of the finding." + }, + { + "name": "ref", + "type": "String", + "description": "Optional pointer to the part of the template the finding refers to." + }, + { + "name": "tier", + "type": "String", + "description": "The validation tier that produced the finding (e.g. html, liquid)." + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_custom_pages": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_custom_pages", + "description": "Accepted Permissions\n\n- `Access: Custom Pages Read`\n- `Access: Custom Pages Write`", + "example": "data \"cloudflare_zero_trust_access_custom_pages\" \"example_zero_trust_access_custom_pages\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "contract_version", + "type": "Number", + "description": "Contract version of the page's Liquid template. Present (>= 1) marks a sanitized template; absent or 0 marks a legacy page served verbatim." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "Custom page name." + }, + { + "name": "type", + "type": "String", + "description": "Custom page type.\nAvailable values: \"identity_denied\", \"forbidden\", \"login\", \"interstitial\"." + }, + { + "name": "uid", + "type": "String", + "description": "UUID." + }, + { + "name": "warnings", + "type": "Attributes List", + "description": "Advisory validation findings returned when creating or updating a template. Omitted when empty.", + "children": [ + { + "name": "message", + "type": "String", + "description": "Human-readable description of the finding." + }, + { + "name": "ref", + "type": "String", + "description": "Optional pointer to the part of the template the finding refers to." + }, + { + "name": "tier", + "type": "String", + "description": "The validation tier that produced the finding (e.g. html, liquid)." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_group": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_group", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "data \"cloudflare_zero_trust_access_group\" \"example_zero_trust_access_group\" {\n group_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the group." + }, + { + "name": "search", + "type": "String", + "description": "Search for groups by other listed query parameters." + } + ] + }, + { + "name": "group_id", + "type": "String", + "description": "UUID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "exclude", + "type": "Attributes List", + "description": "Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "include", + "type": "Attributes List", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "is_default", + "type": "Attributes List", + "description": "Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access group." + }, + { + "name": "require", + "type": "Attributes List", + "description": "Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_access_group": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_group", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "resource \"cloudflare_zero_trust_access_group\" \"example_zero_trust_access_group\" {\n include = [{\n certificate = {\n\n }\n }]\n name = \"Allow devs\"\n zone_id = \"zone_id\"\n exclude = [{\n certificate = {\n\n }\n }]\n is_default = true\n require = [{\n certificate = {\n\n }\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_group.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "include", + "type": "Attributes List", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access group." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "exclude", + "type": "Attributes List", + "description": "Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "is_default", + "type": "Boolean", + "description": "Whether this is the default group" + }, + { + "name": "require", + "type": "Attributes List", + "description": "Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "UUID." + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_groups": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_groups", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "data \"cloudflare_zero_trust_access_groups\" \"example_zero_trust_access_groups\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n name = \"name\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "The name of the group." + }, + { + "name": "search", + "type": "String", + "description": "Search for groups by other listed query parameters." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "exclude", + "type": "Attributes List", + "description": "Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "include", + "type": "Attributes List", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "is_default", + "type": "Attributes List", + "description": "Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access group." + }, + { + "name": "require", + "type": "Attributes List", + "description": "Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_identity_provider": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_identity_provider", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "data \"cloudflare_zero_trust_access_identity_provider\" \"example_zero_trust_access_identity_provider\" {\n identity_provider_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "scim_enabled", + "type": "String", + "description": "Indicates to Access to only retrieve identity providers that have the System for Cross-Domain Identity Management (SCIM) enabled." + } + ] + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "UUID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "config", + "type": "Attributes", + "description": "The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).", + "children": [ + { + "name": "apps_domain", + "type": "String", + "description": "Your companies TLD" + }, + { + "name": "attributes", + "type": "List of String", + "description": "A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules." + }, + { + "name": "auth_url", + "type": "String", + "description": "The authorization_endpoint URL of your IdP" + }, + { + "name": "authorization_server_id", + "type": "String", + "description": "Your okta authorization server id" + }, + { + "name": "centrify_account", + "type": "String", + "description": "Your centrify account url" + }, + { + "name": "centrify_app_id", + "type": "String", + "description": "Your centrify app id" + }, + { + "name": "certs_url", + "type": "String", + "description": "The jwks_uri endpoint of your IdP to allow the IdP keys to sign the tokens" + }, + { + "name": "claims", + "type": "List of String", + "description": "Custom claims" + }, + { + "name": "client_id", + "type": "String", + "description": "Your OAuth Client ID" + }, + { + "name": "client_secret", + "type": "String", + "description": "Your OAuth Client Secret", + "sensitive": true + }, + { + "name": "conditional_access_enabled", + "type": "Boolean", + "description": "Should Cloudflare try to load authentication contexts from your account" + }, + { + "name": "directory_id", + "type": "String", + "description": "Your Azure directory uuid" + }, + { + "name": "email_attribute_name", + "type": "String", + "description": "The attribute name for email in the SAML response." + }, + { + "name": "email_claim_name", + "type": "String", + "description": "The claim name for email in the id_token response." + }, + { + "name": "enable_encryption", + "type": "Boolean", + "description": "Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt\nSAML assertions using the certificate from the assigned certificate set.\n\nTo enable encryption:\n1. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`\n2. Set this field to `true` and include `saml_certificate_set_id` in the PUT request\n3. Configure the public certificate in your external Identity Provider\n\nNote: Requires `saml_certificate_set_id` to be set when `true`." + }, + { + "name": "force_authn", + "type": "Boolean", + "description": "Asks the IdP to reauthenticate the user for each SAML authentication request." + }, + { + "name": "header_attributes", + "type": "Attributes List", + "description": "Add a list of attribute names that will be returned in the response header from the Access callback.", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "attribute name from the IDP" + }, + { + "name": "header_name", + "type": "String", + "description": "header that will be added on the request to the origin" + } + ] + }, + { + "name": "idp_public_certs", + "type": "List of String", + "description": "X509 certificate to verify the signature in the SAML authentication response" + }, + { + "name": "issuer_url", + "type": "String", + "description": "IdP Entity ID or Issuer URL" + }, + { + "name": "max_sso_url_length", + "type": "Number", + "description": "The maximum URL length the IdP accepts for the SSO redirect URL.\nWhen the constructed SSO URL would exceed this length, the RelayState\nis stored server-side and a short nonce is passed to the IdP instead.\nSet this if your IdP enforces a URL length limit." + }, + { + "name": "okta_account", + "type": "String", + "description": "Your okta account url" + }, + { + "name": "onelogin_account", + "type": "String", + "description": "Your OneLogin account url" + }, + { + "name": "ping_env_id", + "type": "String", + "description": "Your PingOne environment identifier" + }, + { + "name": "pkce_enabled", + "type": "Boolean", + "description": "Enable Proof Key for Code Exchange (PKCE)" + }, + { + "name": "prompt", + "type": "String", + "description": "Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn't presented with any interactive prompt. If the request can't be completed silently by using single-sign on, the Microsoft identity platform returns an interaction_required error. prompt=select_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.\nAvailable values: \"login\", \"select_account\", \"none\", \"consent\"." + }, + { + "name": "redirect_url", + "type": "String" + }, + { + "name": "restrict_to_account_members", + "type": "Boolean", + "description": "When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies." + }, + { + "name": "scopes", + "type": "List of String", + "description": "OAuth scopes" + }, + { + "name": "sign_request", + "type": "Boolean", + "description": "Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints." + }, + { + "name": "sso_target_url", + "type": "String", + "description": "URL to send the SAML authentication requests to" + }, + { + "name": "support_groups", + "type": "Boolean", + "description": "Should Cloudflare try to load groups from your account" + }, + { + "name": "token_url", + "type": "String", + "description": "The token_endpoint URL of your IdP" + }, + { + "name": "use_login_hint", + "type": "Boolean", + "description": "Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "The name of the identity provider, shown to users on the login page." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicates that the identity provider is immutable and cannot be updated or deleted via the API." + }, + { + "name": "saml_certificate_set", + "type": "Attributes", + "description": "The SAML encryption certificate set details, including current and previous certificates.\nOnly present for SAML identity providers with a certificate set assigned.", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the certificate set was created" + }, + { + "name": "current_certificate", + "type": "Attributes", + "description": "The currently active certificate used for encrypting SAML assertions", + "children": [ + { + "name": "is_current", + "type": "Boolean", + "description": "Indicates whether this is the currently active certificate" + }, + { + "name": "not_after", + "type": "String", + "description": "Certificate expiration date. Certificates are automatically rotated 30 days before expiration." + }, + { + "name": "public_certificate", + "type": "String", + "description": "PEM-encoded X.509 certificate containing the public key.\nConfigure this certificate in your external SAML Identity Provider to enable encryption." + }, + { + "name": "uid", + "type": "String", + "description": "Unique identifier for the certificate" + } + ] + }, + { + "name": "previous_certificate", + "type": "String", + "description": "The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`." + }, + { + "name": "uid", + "type": "String", + "description": "Unique identifier for the certificate set" + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the certificate set was last updated (e.g., during rotation)" + } + ] + }, + { + "name": "saml_certificate_set_id", + "type": "String", + "description": "The UID of the SAML encryption certificate set assigned to this Identity Provider.\nOnly present for SAML identity providers with encryption configured.\nCreate a certificate set via POST to `/identity_providers/{id}/saml_certificate`." + }, + { + "name": "scim_config", + "type": "Attributes", + "description": "The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "A flag to enable or disable SCIM for the identity provider." + }, + { + "name": "identity_update_behavior", + "type": "String", + "description": "Indicates how a SCIM event updates a user identity used for policy evaluation. Use \"automatic\" to automatically update a user's identity and augment it with fields from the SCIM user resource. Use \"reauth\" to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With \"reauth\" identities will not contain fields from the SCIM user resource. With \"no_action\" identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.\nAvailable values: \"automatic\", \"reauth\", \"no_action\"." + }, + { + "name": "scim_base_url", + "type": "String", + "description": "The base URL of Cloudflare's SCIM V2.0 API endpoint." + }, + { + "name": "seat_deprovision", + "type": "Boolean", + "description": "A flag to remove a user's seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user_deprovision is also enabled." + }, + { + "name": "secret", + "type": "String", + "description": "A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity_providers/:idpID/refresh_scim_secret.", + "sensitive": true + }, + { + "name": "user_deprovision", + "type": "Boolean", + "description": "A flag to enable revoking a user's session in Access and Gateway when they have been deprovisioned in the Identity Provider." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).\nAvailable values: \"onetimepin\", \"azureAD\", \"saml\", \"centrify\", \"facebook\", \"github\", \"google-apps\", \"google\", \"linkedin\", \"oidc\", \"okta\", \"onelogin\", \"pingone\", \"yandex\", \"cloudflare\"." + } + ] + }, + "resource:cloudflare_zero_trust_access_identity_provider": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_identity_provider", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "resource \"cloudflare_zero_trust_access_identity_provider\" \"example_zero_trust_access_identity_provider\" {\n config = {\n claims = [\"email_verified\", \"preferred_username\", \"custom_claim_name\"]\n client_id = \"\"\n client_secret = \"\"\n conditional_access_enabled = true\n directory_id = \"\"\n email_claim_name = \"custom_claim_name\"\n prompt = \"login\"\n support_groups = true\n }\n name = \"Widget Corps IDP\"\n type = \"onetimepin\"\n zone_id = \"zone_id\"\n saml_certificate_set_id = \"c409ef44-e72c-41c8-8c0b-278c8a6f4fd8\"\n scim_config = {\n enabled = true\n identity_update_behavior = \"automatic\"\n seat_deprovision = true\n user_deprovision = true\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_identity_provider.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "config", + "type": "Attributes", + "description": "The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).", + "children": [ + { + "name": "apps_domain", + "type": "String", + "description": "Your companies TLD" + }, + { + "name": "attributes", + "type": "List of String", + "description": "A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules." + }, + { + "name": "auth_url", + "type": "String", + "description": "The authorization_endpoint URL of your IdP" + }, + { + "name": "authorization_server_id", + "type": "String", + "description": "Your okta authorization server id" + }, + { + "name": "centrify_account", + "type": "String", + "description": "Your centrify account url" + }, + { + "name": "centrify_app_id", + "type": "String", + "description": "Your centrify app id" + }, + { + "name": "certs_url", + "type": "String", + "description": "The jwks_uri endpoint of your IdP to allow the IdP keys to sign the tokens" + }, + { + "name": "claims", + "type": "List of String", + "description": "Custom claims" + }, + { + "name": "client_id", + "type": "String", + "description": "Your OAuth Client ID" + }, + { + "name": "client_secret", + "type": "String", + "description": "Your OAuth Client Secret", + "sensitive": true + }, + { + "name": "conditional_access_enabled", + "type": "Boolean", + "description": "Should Cloudflare try to load authentication contexts from your account" + }, + { + "name": "directory_id", + "type": "String", + "description": "Your Azure directory uuid" + }, + { + "name": "email_attribute_name", + "type": "String", + "description": "The attribute name for email in the SAML response." + }, + { + "name": "email_claim_name", + "type": "String", + "description": "The claim name for email in the id_token response." + }, + { + "name": "enable_encryption", + "type": "Boolean", + "description": "Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt\nSAML assertions using the certificate from the assigned certificate set.\n\nTo enable encryption:\n1. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`\n2. Set this field to `true` and include `saml_certificate_set_id` in the PUT request\n3. Configure the public certificate in your external Identity Provider\n\nNote: Requires `saml_certificate_set_id` to be set when `true`." + }, + { + "name": "force_authn", + "type": "Boolean", + "description": "Asks the IdP to reauthenticate the user for each SAML authentication request." + }, + { + "name": "header_attributes", + "type": "Attributes List", + "description": "Add a list of attribute names that will be returned in the response header from the Access callback.", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "attribute name from the IDP" + }, + { + "name": "header_name", + "type": "String", + "description": "header that will be added on the request to the origin" + } + ] + }, + { + "name": "idp_public_certs", + "type": "List of String", + "description": "X509 certificate to verify the signature in the SAML authentication response" + }, + { + "name": "issuer_url", + "type": "String", + "description": "IdP Entity ID or Issuer URL" + }, + { + "name": "max_sso_url_length", + "type": "Number", + "description": "The maximum URL length the IdP accepts for the SSO redirect URL.\nWhen the constructed SSO URL would exceed this length, the RelayState\nis stored server-side and a short nonce is passed to the IdP instead.\nSet this if your IdP enforces a URL length limit." + }, + { + "name": "okta_account", + "type": "String", + "description": "Your okta account url" + }, + { + "name": "onelogin_account", + "type": "String", + "description": "Your OneLogin account url" + }, + { + "name": "ping_env_id", + "type": "String", + "description": "Your PingOne environment identifier" + }, + { + "name": "pkce_enabled", + "type": "Boolean", + "description": "Enable Proof Key for Code Exchange (PKCE)" + }, + { + "name": "prompt", + "type": "String", + "description": "Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn't presented with any interactive prompt. If the request can't be completed silently by using single-sign on, the Microsoft identity platform returns an interaction_required error. prompt=select_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.\nAvailable values: \"login\", \"select_account\", \"none\", \"consent\"." + }, + { + "name": "redirect_url", + "type": "String" + }, + { + "name": "restrict_to_account_members", + "type": "Boolean", + "description": "When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies." + }, + { + "name": "scopes", + "type": "List of String", + "description": "OAuth scopes" + }, + { + "name": "sign_request", + "type": "Boolean", + "description": "Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints." + }, + { + "name": "sso_target_url", + "type": "String", + "description": "URL to send the SAML authentication requests to" + }, + { + "name": "support_groups", + "type": "Boolean", + "description": "Should Cloudflare try to load groups from your account" + }, + { + "name": "token_url", + "type": "String", + "description": "The token_endpoint URL of your IdP" + }, + { + "name": "use_login_hint", + "type": "Boolean", + "description": "Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the identity provider, shown to users on the login page." + }, + { + "name": "type", + "type": "String", + "description": "The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).\nAvailable values: \"onetimepin\", \"azureAD\", \"saml\", \"centrify\", \"facebook\", \"github\", \"google-apps\", \"google\", \"linkedin\", \"oidc\", \"okta\", \"onelogin\", \"pingone\", \"yandex\", \"cloudflare\"." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicates that the identity provider is immutable and cannot be updated or deleted via the API." + }, + { + "name": "saml_certificate_set_id", + "type": "String", + "description": "The UID of the SAML encryption certificate set assigned to this Identity Provider.\nOnly present for SAML identity providers with encryption configured.\nCreate a certificate set via POST to `/identity_providers/{id}/saml_certificate`." + }, + { + "name": "scim_config", + "type": "Attributes", + "description": "The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "A flag to enable or disable SCIM for the identity provider." + }, + { + "name": "identity_update_behavior", + "type": "String", + "description": "Indicates how a SCIM event updates a user identity used for policy evaluation. Use \"automatic\" to automatically update a user's identity and augment it with fields from the SCIM user resource. Use \"reauth\" to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With \"reauth\" identities will not contain fields from the SCIM user resource. With \"no_action\" identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.\nAvailable values: \"automatic\", \"reauth\", \"no_action\"." + }, + { + "name": "scim_base_url", + "type": "String", + "description": "The base URL of Cloudflare's SCIM V2.0 API endpoint." + }, + { + "name": "seat_deprovision", + "type": "Boolean", + "description": "A flag to remove a user's seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user_deprovision is also enabled." + }, + { + "name": "secret", + "type": "String", + "description": "A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity_providers/:idpID/refresh_scim_secret.", + "sensitive": true + }, + { + "name": "user_deprovision", + "type": "Boolean", + "description": "A flag to enable revoking a user's session in Access and Gateway when they have been deprovisioned in the Identity Provider." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "saml_certificate_set", + "type": "Attributes", + "description": "The SAML encryption certificate set details, including current and previous certificates.\nOnly present for SAML identity providers with a certificate set assigned.", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the certificate set was created" + }, + { + "name": "current_certificate", + "type": "Attributes", + "description": "The currently active certificate used for encrypting SAML assertions", + "children": [ + { + "name": "is_current", + "type": "Boolean", + "description": "Indicates whether this is the currently active certificate" + }, + { + "name": "not_after", + "type": "String", + "description": "Certificate expiration date. Certificates are automatically rotated 30 days before expiration." + }, + { + "name": "public_certificate", + "type": "String", + "description": "PEM-encoded X.509 certificate containing the public key.\nConfigure this certificate in your external SAML Identity Provider to enable encryption." + }, + { + "name": "uid", + "type": "String", + "description": "Unique identifier for the certificate" + } + ] + }, + { + "name": "previous_certificate", + "type": "String", + "description": "The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`." + }, + { + "name": "uid", + "type": "String", + "description": "Unique identifier for the certificate set" + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the certificate set was last updated (e.g., during rotation)" + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_identity_providers": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_identity_providers", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "data \"cloudflare_zero_trust_access_identity_providers\" \"example_zero_trust_access_identity_providers\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n scim_enabled = \"scim_enabled\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "scim_enabled", + "type": "String", + "description": "Indicates to Access to only retrieve identity providers that have the System for Cross-Domain Identity Management (SCIM) enabled." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "config", + "type": "Attributes", + "description": "The configuration parameters for the identity provider. To view the required parameters for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).", + "children": [ + { + "name": "apps_domain", + "type": "String", + "description": "Your companies TLD" + }, + { + "name": "attributes", + "type": "List of String", + "description": "A list of SAML attribute names that will be added to your signed JWT token and can be used in SAML policy rules." + }, + { + "name": "auth_url", + "type": "String", + "description": "The authorization_endpoint URL of your IdP" + }, + { + "name": "authorization_server_id", + "type": "String", + "description": "Your okta authorization server id" + }, + { + "name": "centrify_account", + "type": "String", + "description": "Your centrify account url" + }, + { + "name": "centrify_app_id", + "type": "String", + "description": "Your centrify app id" + }, + { + "name": "certs_url", + "type": "String", + "description": "The jwks_uri endpoint of your IdP to allow the IdP keys to sign the tokens" + }, + { + "name": "claims", + "type": "List of String", + "description": "Custom claims" + }, + { + "name": "client_id", + "type": "String", + "description": "Your OAuth Client ID" + }, + { + "name": "client_secret", + "type": "String", + "description": "Your OAuth Client Secret", + "sensitive": true + }, + { + "name": "conditional_access_enabled", + "type": "Boolean", + "description": "Should Cloudflare try to load authentication contexts from your account" + }, + { + "name": "directory_id", + "type": "String", + "description": "Your Azure directory uuid" + }, + { + "name": "email_attribute_name", + "type": "String", + "description": "The attribute name for email in the SAML response." + }, + { + "name": "email_claim_name", + "type": "String", + "description": "The claim name for email in the id_token response." + }, + { + "name": "enable_encryption", + "type": "Boolean", + "description": "Enable SAML assertion encryption. When enabled, the Identity Provider will encrypt\nSAML assertions using the certificate from the assigned certificate set.\n\nTo enable encryption:\n1. Create a certificate set via POST to `/identity_providers/{id}/saml_certificate`\n2. Set this field to `true` and include `saml_certificate_set_id` in the PUT request\n3. Configure the public certificate in your external Identity Provider\n\nNote: Requires `saml_certificate_set_id` to be set when `true`." + }, + { + "name": "force_authn", + "type": "Boolean", + "description": "Asks the IdP to reauthenticate the user for each SAML authentication request." + }, + { + "name": "header_attributes", + "type": "Attributes List", + "description": "Add a list of attribute names that will be returned in the response header from the Access callback.", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "attribute name from the IDP" + }, + { + "name": "header_name", + "type": "String", + "description": "header that will be added on the request to the origin" + } + ] + }, + { + "name": "idp_public_certs", + "type": "List of String", + "description": "X509 certificate to verify the signature in the SAML authentication response" + }, + { + "name": "issuer_url", + "type": "String", + "description": "IdP Entity ID or Issuer URL" + }, + { + "name": "max_sso_url_length", + "type": "Number", + "description": "The maximum URL length the IdP accepts for the SSO redirect URL.\nWhen the constructed SSO URL would exceed this length, the RelayState\nis stored server-side and a short nonce is passed to the IdP instead.\nSet this if your IdP enforces a URL length limit." + }, + { + "name": "okta_account", + "type": "String", + "description": "Your okta account url" + }, + { + "name": "onelogin_account", + "type": "String", + "description": "Your OneLogin account url" + }, + { + "name": "ping_env_id", + "type": "String", + "description": "Your PingOne environment identifier" + }, + { + "name": "pkce_enabled", + "type": "Boolean", + "description": "Enable Proof Key for Code Exchange (PKCE)" + }, + { + "name": "prompt", + "type": "String", + "description": "Indicates the type of user interaction that is required. prompt=login forces the user to enter their credentials on that request, negating single-sign on. prompt=none is the opposite. It ensures that the user isn't presented with any interactive prompt. If the request can't be completed silently by using single-sign on, the Microsoft identity platform returns an interaction_required error. prompt=select_account interrupts single sign-on providing account selection experience listing all the accounts either in session or any remembered account or an option to choose to use a different account altogether.\nAvailable values: \"login\", \"select_account\", \"none\", \"consent\"." + }, + { + "name": "redirect_url", + "type": "String" + }, + { + "name": "restrict_to_account_members", + "type": "Boolean", + "description": "When enabled, only users who are members of your Cloudflare account can authenticate through this identity provider. When disabled, any user with a Cloudflare account can authenticate, subject to your Access policies." + }, + { + "name": "scopes", + "type": "List of String", + "description": "OAuth scopes" + }, + { + "name": "sign_request", + "type": "Boolean", + "description": "Sign the SAML authentication request with Access credentials. To verify the signature, use the public key from the Access certs endpoints." + }, + { + "name": "sso_target_url", + "type": "String", + "description": "URL to send the SAML authentication requests to" + }, + { + "name": "support_groups", + "type": "Boolean", + "description": "Should Cloudflare try to load groups from your account" + }, + { + "name": "token_url", + "type": "String", + "description": "The token_endpoint URL of your IdP" + }, + { + "name": "use_login_hint", + "type": "Boolean", + "description": "Whether to use a previously authenticated Access email as a Google login hint when exactly one email matches the Workspace domain." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "The name of the identity provider, shown to users on the login page." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicates that the identity provider is immutable and cannot be updated or deleted via the API." + }, + { + "name": "saml_certificate_set", + "type": "Attributes", + "description": "The SAML encryption certificate set details, including current and previous certificates.\nOnly present for SAML identity providers with a certificate set assigned.", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the certificate set was created" + }, + { + "name": "current_certificate", + "type": "Attributes", + "description": "The currently active certificate used for encrypting SAML assertions", + "children": [ + { + "name": "is_current", + "type": "Boolean", + "description": "Indicates whether this is the currently active certificate" + }, + { + "name": "not_after", + "type": "String", + "description": "Certificate expiration date. Certificates are automatically rotated 30 days before expiration." + }, + { + "name": "public_certificate", + "type": "String", + "description": "PEM-encoded X.509 certificate containing the public key.\nConfigure this certificate in your external SAML Identity Provider to enable encryption." + }, + { + "name": "uid", + "type": "String", + "description": "Unique identifier for the certificate" + } + ] + }, + { + "name": "previous_certificate", + "type": "String", + "description": "The previous certificate, maintained during rotation to ensure continuity. Null if no rotation has occurred. Mirrors the structure of `saml_certificate`." + }, + { + "name": "uid", + "type": "String", + "description": "Unique identifier for the certificate set" + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the certificate set was last updated (e.g., during rotation)" + } + ] + }, + { + "name": "saml_certificate_set_id", + "type": "String", + "description": "The UID of the SAML encryption certificate set assigned to this Identity Provider.\nOnly present for SAML identity providers with encryption configured.\nCreate a certificate set via POST to `/identity_providers/{id}/saml_certificate`." + }, + { + "name": "scim_config", + "type": "Attributes", + "description": "The configuration settings for enabling a System for Cross-Domain Identity Management (SCIM) with the identity provider.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "A flag to enable or disable SCIM for the identity provider." + }, + { + "name": "identity_update_behavior", + "type": "String", + "description": "Indicates how a SCIM event updates a user identity used for policy evaluation. Use \"automatic\" to automatically update a user's identity and augment it with fields from the SCIM user resource. Use \"reauth\" to force re-authentication on group membership updates, user identity update will only occur after successful re-authentication. With \"reauth\" identities will not contain fields from the SCIM user resource. With \"no_action\" identities will not be changed by SCIM updates in any way and users will not be prompted to reauthenticate.\nAvailable values: \"automatic\", \"reauth\", \"no_action\"." + }, + { + "name": "scim_base_url", + "type": "String", + "description": "The base URL of Cloudflare's SCIM V2.0 API endpoint." + }, + { + "name": "seat_deprovision", + "type": "Boolean", + "description": "A flag to remove a user's seat in Zero Trust when they have been deprovisioned in the Identity Provider. This cannot be enabled unless user_deprovision is also enabled." + }, + { + "name": "secret", + "type": "String", + "description": "A read-only token generated when the SCIM integration is enabled for the first time. It is redacted on subsequent requests. If you lose this you will need to refresh it at /access/identity_providers/:idpID/refresh_scim_secret.", + "sensitive": true + }, + { + "name": "user_deprovision", + "type": "Boolean", + "description": "A flag to enable revoking a user's session in Access and Gateway when they have been deprovisioned in the Identity Provider." + } + ] + }, + { + "name": "type", + "type": "String", + "description": "The type of identity provider. To determine the value for a specific provider, refer to our [developer documentation](https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/).\nAvailable values: \"onetimepin\", \"azureAD\", \"saml\", \"centrify\", \"facebook\", \"github\", \"google-apps\", \"google\", \"linkedin\", \"oidc\", \"okta\", \"onelogin\", \"pingone\", \"yandex\", \"cloudflare\"." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_infrastructure_target": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_infrastructure_target", + "example": "data \"cloudflare_zero_trust_access_infrastructure_target\" \"example_zero_trust_access_infrastructure_target\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n target_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "created_after", + "type": "String", + "description": "Date and time at which the target was created after (inclusive)" + }, + { + "name": "created_before", + "type": "String", + "description": "Date and time at which the target was created before (inclusive)" + }, + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname of a target" + }, + { + "name": "hostname_contains", + "type": "String", + "description": "Partial match to the hostname of a target" + }, + { + "name": "ip_like", + "type": "String", + "description": "Filters for targets whose IP addresses look like the specified string.\nSupports `*` as a wildcard character" + }, + { + "name": "ip_v4", + "type": "String", + "description": "IPv4 address of the target" + }, + { + "name": "ip_v6", + "type": "String", + "description": "IPv6 address of the target" + }, + { + "name": "ips", + "type": "List of String", + "description": "Filters for targets that have any of the following IP addresses. Specify\n`ips` multiple times in query parameter to build list of candidates." + }, + { + "name": "ipv4_end", + "type": "String", + "description": "Defines an IPv4 filter range's ending value (inclusive). Requires\n`ipv4_start` to be specified as well." + }, + { + "name": "ipv4_start", + "type": "String", + "description": "Defines an IPv4 filter range's starting value (inclusive). Requires\n`ipv4_end` to be specified as well." + }, + { + "name": "ipv6_end", + "type": "String", + "description": "Defines an IPv6 filter range's ending value (inclusive). Requires\n`ipv6_start` to be specified as well." + }, + { + "name": "ipv6_start", + "type": "String", + "description": "Defines an IPv6 filter range's starting value (inclusive). Requires\n`ipv6_end` to be specified as well." + }, + { + "name": "modified_after", + "type": "String", + "description": "Date and time at which the target was modified after (inclusive)" + }, + { + "name": "modified_before", + "type": "String", + "description": "Date and time at which the target was modified before (inclusive)" + }, + { + "name": "order", + "type": "String", + "description": "The field to sort by.\nAvailable values: \"hostname\", \"created_at\"." + }, + { + "name": "tag", + "type": "List of String", + "description": "Filter by tag key:value pairs. Multiple `tag` params are AND'd.\nFormat: `tag=key:value` (e.g., `tag=environment:production`).\nKey and value must both be non-empty; `tag=:value` and `tag=key:` return 400." + }, + { + "name": "target_ids", + "type": "List of String", + "description": "Filters for targets that have any of the following UUIDs. Specify\n`target_ids` multiple times in query parameter to build list of\ncandidates." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "Private virtual network identifier of the target" + } + ] + }, + { + "name": "target_id", + "type": "String", + "description": "Target identifier" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Date and time at which the target was created" + }, + { + "name": "hostname", + "type": "String", + "description": "A non-unique field that refers to a target" + }, + { + "name": "id", + "type": "String", + "description": "Target identifier" + }, + { + "name": "ip", + "type": "Attributes", + "description": "The IPv4/IPv6 address that identifies where to reach a target", + "children": [ + { + "name": "ipv4", + "type": "Attributes", + "description": "The target's IPv4 address", + "children": [ + { + "name": "ip_addr", + "type": "String", + "description": "IP address of the target" + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes", + "description": "The target's IPv6 address", + "children": [ + { + "name": "ip_addr", + "type": "String", + "description": "IP address of the target" + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used." + } + ] + } + ] + }, + { + "name": "modified_at", + "type": "String", + "description": "Date and time at which the target was modified" + }, + { + "name": "tags", + "type": "Map of String", + "description": "Tags assigned to the target. Empty when no tags are assigned." + } + ] + }, + "resource:cloudflare_zero_trust_access_infrastructure_target": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_infrastructure_target", + "example": "resource \"cloudflare_zero_trust_access_infrastructure_target\" \"example_zero_trust_access_infrastructure_target\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostname = \"infra-access-target\"\n ip = {\n ipv4 = {\n ip_addr = \"187.26.29.249\"\n virtual_network_id = \"c77b744e-acc8-428f-9257-6878c046ed55\"\n }\n ipv6 = {\n ip_addr = \"64c0:64e8:f0b4:8dbf:7104:72b0:ec8f:f5e0\"\n virtual_network_id = \"c77b744e-acc8-428f-9257-6878c046ed55\"\n }\n }\n tags = {\n foo = \"string\"\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_infrastructure_target.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier" + }, + { + "name": "hostname", + "type": "String", + "description": "A non-unique field that refers to a target. Case insensitive, maximum\nlength of 255 characters, supports the use of special characters dash\nand period, does not support spaces, and must start and end with an\nalphanumeric character." + }, + { + "name": "ip", + "type": "Attributes", + "description": "The IPv4/IPv6 address that identifies where to reach a target", + "children": [ + { + "name": "ipv4", + "type": "Attributes", + "description": "The target's IPv4 address", + "children": [ + { + "name": "ip_addr", + "type": "String", + "description": "IP address of the target" + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes", + "description": "The target's IPv6 address", + "children": [ + { + "name": "ip_addr", + "type": "String", + "description": "IP address of the target" + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used." + } + ] + } + ] + } + ], + "optional": [ + { + "name": "tags", + "type": "Map of String", + "description": "Optional tags to associate with the target. Keys and values are\nuser-defined strings." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Date and time at which the target was created" + }, + { + "name": "id", + "type": "String", + "description": "Target identifier" + }, + { + "name": "modified_at", + "type": "String", + "description": "Date and time at which the target was modified" + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_infrastructure_targets": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_infrastructure_targets", + "example": "data \"cloudflare_zero_trust_access_infrastructure_targets\" \"example_zero_trust_access_infrastructure_targets\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_after = \"2019-12-27T18:11:19.117Z\"\n created_before = \"2019-12-27T18:11:19.117Z\"\n direction = \"asc\"\n hostname = \"hostname\"\n hostname_contains = \"hostname_contains\"\n ip_like = \"ip_like\"\n ip_v4 = \"ip_v4\"\n ip_v6 = \"ip_v6\"\n ips = [\"string\"]\n ipv4_end = \"ipv4_end\"\n ipv4_start = \"ipv4_start\"\n ipv6_end = \"ipv6_end\"\n ipv6_start = \"ipv6_start\"\n modified_after = \"2019-12-27T18:11:19.117Z\"\n modified_before = \"2019-12-27T18:11:19.117Z\"\n order = \"hostname\"\n tag = [\"string\"]\n target_ids = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n virtual_network_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Account identifier" + }, + { + "name": "created_after", + "type": "String", + "description": "Date and time at which the target was created after (inclusive)" + }, + { + "name": "created_before", + "type": "String", + "description": "Date and time at which the target was created before (inclusive)" + }, + { + "name": "direction", + "type": "String", + "description": "The sorting direction.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "hostname", + "type": "String", + "description": "Hostname of a target" + }, + { + "name": "hostname_contains", + "type": "String", + "description": "Partial match to the hostname of a target" + }, + { + "name": "ip_like", + "type": "String", + "description": "Filters for targets whose IP addresses look like the specified string.\nSupports `*` as a wildcard character" + }, + { + "name": "ip_v4", + "type": "String", + "description": "IPv4 address of the target" + }, + { + "name": "ip_v6", + "type": "String", + "description": "IPv6 address of the target" + }, + { + "name": "ips", + "type": "List of String", + "description": "Filters for targets that have any of the following IP addresses. Specify\n`ips` multiple times in query parameter to build list of candidates." + }, + { + "name": "ipv4_end", + "type": "String", + "description": "Defines an IPv4 filter range's ending value (inclusive). Requires\n`ipv4_start` to be specified as well." + }, + { + "name": "ipv4_start", + "type": "String", + "description": "Defines an IPv4 filter range's starting value (inclusive). Requires\n`ipv4_end` to be specified as well." + }, + { + "name": "ipv6_end", + "type": "String", + "description": "Defines an IPv6 filter range's ending value (inclusive). Requires\n`ipv6_start` to be specified as well." + }, + { + "name": "ipv6_start", + "type": "String", + "description": "Defines an IPv6 filter range's starting value (inclusive). Requires\n`ipv6_end` to be specified as well." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "modified_after", + "type": "String", + "description": "Date and time at which the target was modified after (inclusive)" + }, + { + "name": "modified_before", + "type": "String", + "description": "Date and time at which the target was modified before (inclusive)" + }, + { + "name": "order", + "type": "String", + "description": "The field to sort by.\nAvailable values: \"hostname\", \"created_at\"." + }, + { + "name": "tag", + "type": "List of String", + "description": "Filter by tag key:value pairs. Multiple `tag` params are AND'd.\nFormat: `tag=key:value` (e.g., `tag=environment:production`).\nKey and value must both be non-empty; `tag=:value` and `tag=key:` return 400." + }, + { + "name": "target_ids", + "type": "List of String", + "description": "Filters for targets that have any of the following UUIDs. Specify\n`target_ids` multiple times in query parameter to build list of\ncandidates." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "Private virtual network identifier of the target" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "Date and time at which the target was created" + }, + { + "name": "hostname", + "type": "String", + "description": "A non-unique field that refers to a target" + }, + { + "name": "id", + "type": "String", + "description": "Target identifier" + }, + { + "name": "ip", + "type": "Attributes", + "description": "The IPv4/IPv6 address that identifies where to reach a target", + "children": [ + { + "name": "ipv4", + "type": "Attributes", + "description": "The target's IPv4 address", + "children": [ + { + "name": "ip_addr", + "type": "String", + "description": "IP address of the target" + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes", + "description": "The target's IPv6 address", + "children": [ + { + "name": "ip_addr", + "type": "String", + "description": "IP address of the target" + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "(optional) Private virtual network identifier for the target. If omitted, the default virtual network ID will be used." + } + ] + } + ] + }, + { + "name": "modified_at", + "type": "String", + "description": "Date and time at which the target was modified" + }, + { + "name": "tags", + "type": "Map of String", + "description": "Tags assigned to the target. Empty when no tags are assigned." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_key_configuration": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_key_configuration", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "data \"cloudflare_zero_trust_access_key_configuration\" \"example_zero_trust_access_key_configuration\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "days_until_next_rotation", + "type": "Number", + "description": "The number of days until the next key rotation." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "key_rotation_interval_days", + "type": "Number", + "description": "The number of days between key rotations." + }, + { + "name": "last_key_rotation_at", + "type": "String", + "description": "The timestamp of the previous key rotation." + } + ] + }, + "resource:cloudflare_zero_trust_access_key_configuration": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_key_configuration", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "resource \"cloudflare_zero_trust_access_key_configuration\" \"example_zero_trust_access_key_configuration\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n key_rotation_interval_days = 30\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_key_configuration.example ''", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "key_rotation_interval_days", + "type": "Number", + "description": "The number of days between key rotations." + } + ], + "optional": [], + "computed": [ + { + "name": "days_until_next_rotation", + "type": "Number", + "description": "The number of days until the next key rotation." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "last_key_rotation_at", + "type": "String", + "description": "The timestamp of the previous key rotation." + } + ] + }, + "data-source:cloudflare_zero_trust_access_mtls_certificate": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_mtls_certificate", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`", + "example": "data \"cloudflare_zero_trust_access_mtls_certificate\" \"example_zero_trust_access_mtls_certificate\" {\n certificate_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "certificate_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "associated_hostnames", + "type": "List of String", + "description": "The hostnames of the applications that will use this certificate." + }, + { + "name": "expires_on", + "type": "String" + }, + { + "name": "fingerprint", + "type": "String", + "description": "The MD5 fingerprint of the certificate." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "The name of the certificate." + } + ] + }, + "resource:cloudflare_zero_trust_access_mtls_certificate": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_mtls_certificate", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`", + "example": "resource \"cloudflare_zero_trust_access_mtls_certificate\" \"example_zero_trust_access_mtls_certificate\" {\n certificate = </'", + "required": [ + { + "name": "certificate", + "type": "String", + "description": "The certificate content." + }, + { + "name": "name", + "type": "String", + "description": "The name of the certificate." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "associated_hostnames", + "type": "Set of String", + "description": "The hostnames of the applications that will use this certificate." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "expires_on", + "type": "String" + }, + { + "name": "fingerprint", + "type": "String", + "description": "The MD5 fingerprint of the certificate." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the application that will use this certificate." + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_mtls_certificates": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_mtls_certificates", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`", + "example": "data \"cloudflare_zero_trust_access_mtls_certificates\" \"example_zero_trust_access_mtls_certificates\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "associated_hostnames", + "type": "List of String", + "description": "The hostnames of the applications that will use this certificate." + }, + { + "name": "expires_on", + "type": "String" + }, + { + "name": "fingerprint", + "type": "String", + "description": "The MD5 fingerprint of the certificate." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the application that will use this certificate." + }, + { + "name": "name", + "type": "String", + "description": "The name of the certificate." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_mtls_hostname_settings": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_mtls_hostname_settings", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`", + "example": "data \"cloudflare_zero_trust_access_mtls_hostname_settings\" \"example_zero_trust_access_mtls_hostname_settings\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "china_network", + "type": "Boolean", + "description": "Request client certificates for this hostname in China. Can only be set to true if this zone is china network enabled." + }, + { + "name": "client_certificate_forwarding", + "type": "Boolean", + "description": "Client Certificate Forwarding is a feature that takes the client cert provided by the eyeball to the edge, and forwards it to the origin as a HTTP header to allow logging on the origin." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname that these settings apply to." + } + ] + }, + "resource:cloudflare_zero_trust_access_mtls_hostname_settings": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_mtls_hostname_settings", + "description": "Accepted Permissions\n\n- `Access: Mutual TLS Certificates Read`\n- `Access: Mutual TLS Certificates Write`", + "example": "resource \"cloudflare_zero_trust_access_mtls_hostname_settings\" \"example_zero_trust_access_mtls_hostname_settings\" {\n settings = [{\n china_network = false\n client_certificate_forwarding = true\n hostname = \"admin.example.com\"\n }]\n zone_id = \"zone_id\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_mtls_hostname_settings.example '<{accounts|zones}/{account_id|zone_id}>'", + "required": [ + { + "name": "settings", + "type": "Attributes List", + "children": [ + { + "name": "china_network", + "type": "Boolean", + "description": "Request client certificates for this hostname in China. Can only be set to true if this zone is china network enabled." + }, + { + "name": "client_certificate_forwarding", + "type": "Boolean", + "description": "Client Certificate Forwarding is a feature that takes the client cert provided by the eyeball to the edge, and forwards it to the origin as a HTTP header to allow logging on the origin." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname that these settings apply to." + } + ] + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "china_network", + "type": "Boolean", + "description": "Request client certificates for this hostname in China. Can only be set to true if this zone is china network enabled." + }, + { + "name": "client_certificate_forwarding", + "type": "Boolean", + "description": "Client Certificate Forwarding is a feature that takes the client cert provided by the eyeball to the edge, and forwards it to the origin as a HTTP header to allow logging on the origin." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname that these settings apply to." + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_policies": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_policies", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Write`", + "example": "data \"cloudflare_zero_trust_access_policies\" \"example_zero_trust_access_policies\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "app_count", + "type": "Number", + "description": "Number of access applications currently using this policy." + }, + { + "name": "approval_groups", + "type": "Attributes Set", + "description": "Administrators who can approve a temporary authentication request.", + "children": [ + { + "name": "approvals_needed", + "type": "Number", + "description": "The number of approvals needed to obtain access." + }, + { + "name": "email_addresses", + "type": "List of String", + "description": "A list of emails that can approve the access request." + }, + { + "name": "email_list_uuid", + "type": "String", + "description": "The UUID of an re-usable email list." + } + ] + }, + { + "name": "approval_required", + "type": "Boolean", + "description": "Requires the user to request access from an administrator at the start of each session." + }, + { + "name": "connection_rules", + "type": "Attributes", + "description": "The rules that define how users may connect to targets secured by your application.", + "children": [ + { + "name": "rdp", + "type": "Attributes", + "description": "The RDP-specific rules that define clipboard behavior for RDP connections.", + "children": [ + { + "name": "allowed_clipboard_local_to_remote_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from local machine to remote RDP session." + }, + { + "name": "allowed_clipboard_remote_to_local_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from remote RDP session to local machine." + } + ] + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "decision", + "type": "String", + "description": "The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.\nAvailable values: \"allow\", \"deny\", \"non_identity\", \"bypass\"." + }, + { + "name": "exclude", + "type": "Attributes Set", + "description": "Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the policy" + }, + { + "name": "include", + "type": "Attributes Set", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "isolation_required", + "type": "Boolean", + "description": "Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "Lists the MFA methods that users can authenticate with." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Indicates whether to disable MFA for this resource. This option is available at the application and policy level." + }, + { + "name": "session_duration", + "type": "String", + "description": "Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access policy." + }, + { + "name": "purpose_justification_prompt", + "type": "String", + "description": "A custom message that will appear on the purpose justification screen." + }, + { + "name": "purpose_justification_required", + "type": "Boolean", + "description": "Require users to enter a justification when they log in to the application." + }, + { + "name": "require", + "type": "Attributes Set", + "description": "Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "reusable", + "type": "Boolean" + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h." + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_policy": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_policy", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Write`", + "example": "data \"cloudflare_zero_trust_access_policy\" \"example_zero_trust_access_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "policy_id", + "type": "String", + "description": "The UUID of the policy" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "app_count", + "type": "Number", + "description": "Number of access applications currently using this policy." + }, + { + "name": "approval_groups", + "type": "Attributes Set", + "description": "Administrators who can approve a temporary authentication request.", + "children": [ + { + "name": "approvals_needed", + "type": "Number", + "description": "The number of approvals needed to obtain access." + }, + { + "name": "email_addresses", + "type": "List of String", + "description": "A list of emails that can approve the access request." + }, + { + "name": "email_list_uuid", + "type": "String", + "description": "The UUID of an re-usable email list." + } + ] + }, + { + "name": "approval_required", + "type": "Boolean", + "description": "Requires the user to request access from an administrator at the start of each session." + }, + { + "name": "connection_rules", + "type": "Attributes", + "description": "The rules that define how users may connect to targets secured by your application.", + "children": [ + { + "name": "rdp", + "type": "Attributes", + "description": "The RDP-specific rules that define clipboard behavior for RDP connections.", + "children": [ + { + "name": "allowed_clipboard_local_to_remote_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from local machine to remote RDP session." + }, + { + "name": "allowed_clipboard_remote_to_local_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from remote RDP session to local machine." + } + ] + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "decision", + "type": "String", + "description": "The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.\nAvailable values: \"allow\", \"deny\", \"non_identity\", \"bypass\"." + }, + { + "name": "exclude", + "type": "Attributes Set", + "description": "Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the policy" + }, + { + "name": "include", + "type": "Attributes Set", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "isolation_required", + "type": "Boolean", + "description": "Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "Lists the MFA methods that users can authenticate with." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Indicates whether to disable MFA for this resource. This option is available at the application and policy level." + }, + { + "name": "session_duration", + "type": "String", + "description": "Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access policy." + }, + { + "name": "purpose_justification_prompt", + "type": "String", + "description": "A custom message that will appear on the purpose justification screen." + }, + { + "name": "purpose_justification_required", + "type": "Boolean", + "description": "Require users to enter a justification when they log in to the application." + }, + { + "name": "require", + "type": "Attributes Set", + "description": "Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "reusable", + "type": "Boolean" + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_access_policy": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_policy", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Write`", + "example": "resource \"cloudflare_zero_trust_access_policy\" \"example_zero_trust_access_policy\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n decision = \"allow\"\n include = [{\n certificate = {\n\n }\n }]\n name = \"Allow devs\"\n approval_groups = [{\n approvals_needed = 1\n email_addresses = [\"test1@cloudflare.com\", \"test2@cloudflare.com\"]\n email_list_uuid = \"email_list_uuid\"\n }, {\n approvals_needed = 3\n email_addresses = [\"test@cloudflare.com\", \"test2@cloudflare.com\"]\n email_list_uuid = \"597147a1-976b-4ef2-9af0-81d5d007fc34\"\n }]\n approval_required = true\n connection_rules = {\n rdp = {\n allowed_clipboard_local_to_remote_formats = [\"text\", \"file\"]\n allowed_clipboard_remote_to_local_formats = [\"text\", \"file\"]\n }\n }\n exclude = [{\n certificate = {\n\n }\n }]\n isolation_required = false\n mfa_config = {\n allowed_authenticators = [\"totp\", \"biometrics\", \"security_key\"]\n mfa_disabled = false\n session_duration = \"24h\"\n }\n purpose_justification_prompt = \"Please enter a justification for entering this protected domain.\"\n purpose_justification_required = true\n require = [{\n certificate = {\n\n }\n }]\n session_duration = \"24h\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_policy.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "decision", + "type": "String", + "description": "The action Access will take if a user matches this policy. Infrastructure application policies can only use the Allow action.\nAvailable values: \"allow\", \"deny\", \"non_identity\", \"bypass\"." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Access policy." + } + ], + "optional": [ + { + "name": "approval_groups", + "type": "Attributes Set", + "description": "Administrators who can approve a temporary authentication request.", + "children": [ + { + "name": "approvals_needed", + "type": "Number", + "description": "The number of approvals needed to obtain access." + }, + { + "name": "email_addresses", + "type": "List of String", + "description": "A list of emails that can approve the access request." + }, + { + "name": "email_list_uuid", + "type": "String", + "description": "The UUID of an re-usable email list." + } + ] + }, + { + "name": "approval_required", + "type": "Boolean", + "description": "Requires the user to request access from an administrator at the start of each session." + }, + { + "name": "connection_rules", + "type": "Attributes", + "description": "The rules that define how users may connect to targets secured by your application.", + "children": [ + { + "name": "rdp", + "type": "Attributes", + "description": "The RDP-specific rules that define clipboard behavior for RDP connections.", + "children": [ + { + "name": "allowed_clipboard_local_to_remote_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from local machine to remote RDP session." + }, + { + "name": "allowed_clipboard_remote_to_local_formats", + "type": "List of String", + "description": "Clipboard formats allowed when copying from remote RDP session to local machine." + } + ] + } + ] + }, + { + "name": "exclude", + "type": "Attributes Set", + "description": "Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "include", + "type": "Attributes Set", + "description": "Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "isolation_required", + "type": "Boolean", + "description": "Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use this feature." + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "Lists the MFA methods that users can authenticate with." + }, + { + "name": "mfa_disabled", + "type": "Boolean", + "description": "Indicates whether to disable MFA for this resource. This option is available at the application and policy level." + }, + { + "name": "session_duration", + "type": "String", + "description": "Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`." + } + ] + }, + { + "name": "purpose_justification_prompt", + "type": "String", + "description": "A custom message that will appear on the purpose justification screen." + }, + { + "name": "purpose_justification_required", + "type": "Boolean", + "description": "Require users to enter a justification when they log in to the application." + }, + { + "name": "require", + "type": "Attributes Set", + "description": "Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.", + "children": [ + { + "name": "any_valid_service_token", + "type": "Attributes", + "description": "An empty object which matches on all service tokens." + }, + { + "name": "auth_context", + "type": "Attributes", + "children": [ + { + "name": "ac_id", + "type": "String", + "description": "The ACID of an Authentication context." + }, + { + "name": "id", + "type": "String", + "description": "The ID of an Authentication context." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "auth_method", + "type": "Attributes", + "children": [ + { + "name": "auth_method", + "type": "String", + "description": "The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2." + } + ] + }, + { + "name": "azure_ad", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an Azure group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Azure identity provider." + } + ] + }, + { + "name": "certificate", + "type": "Attributes" + }, + { + "name": "cloudflare_account_member", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ] + }, + { + "name": "common_name", + "type": "Attributes", + "children": [ + { + "name": "common_name", + "type": "String", + "description": "The common name to match." + } + ] + }, + { + "name": "device_posture", + "type": "Attributes", + "children": [ + { + "name": "account_id", + "type": "String", + "description": "The ID of the account that owns the device posture integration." + }, + { + "name": "integration_uid", + "type": "String", + "description": "The ID of a device posture integration." + } + ] + }, + { + "name": "email", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the user." + } + ] + }, + { + "name": "email_domain", + "type": "Attributes", + "children": [ + { + "name": "domain", + "type": "String", + "description": "The email domain to match." + } + ] + }, + { + "name": "email_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created email list." + } + ] + }, + { + "name": "everyone", + "type": "Attributes", + "description": "An empty object which matches on all users." + }, + { + "name": "external_evaluation", + "type": "Attributes", + "children": [ + { + "name": "evaluate_url", + "type": "String", + "description": "The API endpoint containing your business logic." + }, + { + "name": "keys_url", + "type": "String", + "description": "The API endpoint containing the key that Access uses to verify that the response came from your API." + } + ] + }, + { + "name": "geo", + "type": "Attributes", + "children": [ + { + "name": "country_code", + "type": "String", + "description": "The country code that should be matched." + } + ] + }, + { + "name": "github_organization", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Github identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the organization." + }, + { + "name": "team", + "type": "String", + "description": "The name of the team" + } + ] + }, + { + "name": "group", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created Access group." + } + ] + }, + { + "name": "gsuite", + "type": "Attributes", + "children": [ + { + "name": "email", + "type": "String", + "description": "The email of the Google Workspace group." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Google Workspace identity provider." + } + ] + }, + { + "name": "ip", + "type": "Attributes", + "children": [ + { + "name": "ip", + "type": "String", + "description": "An IPv4 or IPv6 CIDR block." + } + ] + }, + { + "name": "ip_list", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of a previously created IP list." + } + ] + }, + { + "name": "linked_app_token", + "type": "Attributes", + "children": [ + { + "name": "app_uid", + "type": "String", + "description": "The ID of an Access OIDC SaaS application" + } + ] + }, + { + "name": "login_method", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "The ID of an identity provider." + } + ] + }, + { + "name": "oidc", + "type": "Attributes", + "children": [ + { + "name": "claim_name", + "type": "String", + "description": "The name of the OIDC claim." + }, + { + "name": "claim_value", + "type": "String", + "description": "The OIDC claim value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your OIDC identity provider." + } + ] + }, + { + "name": "okta", + "type": "Attributes", + "children": [ + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your Okta identity provider." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Okta group." + } + ] + }, + { + "name": "saml", + "type": "Attributes", + "children": [ + { + "name": "attribute_name", + "type": "String", + "description": "The name of the SAML attribute." + }, + { + "name": "attribute_value", + "type": "String", + "description": "The SAML attribute value to look for." + }, + { + "name": "identity_provider_id", + "type": "String", + "description": "The ID of your SAML identity provider." + } + ] + }, + { + "name": "service_token", + "type": "Attributes", + "children": [ + { + "name": "token_id", + "type": "String", + "description": "The ID of a Service Token." + } + ] + }, + { + "name": "user_risk_score", + "type": "Attributes", + "children": [ + { + "name": "user_risk_score", + "type": "List of String", + "description": "A list of risk score levels to match. Values can be low, medium, high, or unscored." + } + ] + } + ] + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for the application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h." + } + ], + "computed": [ + { + "name": "app_count", + "type": "Number", + "description": "Number of access applications currently using this policy." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the policy" + }, + { + "name": "reusable", + "type": "Boolean" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "data-source:cloudflare_zero_trust_access_service_token": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_service_token", + "description": "Accepted Permissions\n\n- `Access: Service Tokens Read`\n- `Access: Service Tokens Write`", + "example": "data \"cloudflare_zero_trust_access_service_token\" \"example_zero_trust_access_service_token\" {\n service_token_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "name", + "type": "String", + "description": "The name of the service token." + }, + { + "name": "search", + "type": "String", + "description": "Search for service tokens by other listed query parameters." + } + ] + }, + { + "name": "service_token_id", + "type": "String", + "description": "UUID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "client_id", + "type": "String", + "description": "The Client ID for the service token. Access will check for this value in the `CF-Access-Client-ID` request header." + }, + { + "name": "duration", + "type": "String", + "description": "The duration for how long the service token will be valid. Must be in the format `300ms` or `2h45m`, or the special value `forever` for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h)." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous `client_secret` stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create." + }, + { + "name": "expires_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "name", + "type": "String", + "description": "The name of the service token." + } + ] + }, + "resource:cloudflare_zero_trust_access_service_token": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_service_token", + "description": "Accepted Permissions\n\n- `Access: Service Tokens Read`\n- `Access: Service Tokens Write`", + "example": "resource \"cloudflare_zero_trust_access_service_token\" \"example_zero_trust_access_service_token\" {\n name = \"CI/CD token\"\n zone_id = \"zone_id\"\n client_secret_version = 0\n duration = \"60m\"\n enabled = true\n previous_client_secret_expires_at = \"2014-01-01T05:20:00.12345Z\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_service_token.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "name", + "type": "String", + "description": "The name of the service token." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "client_secret_version", + "type": "Number", + "description": "A version number identifying the current `client_secret` associated with the service token. Incrementing it triggers a rotation; the previous secret will still be accepted until the time indicated by `previous_client_secret_expires_at`." + }, + { + "name": "duration", + "type": "String", + "description": "The duration for how long the service token will be valid. Must be in the format `300ms` or `2h45m`, or the special value `forever` for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h)." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous `client_secret` stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create." + }, + { + "name": "previous_client_secret_expires_at", + "type": "String", + "description": "The expiration of the previous `client_secret`. This can be modified at any point after a rotation. For example, you may extend it further into the future if you need more time to update services with the new secret; or move it into the past to immediately invalidate the previous token in case of compromise." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "client_id", + "type": "String", + "description": "The Client ID for the service token. Access will check for this value in the `CF-Access-Client-ID` request header." + }, + { + "name": "client_secret", + "type": "String", + "description": "The Client Secret for the service token. Access will check for this value in the `CF-Access-Client-Secret` request header.", + "sensitive": true + }, + { + "name": "expires_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of the service token." + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_service_tokens": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_service_tokens", + "description": "Accepted Permissions\n\n- `Access: Service Tokens Read`\n- `Access: Service Tokens Write`", + "example": "data \"cloudflare_zero_trust_access_service_tokens\" \"example_zero_trust_access_service_tokens\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n name = \"name\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "The name of the service token." + }, + { + "name": "search", + "type": "String", + "description": "Search for service tokens by other listed query parameters." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "client_id", + "type": "String", + "description": "The Client ID for the service token. Access will check for this value in the `CF-Access-Client-ID` request header." + }, + { + "name": "duration", + "type": "String", + "description": "The duration for how long the service token will be valid. Must be in the format `300ms` or `2h45m`, or the special value `forever` for non-expiring tokens. Valid time units are: ns, us (or µs), ms, s, m, h. The default is 1 year in hours (8760h)." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the service token is enabled. A disabled service token cannot be used to authenticate; both its current and previous `client_secret` stop being accepted, but the token itself is preserved and can be re-enabled at any time. Defaults to enabled when omitted on create." + }, + { + "name": "expires_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of the service token." + }, + { + "name": "name", + "type": "String", + "description": "The name of the service token." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_short_lived_certificate": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_short_lived_certificate", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Write`", + "example": "data \"cloudflare_zero_trust_access_short_lived_certificate\" \"example_zero_trust_access_short_lived_certificate\" {\n app_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "app_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "aud", + "type": "String", + "description": "The Application Audience (AUD) tag. Identifies the application associated with the CA." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "public_key", + "type": "String", + "description": "The public key to add to your SSH server configuration." + } + ] + }, + "resource:cloudflare_zero_trust_access_short_lived_certificate": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_short_lived_certificate", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Write`", + "example": "resource \"cloudflare_zero_trust_access_short_lived_certificate\" \"example_zero_trust_access_short_lived_certificate\" {\n app_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n zone_id = \"zone_id\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_short_lived_certificate.example '<{accounts|zones}/{account_id|zone_id}>/'", + "required": [ + { + "name": "app_id", + "type": "String", + "description": "UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "aud", + "type": "String", + "description": "The Application Audience (AUD) tag. Identifies the application associated with the CA." + }, + { + "name": "id", + "type": "String", + "description": "UUID." + }, + { + "name": "public_key", + "type": "String", + "description": "The public key to add to your SSH server configuration." + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_short_lived_certificates": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_short_lived_certificates", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Write`", + "example": "data \"cloudflare_zero_trust_access_short_lived_certificates\" \"example_zero_trust_access_short_lived_certificates\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "aud", + "type": "String", + "description": "The Application Audience (AUD) tag. Identifies the application associated with the CA." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the CA." + }, + { + "name": "public_key", + "type": "String", + "description": "The public key to add to your SSH server configuration." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_access_tag": { + "kind": "data-source", + "name": "cloudflare_zero_trust_access_tag", + "example": "data \"cloudflare_zero_trust_access_tag\" \"example_zero_trust_access_tag\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tag_name = \"engineers\"\n}", + "required": [ + { + "name": "tag_name", + "type": "String", + "description": "The name of the tag" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The name of the tag" + }, + { + "name": "name", + "type": "String", + "description": "The name of the tag" + } + ] + }, + "resource:cloudflare_zero_trust_access_tag": { + "kind": "resource", + "name": "cloudflare_zero_trust_access_tag", + "example": "resource \"cloudflare_zero_trust_access_tag\" \"example_zero_trust_access_tag\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"engineers\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_access_tag.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "name", + "type": "String", + "description": "The name of the tag" + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The name of the tag" + } + ] + }, + "list-data-source:cloudflare_zero_trust_access_tags": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_access_tags", + "example": "data \"cloudflare_zero_trust_access_tags\" \"example_zero_trust_access_tags\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "id", + "type": "String", + "description": "The name of the tag" + }, + { + "name": "name", + "type": "String", + "description": "The name of the tag" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_casb_integration": { + "kind": "data-source", + "name": "cloudflare_zero_trust_casb_integration", + "example": "data \"cloudflare_zero_trust_casb_integration\" \"example_zero_trust_casb_integration\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = \"id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "application", + "type": "String", + "description": "Filter by application/vendor (e.g., GOOGLE_WORKSPACE, MICROSOFT_INTERNAL)." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "dlp_enabled", + "type": "Boolean", + "description": "Filter by DLP enabled status (true/false)." + }, + { + "name": "order", + "type": "String", + "description": "Field to order results by.\nAvailable values: \"application\", \"created\", \"name\", \"status\"." + }, + { + "name": "page", + "type": "Number", + "description": "Page number within the paginated result set." + }, + { + "name": "page_size", + "type": "Number", + "description": "Number of results per page." + }, + { + "name": "search", + "type": "String", + "description": "Search integrations by name or application." + }, + { + "name": "status", + "type": "String", + "description": "Filter by integration status.\nAvailable values: \"Healthy\", \"Initializing\", \"Offline\", \"Unhealthy\"." + }, + { + "name": "use_cases", + "type": "String", + "description": "Filter by one enabled use case (for example, casb or ces)." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Integration ID to look up. Exactly one of `id` or `filter` must be configured." + } + ], + "computed": [ + { + "name": "application", + "type": "Map of String" + }, + { + "name": "auth_method", + "type": "Map of String", + "description": "The integration's authentication method." + }, + { + "name": "authorization_link", + "type": "Attributes", + "description": "Authorization link for the integration.", + "children": [ + { + "name": "components", + "type": "Map of String" + }, + { + "name": "link", + "type": "String" + } + ] + }, + { + "name": "created", + "type": "String", + "description": "When the integration was created." + }, + { + "name": "credentials_expiry", + "type": "String", + "description": "Credentials expiry time." + }, + { + "name": "dlp_profiles", + "type": "List of String", + "description": "DLP Profiles enabled for the integration." + }, + { + "name": "health_details", + "type": "List of Map of String", + "description": "Health details with remediation hints." + }, + { + "name": "is_paused", + "type": "Boolean", + "description": "Whether the user paused the integration." + }, + { + "name": "last_hydrated", + "type": "String", + "description": "Last time the integration was hydrated." + }, + { + "name": "name", + "type": "String", + "description": "Name of the integration." + }, + { + "name": "status", + "type": "String", + "description": "Integration status." + }, + { + "name": "updated", + "type": "String", + "description": "When the integration was last updated." + }, + { + "name": "use_cases", + "type": "List of Map of String", + "description": "Use cases enabled for the integration." + } + ] + }, + "resource:cloudflare_zero_trust_casb_integration": { + "kind": "resource", + "name": "cloudflare_zero_trust_casb_integration", + "description": "Creates and manages a CASB integration. Exactly one vendor and exactly one authentication method must be configured.", + "example": "# Exactly one vendor and exactly one authentication method must be configured.\n#\n# Confidential arguments (API keys, service account keys) are write-only:\n# Terraform sends them to the provider but does not store them directly in state.\n# Only a secure digest is stored so Terraform can detect secret rotation. Rotating\n# a secret updates the integration in place; it does not recreate it.\n#\n# Non-confidential arguments are stored in state and diffed normally.\n#\n# Changing the vendor or the authentication method does force the integration to\n# be recreated, because the update API cannot change either one.\n#\n# Write-only arguments require Terraform 1.11 or later, and may be fed from\n# ephemeral resources so the secret never touches disk.\n\nresource \"cloudflare_zero_trust_casb_integration\" \"google_cloud_platform\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Google Cloud Platform integration\"\n paused = false\n\n google_cloud_platform = {\n google_cloud_platform_service_account = {\n service_account_key_json = file(\"service-account-key.json\")\n }\n }\n}\n\nresource \"cloudflare_zero_trust_casb_integration\" \"google_workspace\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Google Workspace integration\"\n paused = false\n\n google_workspace = {\n google_domain_wide_delegation_service_account = {\n service_account_key_json = file(\"service-account-key.json\")\n administrator_email = \"admin@example.com\"\n }\n }\n}\n\nresource \"cloudflare_zero_trust_casb_integration\" \"anthropic\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Anthropic integration\"\n paused = false\n\n anthropic = {\n # One of anthropic_admin_api_key, anthropic_workspace_api_key or\n # anthropic_compliance_api_key.\n anthropic_admin_api_key = {\n api_key = var.anthropic_admin_api_key\n\n # Optional: auto-extracted from the key when omitted.\n tenant_id = \"org_01234567-89ab-cdef-0123-456789abcdef\"\n }\n }\n}\n\nresource \"cloudflare_zero_trust_casb_integration\" \"openai\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My OpenAI integration\"\n paused = false\n\n # Also enrol the integration in continuous evaluation and let it remediate\n # findings automatically. Defaults to [\"casb\"] when omitted.\n use_cases = [\"casb\", \"ces\", \"auto_remediation\"]\n\n openai = {\n # chatgpt_compliance_api_key requires an OpenAI Enterprise plan.\n chatgpt_standard_api_key = {\n admin_api_key = var.openai_admin_api_key\n organization_id = \"org-abc123\"\n\n # Optional: only needed for DLP scanning.\n project_api_key = var.openai_project_api_key\n project_id = \"proj_abc123\"\n }\n }\n}\n\nresource \"cloudflare_zero_trust_casb_integration\" \"aws\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My AWS integration\"\n paused = false\n\n aws = {\n # Nothing here is confidential: the external ID is useless without\n # Cloudflare's AWS principal, so no secrets_digest is needed to track it.\n aws_iam_role = {\n role_arn = \"arn:aws:iam::123456789012:role/Cloudflare_DSPM_Auditor\"\n external_id = var.aws_external_id\n }\n }\n}\n\n# Before creating a Box integration, add the Cloudflare CASB application to\n# your Box account:\n#\n# 1. Sign in to the Box Admin Console with Admin permission.\n# 2. Open Integrations > Platform Apps Manager and select Server Authentication Apps.\n# 3. Click Add Platform App and enter the Cloudflare CASB client ID:\n# puaghckpy0578r8p6f3g0rf860unup4r\n# 4. In Accounts & Billing, copy the Enterprise ID and use it below.\n#\n# For details, refer to:\n# https://developer.box.com/guides/authorization/platform-app-approval/#as-an-admin\nresource \"cloudflare_zero_trust_casb_integration\" \"box\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n name = \"My Box integration\"\n paused = false\n\n # Restrict DLP scanning to specific profiles. Omit to let Cloudflare assign\n # the account defaults.\n dlp_profiles = [\"b0d1e2f3-4567-89ab-cdef-0123456789ab\"]\n\n box = {\n box_server_authentication = {\n enterprise_id = \"1234567\"\n }\n }\n}", + "importExample": "# Define the resource with its vendor, authentication method, and credentials before importing.\n$ terraform import cloudflare_zero_trust_casb_integration.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account identifier." + }, + { + "name": "name", + "type": "String", + "description": "Name of the integration." + }, + { + "name": "paused", + "type": "Boolean", + "description": "Whether the integration is paused." + } + ], + "optional": [ + { + "name": "anthropic", + "type": "Attributes", + "description": "Anthropic integration configuration.", + "children": [ + { + "name": "anthropic_admin_api_key", + "type": "Attributes", + "description": "Authenticate with an Anthropic Admin API key.", + "children": [ + { + "name": "api_key", + "type": "String", + "description": "Anthropic Admin API key. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "tenant_id", + "type": "String", + "description": "Organization ID. Auto-extracted from the key if not provided." + } + ] + }, + { + "name": "anthropic_compliance_api_key", + "type": "Attributes", + "description": "Authenticate with an Anthropic Compliance API key.", + "children": [ + { + "name": "compliance_api_key", + "type": "String", + "description": "Anthropic Compliance API key. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "tenant_id", + "type": "String", + "description": "Organization ID. Auto-extracted from the key if not provided." + } + ] + }, + { + "name": "anthropic_workspace_api_key", + "type": "Attributes", + "description": "Authenticate with an Anthropic Workspace API key.", + "children": [ + { + "name": "api_key", + "type": "String", + "description": "Anthropic Workspace API key. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "tenant_id", + "type": "String", + "description": "Workspace ID, found in the Anthropic Console URL after /workspaces/." + } + ] + } + ] + }, + { + "name": "aws", + "type": "Attributes", + "description": "AWS integration configuration.", + "children": [ + { + "name": "aws_iam_role", + "type": "Attributes", + "description": "Authenticate by delegating to a cross-account IAM role.", + "children": [ + { + "name": "external_id", + "type": "String", + "description": "External ID required when assuming the IAM role." + }, + { + "name": "role_arn", + "type": "String", + "description": "ARN of the cross-account IAM role Cloudflare will assume." + } + ] + } + ] + }, + { + "name": "box", + "type": "Attributes", + "description": "Box integration configuration.", + "children": [ + { + "name": "box_server_authentication", + "type": "Attributes", + "description": "Authenticate with Box server authentication. Before creating the integration, add the Cloudflare CASB application in Box Admin Console > Integrations > Platform Apps Manager > Server Authentication Apps using client ID `puaghckpy0578r8p6f3g0rf860unup4r`.", + "children": [ + { + "name": "enterprise_id", + "type": "String", + "description": "Box Enterprise ID from Admin Console > Accounts & Billing." + } + ] + } + ] + }, + { + "name": "dlp_profiles", + "type": "Set of String", + "description": "DLP profile IDs to associate with the integration." + }, + { + "name": "google_cloud_platform", + "type": "Attributes", + "description": "Google Cloud Platform integration configuration.", + "children": [ + { + "name": "google_cloud_platform_service_account", + "type": "Attributes", + "description": "Authenticate with a service account key.", + "children": [ + { + "name": "service_account_key_json", + "type": "String", + "description": "Contents of a Google service account JSON key file. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + } + ] + } + ] + }, + { + "name": "google_workspace", + "type": "Attributes", + "description": "Google Workspace integration configuration.", + "children": [ + { + "name": "google_domain_wide_delegation_service_account", + "type": "Attributes", + "description": "Authenticate with a service account granted domain-wide delegation.", + "children": [ + { + "name": "administrator_email", + "type": "String", + "description": "A Google Workspace super administrator email address." + }, + { + "name": "service_account_key_json", + "type": "String", + "description": "Contents of a Google service account JSON key file. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + } + ] + } + ] + }, + { + "name": "openai", + "type": "Attributes", + "description": "OpenAI integration configuration.", + "children": [ + { + "name": "chatgpt_compliance_api_key", + "type": "Attributes", + "description": "Authenticate with an OpenAI Compliance API key. Requires an Enterprise plan.", + "children": [ + { + "name": "admin_api_key", + "type": "String", + "description": "OpenAI Admin API key with api.management.read access. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "compliance_api_key", + "type": "String", + "description": "OpenAI Compliance API key for audit logs. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "organization_id", + "type": "String", + "description": "OpenAI Organization ID." + }, + { + "name": "project_api_key", + "type": "String", + "description": "OpenAI Project API key, used for DLP. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "project_id", + "type": "String", + "description": "OpenAI Project ID, used for DLP." + }, + { + "name": "workspace_id", + "type": "String", + "description": "OpenAI Workspace ID for compliance data." + } + ] + }, + { + "name": "chatgpt_standard_api_key", + "type": "Attributes", + "description": "Authenticate with an OpenAI Admin API key.", + "children": [ + { + "name": "admin_api_key", + "type": "String", + "description": "OpenAI Admin API key with api.management.read access. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "organization_id", + "type": "String", + "description": "OpenAI Organization ID." + }, + { + "name": "project_api_key", + "type": "String", + "description": "OpenAI Project API key, used for DLP. This value is write-only and is never persisted to Terraform state.", + "sensitive": true + }, + { + "name": "project_id", + "type": "String", + "description": "OpenAI Project ID, used for DLP." + } + ] + } + ] + }, + { + "name": "permissions", + "type": "Set of String", + "description": "Permission scopes granted to the integration." + }, + { + "name": "use_cases", + "type": "Set of String", + "description": "Use cases to enroll the integration in." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Integration ID." + }, + { + "name": "secrets_digest", + "type": "String", + "description": "Secure digest of the confidential arguments. Managed by the provider." + } + ] + }, + "list-data-source:cloudflare_zero_trust_casb_integrations": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_casb_integrations", + "example": "data \"cloudflare_zero_trust_casb_integrations\" \"example_zero_trust_casb_integrations\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n application = \"application\"\n direction = \"asc\"\n dlp_enabled = true\n order = \"application\"\n page = 0\n page_size = 0\n search = \"search\"\n status = \"Healthy\"\n use_cases = \"use_cases\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "application", + "type": "String", + "description": "Filter by application/vendor (e.g., GOOGLE_WORKSPACE, MICROSOFT_INTERNAL)." + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order results.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "dlp_enabled", + "type": "Boolean", + "description": "Filter by DLP enabled status (true/false)." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order", + "type": "String", + "description": "Field to order results by.\nAvailable values: \"application\", \"created\", \"name\", \"status\"." + }, + { + "name": "page", + "type": "Number", + "description": "Page number within the paginated result set." + }, + { + "name": "page_size", + "type": "Number", + "description": "Number of results per page." + }, + { + "name": "search", + "type": "String", + "description": "Search integrations by name or application." + }, + { + "name": "status", + "type": "String", + "description": "Filter by integration status.\nAvailable values: \"Healthy\", \"Initializing\", \"Offline\", \"Unhealthy\"." + }, + { + "name": "use_cases", + "type": "String", + "description": "Filter by one enabled use case (for example, casb or ces)." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "application", + "type": "Map of String" + }, + { + "name": "created", + "type": "String", + "description": "When the integration was created." + }, + { + "name": "id", + "type": "String", + "description": "Integration ID." + }, + { + "name": "is_paused", + "type": "Boolean", + "description": "Whether the user paused the integration." + }, + { + "name": "name", + "type": "String", + "description": "Name of the integration." + }, + { + "name": "status", + "type": "String", + "description": "Integration status." + }, + { + "name": "updated", + "type": "String", + "description": "When the integration was last updated." + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_casb_policies": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_casb_policies", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_casb_policies\" \"example_zero_trust_casb_policies\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "actions", + "type": "Attributes", + "description": "The actions configured for this policy.", + "children": [ + { + "name": "remediation_types", + "type": "Attributes List", + "description": "List of remediation types that will be executed.", + "children": [ + { + "name": "display_name", + "type": "String", + "description": "Display name/label of the remediation type." + }, + { + "name": "remediation_type", + "type": "String", + "description": "The system name of the remediation type." + }, + { + "name": "remediation_type_id", + "type": "String", + "description": "Unique identifier for the remediation type." + } + ] + }, + { + "name": "webhook_configs", + "type": "Attributes List", + "description": "List of webhook configurations that will be triggered.", + "children": [ + { + "name": "display_name", + "type": "String", + "description": "Display name/label of the webhook configuration." + }, + { + "name": "webhook_config_id", + "type": "String", + "description": "Unique identifier for the webhook configuration." + } + ] + } + ] + }, + { + "name": "applies_to_all_integrations", + "type": "Boolean", + "description": "When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the policy was created." + }, + { + "name": "description", + "type": "String", + "description": "User-set description of what this policy does. Limited to 1000 characters." + }, + { + "name": "disabled_at", + "type": "String", + "description": "Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled." + }, + { + "name": "display_name", + "type": "String", + "description": "Display name for the policy configuration. Limited to 255 characters." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset)." + }, + { + "name": "finding_type_id", + "type": "String", + "description": "The finding type this policy is associated with. Immutable after creation; changing it replaces the policy." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the policy configuration." + }, + { + "name": "integration_ids", + "type": "List of String", + "description": "The integrations this policy applies to." + }, + { + "name": "last_triggered_at", + "type": "String", + "description": "Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the policy was last updated." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_casb_policy": { + "kind": "data-source", + "name": "cloudflare_zero_trust_casb_policy", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_casb_policy\" \"example_zero_trust_casb_policy\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n policy_id = \"497f6eca-6276-4993-bfeb-53cbbbba6f08\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "policy_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "actions", + "type": "Attributes", + "description": "The actions configured for this policy.", + "children": [ + { + "name": "remediation_types", + "type": "Attributes List", + "description": "List of remediation types that will be executed.", + "children": [ + { + "name": "display_name", + "type": "String", + "description": "Display name/label of the remediation type." + }, + { + "name": "remediation_type", + "type": "String", + "description": "The system name of the remediation type." + }, + { + "name": "remediation_type_id", + "type": "String", + "description": "Unique identifier for the remediation type." + } + ] + }, + { + "name": "webhook_configs", + "type": "Attributes List", + "description": "List of webhook configurations that will be triggered.", + "children": [ + { + "name": "display_name", + "type": "String", + "description": "Display name/label of the webhook configuration." + }, + { + "name": "webhook_config_id", + "type": "String", + "description": "Unique identifier for the webhook configuration." + } + ] + } + ] + }, + { + "name": "applies_to_all_integrations", + "type": "Boolean", + "description": "When true, the policy applies to all integrations for the account. When false, it applies only to the specified integration_ids." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the policy was created." + }, + { + "name": "description", + "type": "String", + "description": "User-set description of what this policy does. Limited to 1000 characters." + }, + { + "name": "disabled_at", + "type": "String", + "description": "Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled." + }, + { + "name": "display_name", + "type": "String", + "description": "Display name for the policy configuration. Limited to 255 characters." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy is enabled. Derived from disabled_at (enabled when disabled_at is unset)." + }, + { + "name": "finding_type_id", + "type": "String", + "description": "The finding type this policy is associated with. Immutable after creation; changing it replaces the policy." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "integration_ids", + "type": "List of String", + "description": "The integrations this policy applies to." + }, + { + "name": "last_triggered_at", + "type": "String", + "description": "Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the policy was last updated." + } + ] + }, + "resource:cloudflare_zero_trust_casb_policy": { + "kind": "resource", + "name": "cloudflare_zero_trust_casb_policy", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_casb_policy\" \"example_zero_trust_casb_policy\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n actions = {\n remediation_types = [{\n remediation_type_id = \"5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a\"\n }]\n webhook_configs = [{\n webhook_config_id = \"3f7b8c9d-6e5a-4f3b-9c2d-1e0a8b7c6d5e\"\n }]\n }\n applies_to_all_integrations = false\n display_name = \"Auto-remediate public files\"\n enabled = true\n finding_type_id = \"5a7d9e2f-1b3c-4d5e-8f6a-7b8c9d0e1f2a\"\n description = \"Automatically remove public access from files when detected\"\n integration_ids = [\"497f6eca-6276-4993-bfeb-53cbbbba6f08\"]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_casb_policy.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "actions", + "type": "Attributes", + "description": "Actions to execute when this policy is triggered, grouped by action type.\nA policy must contain at least one action across all groups and may include\nat most one remediation.", + "children": [ + { + "name": "remediation_types", + "type": "Attributes List", + "description": "Remediation actions to execute (at most one).", + "children": [ + { + "name": "remediation_type_id", + "type": "String", + "description": "The ID of the remediation type to execute." + } + ] + }, + { + "name": "webhook_configs", + "type": "Attributes List", + "description": "Webhook actions to execute.", + "children": [ + { + "name": "webhook_config_id", + "type": "String", + "description": "The ID of the webhook configuration to use." + } + ] + } + ] + }, + { + "name": "applies_to_all_integrations", + "type": "Boolean", + "description": "When true, the policy applies to all integrations for the account. When false, integration_ids must be provided." + }, + { + "name": "display_name", + "type": "String", + "description": "Display name for the policy configuration." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Boolean specifying if the policy is enabled or disabled." + }, + { + "name": "finding_type_id", + "type": "String", + "description": "The finding type this policy is associated with. All remediation actions must match this finding type." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Optional description of what this policy does." + }, + { + "name": "integration_ids", + "type": "List of String", + "description": "The integrations this policy applies to. Required when applies_to_all_integrations is false." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the policy was created." + }, + { + "name": "disabled_at", + "type": "String", + "description": "Timestamp when the policy was disabled. Omitted from the response when the policy\nis enabled." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the policy configuration." + }, + { + "name": "last_triggered_at", + "type": "String", + "description": "Timestamp of the most recent successful policy invocation. Omitted\nfrom the response when the policy has never been successfully\ntriggered. Only populated on GET responses; absent on responses from\ncreate/update endpoints." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the policy was last updated." + } + ] + }, + "data-source:cloudflare_zero_trust_casb_webhook": { + "kind": "data-source", + "name": "cloudflare_zero_trust_casb_webhook", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_casb_webhook\" \"example_zero_trust_casb_webhook\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n webhook_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "webhook_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "authentication_type", + "type": "String", + "description": "Type of authentication used for the webhook.\nAvailable values: \"Basic Auth\", \"None\", \"Bearer Auth\", \"Static Headers\", \"HMAC-Signing\"." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the webhook configuration was created." + }, + { + "name": "destination_url", + "type": "String", + "description": "Target URL for the webhook configuration. Where resulting data will be sent." + }, + { + "name": "headers", + "type": "Attributes List", + "description": "List of header keys configured for this webhook. Values are not included for security reasons.", + "children": [ + { + "name": "key", + "type": "String", + "description": "Header key name (lowercase)." + }, + { + "name": "value", + "type": "String", + "description": "Header value. This field is never returned in API responses for security reasons.", + "sensitive": true + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "label", + "type": "String", + "description": "Account-specified display label for the webhook configuration." + }, + { + "name": "status", + "type": "String", + "description": "Current status of the webhook configuration. If disabled, data cannot be sent through this configuration.\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the webhook configuration was last updated." + }, + { + "name": "version", + "type": "Number", + "description": "Version number of the configuration." + } + ] + }, + "resource:cloudflare_zero_trust_casb_webhook": { + "kind": "resource", + "name": "cloudflare_zero_trust_casb_webhook", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_casb_webhook\" \"example_zero_trust_casb_webhook\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n authentication_type = \"Bearer Auth\"\n destination_url = \"https://example.com/webhook\"\n label = \"Send to Slack\"\n headers = [{\n key = \"Authorization\"\n value = \"Bearer token123\"\n }, {\n key = \"X-Custom-Header\"\n value = \"value\"\n }]\n signing_secret = \"my-secret-key\"\n status = \"enabled\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_casb_webhook.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "authentication_type", + "type": "String", + "description": "Type of authentication used for the webhook.\nAvailable values: \"Basic Auth\", \"None\", \"Bearer Auth\", \"Static Headers\", \"HMAC-Signing\"." + }, + { + "name": "destination_url", + "type": "String", + "description": "Target URL for the webhook configuration. Where resulting data will be sent." + }, + { + "name": "label", + "type": "String", + "description": "Account-specified display label for the webhook configuration." + } + ], + "optional": [ + { + "name": "headers", + "type": "Attributes List", + "description": "List of custom headers to include in webhook requests.", + "children": [ + { + "name": "key", + "type": "String", + "description": "Header key name." + }, + { + "name": "value", + "type": "String", + "description": "Header value. Required on Create and Evaluate. On Update, omit or set to null to keep existing value.", + "sensitive": true + } + ] + }, + { + "name": "signing_secret", + "type": "String", + "description": "Secret key used for HMAC signing when authentication_type is \"HMAC-Signing\".", + "sensitive": true + }, + { + "name": "status", + "type": "String", + "description": "Status of the webhook configuration. Defaults to enabled when omitted.\nAvailable values: \"enabled\", \"disabled\"." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the webhook configuration was created." + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the specific webhook configuration." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the webhook configuration was last updated." + }, + { + "name": "version", + "type": "Number", + "description": "Version number of the configuration." + } + ] + }, + "list-data-source:cloudflare_zero_trust_casb_webhooks": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_casb_webhooks", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_casb_webhooks\" \"example_zero_trust_casb_webhooks\" {\n account_id = \"46148281d8a93d002ef242d8b0d5f9f6\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "authentication_type", + "type": "String", + "description": "Type of authentication used for the webhook.\nAvailable values: \"Basic Auth\", \"None\", \"Bearer Auth\", \"Static Headers\", \"HMAC-Signing\"." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp when the webhook configuration was created." + }, + { + "name": "destination_url", + "type": "String", + "description": "Target URL for the webhook configuration. Where resulting data will be sent." + }, + { + "name": "headers", + "type": "Attributes List", + "description": "List of header keys configured for this webhook. Values are not included for security reasons.", + "children": [ + { + "name": "key", + "type": "String", + "description": "Header key name (lowercase)." + }, + { + "name": "value", + "type": "String", + "description": "Header value. This field is never returned in API responses for security reasons.", + "sensitive": true + } + ] + }, + { + "name": "id", + "type": "String", + "description": "Unique identifier for the specific webhook configuration." + }, + { + "name": "label", + "type": "String", + "description": "Account-specified display label for the webhook configuration." + }, + { + "name": "status", + "type": "String", + "description": "Current status of the webhook configuration. If disabled, data cannot be sent through this configuration.\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp when the webhook configuration was last updated." + }, + { + "name": "version", + "type": "Number", + "description": "Version number of the configuration." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_connectivity_settings": { + "kind": "data-source", + "name": "cloudflare_zero_trust_connectivity_settings", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Report`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_connectivity_settings\" \"example_zero_trust_connectivity_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + } + ], + "optional": [], + "computed": [ + { + "name": "icmp_proxy_enabled", + "type": "Boolean", + "description": "A flag to enable the ICMP proxy for the account network." + }, + { + "name": "id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "offramp_warp_enabled", + "type": "Boolean", + "description": "A flag to enable WARP to WARP traffic." + } + ] + }, + "resource:cloudflare_zero_trust_connectivity_settings": { + "kind": "resource", + "name": "cloudflare_zero_trust_connectivity_settings", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Report`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_connectivity_settings\" \"example_zero_trust_connectivity_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n icmp_proxy_enabled = true\n offramp_warp_enabled = true\n}", + "importExample": "$ terraform import cloudflare_zero_trust_connectivity_settings.example ''", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + } + ], + "optional": [ + { + "name": "icmp_proxy_enabled", + "type": "Boolean", + "description": "A flag to enable the ICMP proxy for the account network." + }, + { + "name": "offramp_warp_enabled", + "type": "Boolean", + "description": "A flag to enable WARP to WARP traffic." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Cloudflare account ID" + } + ] + }, + "data-source:cloudflare_zero_trust_device_custom_profile": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_custom_profile", + "example": "data \"cloudflare_zero_trust_device_custom_profile\" \"example_zero_trust_device_custom_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "profile_type", + "type": "String", + "description": "Filter profiles by client type. When omitted, only WARP profiles are returned.\nAvailable values: \"warp\", \"browser_extension\"." + } + ] + }, + { + "name": "policy_id", + "type": "String" + } + ], + "computed": [ + { + "name": "allow_mode_switch", + "type": "Boolean", + "description": "Whether to allow the user to switch WARP between modes." + }, + { + "name": "allow_updates", + "type": "Boolean", + "description": "Whether to receive update notifications when a new version of the client is available." + }, + { + "name": "allowed_to_leave", + "type": "Boolean", + "description": "Whether to allow devices to leave the organization." + }, + { + "name": "auto_connect", + "type": "Number", + "description": "The amount of time in seconds to reconnect after having been disabled." + }, + { + "name": "browser_extension_config", + "type": "Attributes", + "description": "Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.", + "children": [ + { + "name": "proxy_control", + "type": "String", + "description": "Whether the user may disable the browser extension proxy.\nAvailable values: \"unlocked\", \"locked\"." + }, + { + "name": "proxy_enabled", + "type": "Boolean", + "description": "Whether the browser extension proxy is active." + } + ] + }, + { + "name": "captive_portal", + "type": "Number", + "description": "Turn on the captive portal after the specified amount of time." + }, + { + "name": "default", + "type": "Boolean", + "description": "Whether the policy is the account default. WARP group profiles cannot set this field." + }, + { + "name": "description", + "type": "String", + "description": "A description of the policy." + }, + { + "name": "disable_auto_fallback", + "type": "Boolean", + "description": "If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`." + }, + { + "name": "dns_search_suffixes", + "type": "Attributes List", + "description": "List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the DNS search suffix." + }, + { + "name": "suffix", + "type": "String", + "description": "The DNS search suffix to append when resolving short hostnames." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy will be applied to matching devices." + }, + { + "name": "exclude", + "type": "Attributes List", + "description": "List of routes excluded in the WARP client's tunnel.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to exclude from the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "exclude_office_ips", + "type": "Boolean", + "description": "Whether to add Microsoft IPs to Split Tunnel exclusions." + }, + { + "name": "fallback_domains", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + { + "name": "gateway_unique_id", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "include", + "type": "Attributes List", + "description": "List of routes included in the WARP client's tunnel.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to include in the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "lan_allow_minutes", + "type": "Number", + "description": "The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset." + }, + { + "name": "lan_allow_subnet_size", + "type": "Number", + "description": "The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset." + }, + { + "name": "match", + "type": "String", + "description": "The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"." + }, + { + "name": "name", + "type": "String", + "description": "The name of the device settings profile." + }, + { + "name": "precedence", + "type": "Number", + "description": "The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field." + }, + { + "name": "profile_type", + "type": "String", + "description": "The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.\nAvailable values: \"warp\", \"browser_extension\"." + }, + { + "name": "register_interface_ip_with_dns", + "type": "Boolean", + "description": "Determines if the operating system will register WARP's local interface IP with your on-premises DNS server." + }, + { + "name": "sccm_vpn_boundary_support", + "type": "Boolean", + "description": "Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)." + }, + { + "name": "service_mode_v2", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The mode to run the WARP client under." + }, + { + "name": "port", + "type": "Number", + "description": "The port number when used with proxy mode." + } + ] + }, + { + "name": "support_url", + "type": "String", + "description": "The URL to launch when the Send Feedback button is clicked." + }, + { + "name": "switch_locked", + "type": "Boolean", + "description": "Whether to allow the user to turn off the WARP switch and disconnect the client." + }, + { + "name": "target_tests", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "The id of the DEX test targeting this policy." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX test targeting this policy." + } + ] + }, + { + "name": "tunnel_protocol", + "type": "String", + "description": "Determines which tunnel protocol to use." + }, + { + "name": "uninstall_protection", + "type": "Boolean", + "description": "Determines whether uninstalling the WARP client requires an override code. (Windows only)." + }, + { + "name": "virtual_networks", + "type": "Attributes", + "description": "Virtual network access settings for the device.", + "children": [ + { + "name": "allowed", + "type": "List of String", + "description": "List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required." + }, + { + "name": "default", + "type": "String", + "description": "The default virtual network ID. Must be included in the `allowed` list." + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_device_custom_profile": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_custom_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_custom_profile\" \"example_zero_trust_device_custom_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Allow Developers\"\n allow_mode_switch = true\n allow_updates = true\n allowed_to_leave = true\n auto_connect = 0\n browser_extension_config = {\n proxy_control = \"unlocked\"\n proxy_enabled = true\n }\n captive_portal = 180\n default = false\n description = \"Policy for test teams.\"\n disable_auto_fallback = true\n dns_search_suffixes = [{\n suffix = \"internal.corp\"\n description = \"Example internal domains\"\n }]\n enabled = true\n exclude = [{\n address = \"192.0.2.0/24\"\n description = \"Exclude testing domains from the tunnel\"\n }]\n exclude_office_ips = true\n global_acceleration = {\n api_endpoints = [\"198.51.100.1:443\"]\n enabled = true\n masque_endpoints = [\"198.51.100.1:443\"]\n wireguard_endpoints = [\"198.51.100.1:2408\"]\n }\n include = [{\n address = \"192.0.2.0/24\"\n description = \"Include testing domains in the tunnel\"\n }]\n lan_allow_minutes = 30\n lan_allow_subnet_size = 24\n match = \"identity.email == \\\"test@cloudflare.com\\\"\"\n precedence = 100\n profile_type = \"warp\"\n register_interface_ip_with_dns = true\n sccm_vpn_boundary_support = false\n service_mode_v2 = {\n mode = \"proxy\"\n port = 3000\n }\n support_url = \"https://1.1.1.1/help\"\n switch_locked = true\n tunnel_protocol = \"wireguard\"\n uninstall_protection = false\n virtual_networks = {\n allowed = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n default = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_custom_profile.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The name of the device settings profile." + } + ], + "optional": [ + { + "name": "allow_mode_switch", + "type": "Boolean", + "description": "Whether to allow the user to switch WARP between modes." + }, + { + "name": "allow_updates", + "type": "Boolean", + "description": "Whether to receive update notifications when a new version of the client is available." + }, + { + "name": "allowed_to_leave", + "type": "Boolean", + "description": "Whether to allow devices to leave the organization." + }, + { + "name": "auto_connect", + "type": "Number", + "description": "The amount of time in seconds to reconnect after having been disabled." + }, + { + "name": "browser_extension_config", + "type": "Attributes", + "description": "Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.", + "children": [ + { + "name": "proxy_control", + "type": "String", + "description": "Whether the user may disable the browser extension proxy.\nAvailable values: \"unlocked\", \"locked\"." + }, + { + "name": "proxy_enabled", + "type": "Boolean", + "description": "Whether the browser extension proxy is active." + } + ] + }, + { + "name": "captive_portal", + "type": "Number", + "description": "Turn on the captive portal after the specified amount of time." + }, + { + "name": "description", + "type": "String", + "description": "A description of the policy." + }, + { + "name": "disable_auto_fallback", + "type": "Boolean", + "description": "If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`." + }, + { + "name": "dns_search_suffixes", + "type": "Attributes List", + "description": "List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the DNS search suffix." + }, + { + "name": "suffix", + "type": "String", + "description": "The DNS search suffix to append when resolving short hostnames." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy will be applied to matching devices." + }, + { + "name": "exclude", + "type": "Attributes List", + "description": "List of routes excluded in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to exclude from the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "exclude_office_ips", + "type": "Boolean", + "description": "Whether to add Microsoft IPs to Split Tunnel exclusions." + }, + { + "name": "global_acceleration", + "type": "Attributes", + "description": "Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.", + "children": [ + { + "name": "api_endpoints", + "type": "List of String", + "description": "IP:port entries for the API endpoints." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Global acceleration settings are used only when \"enabled\"." + }, + { + "name": "masque_endpoints", + "type": "List of String", + "description": "IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided." + }, + { + "name": "wireguard_endpoints", + "type": "List of String", + "description": "IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided." + } + ] + }, + { + "name": "include", + "type": "Attributes List", + "description": "List of routes included in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to include in the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "lan_allow_minutes", + "type": "Number", + "description": "The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset." + }, + { + "name": "lan_allow_subnet_size", + "type": "Number", + "description": "The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset." + }, + { + "name": "match", + "type": "String", + "description": "The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"." + }, + { + "name": "precedence", + "type": "Number", + "description": "The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field." + }, + { + "name": "profile_type", + "type": "String", + "description": "The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.\nAvailable values: \"warp\", \"browser_extension\"." + }, + { + "name": "register_interface_ip_with_dns", + "type": "Boolean", + "description": "Determines if the operating system will register WARP's local interface IP with your on-premises DNS server." + }, + { + "name": "sccm_vpn_boundary_support", + "type": "Boolean", + "description": "Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)." + }, + { + "name": "service_mode_v2", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The mode to run the WARP client under." + }, + { + "name": "port", + "type": "Number", + "description": "The port number when used with proxy mode." + } + ] + }, + { + "name": "support_url", + "type": "String", + "description": "The URL to launch when the Send Feedback button is clicked." + }, + { + "name": "switch_locked", + "type": "Boolean", + "description": "Whether to allow the user to turn off the WARP switch and disconnect the client." + }, + { + "name": "tunnel_protocol", + "type": "String", + "description": "Determines which tunnel protocol to use." + }, + { + "name": "uninstall_protection", + "type": "Boolean", + "description": "Determines whether uninstalling the WARP client requires an override code. (Windows only)." + }, + { + "name": "virtual_networks", + "type": "Attributes", + "description": "Virtual network access settings for the device.", + "children": [ + { + "name": "allowed", + "type": "List of String", + "description": "List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required." + }, + { + "name": "default", + "type": "String", + "description": "The default virtual network ID. Must be included in the `allowed` list." + } + ] + } + ], + "computed": [ + { + "name": "default", + "type": "Boolean", + "description": "Whether the policy is the default policy for an account." + }, + { + "name": "fallback_domains", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + { + "name": "gateway_unique_id", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "policy_id", + "type": "String" + }, + { + "name": "target_tests", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "The id of the DEX test targeting this policy." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX test targeting this policy." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_device_custom_profile_local_domain_fallback": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_custom_profile_local_domain_fallback", + "example": "data \"cloudflare_zero_trust_device_custom_profile_local_domain_fallback\" \"example_zero_trust_device_custom_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "policy_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + "resource:cloudflare_zero_trust_device_custom_profile_local_domain_fallback": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_custom_profile_local_domain_fallback", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_custom_profile_local_domain_fallback\" \"example_zero_trust_device_custom_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n policy_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n domains = [{\n suffix = \"example.com\"\n description = \"Domain bypass for local development\"\n dns_server = [\"1.1.1.1\"]\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_custom_profile_local_domain_fallback.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "domains", + "type": "Attributes Set", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + { + "name": "policy_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "list-data-source:cloudflare_zero_trust_device_custom_profiles": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_device_custom_profiles", + "example": "data \"cloudflare_zero_trust_device_custom_profiles\" \"example_zero_trust_device_custom_profiles\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "profile_type", + "type": "String", + "description": "Filter profiles by client type. When omitted, only WARP profiles are returned.\nAvailable values: \"warp\", \"browser_extension\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "allow_mode_switch", + "type": "Boolean", + "description": "Whether to allow the user to switch WARP between modes." + }, + { + "name": "allow_updates", + "type": "Boolean", + "description": "Whether to receive update notifications when a new version of the client is available." + }, + { + "name": "allowed_to_leave", + "type": "Boolean", + "description": "Whether to allow devices to leave the organization." + }, + { + "name": "auto_connect", + "type": "Number", + "description": "The amount of time in seconds to reconnect after having been disabled." + }, + { + "name": "browser_extension_config", + "type": "Attributes", + "description": "Browser extension proxy settings. Required when profile_type is browser_extension and invalid for WARP profiles.", + "children": [ + { + "name": "proxy_control", + "type": "String", + "description": "Whether the user may disable the browser extension proxy.\nAvailable values: \"unlocked\", \"locked\"." + }, + { + "name": "proxy_enabled", + "type": "Boolean", + "description": "Whether the browser extension proxy is active." + } + ] + }, + { + "name": "captive_portal", + "type": "Number", + "description": "Turn on the captive portal after the specified amount of time." + }, + { + "name": "default", + "type": "Boolean", + "description": "Whether the policy is the account default. WARP group profiles cannot set this field." + }, + { + "name": "description", + "type": "String", + "description": "A description of the policy." + }, + { + "name": "disable_auto_fallback", + "type": "Boolean", + "description": "If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`." + }, + { + "name": "dns_search_suffixes", + "type": "Attributes List", + "description": "List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the DNS search suffix." + }, + { + "name": "suffix", + "type": "String", + "description": "The DNS search suffix to append when resolving short hostnames." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy will be applied to matching devices." + }, + { + "name": "exclude", + "type": "Attributes List", + "description": "List of routes excluded in the WARP client's tunnel.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to exclude from the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "exclude_office_ips", + "type": "Boolean", + "description": "Whether to add Microsoft IPs to Split Tunnel exclusions." + }, + { + "name": "fallback_domains", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + { + "name": "gateway_unique_id", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "include", + "type": "Attributes List", + "description": "List of routes included in the WARP client's tunnel.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to include in the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "lan_allow_minutes", + "type": "Number", + "description": "The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset." + }, + { + "name": "lan_allow_subnet_size", + "type": "Number", + "description": "The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset." + }, + { + "name": "match", + "type": "String", + "description": "The wirefilter expression to match devices. Available values: \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.service_token_uuid\", \"identity.saml_attributes\", \"network\", \"os.name\", \"os.version\"." + }, + { + "name": "name", + "type": "String", + "description": "The name of the device settings profile." + }, + { + "name": "policy_id", + "type": "String" + }, + { + "name": "precedence", + "type": "Number", + "description": "The precedence of the policy. Lower values indicate higher precedence. Policies will be evaluated in ascending order of this field." + }, + { + "name": "profile_type", + "type": "String", + "description": "The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.\nAvailable values: \"warp\", \"browser_extension\"." + }, + { + "name": "register_interface_ip_with_dns", + "type": "Boolean", + "description": "Determines if the operating system will register WARP's local interface IP with your on-premises DNS server." + }, + { + "name": "sccm_vpn_boundary_support", + "type": "Boolean", + "description": "Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)." + }, + { + "name": "service_mode_v2", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The mode to run the WARP client under." + }, + { + "name": "port", + "type": "Number", + "description": "The port number when used with proxy mode." + } + ] + }, + { + "name": "support_url", + "type": "String", + "description": "The URL to launch when the Send Feedback button is clicked." + }, + { + "name": "switch_locked", + "type": "Boolean", + "description": "Whether to allow the user to turn off the WARP switch and disconnect the client." + }, + { + "name": "target_tests", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String", + "description": "The id of the DEX test targeting this policy." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX test targeting this policy." + } + ] + }, + { + "name": "tunnel_protocol", + "type": "String", + "description": "Determines which tunnel protocol to use." + }, + { + "name": "uninstall_protection", + "type": "Boolean", + "description": "Determines whether uninstalling the WARP client requires an override code. (Windows only)." + }, + { + "name": "virtual_networks", + "type": "Attributes", + "description": "Virtual network access settings for the device.", + "children": [ + { + "name": "allowed", + "type": "List of String", + "description": "List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required." + }, + { + "name": "default", + "type": "String", + "description": "The default virtual network ID. Must be included in the `allowed` list." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_device_default_profile": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_default_profile", + "example": "data \"cloudflare_zero_trust_device_default_profile\" \"example_zero_trust_device_default_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "allow_mode_switch", + "type": "Boolean", + "description": "Whether to allow the user to switch WARP between modes." + }, + { + "name": "allow_updates", + "type": "Boolean", + "description": "Whether to receive update notifications when a new version of the client is available." + }, + { + "name": "allowed_to_leave", + "type": "Boolean", + "description": "Whether to allow devices to leave the organization." + }, + { + "name": "auto_connect", + "type": "Number", + "description": "The amount of time in seconds to reconnect after having been disabled." + }, + { + "name": "captive_portal", + "type": "Number", + "description": "Turn on the captive portal after the specified amount of time." + }, + { + "name": "default", + "type": "Boolean", + "description": "Whether the policy will be applied to matching devices." + }, + { + "name": "disable_auto_fallback", + "type": "Boolean", + "description": "If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`." + }, + { + "name": "dns_search_suffixes", + "type": "Attributes List", + "description": "List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the DNS search suffix." + }, + { + "name": "suffix", + "type": "String", + "description": "The DNS search suffix to append when resolving short hostnames." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy will be applied to matching devices." + }, + { + "name": "exclude", + "type": "Attributes List", + "description": "List of routes excluded in the WARP client's tunnel.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to exclude from the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "exclude_office_ips", + "type": "Boolean", + "description": "Whether to add Microsoft IPs to Split Tunnel exclusions." + }, + { + "name": "fallback_domains", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + { + "name": "gateway_unique_id", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "include", + "type": "Attributes List", + "description": "List of routes included in the WARP client's tunnel.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to include in the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "policy_id", + "type": "String" + }, + { + "name": "profile_type", + "type": "String", + "description": "The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.\nAvailable values: \"warp\", \"browser_extension\"." + }, + { + "name": "register_interface_ip_with_dns", + "type": "Boolean", + "description": "Determines if the operating system will register WARP's local interface IP with your on-premises DNS server." + }, + { + "name": "sccm_vpn_boundary_support", + "type": "Boolean", + "description": "Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)." + }, + { + "name": "service_mode_v2", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The mode to run the WARP client under." + }, + { + "name": "port", + "type": "Number", + "description": "The port number when used with proxy mode." + } + ] + }, + { + "name": "support_url", + "type": "String", + "description": "The URL to launch when the Send Feedback button is clicked." + }, + { + "name": "switch_locked", + "type": "Boolean", + "description": "Whether to allow the user to turn off the WARP switch and disconnect the client." + }, + { + "name": "tunnel_protocol", + "type": "String", + "description": "Determines which tunnel protocol to use." + }, + { + "name": "uninstall_protection", + "type": "Boolean", + "description": "Determines whether uninstalling the WARP client requires an override code. (Windows only)." + }, + { + "name": "virtual_networks", + "type": "Attributes", + "description": "Virtual network access settings for the device.", + "children": [ + { + "name": "allowed", + "type": "List of String", + "description": "List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required." + }, + { + "name": "default", + "type": "String", + "description": "The default virtual network ID. Must be included in the `allowed` list." + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_device_default_profile": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_default_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_default_profile\" \"example_zero_trust_device_default_profile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n allow_mode_switch = true\n allow_updates = true\n allowed_to_leave = true\n auto_connect = 0\n captive_portal = 180\n disable_auto_fallback = true\n dns_search_suffixes = [{\n suffix = \"internal.corp\"\n description = \"Example internal domains\"\n }]\n exclude = [{\n address = \"192.0.2.0/24\"\n description = \"Exclude testing domains from the tunnel\"\n }]\n exclude_office_ips = true\n global_acceleration = {\n api_endpoints = [\"198.51.100.1:443\"]\n enabled = true\n masque_endpoints = [\"198.51.100.1:443\"]\n wireguard_endpoints = [\"198.51.100.1:2408\"]\n }\n include = [{\n address = \"192.0.2.0/24\"\n description = \"Include testing domains in the tunnel\"\n }]\n lan_allow_minutes = 30\n lan_allow_subnet_size = 24\n register_interface_ip_with_dns = true\n sccm_vpn_boundary_support = false\n service_mode_v2 = {\n mode = \"proxy\"\n port = 3000\n }\n support_url = \"https://1.1.1.1/help\"\n switch_locked = true\n tunnel_protocol = \"wireguard\"\n uninstall_protection = false\n virtual_networks = {\n allowed = [\"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"]\n default = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_default_profile.example ''", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "allow_mode_switch", + "type": "Boolean", + "description": "Whether to allow the user to switch WARP between modes." + }, + { + "name": "allow_updates", + "type": "Boolean", + "description": "Whether to receive update notifications when a new version of the client is available." + }, + { + "name": "allowed_to_leave", + "type": "Boolean", + "description": "Whether to allow devices to leave the organization." + }, + { + "name": "auto_connect", + "type": "Number", + "description": "The amount of time in seconds to reconnect after having been disabled." + }, + { + "name": "captive_portal", + "type": "Number", + "description": "Turn on the captive portal after the specified amount of time." + }, + { + "name": "disable_auto_fallback", + "type": "Boolean", + "description": "If the `dns_server` field of a fallback domain is not present, the client will fall back to a best guess of the default/system DNS resolvers unless this policy option is set to `true`." + }, + { + "name": "dns_search_suffixes", + "type": "Attributes List", + "description": "List of DNS search suffixes to apply to clients. Suffixes are evaluated in order. Use an empty array to clear.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the DNS search suffix." + }, + { + "name": "suffix", + "type": "String", + "description": "The DNS search suffix to append when resolving short hostnames." + } + ] + }, + { + "name": "exclude", + "type": "Attributes List", + "description": "List of routes excluded in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to exclude from the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to exclude from the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "exclude_office_ips", + "type": "Boolean", + "description": "Whether to add Microsoft IPs to Split Tunnel exclusions." + }, + { + "name": "global_acceleration", + "type": "Attributes", + "description": "Global Acceleration settings for China. When configured, WARP clients connect to the Global Accelerator addresses instead of the default ones. Please contact your account representative to enable this feature on your account. See https://developers.cloudflare.com/china-network/concepts/global-acceleration/.", + "children": [ + { + "name": "api_endpoints", + "type": "List of String", + "description": "IP:port entries for the API endpoints." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Global acceleration settings are used only when \"enabled\"." + }, + { + "name": "masque_endpoints", + "type": "List of String", + "description": "IP:port entries for the MASQUE tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided." + }, + { + "name": "wireguard_endpoints", + "type": "List of String", + "description": "IP:port entries for the WireGuard tunnel endpoints. Either wireguard_endpoints or masque_endpoints must be provided." + } + ] + }, + { + "name": "include", + "type": "Attributes List", + "description": "List of routes included in the WARP client's tunnel. Both 'exclude' and 'include' cannot be set in the same request.", + "children": [ + { + "name": "address", + "type": "String", + "description": "The address in CIDR format to include in the tunnel. If `address` is present, `host` must not be present." + }, + { + "name": "description", + "type": "String", + "description": "A description of the Split Tunnel item, displayed in the client UI." + }, + { + "name": "host", + "type": "String", + "description": "The domain name to include in the tunnel. If `host` is present, `address` must not be present." + } + ] + }, + { + "name": "lan_allow_minutes", + "type": "Number", + "description": "The amount of time in minutes a user is allowed access to their LAN. A value of 0 will allow LAN access until the next WARP reconnection, such as a reboot or a laptop waking from sleep. Note that this field is omitted from the response if null or unset." + }, + { + "name": "lan_allow_subnet_size", + "type": "Number", + "description": "The size of the subnet for the local access network. Note that this field is omitted from the response if null or unset." + }, + { + "name": "register_interface_ip_with_dns", + "type": "Boolean", + "description": "Determines if the operating system will register WARP's local interface IP with your on-premises DNS server." + }, + { + "name": "sccm_vpn_boundary_support", + "type": "Boolean", + "description": "Determines whether the WARP client indicates to SCCM that it is inside a VPN boundary. (Windows only)." + }, + { + "name": "service_mode_v2", + "type": "Attributes", + "children": [ + { + "name": "mode", + "type": "String", + "description": "The mode to run the WARP client under." + }, + { + "name": "port", + "type": "Number", + "description": "The port number when used with proxy mode." + } + ] + }, + { + "name": "support_url", + "type": "String", + "description": "The URL to launch when the Send Feedback button is clicked." + }, + { + "name": "switch_locked", + "type": "Boolean", + "description": "Whether to allow the user to turn off the WARP switch and disconnect the client." + }, + { + "name": "tunnel_protocol", + "type": "String", + "description": "Determines which tunnel protocol to use." + }, + { + "name": "uninstall_protection", + "type": "Boolean", + "description": "Determines whether uninstalling the WARP client requires an override code. (Windows only)." + }, + { + "name": "virtual_networks", + "type": "Attributes", + "description": "Virtual network access settings for the device.", + "children": [ + { + "name": "allowed", + "type": "List of String", + "description": "List of virtual network IDs the device is allowed to access. When virtual_networks is set, at least one entry is required." + }, + { + "name": "default", + "type": "String", + "description": "The default virtual network ID. Must be included in the `allowed` list." + } + ] + } + ], + "computed": [ + { + "name": "default", + "type": "Boolean", + "description": "Whether the policy will be applied to matching devices." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the policy will be applied to matching devices." + }, + { + "name": "fallback_domains", + "type": "Attributes List", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + { + "name": "gateway_unique_id", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "policy_id", + "type": "String" + }, + { + "name": "profile_type", + "type": "String", + "description": "The client type to which the device settings profile applies. This field is set when the profile is created and cannot be changed.\nAvailable values: \"warp\", \"browser_extension\"." + } + ] + }, + "data-source:cloudflare_zero_trust_device_default_profile_certificates": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_default_profile_certificates", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "data \"cloudflare_zero_trust_device_default_profile_certificates\" \"example_zero_trust_device_default_profile_certificates\" {\n zone_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String" + } + ], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "The current status of the device policy certificate provisioning feature for WARP clients." + } + ] + }, + "resource:cloudflare_zero_trust_device_default_profile_certificates": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_default_profile_certificates", + "description": "Accepted Permissions\n\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`", + "example": "resource \"cloudflare_zero_trust_device_default_profile_certificates\" \"example_zero_trust_device_default_profile_certificates\" {\n zone_id = \"699d98642c564d2e855e9661899b7252\"\n enabled = true\n}", + "required": [ + { + "name": "enabled", + "type": "Boolean", + "description": "The current status of the device policy certificate provisioning feature for WARP clients." + }, + { + "name": "zone_id", + "type": "String" + } + ], + "optional": [], + "computed": [] + }, + "data-source:cloudflare_zero_trust_device_default_profile_local_domain_fallback": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_default_profile_local_domain_fallback", + "example": "data \"cloudflare_zero_trust_device_default_profile_local_domain_fallback\" \"example_zero_trust_device_default_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + }, + "resource:cloudflare_zero_trust_device_default_profile_local_domain_fallback": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_default_profile_local_domain_fallback", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_default_profile_local_domain_fallback\" \"example_zero_trust_device_default_profile_local_domain_fallback\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n domains = [{\n suffix = \"example.com\"\n description = \"Domain bypass for local development\"\n dns_server = [\"1.1.1.1\"]\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_default_profile_local_domain_fallback.example ''", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "domains", + "type": "Attributes Set", + "children": [ + { + "name": "description", + "type": "String", + "description": "A description of the fallback domain, displayed in the client UI." + }, + { + "name": "dns_server", + "type": "List of String", + "description": "A list of IP addresses to handle domain resolution." + }, + { + "name": "suffix", + "type": "String", + "description": "The domain suffix to match when resolving locally." + } + ] + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "data-source:cloudflare_zero_trust_device_deployment_groups": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_deployment_groups", + "example": "data \"cloudflare_zero_trust_device_deployment_groups\" \"example_zero_trust_device_deployment_groups\" {\n account_id = \"account_id\"\n group_id = \"group_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "group_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the deployment group was created." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the deployment group." + }, + { + "name": "policy_ids", + "type": "List of String", + "description": "Contains a list of policy IDs assigned to this deployment group." + }, + { + "name": "updated_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the deployment group was last updated." + }, + { + "name": "version_config", + "type": "Attributes List", + "description": "Contains version configurations for different target environments.", + "children": [ + { + "name": "target_environment", + "type": "String", + "description": "The target environment for the client version (e.g., windows, macos)." + }, + { + "name": "version", + "type": "String", + "description": "The specific client version to deploy." + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_device_deployment_groups": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_deployment_groups", + "example": "resource \"cloudflare_zero_trust_device_deployment_groups\" \"example_zero_trust_device_deployment_groups\" {\n account_id = \"account_id\"\n name = \"Engineering Ring 0\"\n version_config = [{\n target_environment = \"windows\"\n version = \"2026.6.234.0\"\n }]\n policy_ids = [\"string\"]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_deployment_groups.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the deployment group." + }, + { + "name": "version_config", + "type": "Attributes List", + "description": "Contains at least one version configuration.", + "children": [ + { + "name": "target_environment", + "type": "String", + "description": "The target environment for the client version (e.g., windows, macos)." + }, + { + "name": "version", + "type": "String", + "description": "The specific client version to deploy." + } + ] + } + ], + "optional": [ + { + "name": "policy_ids", + "type": "List of String", + "description": "Contains an optional list of policy IDs assigned to a group." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the deployment group was created." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the deployment group." + }, + { + "name": "updated_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the deployment group was last updated." + } + ] + }, + "list-data-source:cloudflare_zero_trust_device_deployment_groups_list": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_device_deployment_groups_list", + "example": "data \"cloudflare_zero_trust_device_deployment_groups_list\" \"example_zero_trust_device_deployment_groups_list\" {\n account_id = \"account_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the deployment group was created." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the deployment group." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the deployment group." + }, + { + "name": "policy_ids", + "type": "List of String", + "description": "Contains a list of policy IDs assigned to this deployment group." + }, + { + "name": "updated_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the deployment group was last updated." + }, + { + "name": "version_config", + "type": "Attributes List", + "description": "Contains version configurations for different target environments.", + "children": [ + { + "name": "target_environment", + "type": "String", + "description": "The target environment for the client version (e.g., windows, macos)." + }, + { + "name": "version", + "type": "String", + "description": "The specific client version to deploy." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_device_ip_profile": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_ip_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_device_ip_profile\" \"example_zero_trust_device_ip_profile\" {\n account_id = \"account_id\"\n profile_id = \"profile_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "per_page", + "type": "Number", + "description": "The number of IP profiles to return per page." + } + ] + }, + { + "name": "profile_id", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the Device IP profile was created." + }, + { + "name": "description", + "type": "String", + "description": "An optional description of the Device IP profile." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Device IP profile is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "match", + "type": "String", + "description": "The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the Device IP profile." + }, + { + "name": "precedence", + "type": "Number", + "description": "The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field." + }, + { + "name": "subnet_id", + "type": "String", + "description": "The ID of the Subnet." + }, + { + "name": "updated_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the Device IP profile was last updated." + } + ] + }, + "resource:cloudflare_zero_trust_device_ip_profile": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_ip_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_ip_profile\" \"example_zero_trust_device_ip_profile\" {\n account_id = \"account_id\"\n match = \"identity.email == \\\"test@cloudflare.com\\\"\"\n name = \"IPv4 Cloudflare Source IPs\"\n precedence = 100\n subnet_id = \"b70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n description = \"example comment\"\n enabled = true\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_ip_profile.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "match", + "type": "String", + "description": "The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the Device IP profile." + }, + { + "name": "precedence", + "type": "Number", + "description": "The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field." + }, + { + "name": "subnet_id", + "type": "String", + "description": "The ID of the Subnet." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "An optional description of the Device IP profile." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Device IP profile will be applied to matching devices." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the Device IP profile was created." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the Device IP profile." + }, + { + "name": "updated_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the Device IP profile was last updated." + } + ] + }, + "list-data-source:cloudflare_zero_trust_device_ip_profiles": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_device_ip_profiles", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_device_ip_profiles\" \"example_zero_trust_device_ip_profiles\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "per_page", + "type": "Number", + "description": "The number of IP profiles to return per page." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the Device IP profile was created." + }, + { + "name": "description", + "type": "String", + "description": "An optional description of the Device IP profile." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the Device IP profile is enabled." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the Device IP profile." + }, + { + "name": "match", + "type": "String", + "description": "The wirefilter expression to match registrations. Available values: \"identity.name\", \"identity.email\", \"identity.groups.id\", \"identity.groups.name\", \"identity.groups.email\", \"identity.saml_attributes\"." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the Device IP profile." + }, + { + "name": "precedence", + "type": "Number", + "description": "The precedence of the Device IP profile. Lower values indicate higher precedence. Device IP profile will be evaluated in ascending order of this field." + }, + { + "name": "subnet_id", + "type": "String", + "description": "The ID of the Subnet." + }, + { + "name": "updated_at", + "type": "String", + "description": "The RFC3339Nano timestamp when the Device IP profile was last updated." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_device_managed_networks": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_managed_networks", + "example": "data \"cloudflare_zero_trust_device_managed_networks\" \"example_zero_trust_device_managed_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n network_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "network_id", + "type": "String", + "description": "API UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "config", + "type": "Attributes", + "description": "The configuration object containing information for the WARP client to detect the managed network.", + "children": [ + { + "name": "sha256", + "type": "String", + "description": "The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate." + }, + { + "name": "tls_sockaddr", + "type": "String", + "description": "A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "API UUID." + }, + { + "name": "name", + "type": "String", + "description": "The name of the device managed network. This name must be unique." + }, + { + "name": "type", + "type": "String", + "description": "The type of device managed network.\nAvailable values: \"tls\"." + } + ] + }, + "resource:cloudflare_zero_trust_device_managed_networks": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_managed_networks", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_managed_networks\" \"example_zero_trust_device_managed_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n config = {\n tls_sockaddr = \"foo.bar:1234\"\n sha256 = \"b5bb9d8014a0f9b1d61e21e796d78dccdf1352f23cd32812f4850b878ae4944c\"\n }\n name = \"managed-network-1\"\n type = \"tls\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_managed_networks.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "config", + "type": "Attributes", + "description": "The configuration object containing information for the WARP client to detect the managed network.", + "children": [ + { + "name": "sha256", + "type": "String", + "description": "The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate." + }, + { + "name": "tls_sockaddr", + "type": "String", + "description": "A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the device managed network. This name must be unique." + }, + { + "name": "type", + "type": "String", + "description": "The type of device managed network.\nAvailable values: \"tls\"." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "API UUID." + }, + { + "name": "network_id", + "type": "String", + "description": "API UUID." + } + ] + }, + "list-data-source:cloudflare_zero_trust_device_managed_networks_list": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_device_managed_networks_list", + "example": "data \"cloudflare_zero_trust_device_managed_networks_list\" \"example_zero_trust_device_managed_networks_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "config", + "type": "Attributes", + "description": "The configuration object containing information for the WARP client to detect the managed network.", + "children": [ + { + "name": "sha256", + "type": "String", + "description": "The SHA-256 hash of the TLS certificate presented by the host found at tls_sockaddr. If absent, regular certificate verification (trusted roots, valid timestamp, etc) will be used to validate the certificate." + }, + { + "name": "tls_sockaddr", + "type": "String", + "description": "A network address of the form \"host:port\" that the WARP client will use to detect the presence of a TLS host." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "API UUID." + }, + { + "name": "name", + "type": "String", + "description": "The name of the device managed network. This name must be unique." + }, + { + "name": "network_id", + "type": "String", + "description": "API UUID." + }, + { + "name": "type", + "type": "String", + "description": "The type of device managed network.\nAvailable values: \"tls\"." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_device_posture_integration": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_posture_integration", + "example": "data \"cloudflare_zero_trust_device_posture_integration\" \"example_zero_trust_device_posture_integration\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n integration_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "integration_id", + "type": "String", + "description": "API UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "config", + "type": "Attributes", + "description": "The configuration object containing third-party integration information.", + "children": [ + { + "name": "api_url", + "type": "String", + "description": "The Workspace One API URL provided in the Workspace One Admin Dashboard." + }, + { + "name": "auth_url", + "type": "String", + "description": "The Workspace One Authorization URL depending on your region." + }, + { + "name": "client_id", + "type": "String", + "description": "The Workspace One client ID provided in the Workspace One Admin Dashboard." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "API UUID." + }, + { + "name": "interval", + "type": "String", + "description": "The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)." + }, + { + "name": "name", + "type": "String", + "description": "The name of the device posture integration." + }, + { + "name": "type", + "type": "String", + "description": "The type of device posture integration.\nAvailable values: \"workspace_one\", \"crowdstrike_s2s\", \"uptycs\", \"intune\", \"kolide\", \"tanium_s2s\", \"sentinelone_s2s\", \"custom_s2s\"." + } + ] + }, + "resource:cloudflare_zero_trust_device_posture_integration": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_posture_integration", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_posture_integration\" \"example_zero_trust_device_posture_integration\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n config = {\n api_url = \"https://as123.awmdm.com/API\"\n auth_url = \"https://na.uemauth.workspaceone.com/connect/token\"\n client_id = \"example client id\"\n client_secret = \"example client secret\"\n }\n interval = \"10m\"\n name = \"My Workspace One Integration\"\n type = \"workspace_one\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_posture_integration.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "config", + "type": "Attributes", + "description": "The configuration object containing third-party integration information.", + "children": [ + { + "name": "access_client_id", + "type": "String", + "description": "If present, this id will be passed in the `CF-Access-Client-ID` header when hitting the `api_url`." + }, + { + "name": "access_client_secret", + "type": "String", + "description": "If present, this secret will be passed in the `CF-Access-Client-Secret` header when hitting the `api_url`.", + "sensitive": true + }, + { + "name": "api_url", + "type": "String", + "description": "The Workspace One API URL provided in the Workspace One Admin Dashboard." + }, + { + "name": "auth_url", + "type": "String", + "description": "The Workspace One Authorization URL depending on your region." + }, + { + "name": "client_id", + "type": "String", + "description": "The Workspace One client ID provided in the Workspace One Admin Dashboard." + }, + { + "name": "client_key", + "type": "String", + "description": "The Uptycs client secret.", + "sensitive": true + }, + { + "name": "client_secret", + "type": "String", + "description": "The Workspace One client secret provided in the Workspace One Admin Dashboard.", + "sensitive": true + }, + { + "name": "customer_id", + "type": "String", + "description": "The Crowdstrike customer ID." + } + ] + }, + { + "name": "interval", + "type": "String", + "description": "The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)." + }, + { + "name": "name", + "type": "String", + "description": "The name of the device posture integration." + }, + { + "name": "type", + "type": "String", + "description": "The type of device posture integration.\nAvailable values: \"workspace_one\", \"crowdstrike_s2s\", \"uptycs\", \"intune\", \"kolide\", \"tanium_s2s\", \"sentinelone_s2s\", \"custom_s2s\"." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "API UUID." + } + ] + }, + "list-data-source:cloudflare_zero_trust_device_posture_integrations": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_device_posture_integrations", + "example": "data \"cloudflare_zero_trust_device_posture_integrations\" \"example_zero_trust_device_posture_integrations\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "config", + "type": "Attributes", + "description": "The configuration object containing third-party integration information.", + "children": [ + { + "name": "api_url", + "type": "String", + "description": "The Workspace One API URL provided in the Workspace One Admin Dashboard." + }, + { + "name": "auth_url", + "type": "String", + "description": "The Workspace One Authorization URL depending on your region." + }, + { + "name": "client_id", + "type": "String", + "description": "The Workspace One client ID provided in the Workspace One Admin Dashboard." + } + ] + }, + { + "name": "id", + "type": "String", + "description": "API UUID." + }, + { + "name": "interval", + "type": "String", + "description": "The interval between each posture check with the third-party API. Use `m` for minutes (e.g. `5m`) and `h` for hours (e.g. `12h`)." + }, + { + "name": "name", + "type": "String", + "description": "The name of the device posture integration." + }, + { + "name": "type", + "type": "String", + "description": "The type of device posture integration.\nAvailable values: \"workspace_one\", \"crowdstrike_s2s\", \"uptycs\", \"intune\", \"kolide\", \"tanium_s2s\", \"sentinelone_s2s\", \"custom_s2s\"." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_device_posture_rule": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_posture_rule", + "example": "data \"cloudflare_zero_trust_device_posture_rule\" \"example_zero_trust_device_posture_rule\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "rule_id", + "type": "String", + "description": "API UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "description", + "type": "String", + "description": "The description of the device posture rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise." + }, + { + "name": "expiration", + "type": "String", + "description": "Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client." + }, + { + "name": "id", + "type": "String", + "description": "API UUID." + }, + { + "name": "input", + "type": "Attributes", + "description": "The value to be checked against.", + "children": [ + { + "name": "active_threats", + "type": "Number", + "description": "The Number of active threats." + }, + { + "name": "auth_state", + "type": "List of String", + "description": "The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states." + }, + { + "name": "certificate_id", + "type": "String", + "description": "UUID of Cloudflare managed certificate." + }, + { + "name": "check_disks", + "type": "List of String", + "description": "List of volume names to be checked for encryption." + }, + { + "name": "check_private_key", + "type": "Boolean", + "description": "Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key." + }, + { + "name": "cn", + "type": "String", + "description": "Common Name that is protected by the certificate." + }, + { + "name": "compliance_status", + "type": "String", + "description": "Compliance Status.\nAvailable values: \"compliant\", \"noncompliant\", \"unknown\", \"notapplicable\", \"ingraceperiod\", \"error\"." + }, + { + "name": "connection_id", + "type": "String", + "description": "Posture Integration ID." + }, + { + "name": "count_operator", + "type": "String", + "description": "Count Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "domain", + "type": "String", + "description": "Domain." + }, + { + "name": "eid_last_seen", + "type": "String", + "description": "For more details on eid last seen, refer to the Tanium documentation." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Enabled." + }, + { + "name": "exists", + "type": "Boolean", + "description": "Whether or not file exists." + }, + { + "name": "extended_key_usage", + "type": "List of String", + "description": "List of values indicating purposes for which the certificate public key can be used." + }, + { + "name": "id", + "type": "String", + "description": "List ID." + }, + { + "name": "infected", + "type": "Boolean", + "description": "Whether device is infected." + }, + { + "name": "is_active", + "type": "Boolean", + "description": "Whether device is active." + }, + { + "name": "issue_count", + "type": "String", + "description": "The Number of Issues." + }, + { + "name": "last_seen", + "type": "String", + "description": "For more details on last seen, please refer to the Crowdstrike documentation." + }, + { + "name": "locations", + "type": "Attributes", + "children": [ + { + "name": "paths", + "type": "List of String", + "description": "List of paths to check for client certificate on linux." + }, + { + "name": "trust_stores", + "type": "List of String", + "description": "List of trust stores to check for client certificate." + } + ] + }, + { + "name": "network_status", + "type": "String", + "description": "Network status of device.\nAvailable values: \"connected\", \"disconnected\", \"disconnecting\", \"connecting\"." + }, + { + "name": "operating_system", + "type": "String", + "description": "Operating system.\nAvailable values: \"windows\", \"linux\", \"mac\", \"android\", \"ios\", \"chromeos\"." + }, + { + "name": "operational_state", + "type": "String", + "description": "Agent operational state.\nAvailable values: \"na\", \"partially_disabled\", \"auto_fully_disabled\", \"fully_disabled\", \"auto_partially_disabled\", \"disabled_error\", \"db_corruption\"." + }, + { + "name": "operator", + "type": "String", + "description": "Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "os", + "type": "String", + "description": "Os Version." + }, + { + "name": "os_distro_name", + "type": "String", + "description": "Operating System Distribution Name (linux only)." + }, + { + "name": "os_distro_revision", + "type": "String", + "description": "Version of OS Distribution (linux only)." + }, + { + "name": "os_version_extra", + "type": "String", + "description": "Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version." + }, + { + "name": "overall", + "type": "String", + "description": "Overall." + }, + { + "name": "path", + "type": "String", + "description": "File path." + }, + { + "name": "require_all", + "type": "Boolean", + "description": "Whether to check all disks for encryption." + }, + { + "name": "risk_level", + "type": "String", + "description": "For more details on risk level, refer to the Tanium documentation.\nAvailable values: \"low\", \"medium\", \"high\", \"critical\"." + }, + { + "name": "score", + "type": "Number", + "description": "A value between 0-100 assigned to devices set by the 3rd party posture provider." + }, + { + "name": "score_operator", + "type": "String", + "description": "Score Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "sensor_config", + "type": "String", + "description": "SensorConfig." + }, + { + "name": "sha256", + "type": "String", + "description": "SHA-256." + }, + { + "name": "state", + "type": "String", + "description": "For more details on state, please refer to the Crowdstrike documentation.\nAvailable values: \"online\", \"offline\", \"unknown\"." + }, + { + "name": "subject_alternative_names", + "type": "List of String", + "description": "List of certificate Subject Alternative Names." + }, + { + "name": "thumbprint", + "type": "String", + "description": "Signing certificate thumbprint." + }, + { + "name": "total_score", + "type": "Number", + "description": "For more details on total score, refer to the Tanium documentation." + }, + { + "name": "update_window_days", + "type": "Number", + "description": "Number of days that the antivirus should be updated within." + }, + { + "name": "version", + "type": "String", + "description": "Version of OS." + }, + { + "name": "version_operator", + "type": "String", + "description": "Version Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + } + ] + }, + { + "name": "match", + "type": "Attributes List", + "description": "The conditions that the client must match to run the rule.", + "children": [ + { + "name": "platform", + "type": "String", + "description": "Available values: \"windows\", \"mac\", \"linux\", \"android\", \"ios\", \"chromeos\"." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the device posture rule." + }, + { + "name": "schedule", + "type": "String", + "description": "Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`." + }, + { + "name": "type", + "type": "String", + "description": "The type of device posture rule.\nAvailable values: \"file\", \"application\", \"tanium\", \"gateway\", \"warp\", \"disk_encryption\", \"serial_number\", \"sentinelone\", \"carbonblack\", \"firewall\", \"os_version\", \"domain_joined\", \"client_certificate\", \"client_certificate_v2\", \"antivirus\", \"unique_client_id\", \"kolide\", \"tanium_s2s\", \"crowdstrike_s2s\", \"intune\", \"workspace_one\", \"sentinelone_s2s\", \"custom_s2s\"." + } + ] + }, + "resource:cloudflare_zero_trust_device_posture_rule": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_posture_rule", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_posture_rule\" \"example_zero_trust_device_posture_rule\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Admin Serial Numbers\"\n type = \"file\"\n description = \"The rule for admin serial numbers\"\n expiration = \"1h\"\n input = {\n operating_system = \"linux\"\n path = \"/bin/cat\"\n exists = true\n sha256 = \"https://api.us-2.crowdstrike.com\"\n thumbprint = \"0aabab210bdb998e9cf45da2c9ce352977ab531c681b74cf1e487be1bbe9fe6e\"\n }\n match = [{\n platform = \"windows\"\n }]\n schedule = \"1h\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_posture_rule.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "The type of device posture rule.\nAvailable values: \"file\", \"application\", \"tanium\", \"gateway\", \"warp\", \"disk_encryption\", \"serial_number\", \"sentinelone\", \"carbonblack\", \"firewall\", \"os_version\", \"domain_joined\", \"client_certificate\", \"client_certificate_v2\", \"antivirus\", \"unique_client_id\", \"kolide\", \"tanium_s2s\", \"crowdstrike_s2s\", \"intune\", \"workspace_one\", \"sentinelone_s2s\", \"custom_s2s\"." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "The description of the device posture rule." + }, + { + "name": "expiration", + "type": "String", + "description": "Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client." + }, + { + "name": "input", + "type": "Attributes", + "description": "The value to be checked against.", + "children": [ + { + "name": "active_threats", + "type": "Number", + "description": "The Number of active threats." + }, + { + "name": "auth_state", + "type": "List of String", + "description": "The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states." + }, + { + "name": "certificate_id", + "type": "String", + "description": "UUID of Cloudflare managed certificate." + }, + { + "name": "check_disks", + "type": "List of String", + "description": "List of volume names to be checked for encryption." + }, + { + "name": "check_private_key", + "type": "Boolean", + "description": "Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key." + }, + { + "name": "cn", + "type": "String", + "description": "Common Name that is protected by the certificate." + }, + { + "name": "compliance_status", + "type": "String", + "description": "Compliance Status.\nAvailable values: \"compliant\", \"noncompliant\", \"unknown\", \"notapplicable\", \"ingraceperiod\", \"error\"." + }, + { + "name": "connection_id", + "type": "String", + "description": "Posture Integration ID." + }, + { + "name": "count_operator", + "type": "String", + "description": "Count Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "domain", + "type": "String", + "description": "Domain." + }, + { + "name": "eid_last_seen", + "type": "String", + "description": "For more details on eid last seen, refer to the Tanium documentation." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Enabled." + }, + { + "name": "exists", + "type": "Boolean", + "description": "Whether or not file exists." + }, + { + "name": "extended_key_usage", + "type": "List of String", + "description": "List of values indicating purposes for which the certificate public key can be used." + }, + { + "name": "id", + "type": "String", + "description": "List ID." + }, + { + "name": "infected", + "type": "Boolean", + "description": "Whether device is infected." + }, + { + "name": "is_active", + "type": "Boolean", + "description": "Whether device is active." + }, + { + "name": "issue_count", + "type": "String", + "description": "The Number of Issues." + }, + { + "name": "last_seen", + "type": "String", + "description": "For more details on last seen, please refer to the Crowdstrike documentation." + }, + { + "name": "locations", + "type": "Attributes", + "children": [ + { + "name": "paths", + "type": "List of String", + "description": "List of paths to check for client certificate on linux." + }, + { + "name": "trust_stores", + "type": "List of String", + "description": "List of trust stores to check for client certificate." + } + ] + }, + { + "name": "network_status", + "type": "String", + "description": "Network status of device.\nAvailable values: \"connected\", \"disconnected\", \"disconnecting\", \"connecting\"." + }, + { + "name": "operating_system", + "type": "String", + "description": "Operating system.\nAvailable values: \"windows\", \"linux\", \"mac\", \"android\", \"ios\", \"chromeos\"." + }, + { + "name": "operational_state", + "type": "String", + "description": "Agent operational state.\nAvailable values: \"na\", \"partially_disabled\", \"auto_fully_disabled\", \"fully_disabled\", \"auto_partially_disabled\", \"disabled_error\", \"db_corruption\"." + }, + { + "name": "operator", + "type": "String", + "description": "Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "os", + "type": "String", + "description": "Os Version." + }, + { + "name": "os_distro_name", + "type": "String", + "description": "Operating System Distribution Name (linux only)." + }, + { + "name": "os_distro_revision", + "type": "String", + "description": "Version of OS Distribution (linux only)." + }, + { + "name": "os_version_extra", + "type": "String", + "description": "Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version." + }, + { + "name": "overall", + "type": "String", + "description": "Overall." + }, + { + "name": "path", + "type": "String", + "description": "File path." + }, + { + "name": "require_all", + "type": "Boolean", + "description": "Whether to check all disks for encryption." + }, + { + "name": "risk_level", + "type": "String", + "description": "For more details on risk level, refer to the Tanium documentation.\nAvailable values: \"low\", \"medium\", \"high\", \"critical\"." + }, + { + "name": "score", + "type": "Number", + "description": "A value between 0-100 assigned to devices set by the 3rd party posture provider." + }, + { + "name": "score_operator", + "type": "String", + "description": "Score Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "sensor_config", + "type": "String", + "description": "SensorConfig." + }, + { + "name": "sha256", + "type": "String", + "description": "SHA-256." + }, + { + "name": "state", + "type": "String", + "description": "For more details on state, please refer to the Crowdstrike documentation.\nAvailable values: \"online\", \"offline\", \"unknown\"." + }, + { + "name": "subject_alternative_names", + "type": "List of String", + "description": "List of certificate Subject Alternative Names." + }, + { + "name": "thumbprint", + "type": "String", + "description": "Signing certificate thumbprint." + }, + { + "name": "total_score", + "type": "Number", + "description": "For more details on total score, refer to the Tanium documentation." + }, + { + "name": "update_window_days", + "type": "Number", + "description": "Number of days that the antivirus should be updated within." + }, + { + "name": "version", + "type": "String", + "description": "Version of OS." + }, + { + "name": "version_operator", + "type": "String", + "description": "Version Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + } + ] + }, + { + "name": "match", + "type": "Attributes List", + "description": "The conditions that the client must match to run the rule.", + "children": [ + { + "name": "platform", + "type": "String", + "description": "Available values: \"windows\", \"mac\", \"linux\", \"android\", \"ios\", \"chromeos\"." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the device posture rule." + }, + { + "name": "schedule", + "type": "String", + "description": "Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`." + } + ], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise." + }, + { + "name": "id", + "type": "String", + "description": "API UUID." + } + ] + }, + "list-data-source:cloudflare_zero_trust_device_posture_rules": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_device_posture_rules", + "example": "data \"cloudflare_zero_trust_device_posture_rules\" \"example_zero_trust_device_posture_rules\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "description", + "type": "String", + "description": "The description of the device posture rule." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether the rule is enabled. This is a computed, read-only value. It is false for deprecated Kolide posture rules that still use the issue_count input, and true otherwise." + }, + { + "name": "expiration", + "type": "String", + "description": "Sets the expiration time for a posture check result. If empty, the result remains valid until it is overwritten by new data from the WARP client." + }, + { + "name": "id", + "type": "String", + "description": "API UUID." + }, + { + "name": "input", + "type": "Attributes", + "description": "The value to be checked against.", + "children": [ + { + "name": "active_threats", + "type": "Number", + "description": "The Number of active threats." + }, + { + "name": "auth_state", + "type": "List of String", + "description": "The set of Kolide device authentication states that pass the posture check. Device must match one of the specified states." + }, + { + "name": "certificate_id", + "type": "String", + "description": "UUID of Cloudflare managed certificate." + }, + { + "name": "check_disks", + "type": "List of String", + "description": "List of volume names to be checked for encryption." + }, + { + "name": "check_private_key", + "type": "Boolean", + "description": "Confirm the certificate was not imported from another device. We recommend keeping this enabled unless the certificate was deployed without a private key." + }, + { + "name": "cn", + "type": "String", + "description": "Common Name that is protected by the certificate." + }, + { + "name": "compliance_status", + "type": "String", + "description": "Compliance Status.\nAvailable values: \"compliant\", \"noncompliant\", \"unknown\", \"notapplicable\", \"ingraceperiod\", \"error\"." + }, + { + "name": "connection_id", + "type": "String", + "description": "Posture Integration ID." + }, + { + "name": "count_operator", + "type": "String", + "description": "Count Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "domain", + "type": "String", + "description": "Domain." + }, + { + "name": "eid_last_seen", + "type": "String", + "description": "For more details on eid last seen, refer to the Tanium documentation." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Enabled." + }, + { + "name": "exists", + "type": "Boolean", + "description": "Whether or not file exists." + }, + { + "name": "extended_key_usage", + "type": "List of String", + "description": "List of values indicating purposes for which the certificate public key can be used." + }, + { + "name": "id", + "type": "String", + "description": "List ID." + }, + { + "name": "infected", + "type": "Boolean", + "description": "Whether device is infected." + }, + { + "name": "is_active", + "type": "Boolean", + "description": "Whether device is active." + }, + { + "name": "issue_count", + "type": "String", + "description": "The Number of Issues." + }, + { + "name": "last_seen", + "type": "String", + "description": "For more details on last seen, please refer to the Crowdstrike documentation." + }, + { + "name": "locations", + "type": "Attributes", + "children": [ + { + "name": "paths", + "type": "List of String", + "description": "List of paths to check for client certificate on linux." + }, + { + "name": "trust_stores", + "type": "List of String", + "description": "List of trust stores to check for client certificate." + } + ] + }, + { + "name": "network_status", + "type": "String", + "description": "Network status of device.\nAvailable values: \"connected\", \"disconnected\", \"disconnecting\", \"connecting\"." + }, + { + "name": "operating_system", + "type": "String", + "description": "Operating system.\nAvailable values: \"windows\", \"linux\", \"mac\", \"android\", \"ios\", \"chromeos\"." + }, + { + "name": "operational_state", + "type": "String", + "description": "Agent operational state.\nAvailable values: \"na\", \"partially_disabled\", \"auto_fully_disabled\", \"fully_disabled\", \"auto_partially_disabled\", \"disabled_error\", \"db_corruption\"." + }, + { + "name": "operator", + "type": "String", + "description": "Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "os", + "type": "String", + "description": "Os Version." + }, + { + "name": "os_distro_name", + "type": "String", + "description": "Operating System Distribution Name (linux only)." + }, + { + "name": "os_distro_revision", + "type": "String", + "description": "Version of OS Distribution (linux only)." + }, + { + "name": "os_version_extra", + "type": "String", + "description": "Additional operating system version details. For Windows, the UBR (Update Build Revision). For Mac or iOS, the Product Version Extra. For Linux, the distribution name and version." + }, + { + "name": "overall", + "type": "String", + "description": "Overall." + }, + { + "name": "path", + "type": "String", + "description": "File path." + }, + { + "name": "require_all", + "type": "Boolean", + "description": "Whether to check all disks for encryption." + }, + { + "name": "risk_level", + "type": "String", + "description": "For more details on risk level, refer to the Tanium documentation.\nAvailable values: \"low\", \"medium\", \"high\", \"critical\"." + }, + { + "name": "score", + "type": "Number", + "description": "A value between 0-100 assigned to devices set by the 3rd party posture provider." + }, + { + "name": "score_operator", + "type": "String", + "description": "Score Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + }, + { + "name": "sensor_config", + "type": "String", + "description": "SensorConfig." + }, + { + "name": "sha256", + "type": "String", + "description": "SHA-256." + }, + { + "name": "state", + "type": "String", + "description": "For more details on state, please refer to the Crowdstrike documentation.\nAvailable values: \"online\", \"offline\", \"unknown\"." + }, + { + "name": "subject_alternative_names", + "type": "List of String", + "description": "List of certificate Subject Alternative Names." + }, + { + "name": "thumbprint", + "type": "String", + "description": "Signing certificate thumbprint." + }, + { + "name": "total_score", + "type": "Number", + "description": "For more details on total score, refer to the Tanium documentation." + }, + { + "name": "update_window_days", + "type": "Number", + "description": "Number of days that the antivirus should be updated within." + }, + { + "name": "version", + "type": "String", + "description": "Version of OS." + }, + { + "name": "version_operator", + "type": "String", + "description": "Version Operator.\nAvailable values: \"<\", \"<=\", \">\", \">=\", \"==\"." + } + ] + }, + { + "name": "match", + "type": "Attributes List", + "description": "The conditions that the client must match to run the rule.", + "children": [ + { + "name": "platform", + "type": "String", + "description": "Available values: \"windows\", \"mac\", \"linux\", \"android\", \"ios\", \"chromeos\"." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of the device posture rule." + }, + { + "name": "schedule", + "type": "String", + "description": "Polling frequency for the WARP client posture check. Default: `5m` (poll every five minutes). Minimum: `1m`." + }, + { + "name": "type", + "type": "String", + "description": "The type of device posture rule.\nAvailable values: \"file\", \"application\", \"tanium\", \"gateway\", \"warp\", \"disk_encryption\", \"serial_number\", \"sentinelone\", \"carbonblack\", \"firewall\", \"os_version\", \"domain_joined\", \"client_certificate\", \"client_certificate_v2\", \"antivirus\", \"unique_client_id\", \"kolide\", \"tanium_s2s\", \"crowdstrike_s2s\", \"intune\", \"workspace_one\", \"sentinelone_s2s\", \"custom_s2s\"." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_device_settings": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_settings", + "example": "data \"cloudflare_zero_trust_device_settings\" \"example_zero_trust_device_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "disable_for_time", + "type": "Number", + "description": "Sets the time limit, in seconds, that a user can use an override code to bypass WARP." + }, + { + "name": "external_emergency_signal_enabled", + "type": "Boolean", + "description": "Controls whether the external emergency disconnect feature is enabled." + }, + { + "name": "external_emergency_signal_fingerprint", + "type": "String", + "description": "The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external_emergency_signal_url. If provided, the WARP client will use this value to verify the server's identity. The device will ignore any response if the server's certificate fingerprint does not exactly match this value." + }, + { + "name": "external_emergency_signal_interval", + "type": "String", + "description": "The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., \"5m\", \"2m30s\", \"1h\"). Minimum 30 seconds." + }, + { + "name": "external_emergency_signal_url", + "type": "String", + "description": "The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host." + }, + { + "name": "gateway_proxy_enabled", + "type": "Boolean", + "description": "Enable gateway proxy filtering on TCP." + }, + { + "name": "gateway_udp_proxy_enabled", + "type": "Boolean", + "description": "Enable gateway proxy filtering on UDP." + }, + { + "name": "root_certificate_installation_enabled", + "type": "Boolean", + "description": "Enable installation of cloudflare managed root certificate." + }, + { + "name": "use_zt_virtual_ip", + "type": "Boolean", + "description": "Enable using CGNAT virtual IPv4." + } + ] + }, + "resource:cloudflare_zero_trust_device_settings": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_settings", + "description": "Accepted Permissions\n\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_device_settings\" \"example_zero_trust_device_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n disable_for_time = 0\n external_emergency_signal_enabled = true\n external_emergency_signal_fingerprint = \"abcd1234567890abcd1234567890abcd1234567890abcd1234567890abcd1234\"\n external_emergency_signal_interval = \"5m\"\n external_emergency_signal_url = \"https://192.0.2.1/signal\"\n gateway_proxy_enabled = true\n gateway_udp_proxy_enabled = true\n root_certificate_installation_enabled = true\n use_zt_virtual_ip = true\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "disable_for_time", + "type": "Number", + "description": "Sets the time limit, in seconds, that a user can use an override code to bypass WARP." + }, + { + "name": "external_emergency_signal_enabled", + "type": "Boolean", + "description": "Controls whether the external emergency disconnect feature is enabled." + }, + { + "name": "external_emergency_signal_fingerprint", + "type": "String", + "description": "The SHA256 fingerprint (64 hexadecimal characters) of the HTTPS server certificate for the external_emergency_signal_url. If provided, the WARP client will use this value to verify the server's identity. The device will ignore any response if the server's certificate fingerprint does not exactly match this value." + }, + { + "name": "external_emergency_signal_interval", + "type": "String", + "description": "The interval at which the WARP client fetches the emergency disconnect signal, formatted as a duration string (e.g., \"5m\", \"2m30s\", \"1h\"). Minimum 30 seconds." + }, + { + "name": "external_emergency_signal_url", + "type": "String", + "description": "The HTTPS URL from which to fetch the emergency disconnect signal. Must use HTTPS and have an IPv4 or IPv6 address as the host." + }, + { + "name": "gateway_proxy_enabled", + "type": "Boolean", + "description": "Enable gateway proxy filtering on TCP." + }, + { + "name": "gateway_udp_proxy_enabled", + "type": "Boolean", + "description": "Enable gateway proxy filtering on UDP." + }, + { + "name": "root_certificate_installation_enabled", + "type": "Boolean", + "description": "Enable installation of cloudflare managed root certificate." + }, + { + "name": "use_zt_virtual_ip", + "type": "Boolean", + "description": "Enable using CGNAT virtual IPv4." + } + ], + "computed": [] + }, + "data-source:cloudflare_zero_trust_device_subnet": { + "kind": "data-source", + "name": "cloudflare_zero_trust_device_subnet", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`", + "example": "data \"cloudflare_zero_trust_device_subnet\" \"example_zero_trust_device_subnet\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n subnet_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "subnet_id", + "type": "String", + "description": "The UUID of the subnet." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + } + ], + "computed": [ + { + "name": "capacity", + "type": "Attributes", + "description": "IP capacity information for the subnet.", + "children": [ + { + "name": "total", + "type": "Number", + "description": "Total number of assignable IPs in the subnet." + }, + { + "name": "used", + "type": "Number", + "description": "Number of assigned IPs in the subnet." + } + ] + }, + { + "name": "comment", + "type": "String", + "description": "An optional description of the subnet." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the subnet." + }, + { + "name": "is_default_network", + "type": "Boolean", + "description": "If `true`, this is the default subnet for the account. There can only be one default subnet per account." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the subnet." + }, + { + "name": "network", + "type": "String", + "description": "The private IPv4 or IPv6 range defining the subnet, in CIDR notation." + }, + { + "name": "subnet_type", + "type": "String", + "description": "The type of subnet.\nAvailable values: \"cloudflare_source\", \"initial_resolved_ip\", \"warp\"." + } + ] + }, + "resource:cloudflare_zero_trust_device_subnet": { + "kind": "resource", + "name": "cloudflare_zero_trust_device_subnet", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`", + "example": "resource \"cloudflare_zero_trust_device_subnet\" \"example_zero_trust_device_subnet\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"IPv4 Cloudflare Source IPs\"\n network = \"100.64.0.0/12\"\n comment = \"example comment\"\n is_default_network = true\n}", + "importExample": "$ terraform import cloudflare_zero_trust_device_subnet.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the subnet." + }, + { + "name": "network", + "type": "String", + "description": "The private IPv4 or IPv6 range defining the subnet, in CIDR notation." + } + ], + "optional": [ + { + "name": "comment", + "type": "String", + "description": "An optional description of the subnet." + }, + { + "name": "is_default_network", + "type": "Boolean", + "description": "If `true`, this is the default subnet for the account. There can only be one default subnet per account." + } + ], + "computed": [ + { + "name": "capacity", + "type": "Attributes", + "description": "IP capacity information for the subnet.", + "children": [ + { + "name": "total", + "type": "Number", + "description": "Total number of assignable IPs in the subnet." + }, + { + "name": "used", + "type": "Number", + "description": "Number of assigned IPs in the subnet." + } + ] + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "The UUID of the subnet." + }, + { + "name": "subnet_type", + "type": "String", + "description": "The type of subnet.\nAvailable values: \"cloudflare_source\", \"initial_resolved_ip\", \"warp\"." + } + ] + }, + "data-source:cloudflare_zero_trust_dex_rule": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dex_rule", + "description": "Accepted Permissions\n\n- `Cloudflare DEX Read`\n- `Cloudflare DEX Write`\n- `Zero Trust Read`\n- `Zero Trust Report`", + "example": "data \"cloudflare_zero_trust_dex_rule\" \"example_zero_trust_dex_rule\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "rule_id", + "type": "String", + "description": "API Resource UUID tag." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Unique identifier linked to an account." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "API Resource UUID tag." + }, + { + "name": "match", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "targeted_tests", + "type": "Attributes List", + "children": [ + { + "name": "data", + "type": "Attributes", + "description": "The configuration object which contains the details for the WARP client to conduct the test.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The desired endpoint to test." + }, + { + "name": "kind", + "type": "String", + "description": "The type of test.\nAvailable values: \"http\", \"traceroute\"." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP request method type.\nAvailable values: \"GET\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "test_id", + "type": "String" + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dex_rule": { + "kind": "resource", + "name": "cloudflare_zero_trust_dex_rule", + "description": "Accepted Permissions\n\n- `Cloudflare DEX Read`\n- `Cloudflare DEX Write`\n- `Zero Trust Read`\n- `Zero Trust Report`", + "example": "resource \"cloudflare_zero_trust_dex_rule\" \"example_zero_trust_dex_rule\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n match = \"match\"\n name = \"name\"\n description = \"description\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dex_rule.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Unique identifier linked to an account." + }, + { + "name": "match", + "type": "String", + "description": "The wirefilter expression to match." + }, + { + "name": "name", + "type": "String", + "description": "The name of the Rule." + } + ], + "optional": [ + { + "name": "description", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "API Resource UUID tag." + }, + { + "name": "targeted_tests", + "type": "Attributes List", + "children": [ + { + "name": "data", + "type": "Attributes", + "description": "The configuration object which contains the details for the WARP client to conduct the test.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The desired endpoint to test." + }, + { + "name": "kind", + "type": "String", + "description": "The type of test.\nAvailable values: \"http\", \"traceroute\"." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP request method type.\nAvailable values: \"GET\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "test_id", + "type": "String" + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dex_rules": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dex_rules", + "description": "Accepted Permissions\n\n- `Cloudflare DEX Read`\n- `Cloudflare DEX Write`\n- `Zero Trust Read`\n- `Zero Trust Report`", + "example": "data \"cloudflare_zero_trust_dex_rules\" \"example_zero_trust_dex_rules\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n name = \"name\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Unique identifier linked to an account." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "Filter results by rule name." + }, + { + "name": "sort_by", + "type": "String", + "description": "Which property to sort results by.\nAvailable values: \"name\", \"created_at\", \"updated_at\"." + }, + { + "name": "sort_order", + "type": "String", + "description": "Sort direction for sort_by property.\nAvailable values: \"ASC\", \"DESC\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "rules", + "type": "Attributes List", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "API Resource UUID tag." + }, + { + "name": "match", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "targeted_tests", + "type": "Attributes List", + "children": [ + { + "name": "data", + "type": "Attributes", + "description": "The configuration object which contains the details for the WARP client to conduct the test.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The desired endpoint to test." + }, + { + "name": "kind", + "type": "String", + "description": "The type of test.\nAvailable values: \"http\", \"traceroute\"." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP request method type.\nAvailable values: \"GET\"." + } + ] + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "test_id", + "type": "String" + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dex_test": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dex_test", + "description": "Accepted Permissions\n\n- `Cloudflare DEX Read`\n- `Cloudflare DEX Write`\n- `Zero Trust Read`\n- `Zero Trust Report`", + "example": "data \"cloudflare_zero_trust_dex_test\" \"example_zero_trust_dex_test\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n dex_test_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Unique identifier linked to an account." + }, + { + "name": "dex_test_id", + "type": "String", + "description": "The unique identifier for the test." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "kind", + "type": "String", + "description": "Filter by test type.\nAvailable values: \"http\", \"traceroute\"." + }, + { + "name": "test_name", + "type": "String", + "description": "Filter by test name." + } + ] + }, + { + "name": "target_policies", + "type": "Attributes List", + "description": "DEX rules targeted by this test", + "children": [ + { + "name": "default", + "type": "Boolean", + "description": "Whether the DEX rule is the account default." + }, + { + "name": "id", + "type": "String", + "description": "The id of the DEX rule." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX rule." + } + ] + } + ], + "computed": [ + { + "name": "created", + "type": "String", + "description": "Date the test was created, in RFC 3339 format." + }, + { + "name": "data", + "type": "Attributes", + "description": "The configuration object which contains the details for the WARP client to conduct the test.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The desired endpoint to test." + }, + { + "name": "kind", + "type": "String", + "description": "The type of test.\nAvailable values: \"http\", \"traceroute\"." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP request method type.\nAvailable values: \"GET\"." + } + ] + }, + { + "name": "description", + "type": "String", + "description": "Additional details about the test." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether or not the test is active." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier for the test." + }, + { + "name": "interval", + "type": "String", + "description": "How often the test will run." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX test. Must be unique." + }, + { + "name": "targeted", + "type": "Boolean" + }, + { + "name": "test_id", + "type": "String", + "description": "The unique identifier for the test." + }, + { + "name": "updated", + "type": "String", + "description": "Date the test was last updated, in RFC 3339 format." + } + ] + }, + "resource:cloudflare_zero_trust_dex_test": { + "kind": "resource", + "name": "cloudflare_zero_trust_dex_test", + "description": "Accepted Permissions\n\n- `Cloudflare DEX Read`\n- `Cloudflare DEX Write`\n- `Zero Trust Read`\n- `Zero Trust Report`", + "example": "resource \"cloudflare_zero_trust_dex_test\" \"example_zero_trust_dex_test\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n data = {\n host = \"https://dash.cloudflare.com\"\n kind = \"http\"\n method = \"GET\"\n }\n enabled = true\n interval = \"30m\"\n name = \"HTTP dash health check\"\n description = \"Checks the dash endpoint every 30 minutes\"\n target_policies = [{\n id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n default = true\n name = \"name\"\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dex_test.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Unique identifier linked to an account." + }, + { + "name": "data", + "type": "Attributes", + "description": "The configuration object which contains the details for the WARP client to conduct the test.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The desired endpoint to test." + }, + { + "name": "kind", + "type": "String", + "description": "The type of test." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP request method type." + } + ] + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether or not the test is active." + }, + { + "name": "interval", + "type": "String", + "description": "How often the test will run." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX test. Must be unique." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Additional details about the test." + }, + { + "name": "target_policies", + "type": "Attributes List", + "description": "DEX rules targeted by this test", + "children": [ + { + "name": "default", + "type": "Boolean", + "description": "Whether the DEX rule is the account default." + }, + { + "name": "id", + "type": "String", + "description": "The id of the DEX rule." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX rule." + } + ] + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The unique identifier for the test." + }, + { + "name": "targeted", + "type": "Boolean" + }, + { + "name": "test_id", + "type": "String", + "description": "The unique identifier for the test." + } + ] + }, + "list-data-source:cloudflare_zero_trust_dex_tests": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dex_tests", + "description": "Accepted Permissions\n\n- `Cloudflare DEX Read`\n- `Cloudflare DEX Write`\n- `Zero Trust Read`\n- `Zero Trust Report`", + "example": "data \"cloudflare_zero_trust_dex_tests\" \"example_zero_trust_dex_tests\" {\n account_id = \"01a7362d577a6c3019a474fd6f485823\"\n kind = \"http\"\n test_name = \"testName\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Unique identifier linked to an account." + }, + { + "name": "kind", + "type": "String", + "description": "Filter by test type.\nAvailable values: \"http\", \"traceroute\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "test_name", + "type": "String", + "description": "Filter by test name." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created", + "type": "String", + "description": "Date the test was created, in RFC 3339 format." + }, + { + "name": "data", + "type": "Attributes", + "description": "The configuration object which contains the details for the WARP client to conduct the test.", + "children": [ + { + "name": "host", + "type": "String", + "description": "The desired endpoint to test." + }, + { + "name": "kind", + "type": "String", + "description": "The type of test.\nAvailable values: \"http\", \"traceroute\"." + }, + { + "name": "method", + "type": "String", + "description": "The HTTP request method type.\nAvailable values: \"GET\"." + } + ] + }, + { + "name": "description", + "type": "String", + "description": "Additional details about the test." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Determines whether or not the test is active." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier for the test." + }, + { + "name": "interval", + "type": "String", + "description": "How often the test will run." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX test. Must be unique." + }, + { + "name": "target_policies", + "type": "Attributes List", + "description": "DEX rules targeted by this test", + "children": [ + { + "name": "default", + "type": "Boolean", + "description": "Whether the DEX rule is the account default." + }, + { + "name": "id", + "type": "String", + "description": "The id of the DEX rule." + }, + { + "name": "name", + "type": "String", + "description": "The name of the DEX rule." + } + ] + }, + { + "name": "targeted", + "type": "Boolean" + }, + { + "name": "test_id", + "type": "String", + "description": "The unique identifier for the test." + }, + { + "name": "updated", + "type": "String", + "description": "Date the test was last updated, in RFC 3339 format." + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_custom_entries": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_custom_entries", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_custom_entries\" \"example_zero_trust_dlp_custom_entries\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_custom_entry": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_custom_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_custom_entry\" \"example_zero_trust_dlp_custom_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "entry_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_custom_entry": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_custom_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_custom_entry\" \"example_zero_trust_dlp_custom_entry\" {\n account_id = \"account_id\"\n enabled = true\n name = \"name\"\n pattern = {\n regex = \"regex\"\n validation = \"luhn\"\n }\n description = \"description\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_custom_entry.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + } + ], + "optional": [ + { + "name": "description", + "type": "String" + }, + { + "name": "profile_id", + "type": "String" + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_custom_profile": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_custom_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_custom_profile\" \"example_zero_trust_dlp_custom_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "profile_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "ai_context_enabled", + "type": "Boolean" + }, + { + "name": "allowed_match_count", + "type": "Number", + "description": "Related DLP policies will trigger when the match count exceeds the number set." + }, + { + "name": "confidence_threshold", + "type": "String", + "description": "Available values: \"low\", \"medium\", \"high\", \"very_high\"." + }, + { + "name": "context_awareness", + "type": "Attributes", + "description": "Scan the context of predefined entries to only return matches surrounded by keywords.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "If true, scan the context of predefined entries to only return matches surrounded by keywords." + }, + { + "name": "skip", + "type": "Attributes", + "description": "Content types to exclude from context analysis and return all matches.", + "children": [ + { + "name": "files", + "type": "Boolean", + "description": "If the content type is a file, skip context analysis and return all matches." + } + ] + } + ] + }, + { + "name": "created_at", + "type": "String", + "description": "When the profile was created." + }, + { + "name": "data_classes", + "type": "List of String", + "description": "Data classes associated with this profile." + }, + { + "name": "data_tags", + "type": "List of String", + "description": "Data tags associated with this profile." + }, + { + "name": "description", + "type": "String", + "description": "The description of the profile." + }, + { + "name": "entries", + "type": "Attributes List", + "deprecated": "Deprecated.", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "integration_id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "The name of the profile." + }, + { + "name": "ocr_enabled", + "type": "Boolean" + }, + { + "name": "open_access", + "type": "Boolean", + "description": "Whether this profile can be accessed by anyone." + }, + { + "name": "sensitivity_levels", + "type": "Attributes List", + "description": "Sensitivity levels associated with this profile.", + "children": [ + { + "name": "group_id", + "type": "String" + }, + { + "name": "level_id", + "type": "String" + } + ] + }, + { + "name": "shared_entries", + "type": "Attributes List", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"predefined\", \"integration\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "When the profile was lasted updated." + } + ] + }, + "resource:cloudflare_zero_trust_dlp_custom_profile": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_custom_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_custom_profile\" \"example_zero_trust_dlp_custom_profile\" {\n account_id = \"account_id\"\n name = \"name\"\n ai_context_enabled = true\n allowed_match_count = 5\n confidence_threshold = \"confidence_threshold\"\n context_awareness = {\n enabled = true\n skip = {\n files = true\n }\n }\n data_classes = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n data_tags = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n description = \"description\"\n ocr_enabled = true\n sensitivity_levels = [{\n group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n shared_entries = [{\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_custom_profile.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "ai_context_enabled", + "type": "Boolean" + }, + { + "name": "allowed_match_count", + "type": "Number", + "description": "Related DLP policies will trigger when the match count exceeds the number set." + }, + { + "name": "confidence_threshold", + "type": "String" + }, + { + "name": "context_awareness", + "type": "Attributes", + "description": "Scan the context of predefined entries to only return matches surrounded by keywords.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "If true, scan the context of predefined entries to only return matches surrounded by keywords." + }, + { + "name": "skip", + "type": "Attributes", + "description": "Content types to exclude from context analysis and return all matches.", + "children": [ + { + "name": "files", + "type": "Boolean", + "description": "If the content type is a file, skip context analysis and return all matches." + } + ] + } + ] + }, + { + "name": "data_classes", + "type": "List of String", + "description": "Data class IDs to associate with the profile." + }, + { + "name": "data_tags", + "type": "List of String", + "description": "Data tag IDs to associate with the profile." + }, + { + "name": "description", + "type": "String", + "description": "The description of the profile." + }, + { + "name": "entries", + "type": "Attributes Set", + "description": "Custom entries from this profile.\nIf this field is omitted, entries owned by this profile will not be changed.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "entry_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + } + ] + }, + { + "name": "ocr_enabled", + "type": "Boolean" + }, + { + "name": "sensitivity_levels", + "type": "Attributes List", + "description": "Sensitivity levels to associate with the profile.", + "children": [ + { + "name": "group_id", + "type": "String" + }, + { + "name": "level_id", + "type": "String" + } + ] + }, + { + "name": "shared_entries", + "type": "Attributes Set", + "description": "Entries from other profiles (e.g. pre-defined Cloudflare profiles, or your Microsoft Information Protection profiles).", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "entry_id", + "type": "String" + }, + { + "name": "entry_type", + "type": "String", + "description": "Available values: \"custom\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\"." + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "When the profile was created." + }, + { + "name": "id", + "type": "String", + "description": "The id of the profile (uuid)." + }, + { + "name": "integration_id", + "type": "String" + }, + { + "name": "open_access", + "type": "Boolean", + "description": "Whether this profile can be accessed by anyone." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"predefined\", \"integration\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "When the profile was lasted updated." + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_custom_prompt_topic": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_custom_prompt_topic", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_custom_prompt_topic\" \"example_zero_trust_dlp_custom_prompt_topic\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "entry_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "profile_id", + "type": "String", + "deprecated": "Deprecated." + }, + { + "name": "topic", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_custom_prompt_topics": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_custom_prompt_topics", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_custom_prompt_topics\" \"example_zero_trust_dlp_custom_prompt_topics\" {\n account_id = \"account_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean", + "deprecated": "Deprecated." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "profile_id", + "type": "String", + "deprecated": "Deprecated." + }, + { + "name": "topic", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_data_class": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_data_class", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_data_class\" \"example_zero_trust_dlp_data_class\" {\n account_id = \"account_id\"\n data_class_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "data_class_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "data_tags", + "type": "List of String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "expression", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "sensitivity_levels", + "type": "Attributes List", + "children": [ + { + "name": "group_id", + "type": "String" + }, + { + "name": "level_id", + "type": "String" + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_data_class": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_data_class", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_data_class\" \"example_zero_trust_dlp_data_class\" {\n account_id = \"account_id\"\n data_tags = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n expression = \"expression\"\n name = \"name\"\n sensitivity_levels = [{\n group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n }]\n description = \"description\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_data_class.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "data_tags", + "type": "List of String" + }, + { + "name": "expression", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "sensitivity_levels", + "type": "Attributes List", + "children": [ + { + "name": "group_id", + "type": "String" + }, + { + "name": "level_id", + "type": "String" + } + ] + } + ], + "optional": [ + { + "name": "description", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_data_classes": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_data_classes", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_data_classes\" \"example_zero_trust_dlp_data_classes\" {\n account_id = \"account_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "data_tags", + "type": "List of String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "expression", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "sensitivity_levels", + "type": "Attributes List", + "children": [ + { + "name": "group_id", + "type": "String" + }, + { + "name": "level_id", + "type": "String" + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_data_tag": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_data_tag", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_data_tag\" \"example_zero_trust_dlp_data_tag\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n tag_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "category_id", + "type": "String" + }, + { + "name": "tag_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_data_tag": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_data_tag", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_data_tag\" \"example_zero_trust_dlp_data_tag\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n name = \"name\"\n description = \"description\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_data_tag.example '//'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "category_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "description", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_data_tag_categories": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_data_tag_categories", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_data_tag_categories\" \"example_zero_trust_dlp_data_tag_categories\" {\n account_id = \"account_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "tags", + "type": "Attributes List", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "template_id", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_data_tag_category": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_data_tag_category", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_data_tag_category\" \"example_zero_trust_dlp_data_tag_category\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "category_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "tags", + "type": "Attributes List", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "template_id", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_data_tag_category": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_data_tag_category", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_data_tag_category\" \"example_zero_trust_dlp_data_tag_category\" {\n account_id = \"account_id\"\n name = \"name\"\n description = \"description\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_data_tag_category.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "description", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "tags", + "type": "Attributes List", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "template_id", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_data_tags": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_data_tags", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_data_tags\" \"example_zero_trust_dlp_data_tags\" {\n account_id = \"account_id\"\n category_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "category_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_dataset": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_dataset", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_dataset\" \"example_zero_trust_dlp_dataset\" {\n account_id = \"account_id\"\n dataset_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "dataset_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean" + }, + { + "name": "columns", + "type": "Attributes List", + "children": [ + { + "name": "entry_id", + "type": "String" + }, + { + "name": "header_name", + "type": "String" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "The description of the dataset." + }, + { + "name": "encoding_version", + "type": "Number" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads." + }, + { + "name": "uploads", + "type": "Attributes List", + "children": [ + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "version", + "type": "Number" + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_dlp_dataset": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_dataset", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_dataset\" \"example_zero_trust_dlp_dataset\" {\n account_id = \"account_id\"\n name = \"name\"\n case_sensitive = true\n description = \"description\"\n encoding_version = 0\n secret = true\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if `secret` is true or undefined" + }, + { + "name": "dataset_id", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "The description of the dataset." + }, + { + "name": "encoding_version", + "type": "Number", + "description": "Dataset encoding version\n\nNon-secret custom word lists with no header are always version 1.\nSecret EDM lists with no header are version 1.\nMulticolumn CSV with headers are version 2.\nOmitting this field provides the default value 0, which is interpreted\nthe same as 1." + }, + { + "name": "secret", + "type": "Boolean", + "description": "Generate a secret dataset.\n\nIf true, the response will include a secret to use with the EDM encoder.\nIf false, the response has no secret and the dataset is uploaded in plaintext." + } + ], + "computed": [ + { + "name": "columns", + "type": "Attributes List", + "children": [ + { + "name": "entry_id", + "type": "String" + }, + { + "name": "header_name", + "type": "String" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dataset", + "type": "Attributes", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean" + }, + { + "name": "columns", + "type": "Attributes List", + "children": [ + { + "name": "entry_id", + "type": "String" + }, + { + "name": "header_name", + "type": "String" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "The description of the dataset." + }, + { + "name": "encoding_version", + "type": "Number" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads." + }, + { + "name": "uploads", + "type": "Attributes List", + "children": [ + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "version", + "type": "Number" + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "max_cells", + "type": "Number" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads." + }, + { + "name": "uploads", + "type": "Attributes List", + "children": [ + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "version", + "type": "Number" + } + ] + }, + { + "name": "version", + "type": "Number", + "description": "The version to use when uploading the dataset." + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_datasets": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_datasets", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_datasets\" \"example_zero_trust_dlp_datasets\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean" + }, + { + "name": "columns", + "type": "Attributes List", + "children": [ + { + "name": "entry_id", + "type": "String" + }, + { + "name": "header_name", + "type": "String" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "The description of the dataset." + }, + { + "name": "encoding_version", + "type": "Number" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "Stores when the dataset was last updated.\n\nThis includes name or description changes as well as uploads." + }, + { + "name": "uploads", + "type": "Attributes List", + "children": [ + { + "name": "num_cells", + "type": "Number" + }, + { + "name": "status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "version", + "type": "Number" + } + ] + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_entries": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_entries", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_entries\" \"example_zero_trust_dlp_entries\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_entry": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_entry\" \"example_zero_trust_dlp_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "entry_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_entry": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_entry\" \"example_zero_trust_dlp_entry\" {\n account_id = \"account_id\"\n enabled = true\n name = \"name\"\n pattern = {\n regex = \"regex\"\n validation = \"luhn\"\n }\n description = \"description\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_entry.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + } + ], + "optional": [ + { + "name": "description", + "type": "String" + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"predefined\", \"integration\"." + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_integration_entries": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_integration_entries", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_integration_entries\" \"example_zero_trust_dlp_integration_entries\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_integration_entry": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_integration_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_integration_entry\" \"example_zero_trust_dlp_integration_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "entry_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_integration_entry": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_integration_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_integration_entry\" \"example_zero_trust_dlp_integration_entry\" {\n account_id = \"account_id\"\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_integration_entry.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "entry_id", + "type": "String" + } + ], + "optional": [ + { + "name": "profile_id", + "type": "String", + "description": "This field is not used as the owning profile.\nFor predefined entries it is already set to a predefined profile." + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_predefined_entries": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_predefined_entries", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_predefined_entries\" \"example_zero_trust_dlp_predefined_entries\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_predefined_entry": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_predefined_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_predefined_entry\" \"example_zero_trust_dlp_predefined_entry\" {\n account_id = \"account_id\"\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "entry_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_predefined_entry": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_predefined_entry", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_predefined_entry\" \"example_zero_trust_dlp_predefined_entry\" {\n account_id = \"account_id\"\n enabled = true\n entry_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_predefined_entry.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "entry_id", + "type": "String" + } + ], + "optional": [ + { + "name": "profile_id", + "type": "String", + "description": "This field is not used as the owning profile.\nFor predefined entries it is already set to a predefined profile." + } + ], + "computed": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profiles", + "type": "Attributes List", + "children": [ + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ] + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "upload_status", + "type": "String", + "description": "Available values: \"empty\", \"uploading\", \"pending\", \"processing\", \"failed\", \"complete\"." + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_predefined_profile": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_predefined_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_predefined_profile\" \"example_zero_trust_dlp_predefined_profile\" {\n account_id = \"account_id\"\n profile_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "profile_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "ai_context_enabled", + "type": "Boolean" + }, + { + "name": "allowed_match_count", + "type": "Number" + }, + { + "name": "confidence_threshold", + "type": "String" + }, + { + "name": "enabled_entries", + "type": "List of String", + "description": "Entries to enable for this predefined profile. Any entries not provided will be disabled." + }, + { + "name": "entries", + "type": "Attributes List", + "description": "This field has been deprecated for `enabled_entries`.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "case_sensitive", + "type": "Boolean", + "description": "Only applies to custom word lists.\nDetermines if the words should be matched in a case-sensitive manner\nCannot be set to false if secret is true" + }, + { + "name": "confidence", + "type": "Attributes", + "children": [ + { + "name": "ai_context_available", + "type": "Boolean", + "description": "Indicates whether this entry has AI remote service validation." + }, + { + "name": "available", + "type": "Boolean", + "description": "Indicates whether this entry has any form of validation that is not an AI remote service." + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deprecated", + "type": "Boolean", + "description": "Whether this entry is deprecated for new use. This is computed from the static catalog and\nemitted only when true." + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "pattern", + "type": "Attributes", + "children": [ + { + "name": "regex", + "type": "String" + }, + { + "name": "validation", + "type": "String", + "description": "Available values: \"luhn\".", + "deprecated": "Deprecated." + } + ] + }, + { + "name": "profile_id", + "type": "String" + }, + { + "name": "secret", + "type": "Boolean" + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"custom\", \"custom_prompt_topic\", \"predefined\", \"integration\", \"exact_data\", \"document_fingerprint\", \"word_list\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "variant", + "type": "Attributes", + "description": "A Predefined AI prompt classification topic entry.", + "children": [ + { + "name": "description", + "type": "String", + "description": "A customer-facing explanation of what this predefined AI prompt topic represents." + }, + { + "name": "topic_type", + "type": "String", + "description": "Available values: \"Intent\", \"Content\"." + }, + { + "name": "type", + "type": "String", + "description": "Available values: \"PromptTopic\", \"General\"." + } + ] + }, + { + "name": "word_list", + "type": "String" + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String", + "description": "The name of the predefined profile." + }, + { + "name": "ocr_enabled", + "type": "Boolean" + }, + { + "name": "open_access", + "type": "Boolean", + "description": "Whether this profile can be accessed by anyone." + } + ] + }, + "resource:cloudflare_zero_trust_dlp_predefined_profile": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_predefined_profile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_predefined_profile\" \"example_zero_trust_dlp_predefined_profile\" {\n profile_id = \"e91a2360-da51-4fdf-9711-bcdecd462614\"\n account_id = \"account_id\"\n ocr_enabled = true\n // Entries in this predefined profile we want to enable. Any entries not included will be disabled\n enabled_entries = [\n \"56a8c060-01bb-4f89-ba1e-3ad42770a342\",\n \"7f575e6d-039a-465e-85cf-175bda88d4f2\",\n \"03ebabfd-ce7e-45ed-8061-65e28f0a6e53\",\n \"2d9c356d-b5a3-482a-b01e-0363e0de7458\",\n \"2f3657af-c39b-4899-9a98-22f7d187dd28\",\n \"753a16f9-f533-4208-a5b8-6319b201e9fb\",\n \"ebcea2c4-335a-457c-853b-f7ae7cc74e07\",\n \"3f5c4c83-f34c-4d17-81c7-3028385737b3\",\n \"d1a84fde-c375-4d3c-8a27-8c4eaa33cf60\",\n \"6dbe5604-d3a3-4c3e-905c-57985704bea7\",\n \"55ba2c6c-8ef4-4b2e-9148-e75e8b6ccac1\",\n \"5b1d5035-8c53-4bc9-a151-404eb32b34b4\",\n \"acf28d88-2daf-4bc4-aa36-5ac1fac0540a\"\n ]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_predefined_profile.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "profile_id", + "type": "String" + } + ], + "optional": [ + { + "name": "ai_context_enabled", + "type": "Boolean" + }, + { + "name": "allowed_match_count", + "type": "Number" + }, + { + "name": "confidence_threshold", + "type": "String" + }, + { + "name": "enabled_entries", + "type": "List of String" + }, + { + "name": "entries", + "type": "Attributes List", + "deprecated": "Deprecated.", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "id", + "type": "String" + } + ] + }, + { + "name": "ocr_enabled", + "type": "Boolean" + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String", + "description": "The name of the predefined profile." + }, + { + "name": "open_access", + "type": "Boolean", + "description": "Whether this profile can be accessed by anyone." + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_sensitivity_group": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_sensitivity_group", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_sensitivity_group\" \"example_zero_trust_dlp_sensitivity_group\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "sensitivity_group_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "levels", + "type": "Attributes List", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String" + }, + { + "name": "template_id", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_sensitivity_group": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_sensitivity_group", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_sensitivity_group\" \"example_zero_trust_dlp_sensitivity_group\" {\n account_id = \"account_id\"\n name = \"name\"\n description = \"description\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_sensitivity_group.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + } + ], + "optional": [ + { + "name": "description", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "levels", + "type": "Attributes List", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "template_id", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_sensitivity_groups": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_sensitivity_groups", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_sensitivity_groups\" \"example_zero_trust_dlp_sensitivity_groups\" {\n account_id = \"account_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "levels", + "type": "Attributes List", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "name", + "type": "String" + }, + { + "name": "template_id", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_sensitivity_level": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_sensitivity_level", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_sensitivity_level\" \"example_zero_trust_dlp_sensitivity_level\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n sensitivity_level_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "sensitivity_group_id", + "type": "String" + }, + { + "name": "sensitivity_level_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_sensitivity_level": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_sensitivity_level", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_sensitivity_level\" \"example_zero_trust_dlp_sensitivity_level\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n name = \"name\"\n description = \"description\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_sensitivity_level.example '//'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "sensitivity_group_id", + "type": "String" + } + ], + "optional": [ + { + "name": "description", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_sensitivity_level_order": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_sensitivity_level_order", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_sensitivity_level_order\" \"example_zero_trust_dlp_sensitivity_level_order\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "sensitivity_group_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "level_ids", + "type": "List of String" + } + ] + }, + "resource:cloudflare_zero_trust_dlp_sensitivity_level_order": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_sensitivity_level_order", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_sensitivity_level_order\" \"example_zero_trust_dlp_sensitivity_level_order\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n level_ids = [\"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_sensitivity_level_order.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "level_ids", + "type": "List of String" + }, + { + "name": "sensitivity_group_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "list-data-source:cloudflare_zero_trust_dlp_sensitivity_levels": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dlp_sensitivity_levels", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_sensitivity_levels\" \"example_zero_trust_dlp_sensitivity_levels\" {\n account_id = \"account_id\"\n sensitivity_group_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "sensitivity_group_id", + "type": "String" + } + ], + "optional": [ + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_dlp_settings": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dlp_settings", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dlp_settings\" \"example_zero_trust_dlp_settings\" {\n account_id = \"account_id\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "ai_context_analysis", + "type": "Boolean", + "description": "Whether AI context analysis is enabled at the account level." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "ocr", + "type": "Boolean", + "description": "Whether OCR is enabled at the account level." + }, + { + "name": "payload_logging", + "type": "Attributes", + "children": [ + { + "name": "masking_level", + "type": "String", + "description": "Masking level for payload logs.\n\n- `full`: The entire payload is masked.\n- `partial`: Only partial payload content is masked.\n- `clear`: No masking is applied to the payload content.\n- `default`: DLP uses its default masking behavior.\nAvailable values: \"full\", \"partial\", \"clear\", \"default\"." + }, + { + "name": "public_key", + "type": "String", + "description": "Base64-encoded public key for encrypting payload logs. Null when payload logging is disabled." + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_dlp_settings": { + "kind": "resource", + "name": "cloudflare_zero_trust_dlp_settings", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dlp_settings\" \"example_zero_trust_dlp_settings\" {\n account_id = \"account_id\"\n ai_context_analysis = true\n ocr = true\n payload_logging = {\n masking_level = \"full\"\n public_key = \"public_key\"\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dlp_settings.example ''", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "ai_context_analysis", + "type": "Boolean", + "description": "Whether AI context analysis is enabled at the account level." + }, + { + "name": "ocr", + "type": "Boolean", + "description": "Whether OCR is enabled at the account level." + }, + { + "name": "payload_logging", + "type": "Attributes", + "description": "Request model for payload log settings within the DLP settings endpoint.\nUnlike the legacy endpoint, null and missing are treated identically here\n(both mean \"not provided\" for PATCH, \"reset to default\" for PUT).", + "children": [ + { + "name": "masking_level", + "type": "String", + "description": "Masking level for payload logs.\n\n- `full`: The entire payload is masked.\n- `partial`: Only partial payload content is masked.\n- `clear`: No masking is applied to the payload content.\n- `default`: DLP uses its default masking behavior.\nAvailable values: \"full\", \"partial\", \"clear\", \"default\"." + }, + { + "name": "public_key", + "type": "String", + "description": "Base64-encoded public key for encrypting payload logs.\n\n- Set to a non-empty base64 string to enable payload logging with the given key.\n- Set to an empty string to disable payload logging.\n- Omit or set to null to leave unchanged (PATCH) or reset to disabled (PUT)." + } + ] + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + } + ] + }, + "data-source:cloudflare_zero_trust_dns_location": { + "kind": "data-source", + "name": "cloudflare_zero_trust_dns_location", + "description": "Accepted Permissions\n\n- `Cloudflare Zero Trust Secure DNS Locations Write`\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dns_location\" \"example_zero_trust_dns_location\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n location_id = \"ed35569b41ce4d1facfe683550f54086\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned locations by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a location must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the location name.\n * `id` — substring match on the location ID (UUID), with or without dashes.\n * `is_default` — whether it is the default for the account.\n\nEach entry must match one of the per-field patterns below:\n * the field must be one of `name`, `id`, or `is_default`;\n * `name`/`id` accept any value;\n * `is_default` only accepts `true` or `false`; any other value returns `400`" + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned locations by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by location name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\nAvailable values: \"name\", \"created_at\", \"updated_at\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring match on the location name. When combined\nwith `filter`, both must match (logical AND)." + } + ] + }, + { + "name": "location_id", + "type": "String" + } + ], + "computed": [ + { + "name": "client_default", + "type": "Boolean", + "description": "Indicate whether this location is the default location." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dns_destination_ips_id", + "type": "String", + "description": "Indicate the identifier of the pair of IPv4 addresses assigned to this location." + }, + { + "name": "dns_destination_ipv6_block_id", + "type": "String", + "description": "Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block." + }, + { + "name": "doh_subdomain", + "type": "String", + "description": "Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value." + }, + { + "name": "ecs_support", + "type": "Boolean", + "description": "Indicate whether the location must resolve EDNS queries." + }, + { + "name": "endpoints", + "type": "Attributes", + "description": "Configure the destination endpoints for this location.", + "children": [ + { + "name": "doh", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the DOH endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IP address or IP CIDR." + } + ] + }, + { + "name": "require_token", + "type": "Boolean", + "description": "Specify whether the DOH endpoint requires user identity authentication." + } + ] + }, + { + "name": "dot", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the DOT endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IP address or IP CIDR." + } + ] + } + ] + }, + { + "name": "ipv4", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the IPv4 endpoint is enabled for this location." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the IPV6 endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IPv6 address or IPv6 CIDR." + } + ] + } + ] + } + ] + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "ip", + "type": "String", + "description": "Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location." + }, + { + "name": "ipv4_destination", + "type": "String", + "description": "Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only." + }, + { + "name": "ipv4_destination_backup", + "type": "String", + "description": "Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only." + }, + { + "name": "max_ttl", + "type": "Attributes", + "description": "Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged.\nAvailable values: \"inherit\", \"override\", \"disabled\"." + }, + { + "name": "ttl_secs", + "type": "Number", + "description": "Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Specify the location name." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24." + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_dns_location": { + "kind": "resource", + "name": "cloudflare_zero_trust_dns_location", + "description": "Accepted Permissions\n\n- `Cloudflare Zero Trust Secure DNS Locations Write`\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_dns_location\" \"example_zero_trust_dns_location\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Austin Office Location\"\n client_default = false\n dns_destination_ips_id = \"0e4a32c6-6fb8-4858-9296-98f51631e8e6\"\n ecs_support = false\n endpoints = {\n doh = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n require_token = true\n }\n dot = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n }\n ipv4 = {\n enabled = true\n }\n ipv6 = {\n enabled = true\n networks = [{\n network = \"2001:85a3::/64\"\n }]\n }\n }\n max_ttl = {\n mode = \"override\"\n ttl_secs = 3600\n }\n networks = [{\n network = \"192.0.2.1/32\"\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_dns_location.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "name", + "type": "String", + "description": "Specify the location name." + } + ], + "optional": [ + { + "name": "client_default", + "type": "Boolean", + "description": "Indicate whether this location is the default location." + }, + { + "name": "dns_destination_ips_id", + "type": "String", + "description": "Specify the identifier of the pair of IPv4 addresses assigned to this location. When creating a location, if this field is absent or set to null, the pair of shared IPv4 addresses (0e4a32c6-6fb8-4858-9296-98f51631e8e6) is auto-assigned. When updating a location, if this field is absent or set to null, the pre-assigned pair remains unchanged." + }, + { + "name": "ecs_support", + "type": "Boolean", + "description": "Indicate whether the location must resolve EDNS queries." + }, + { + "name": "endpoints", + "type": "Attributes", + "description": "Configure the destination endpoints for this location.", + "children": [ + { + "name": "doh", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the DOH endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IP address or IP CIDR." + } + ] + }, + { + "name": "require_token", + "type": "Boolean", + "description": "Specify whether the DOH endpoint requires user identity authentication." + } + ] + }, + { + "name": "dot", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the DOT endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IP address or IP CIDR." + } + ] + } + ] + }, + { + "name": "ipv4", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the IPv4 endpoint is enabled for this location." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the IPV6 endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IPv6 address or IPv6 CIDR." + } + ] + } + ] + } + ] + }, + { + "name": "max_ttl", + "type": "Attributes", + "description": "Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged.\nAvailable values: \"inherit\", \"override\", \"disabled\"." + }, + { + "name": "ttl_secs", + "type": "Number", + "description": "Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`." + } + ] + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24." + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "dns_destination_ipv6_block_id", + "type": "String", + "description": "Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block." + }, + { + "name": "doh_subdomain", + "type": "String", + "description": "Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "ip", + "type": "String", + "description": "Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location." + }, + { + "name": "ipv4_destination", + "type": "String", + "description": "Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only." + }, + { + "name": "ipv4_destination_backup", + "type": "String", + "description": "Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_dns_locations": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_dns_locations", + "description": "Accepted Permissions\n\n- `Cloudflare Zero Trust Secure DNS Locations Write`\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_dns_locations\" \"example_zero_trust_dns_locations\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "direction", + "type": "String", + "description": "Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned locations by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a location must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the location name.\n * `id` — substring match on the location ID (UUID), with or without dashes.\n * `is_default` — whether it is the default for the account.\n\nEach entry must match one of the per-field patterns below:\n * the field must be one of `name`, `id`, or `is_default`;\n * `name`/`id` accept any value;\n * `is_default` only accepts `true` or `false`; any other value returns `400`" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned locations by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by location name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\nAvailable values: \"name\", \"created_at\", \"updated_at\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring match on the location name. When combined\nwith `filter`, both must match (logical AND)." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "client_default", + "type": "Boolean", + "description": "Indicate whether this location is the default location." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "dns_destination_ips_id", + "type": "String", + "description": "Indicate the identifier of the pair of IPv4 addresses assigned to this location." + }, + { + "name": "dns_destination_ipv6_block_id", + "type": "String", + "description": "Specify the UUID of the IPv6 block brought to the gateway so that this location's IPv6 address is allocated from the Bring Your Own IPv6 (BYOIPv6) block rather than the standard Cloudflare IPv6 block." + }, + { + "name": "doh_subdomain", + "type": "String", + "description": "Specify the DNS over HTTPS domain that receives DNS requests. Gateway automatically generates this value." + }, + { + "name": "ecs_support", + "type": "Boolean", + "description": "Indicate whether the location must resolve EDNS queries." + }, + { + "name": "endpoints", + "type": "Attributes", + "description": "Configure the destination endpoints for this location.", + "children": [ + { + "name": "doh", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the DOH endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IP address or IP CIDR." + } + ] + }, + { + "name": "require_token", + "type": "Boolean", + "description": "Specify whether the DOH endpoint requires user identity authentication." + } + ] + }, + { + "name": "dot", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the DOT endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IP network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IP address or IP CIDR." + } + ] + } + ] + }, + { + "name": "ipv4", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the IPv4 endpoint is enabled for this location." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Indicate whether the IPV6 endpoint is enabled for this location." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of allowed source IPv6 network ranges for this endpoint. When the list is empty, the endpoint allows all source IPs. The list takes effect only if the endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IPv6 address or IPv6 CIDR." + } + ] + } + ] + } + ] + }, + { + "name": "id", + "type": "String" + }, + { + "name": "ip", + "type": "String", + "description": "Defines the automatically generated IPv6 destination IP assigned to this location. Gateway counts all DNS requests sent to this IP as requests under this location." + }, + { + "name": "ipv4_destination", + "type": "String", + "description": "Show the primary destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only." + }, + { + "name": "ipv4_destination_backup", + "type": "String", + "description": "Show the backup destination IPv4 address from the pair identified dns_destination_ips_id. This field read-only." + }, + { + "name": "max_ttl", + "type": "Attributes", + "description": "Controls how DNS response TTLs are capped for this location relative to the account `max_ttl_secs` setting. Omitting `max_ttl` on update resets it to `inherit`.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "`inherit` uses the account `max_ttl_secs`. `override` uses this location's `ttl_secs`. `disabled` leaves returned TTLs unchanged.\nAvailable values: \"inherit\", \"override\", \"disabled\"." + }, + { + "name": "ttl_secs", + "type": "Number", + "description": "Location-specific cap on DNS response TTLs, in seconds. Required when `mode` is `override`. Must be omitted when `mode` is `inherit` or `disabled`." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "Specify the location name." + }, + { + "name": "networks", + "type": "Attributes List", + "description": "Specify the list of network ranges from which requests at this location originate. The list takes effect only if it is non-empty and the IPv4 endpoint is enabled for this location.", + "children": [ + { + "name": "network", + "type": "String", + "description": "Specify the IPv4 address or IPv4 CIDR. Limit IPv4 CIDRs to a maximum of /24." + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_gateway_app_types_list": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_gateway_app_types_list", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_gateway_app_types_list\" \"example_zero_trust_gateway_app_types_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Provide the identifier string." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "application_type_id", + "type": "Number", + "description": "Identify the type of this application. Multiple applications can share the same type. Refers to the `id` of a returned application type." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Provide a short summary of applications with this type." + }, + { + "name": "id", + "type": "Number", + "description": "Identify this application. Only one application per ID." + }, + { + "name": "name", + "type": "String", + "description": "Specify the name of the application or application type." + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_gateway_categories_list": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_gateway_categories_list", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_gateway_categories_list\" \"example_zero_trust_gateway_categories_list\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Provide the identifier string." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "beta", + "type": "Boolean", + "description": "Indicate whether the category is in beta and subject to change." + }, + { + "name": "class", + "type": "String", + "description": "Specify which account types can create policies for this category. `blocked` Blocks unconditionally for all accounts. `removalPending` Allows removal from policies but disables addition. `noBlock` Prevents blocking.\nAvailable values: \"free\", \"premium\", \"blocked\", \"removalPending\", \"noBlock\"." + }, + { + "name": "description", + "type": "String", + "description": "Provide a short summary of domains in the category." + }, + { + "name": "id", + "type": "Number", + "description": "Identify this category. Only one category per ID." + }, + { + "name": "name", + "type": "String", + "description": "Specify the category name." + }, + { + "name": "subcategories", + "type": "Attributes List", + "description": "Provide all subcategories for this category.", + "children": [ + { + "name": "beta", + "type": "Boolean", + "description": "Indicate whether the category is in beta and subject to change." + }, + { + "name": "class", + "type": "String", + "description": "Specify which account types can create policies for this category. `blocked` Blocks unconditionally for all accounts. `removalPending` Allows removal from policies but disables addition. `noBlock` Prevents blocking.\nAvailable values: \"free\", \"premium\", \"blocked\", \"removalPending\", \"noBlock\"." + }, + { + "name": "description", + "type": "String", + "description": "Provide a short summary of domains in the category." + }, + { + "name": "id", + "type": "Number", + "description": "Identify this category. Only one category per ID." + }, + { + "name": "name", + "type": "String", + "description": "Specify the category name." + } + ] + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_gateway_certificate": { + "kind": "data-source", + "name": "cloudflare_zero_trust_gateway_certificate", + "example": "data \"cloudflare_zero_trust_gateway_certificate\" \"example_zero_trust_gateway_certificate\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n certificate_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "certificate_id", + "type": "String", + "description": "Identify the certificate with a UUID." + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ], + "computed": [ + { + "name": "binding_status", + "type": "String", + "description": "Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state.\nAvailable values: \"pending_deployment\", \"available\", \"pending_deletion\", \"inactive\"." + }, + { + "name": "certificate", + "type": "String", + "description": "Provide the CA certificate (read-only)." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "expires_on", + "type": "String" + }, + { + "name": "fingerprint", + "type": "String", + "description": "Provide the SHA256 fingerprint of the certificate (read-only)." + }, + { + "name": "id", + "type": "String", + "description": "Identify the certificate with a UUID." + }, + { + "name": "in_use", + "type": "Boolean", + "description": "Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)." + }, + { + "name": "issuer_org", + "type": "String", + "description": "Indicate the organization that issued the certificate (read-only)." + }, + { + "name": "issuer_raw", + "type": "String", + "description": "Provide the entire issuer field of the certificate (read-only)." + }, + { + "name": "type", + "type": "String", + "description": "Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.\nAvailable values: \"custom\", \"gateway_managed\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "uploaded_on", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_gateway_certificate": { + "kind": "resource", + "name": "cloudflare_zero_trust_gateway_certificate", + "example": "resource \"cloudflare_zero_trust_gateway_certificate\" \"example_zero_trust_gateway_certificate\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n validity_period_days = 1826\n}", + "importExample": "$ terraform import cloudflare_zero_trust_gateway_certificate.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ], + "optional": [ + { + "name": "activate", + "type": "Boolean", + "description": "Whether to activate the certificate on Cloudflare's edge. When true, the certificate will be activated. When false, the certificate will be deactivated at the edge. This is a Terraform-only field and does not appear in the API response. Monitor `binding_status` for the activation status. Once a certificate is activated, you may use the certificate to intercept traffic" + }, + { + "name": "validity_period_days", + "type": "Number", + "description": "Sets the certificate validity period in days (range: 1-10,950 days / ~30 years). Defaults to 1,825 days (5 years). **Important**: This field is only settable during the certificate creation. Certificates becomes immutable after creation - use the `/activate` and `/deactivate` endpoints to manage certificate lifecycle." + } + ], + "computed": [ + { + "name": "binding_status", + "type": "String", + "description": "Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state.\nAvailable values: \"pending_deployment\", \"available\", \"pending_deletion\", \"inactive\"." + }, + { + "name": "certificate", + "type": "String", + "description": "Provide the CA certificate (read-only)." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "expires_on", + "type": "String" + }, + { + "name": "fingerprint", + "type": "String", + "description": "Provide the SHA256 fingerprint of the certificate (read-only)." + }, + { + "name": "id", + "type": "String", + "description": "Identify the certificate with a UUID." + }, + { + "name": "in_use", + "type": "Boolean", + "description": "Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)." + }, + { + "name": "issuer_org", + "type": "String", + "description": "Indicate the organization that issued the certificate (read-only)." + }, + { + "name": "issuer_raw", + "type": "String", + "description": "Provide the entire issuer field of the certificate (read-only)." + }, + { + "name": "type", + "type": "String", + "description": "Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.\nAvailable values: \"custom\", \"gateway_managed\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "uploaded_on", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_gateway_certificates": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_gateway_certificates", + "example": "data \"cloudflare_zero_trust_gateway_certificates\" \"example_zero_trust_gateway_certificates\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "binding_status", + "type": "String", + "description": "Indicate the read-only deployment status of the certificate on Cloudflare's edge. Gateway TLS interception can use certificates in the 'available' (previously called 'active') state.\nAvailable values: \"pending_deployment\", \"available\", \"pending_deletion\", \"inactive\"." + }, + { + "name": "certificate", + "type": "String", + "description": "Provide the CA certificate (read-only)." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "expires_on", + "type": "String" + }, + { + "name": "fingerprint", + "type": "String", + "description": "Provide the SHA256 fingerprint of the certificate (read-only)." + }, + { + "name": "id", + "type": "String", + "description": "Identify the certificate with a UUID." + }, + { + "name": "in_use", + "type": "Boolean", + "description": "Indicate whether Gateway TLS interception uses this certificate (read-only). You cannot set this value directly. To configure interception, use the Gateway configuration setting named `certificate` (read-only)." + }, + { + "name": "issuer_org", + "type": "String", + "description": "Indicate the organization that issued the certificate (read-only)." + }, + { + "name": "issuer_raw", + "type": "String", + "description": "Provide the entire issuer field of the certificate (read-only)." + }, + { + "name": "type", + "type": "String", + "description": "Indicate the read-only certificate type, BYO-PKI (custom) or Gateway-managed.\nAvailable values: \"custom\", \"gateway_managed\"." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "uploaded_on", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_gateway_logging": { + "kind": "data-source", + "name": "cloudflare_zero_trust_gateway_logging", + "example": "data \"cloudflare_zero_trust_gateway_logging\" \"example_zero_trust_gateway_logging\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "redact_pii", + "type": "Boolean", + "description": "Indicate whether to redact personally identifiable information from activity logging (PII fields include source IP, user email, user ID, device ID, URL, referrer, and user agent)." + }, + { + "name": "settings_by_rule_type", + "type": "Attributes", + "description": "Configure logging settings for each rule type.", + "children": [ + { + "name": "dns", + "type": "Attributes", + "description": "Configure logging settings for DNS firewall.", + "children": [ + { + "name": "log_all", + "type": "Boolean", + "description": "Specify whether to log all requests to this service." + }, + { + "name": "log_blocks", + "type": "Boolean", + "description": "Specify whether to log only blocking requests to this service." + } + ] + }, + { + "name": "http", + "type": "Attributes", + "description": "Configure logging settings for HTTP/HTTPS firewall.", + "children": [ + { + "name": "log_all", + "type": "Boolean", + "description": "Specify whether to log all requests to this service." + }, + { + "name": "log_blocks", + "type": "Boolean", + "description": "Specify whether to log only blocking requests to this service." + } + ] + }, + { + "name": "l4", + "type": "Attributes", + "description": "Configure logging settings for Network firewall.", + "children": [ + { + "name": "log_all", + "type": "Boolean", + "description": "Specify whether to log all requests to this service." + }, + { + "name": "log_blocks", + "type": "Boolean", + "description": "Specify whether to log only blocking requests to this service." + } + ] + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_gateway_logging": { + "kind": "resource", + "name": "cloudflare_zero_trust_gateway_logging", + "example": "resource \"cloudflare_zero_trust_gateway_logging\" \"example_zero_trust_gateway_logging\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n redact_pii = true\n settings_by_rule_type = {\n dns = {\n log_all = false\n log_blocks = true\n }\n http = {\n log_all = false\n log_blocks = true\n }\n l4 = {\n log_all = false\n log_blocks = true\n }\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_gateway_logging.example ''", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ], + "optional": [ + { + "name": "redact_pii", + "type": "Boolean", + "description": "Indicate whether to redact personally identifiable information from activity logging (PII fields include source IP, user email, user ID, device ID, URL, referrer, and user agent)." + }, + { + "name": "settings_by_rule_type", + "type": "Attributes", + "description": "Configure logging settings for each rule type.", + "children": [ + { + "name": "dns", + "type": "Attributes", + "description": "Configure logging settings for DNS firewall.", + "children": [ + { + "name": "log_all", + "type": "Boolean", + "description": "Specify whether to log all requests to this service." + }, + { + "name": "log_blocks", + "type": "Boolean", + "description": "Specify whether to log only blocking requests to this service." + } + ] + }, + { + "name": "http", + "type": "Attributes", + "description": "Configure logging settings for HTTP/HTTPS firewall.", + "children": [ + { + "name": "log_all", + "type": "Boolean", + "description": "Specify whether to log all requests to this service." + }, + { + "name": "log_blocks", + "type": "Boolean", + "description": "Specify whether to log only blocking requests to this service." + } + ] + }, + { + "name": "l4", + "type": "Attributes", + "description": "Configure logging settings for Network firewall.", + "children": [ + { + "name": "log_all", + "type": "Boolean", + "description": "Specify whether to log all requests to this service." + }, + { + "name": "log_blocks", + "type": "Boolean", + "description": "Specify whether to log only blocking requests to this service." + } + ] + } + ] + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ] + }, + "data-source:cloudflare_zero_trust_gateway_pacfile": { + "kind": "data-source", + "name": "cloudflare_zero_trust_gateway_pacfile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_gateway_pacfile\" \"example_zero_trust_gateway_pacfile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n pacfile_id = \"ed35569b41ce4d1facfe683550f54086\"\n}", + "required": [ + { + "name": "pacfile_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ], + "computed": [ + { + "name": "contents", + "type": "String", + "description": "Actual contents of the PAC file" + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Detailed description of the PAC file." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "name", + "type": "String", + "description": "Name of the PAC file." + }, + { + "name": "slug", + "type": "String", + "description": "URL-friendly version of the PAC file name." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "url", + "type": "String", + "description": "Unique URL to download the PAC file." + } + ] + }, + "resource:cloudflare_zero_trust_gateway_pacfile": { + "kind": "resource", + "name": "cloudflare_zero_trust_gateway_pacfile", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_gateway_pacfile\" \"example_zero_trust_gateway_pacfile\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n contents = \"function FindProxyForURL(url, host) { return \\\"DIRECT\\\"; }\"\n name = \"Devops team\"\n description = \"PAC file for Devops team\"\n slug = \"pac_devops\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_gateway_pacfile.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "contents", + "type": "String", + "description": "Actual contents of the PAC file" + }, + { + "name": "name", + "type": "String", + "description": "Name of the PAC file." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Detailed description of the PAC file." + }, + { + "name": "slug", + "type": "String", + "description": "URL-friendly version of the PAC file name. If not provided, it will be auto-generated" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "url", + "type": "String", + "description": "Unique URL to download the PAC file." + } + ] + }, + "list-data-source:cloudflare_zero_trust_gateway_pacfiles": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_gateway_pacfiles", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_gateway_pacfiles\" \"example_zero_trust_gateway_pacfiles\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Detailed description of the PAC file." + }, + { + "name": "id", + "type": "String" + }, + { + "name": "name", + "type": "String", + "description": "Name of the PAC file." + }, + { + "name": "slug", + "type": "String", + "description": "URL-friendly version of the PAC file name." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "url", + "type": "String", + "description": "Unique URL to download the PAC file." + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_gateway_policies": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_gateway_policies", + "example": "data \"cloudflare_zero_trust_gateway_policies\" \"example_zero_trust_gateway_policies\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "direction", + "type": "String", + "description": "Sort direction. When `order_by` is omitted, this controls the direction\nof the existing precedence ordering. Shared rules remain first in either\ndirection. Accepted values are `asc` and `desc`.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned rules by one or more `field:value` pairs. Repeat the\nparameter to combine filters with logical AND.\n\nSupported fields are `name`, `id`, `action`, `enabled`, `source_account`,\n`is_shared`, `filters`, and `expression` (max 1024 bytes). The `source_account`\nvalue is matched as a normalized UUID substring. The `filters` value must\nbe one of the rule filter names and matches a member of the rule's `filters`\narray. The `expression` filter performs a case-insensitive literal\nsubstring match across traffic, identity, and device posture expressions." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned rules by. Supported values are `name`,\n`created_at`, `updated_at`, and `precedence`.\nAvailable values: \"name\", \"created_at\", \"updated_at\", \"precedence\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring search across rule name and description." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "action", + "type": "String", + "description": "Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`.\nAvailable values: \"on\", \"off\", \"allow\", \"block\", \"scan\", \"noscan\", \"safesearch\", \"ytrestricted\", \"isolate\", \"noisolate\", \"override\", \"l4_override\", \"egress\", \"resolve\", \"quarantine\", \"redirect\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deleted_at", + "type": "String", + "description": "Indicate the date of deletion, if any." + }, + { + "name": "description", + "type": "String", + "description": "Specify the rule description." + }, + { + "name": "device_posture", + "type": "String", + "description": "Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether the rule is enabled." + }, + { + "name": "expiration", + "type": "Attributes", + "description": "Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.", + "children": [ + { + "name": "duration", + "type": "Number", + "description": "Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule." + }, + { + "name": "expired", + "type": "Boolean", + "description": "Indicates whether the policy is expired." + }, + { + "name": "expires_at", + "type": "String", + "description": "Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time." + } + ] + }, + { + "name": "filters", + "type": "List of String", + "description": "Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value." + }, + { + "name": "id", + "type": "String", + "description": "Identify the API resource with a UUID." + }, + { + "name": "identity", + "type": "String", + "description": "Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "name", + "type": "String", + "description": "Specify the rule name." + }, + { + "name": "precedence", + "type": "Number", + "description": "Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicate that this rule is shared via the Orgs API and read only." + }, + { + "name": "rule_settings", + "type": "Attributes", + "description": "Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.", + "children": [ + { + "name": "add_headers", + "type": "Map of List of String", + "description": "Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "allow_child_bypass", + "type": "Boolean", + "description": "Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules." + }, + { + "name": "audit_ssh", + "type": "Attributes", + "description": "Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.", + "children": [ + { + "name": "command_logging", + "type": "Boolean", + "description": "Enable SSH command logging." + } + ] + }, + { + "name": "biso_admin_controls", + "type": "Attributes", + "description": "Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.", + "children": [ + { + "name": "copy", + "type": "String", + "description": "Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "dcp", + "type": "Boolean", + "description": "Set to false to enable copy-pasting. Only applies when `version == \"v1\"`." + }, + { + "name": "dd", + "type": "Boolean", + "description": "Set to false to enable downloading. Only applies when `version == \"v1\"`." + }, + { + "name": "dk", + "type": "Boolean", + "description": "Set to false to enable keyboard usage. Only applies when `version == \"v1\"`." + }, + { + "name": "download", + "type": "String", + "description": "Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "dp", + "type": "Boolean", + "description": "Set to false to enable printing. Only applies when `version == \"v1\"`." + }, + { + "name": "du", + "type": "Boolean", + "description": "Set to false to enable uploading. Only applies when `version == \"v1\"`." + }, + { + "name": "keyboard", + "type": "String", + "description": "Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "paste", + "type": "String", + "description": "Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "printing", + "type": "String", + "description": "Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "upload", + "type": "String", + "description": "Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "version", + "type": "String", + "description": "Indicate which version of the browser isolation controls should apply.\nAvailable values: \"v1\", \"v2\"." + }, + { + "name": "wm_id", + "type": "String", + "description": "Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser." + } + ] + }, + { + "name": "block_page", + "type": "Attributes", + "description": "Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.", + "children": [ + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to pass the context information as query parameters." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to which the user is redirected." + } + ] + }, + { + "name": "block_page_enabled", + "type": "Boolean", + "description": "Enable the custom block page. Settable only for `dns` rules with action `block`." + }, + { + "name": "block_reason", + "type": "String", + "description": "Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`." + }, + { + "name": "bypass_parent_rule", + "type": "Boolean", + "description": "Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules." + }, + { + "name": "check_session", + "type": "Attributes", + "description": "Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.", + "children": [ + { + "name": "duration", + "type": "String", + "description": "Sets the required session freshness threshold. The API returns a normalized version of this value." + }, + { + "name": "enforce", + "type": "Boolean", + "description": "Enable session enforcement." + } + ] + }, + { + "name": "delete_headers", + "type": "List of String", + "description": "Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "dns_resolvers", + "type": "Attributes", + "description": "Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.", + "children": [ + { + "name": "ipv4", + "type": "Attributes List", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Specify the IPv4 address of the upstream resolver." + }, + { + "name": "port", + "type": "Number", + "description": "Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified." + }, + { + "name": "route_through_private_network", + "type": "Boolean", + "description": "Indicate whether to connect to this resolver over a private network. Must set when vnet_id set." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Specify an optional virtual network for this resolver. Uses default virtual network id if omitted." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes List", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Specify the IPv6 address of the upstream resolver." + }, + { + "name": "port", + "type": "Number", + "description": "Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified." + }, + { + "name": "route_through_private_network", + "type": "Boolean", + "description": "Indicate whether to connect to this resolver over a private network. Must set when vnet_id set." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Specify an optional virtual network for this resolver. Uses default virtual network id if omitted." + } + ] + } + ] + }, + { + "name": "egress", + "type": "Attributes", + "description": "Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.", + "children": [ + { + "name": "ipv4", + "type": "String", + "description": "Specify the IPv4 address to use for egress." + }, + { + "name": "ipv4_fallback", + "type": "String", + "description": "Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs." + }, + { + "name": "ipv6", + "type": "String", + "description": "Specify the IPv6 range to use for egress." + } + ] + }, + { + "name": "forensic_copy", + "type": "Attributes", + "description": "Configure whether a copy of the HTTP request will be sent to storage when the rule matches.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable sending the copy to storage." + } + ] + }, + { + "name": "ignore_cname_category_matches", + "type": "Boolean", + "description": "Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "insecure_disable_dnssec_validation", + "type": "Boolean", + "description": "Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules." + }, + { + "name": "ip_categories", + "type": "Boolean", + "description": "Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "ip_indicator_feeds", + "type": "Boolean", + "description": "Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "l4override", + "type": "Attributes", + "description": "Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Defines the IPv4 or IPv6 address." + }, + { + "name": "port", + "type": "Number", + "description": "Defines a port number to use for TCP/UDP overrides." + } + ] + }, + { + "name": "notification_settings", + "type": "Attributes", + "description": "Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable notification." + }, + { + "name": "include_context", + "type": "Boolean", + "description": "Indicates whether to pass the context information as query parameters." + }, + { + "name": "msg", + "type": "String", + "description": "Customize the message shown in the notification." + }, + { + "name": "support_url", + "type": "String", + "description": "Defines an optional URL to direct users to additional information. If unset, the notification opens a block page." + } + ] + }, + { + "name": "override_host", + "type": "String", + "description": "Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`." + }, + { + "name": "override_ips", + "type": "List of String", + "description": "Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`." + }, + { + "name": "payload_log", + "type": "Attributes", + "description": "Configure DLP payload logging. Settable only for `http` rules.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable DLP payload logging for this rule." + } + ] + }, + { + "name": "quarantine", + "type": "Attributes", + "description": "Configure settings that apply to quarantine rules. Settable only for `http` rules.", + "children": [ + { + "name": "file_types", + "type": "List of String", + "description": "Specify the types of files to sandbox." + } + ] + }, + { + "name": "redirect", + "type": "Attributes", + "description": "Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.", + "children": [ + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to pass the context information as query parameters." + }, + { + "name": "preserve_path_and_query", + "type": "Boolean", + "description": "Specify whether to append the path and query parameters from the original request to target_uri." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to which the user is redirected." + } + ] + }, + { + "name": "resolve_dns_internally", + "type": "Attributes", + "description": "Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.", + "children": [ + { + "name": "fallback", + "type": "String", + "description": "Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries.\nAvailable values: \"none\", \"public_dns\"." + }, + { + "name": "view_id", + "type": "String", + "description": "Specify the internal DNS view identifier to pass to the internal DNS service." + } + ] + }, + { + "name": "resolve_dns_through_cloudflare", + "type": "Boolean", + "description": "Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules." + }, + { + "name": "set_headers", + "type": "Map of List of String", + "description": "Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "untrusted_cert", + "type": "Attributes", + "description": "Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.", + "children": [ + { + "name": "action", + "type": "String", + "description": "Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526.\nAvailable values: \"pass_through\", \"block\", \"error\"." + } + ] + } + ] + }, + { + "name": "schedule", + "type": "Attributes", + "description": "Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.", + "children": [ + { + "name": "fri", + "type": "String", + "description": "Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "mon", + "type": "String", + "description": "Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "sat", + "type": "String", + "description": "Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "sun", + "type": "String", + "description": "Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "thu", + "type": "String", + "description": "Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "time_zone", + "type": "String", + "description": "Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location." + }, + { + "name": "tue", + "type": "String", + "description": "Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "wed", + "type": "String", + "description": "Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + } + ] + }, + { + "name": "sharable", + "type": "Boolean", + "description": "Indicate that this rule is sharable via the Orgs API." + }, + { + "name": "source_account", + "type": "String", + "description": "Provide the account tag of the account that created the rule." + }, + { + "name": "traffic", + "type": "String", + "description": "Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "version", + "type": "Number", + "description": "Indicate the version number of the rule(read-only)." + }, + { + "name": "warning_status", + "type": "String", + "description": "Indicate a warning for a misconfigured rule, if any." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_gateway_policy": { + "kind": "data-source", + "name": "cloudflare_zero_trust_gateway_policy", + "example": "data \"cloudflare_zero_trust_gateway_policy\" \"example_zero_trust_gateway_policy\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n rule_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Sort direction. When `order_by` is omitted, this controls the direction\nof the existing precedence ordering. Shared rules remain first in either\ndirection. Accepted values are `asc` and `desc`.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned rules by one or more `field:value` pairs. Repeat the\nparameter to combine filters with logical AND.\n\nSupported fields are `name`, `id`, `action`, `enabled`, `source_account`,\n`is_shared`, `filters`, and `expression` (max 1024 bytes). The `source_account`\nvalue is matched as a normalized UUID substring. The `filters` value must\nbe one of the rule filter names and matches a member of the rule's `filters`\narray. The `expression` filter performs a case-insensitive literal\nsubstring match across traffic, identity, and device posture expressions." + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned rules by. Supported values are `name`,\n`created_at`, `updated_at`, and `precedence`.\nAvailable values: \"name\", \"created_at\", \"updated_at\", \"precedence\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring search across rule name and description." + } + ] + }, + { + "name": "rule_id", + "type": "String", + "description": "Identify the API resource with a UUID." + } + ], + "computed": [ + { + "name": "action", + "type": "String", + "description": "Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`.\nAvailable values: \"on\", \"off\", \"allow\", \"block\", \"scan\", \"noscan\", \"safesearch\", \"ytrestricted\", \"isolate\", \"noisolate\", \"override\", \"l4_override\", \"egress\", \"resolve\", \"quarantine\", \"redirect\"." + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "deleted_at", + "type": "String", + "description": "Indicate the date of deletion, if any." + }, + { + "name": "description", + "type": "String", + "description": "Specify the rule description." + }, + { + "name": "device_posture", + "type": "String", + "description": "Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether the rule is enabled." + }, + { + "name": "expiration", + "type": "Attributes", + "description": "Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.", + "children": [ + { + "name": "duration", + "type": "Number", + "description": "Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule." + }, + { + "name": "expired", + "type": "Boolean", + "description": "Indicates whether the policy is expired." + }, + { + "name": "expires_at", + "type": "String", + "description": "Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time." + } + ] + }, + { + "name": "filters", + "type": "List of String", + "description": "Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value." + }, + { + "name": "id", + "type": "String", + "description": "Identify the API resource with a UUID." + }, + { + "name": "identity", + "type": "String", + "description": "Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "name", + "type": "String", + "description": "Specify the rule name." + }, + { + "name": "precedence", + "type": "Number", + "description": "Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicate that this rule is shared via the Orgs API and read only." + }, + { + "name": "rule_settings", + "type": "Attributes", + "description": "Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.", + "children": [ + { + "name": "add_headers", + "type": "Map of List of String", + "description": "Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "allow_child_bypass", + "type": "Boolean", + "description": "Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules." + }, + { + "name": "audit_ssh", + "type": "Attributes", + "description": "Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.", + "children": [ + { + "name": "command_logging", + "type": "Boolean", + "description": "Enable SSH command logging." + } + ] + }, + { + "name": "biso_admin_controls", + "type": "Attributes", + "description": "Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.", + "children": [ + { + "name": "copy", + "type": "String", + "description": "Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "dcp", + "type": "Boolean", + "description": "Set to false to enable copy-pasting. Only applies when `version == \"v1\"`." + }, + { + "name": "dd", + "type": "Boolean", + "description": "Set to false to enable downloading. Only applies when `version == \"v1\"`." + }, + { + "name": "dk", + "type": "Boolean", + "description": "Set to false to enable keyboard usage. Only applies when `version == \"v1\"`." + }, + { + "name": "download", + "type": "String", + "description": "Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "dp", + "type": "Boolean", + "description": "Set to false to enable printing. Only applies when `version == \"v1\"`." + }, + { + "name": "du", + "type": "Boolean", + "description": "Set to false to enable uploading. Only applies when `version == \"v1\"`." + }, + { + "name": "keyboard", + "type": "String", + "description": "Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "paste", + "type": "String", + "description": "Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "printing", + "type": "String", + "description": "Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "upload", + "type": "String", + "description": "Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "version", + "type": "String", + "description": "Indicate which version of the browser isolation controls should apply.\nAvailable values: \"v1\", \"v2\"." + }, + { + "name": "wm_id", + "type": "String", + "description": "Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser." + } + ] + }, + { + "name": "block_page", + "type": "Attributes", + "description": "Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.", + "children": [ + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to pass the context information as query parameters." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to which the user is redirected." + } + ] + }, + { + "name": "block_page_enabled", + "type": "Boolean", + "description": "Enable the custom block page. Settable only for `dns` rules with action `block`." + }, + { + "name": "block_reason", + "type": "String", + "description": "Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`." + }, + { + "name": "bypass_parent_rule", + "type": "Boolean", + "description": "Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules." + }, + { + "name": "check_session", + "type": "Attributes", + "description": "Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.", + "children": [ + { + "name": "duration", + "type": "String", + "description": "Sets the required session freshness threshold. The API returns a normalized version of this value." + }, + { + "name": "enforce", + "type": "Boolean", + "description": "Enable session enforcement." + } + ] + }, + { + "name": "delete_headers", + "type": "List of String", + "description": "Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "dns_resolvers", + "type": "Attributes", + "description": "Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.", + "children": [ + { + "name": "ipv4", + "type": "Attributes List", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Specify the IPv4 address of the upstream resolver." + }, + { + "name": "port", + "type": "Number", + "description": "Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified." + }, + { + "name": "route_through_private_network", + "type": "Boolean", + "description": "Indicate whether to connect to this resolver over a private network. Must set when vnet_id set." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Specify an optional virtual network for this resolver. Uses default virtual network id if omitted." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes List", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Specify the IPv6 address of the upstream resolver." + }, + { + "name": "port", + "type": "Number", + "description": "Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified." + }, + { + "name": "route_through_private_network", + "type": "Boolean", + "description": "Indicate whether to connect to this resolver over a private network. Must set when vnet_id set." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Specify an optional virtual network for this resolver. Uses default virtual network id if omitted." + } + ] + } + ] + }, + { + "name": "egress", + "type": "Attributes", + "description": "Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.", + "children": [ + { + "name": "ipv4", + "type": "String", + "description": "Specify the IPv4 address to use for egress." + }, + { + "name": "ipv4_fallback", + "type": "String", + "description": "Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs." + }, + { + "name": "ipv6", + "type": "String", + "description": "Specify the IPv6 range to use for egress." + } + ] + }, + { + "name": "forensic_copy", + "type": "Attributes", + "description": "Configure whether a copy of the HTTP request will be sent to storage when the rule matches.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable sending the copy to storage." + } + ] + }, + { + "name": "ignore_cname_category_matches", + "type": "Boolean", + "description": "Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "insecure_disable_dnssec_validation", + "type": "Boolean", + "description": "Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules." + }, + { + "name": "ip_categories", + "type": "Boolean", + "description": "Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "ip_indicator_feeds", + "type": "Boolean", + "description": "Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "l4override", + "type": "Attributes", + "description": "Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Defines the IPv4 or IPv6 address." + }, + { + "name": "port", + "type": "Number", + "description": "Defines a port number to use for TCP/UDP overrides." + } + ] + }, + { + "name": "notification_settings", + "type": "Attributes", + "description": "Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable notification." + }, + { + "name": "include_context", + "type": "Boolean", + "description": "Indicates whether to pass the context information as query parameters." + }, + { + "name": "msg", + "type": "String", + "description": "Customize the message shown in the notification." + }, + { + "name": "support_url", + "type": "String", + "description": "Defines an optional URL to direct users to additional information. If unset, the notification opens a block page." + } + ] + }, + { + "name": "override_host", + "type": "String", + "description": "Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`." + }, + { + "name": "override_ips", + "type": "List of String", + "description": "Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`." + }, + { + "name": "payload_log", + "type": "Attributes", + "description": "Configure DLP payload logging. Settable only for `http` rules.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable DLP payload logging for this rule." + } + ] + }, + { + "name": "quarantine", + "type": "Attributes", + "description": "Configure settings that apply to quarantine rules. Settable only for `http` rules.", + "children": [ + { + "name": "file_types", + "type": "List of String", + "description": "Specify the types of files to sandbox." + } + ] + }, + { + "name": "redirect", + "type": "Attributes", + "description": "Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.", + "children": [ + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to pass the context information as query parameters." + }, + { + "name": "preserve_path_and_query", + "type": "Boolean", + "description": "Specify whether to append the path and query parameters from the original request to target_uri." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to which the user is redirected." + } + ] + }, + { + "name": "resolve_dns_internally", + "type": "Attributes", + "description": "Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.", + "children": [ + { + "name": "fallback", + "type": "String", + "description": "Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries.\nAvailable values: \"none\", \"public_dns\"." + }, + { + "name": "view_id", + "type": "String", + "description": "Specify the internal DNS view identifier to pass to the internal DNS service." + } + ] + }, + { + "name": "resolve_dns_through_cloudflare", + "type": "Boolean", + "description": "Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules." + }, + { + "name": "set_headers", + "type": "Map of List of String", + "description": "Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "untrusted_cert", + "type": "Attributes", + "description": "Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.", + "children": [ + { + "name": "action", + "type": "String", + "description": "Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526.\nAvailable values: \"pass_through\", \"block\", \"error\"." + } + ] + } + ] + }, + { + "name": "schedule", + "type": "Attributes", + "description": "Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.", + "children": [ + { + "name": "fri", + "type": "String", + "description": "Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "mon", + "type": "String", + "description": "Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "sat", + "type": "String", + "description": "Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "sun", + "type": "String", + "description": "Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "thu", + "type": "String", + "description": "Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "time_zone", + "type": "String", + "description": "Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location." + }, + { + "name": "tue", + "type": "String", + "description": "Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "wed", + "type": "String", + "description": "Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + } + ] + }, + { + "name": "sharable", + "type": "Boolean", + "description": "Indicate that this rule is sharable via the Orgs API." + }, + { + "name": "source_account", + "type": "String", + "description": "Provide the account tag of the account that created the rule." + }, + { + "name": "traffic", + "type": "String", + "description": "Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "version", + "type": "Number", + "description": "Indicate the version number of the rule(read-only)." + }, + { + "name": "warning_status", + "type": "String", + "description": "Indicate a warning for a misconfigured rule, if any." + } + ] + }, + "resource:cloudflare_zero_trust_gateway_policy": { + "kind": "resource", + "name": "cloudflare_zero_trust_gateway_policy", + "example": "resource \"cloudflare_zero_trust_gateway_policy\" \"example_zero_trust_gateway_policy\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n action = \"allow\"\n name = \"block bad websites\"\n description = \"Block bad websites based on their host name.\"\n device_posture = \"any(device_posture.checks.passed[*] in {\\\"1308749e-fcfb-4ebc-b051-fe022b632644\\\"})\"\n enabled = true\n expiration = {\n expires_at = \"2014-01-01T05:20:20Z\"\n duration = 10\n }\n filters = [\"http\"]\n identity = \"any(identity.groups.name[*] in {\\\"finance\\\"})\"\n precedence = 0\n rule_settings = {\n add_headers = {\n My-Next-Header = [\"foo\", \"bar\"]\n X-Custom-Header-Name = [\"somecustomvalue\"]\n }\n allow_child_bypass = false\n audit_ssh = {\n command_logging = false\n }\n biso_admin_controls = {\n copy = \"remote_only\"\n dcp = true\n dd = true\n dk = true\n download = \"enabled\"\n dp = false\n du = true\n keyboard = \"enabled\"\n paste = \"enabled\"\n printing = \"enabled\"\n upload = \"enabled\"\n version = \"v1\"\n wm_id = \"475345dc-5299-4b6e-8f6a-3d3e4c8e9f1a\"\n }\n block_page = {\n target_uri = \"https://example.com\"\n include_context = true\n }\n block_page_enabled = true\n block_reason = \"This website is a security risk\"\n bypass_parent_rule = false\n check_session = {\n duration = \"300s\"\n enforce = true\n }\n delete_headers = [\"X-Old-Header\", \"X-Remove-Me\"]\n dns_resolvers = {\n ipv4 = [{\n ip = \"2.2.2.2\"\n port = 5053\n route_through_private_network = true\n vnet_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }]\n ipv6 = [{\n ip = \"2001:DB8::\"\n port = 5053\n route_through_private_network = true\n vnet_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n }]\n }\n egress = {\n ipv4 = \"192.0.2.2\"\n ipv4_fallback = \"192.0.2.3\"\n ipv6 = \"2001:DB8::/64\"\n }\n forensic_copy = {\n enabled = true\n }\n ignore_cname_category_matches = true\n insecure_disable_dnssec_validation = false\n ip_categories = true\n ip_indicator_feeds = true\n l4override = {\n ip = \"1.1.1.1\"\n port = 0\n }\n notification_settings = {\n enabled = true\n include_context = true\n msg = \"msg\"\n support_url = \"support_url\"\n }\n override_host = \"example.com\"\n override_ips = [\"1.1.1.1\", \"2.2.2.2\"]\n payload_log = {\n enabled = true\n }\n quarantine = {\n file_types = [\"exe\"]\n }\n redirect = {\n target_uri = \"https://example.com\"\n include_context = true\n preserve_path_and_query = true\n }\n resolve_dns_internally = {\n fallback = \"none\"\n view_id = \"view_id\"\n }\n resolve_dns_through_cloudflare = true\n set_headers = {\n X-User-Identity = [\"user=@{identity.name}\"]\n }\n untrusted_cert = {\n action = \"error\"\n }\n }\n schedule = {\n fri = \"08:00-12:30,13:30-17:00\"\n mon = \"08:00-12:30,13:30-17:00\"\n sat = \"08:00-12:30,13:30-17:00\"\n sun = \"08:00-12:30,13:30-17:00\"\n thu = \"08:00-12:30,13:30-17:00\"\n time_zone = \"America/New York\"\n tue = \"08:00-12:30,13:30-17:00\"\n wed = \"08:00-12:30,13:30-17:00\"\n }\n traffic = \"http.request.uri matches \\\".*a/partial/uri.*\\\" and http.request.host in $01302951-49f9-47c9-a400-0297e60b6a10\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_gateway_policy.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "action", + "type": "String", + "description": "Specify the action to perform when the associated traffic, identity, and device posture expressions either absent or evaluate to `true`.\nAvailable values: \"on\", \"off\", \"allow\", \"block\", \"scan\", \"noscan\", \"safesearch\", \"ytrestricted\", \"isolate\", \"noisolate\", \"override\", \"l4_override\", \"egress\", \"resolve\", \"quarantine\", \"redirect\"." + }, + { + "name": "name", + "type": "String", + "description": "Specify the rule name." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Specify the rule description." + }, + { + "name": "device_posture", + "type": "String", + "description": "Specify the wirefilter expression used for device posture check. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether the rule is enabled." + }, + { + "name": "expiration", + "type": "Attributes", + "description": "Defines the expiration time stamp and default duration of a DNS policy. Takes precedence over the policy's `schedule` configuration, if any. This does not apply to HTTP or network policies. Settable only for `dns` rules.", + "children": [ + { + "name": "duration", + "type": "Number", + "description": "Defines the default duration a policy active in minutes. Must set in order to use the `reset_expiration` endpoint on this rule." + }, + { + "name": "expired", + "type": "Boolean", + "description": "Indicates whether the policy is expired." + }, + { + "name": "expires_at", + "type": "String", + "description": "Show the timestamp when the policy expires and stops applying. The value must follow RFC 3339 and include a UTC offset. The system accepts non-zero offsets but converts them to the equivalent UTC+00:00 value and returns timestamps with a trailing Z. Expiration policies ignore client timezones and expire globally at the specified expires_at time." + } + ] + }, + { + "name": "filters", + "type": "List of String", + "description": "Specify the protocol or layer to evaluate the traffic, identity, and device posture expressions. Can only contain a single value." + }, + { + "name": "identity", + "type": "String", + "description": "Specify the wirefilter expression used for identity matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + }, + { + "name": "precedence", + "type": "Number", + "description": "Set the order of your rules. Lower values indicate higher precedence. At each processing phase, evaluate applicable rules in ascending order of this value. Refer to [Order of enforcement](http://developers.cloudflare.com/learning-paths/secure-internet-traffic/understand-policies/order-of-enforcement/#manage-precedence-with-terraform) to manage precedence via Terraform." + }, + { + "name": "rule_settings", + "type": "Attributes", + "description": "Defines settings for this rule. Settings apply only to specific rule types and must use compatible selectors. If Terraform detects drift, confirm the setting supports your rule type and check whether the API modifies the value. Use API-returned values in your configuration to prevent drift.", + "children": [ + { + "name": "add_headers", + "type": "Map of List of String", + "description": "Add custom headers to allowed requests as key-value pairs. Use header names as keys that map to arrays of header values. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "allow_child_bypass", + "type": "Boolean", + "description": "Set to enable MSP children to bypass this rule. Only parent MSP accounts can set this. this rule. Settable for all types of rules." + }, + { + "name": "audit_ssh", + "type": "Attributes", + "description": "Define the settings for the Audit SSH action. Settable only for `l4` rules with `audit_ssh` action.", + "children": [ + { + "name": "command_logging", + "type": "Boolean", + "description": "Enable SSH command logging." + } + ] + }, + { + "name": "biso_admin_controls", + "type": "Attributes", + "description": "Configure browser isolation behavior. Settable only for `http` rules with the action set to `isolate`.", + "children": [ + { + "name": "copy", + "type": "String", + "description": "Configure copy behavior. If set to remote_only, users cannot copy isolated content from the remote browser to the local clipboard. If this field is absent, copying remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "dcp", + "type": "Boolean", + "description": "Set to false to enable copy-pasting. Only applies when `version == \"v1\"`." + }, + { + "name": "dd", + "type": "Boolean", + "description": "Set to false to enable downloading. Only applies when `version == \"v1\"`." + }, + { + "name": "dk", + "type": "Boolean", + "description": "Set to false to enable keyboard usage. Only applies when `version == \"v1\"`." + }, + { + "name": "download", + "type": "String", + "description": "Configure download behavior. When set to remote_only, users can view downloads but cannot save them. If this field is absent, downloading remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "dp", + "type": "Boolean", + "description": "Set to false to enable printing. Only applies when `version == \"v1\"`." + }, + { + "name": "du", + "type": "Boolean", + "description": "Set to false to enable uploading. Only applies when `version == \"v1\"`." + }, + { + "name": "keyboard", + "type": "String", + "description": "Configure keyboard usage behavior. If this field is absent, keyboard usage remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "paste", + "type": "String", + "description": "Configure paste behavior. If set to remote_only, users cannot paste content from the local clipboard into isolated pages. If this field is absent, pasting remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\", \"remote_only\"." + }, + { + "name": "printing", + "type": "String", + "description": "Configure print behavior. Default, Printing is enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "upload", + "type": "String", + "description": "Configure upload behavior. If this field is absent, uploading remains enabled. Applies only when version == \"v2\".\nAvailable values: \"enabled\", \"disabled\"." + }, + { + "name": "version", + "type": "String", + "description": "Indicate which version of the browser isolation controls should apply.\nAvailable values: \"v1\", \"v2\"." + }, + { + "name": "wm_id", + "type": "String", + "description": "Specify the watermark ID (UUID) to apply to the isolated browser session. When present, enables watermark rendering in the isolated browser." + } + ] + }, + { + "name": "block_page", + "type": "Attributes", + "description": "Configure custom block page settings. If missing or null, use the account settings. Settable only for `http` rules with the action set to `block`.", + "children": [ + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to pass the context information as query parameters." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to which the user is redirected." + } + ] + }, + { + "name": "block_page_enabled", + "type": "Boolean", + "description": "Enable the custom block page. Settable only for `dns` rules with action `block`." + }, + { + "name": "block_reason", + "type": "String", + "description": "Explain why the rule blocks the request. The custom block page shows this text (if enabled). Settable only for `dns`, `l4`, and `http` rules when the action set to `block`." + }, + { + "name": "bypass_parent_rule", + "type": "Boolean", + "description": "Set to enable MSP accounts to bypass their parent's rules. Only MSP child accounts can set this. Settable for all types of rules." + }, + { + "name": "check_session", + "type": "Attributes", + "description": "Configure session check behavior. Settable only for `l4` and `http` rules with the action set to `allow`.", + "children": [ + { + "name": "duration", + "type": "String", + "description": "Sets the required session freshness threshold. The API returns a normalized version of this value." + }, + { + "name": "enforce", + "type": "Boolean", + "description": "Enable session enforcement." + } + ] + }, + { + "name": "delete_headers", + "type": "List of String", + "description": "Remove headers from allowed requests by name. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "dns_resolvers", + "type": "Attributes", + "description": "Configure custom resolvers to route queries that match the resolver policy. Unused with 'resolve_dns_through_cloudflare' or 'resolve_dns_internally' settings. DNS queries get routed to the address closest to their origin. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.", + "children": [ + { + "name": "ipv4", + "type": "Attributes List", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Specify the IPv4 address of the upstream resolver." + }, + { + "name": "port", + "type": "Number", + "description": "Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified." + }, + { + "name": "route_through_private_network", + "type": "Boolean", + "description": "Indicate whether to connect to this resolver over a private network. Must set when vnet_id set." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Specify an optional virtual network for this resolver. Uses default virtual network id if omitted." + } + ] + }, + { + "name": "ipv6", + "type": "Attributes List", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Specify the IPv6 address of the upstream resolver." + }, + { + "name": "port", + "type": "Number", + "description": "Specify a port number to use for the upstream resolver. Defaults to 53 if unspecified." + }, + { + "name": "route_through_private_network", + "type": "Boolean", + "description": "Indicate whether to connect to this resolver over a private network. Must set when vnet_id set." + }, + { + "name": "vnet_id", + "type": "String", + "description": "Specify an optional virtual network for this resolver. Uses default virtual network id if omitted." + } + ] + } + ] + }, + { + "name": "egress", + "type": "Attributes", + "description": "Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs. Settable only for `egress` rules.", + "children": [ + { + "name": "ipv4", + "type": "String", + "description": "Specify the IPv4 address to use for egress." + }, + { + "name": "ipv4_fallback", + "type": "String", + "description": "Specify the fallback IPv4 address to use for egress when the primary IPv4 fails. Set '0.0.0.0' to indicate local egress via WARP IPs." + }, + { + "name": "ipv6", + "type": "String", + "description": "Specify the IPv6 range to use for egress." + } + ] + }, + { + "name": "forensic_copy", + "type": "Attributes", + "description": "Configure whether a copy of the HTTP request will be sent to storage when the rule matches.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable sending the copy to storage." + } + ] + }, + { + "name": "ignore_cname_category_matches", + "type": "Boolean", + "description": "Ignore category matches at CNAME domains in a response. When off, evaluate categories in this rule against all CNAME domain categories in the response. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "insecure_disable_dnssec_validation", + "type": "Boolean", + "description": "Specify whether to disable DNSSEC validation (for Allow actions) [INSECURE]. Settable only for `dns` rules." + }, + { + "name": "ip_categories", + "type": "Boolean", + "description": "Enable IPs in DNS resolver category blocks. The system blocks only domain name categories unless you enable this setting. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "ip_indicator_feeds", + "type": "Boolean", + "description": "Indicates whether to include IPs in DNS resolver indicator feed blocks. Default, indicator feeds block only domain names. Settable only for `dns` and `dns_resolver` rules." + }, + { + "name": "l4override", + "type": "Attributes", + "description": "Send matching traffic to the supplied destination IP address and port. Settable only for `l4` rules with the action set to `l4_override`.", + "children": [ + { + "name": "ip", + "type": "String", + "description": "Defines the IPv4 or IPv6 address." + }, + { + "name": "port", + "type": "Number", + "description": "Defines a port number to use for TCP/UDP overrides." + } + ] + }, + { + "name": "notification_settings", + "type": "Attributes", + "description": "Configure a notification to display on the user's device when this rule matched. Settable for all types of rules with the action set to `block`.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable notification." + }, + { + "name": "include_context", + "type": "Boolean", + "description": "Indicates whether to pass the context information as query parameters." + }, + { + "name": "msg", + "type": "String", + "description": "Customize the message shown in the notification." + }, + { + "name": "support_url", + "type": "String", + "description": "Defines an optional URL to direct users to additional information. If unset, the notification opens a block page." + } + ] + }, + { + "name": "override_host", + "type": "String", + "description": "Defines a hostname for override, for the matching DNS queries. Settable only for `dns` rules with the action set to `override`." + }, + { + "name": "override_ips", + "type": "List of String", + "description": "Defines a an IP or set of IPs for overriding matched DNS queries. Settable only for `dns` rules with the action set to `override`." + }, + { + "name": "payload_log", + "type": "Attributes", + "description": "Configure DLP payload logging. Settable only for `http` rules.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Enable DLP payload logging for this rule." + } + ] + }, + { + "name": "quarantine", + "type": "Attributes", + "description": "Configure settings that apply to quarantine rules. Settable only for `http` rules.", + "children": [ + { + "name": "file_types", + "type": "List of String", + "description": "Specify the types of files to sandbox." + } + ] + }, + { + "name": "redirect", + "type": "Attributes", + "description": "Apply settings to redirect rules. Settable only for `http` rules with the action set to `redirect`.", + "children": [ + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to pass the context information as query parameters." + }, + { + "name": "preserve_path_and_query", + "type": "Boolean", + "description": "Specify whether to append the path and query parameters from the original request to target_uri." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to which the user is redirected." + } + ] + }, + { + "name": "resolve_dns_internally", + "type": "Attributes", + "description": "Configure to forward the query to the internal DNS service, passing the specified 'view_id' as input. Not used when 'dns_resolvers' is specified or 'resolve_dns_through_cloudflare' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules.", + "children": [ + { + "name": "fallback", + "type": "String", + "description": "Specify the fallback behavior to apply when the internal DNS response code differs from 'NOERROR' or when the response data contains only CNAME records for 'A' or 'AAAA' queries.\nAvailable values: \"none\", \"public_dns\"." + }, + { + "name": "view_id", + "type": "String", + "description": "Specify the internal DNS view identifier to pass to the internal DNS service." + } + ] + }, + { + "name": "resolve_dns_through_cloudflare", + "type": "Boolean", + "description": "Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot set when 'dns_resolvers' specified or 'resolve_dns_internally' is set. Only valid when a rule's action set to 'resolve'. Settable only for `dns_resolver` rules." + }, + { + "name": "set_headers", + "type": "Map of List of String", + "description": "Replace existing headers on allowed requests with the specified key-value pairs. If a header does not exist, it is added. Header values may contain `@{selector.name}` variable references that are interpolated at the edge. Use `@@{` to escape a literal `@{`. A maximum of 20 header operations (add + set + delete) is allowed per policy. Each header name may not exceed 256 bytes and each header value may not exceed 4 KB. Settable only for `http` rules with the action set to `allow`." + }, + { + "name": "untrusted_cert", + "type": "Attributes", + "description": "Configure behavior when an upstream certificate is invalid or an SSL error occurs. Settable only for `http` rules with the action set to `allow`.", + "children": [ + { + "name": "action", + "type": "String", + "description": "Defines the action performed when an untrusted certificate seen. The default action an error with HTTP code 526.\nAvailable values: \"pass_through\", \"block\", \"error\"." + } + ] + } + ] + }, + { + "name": "schedule", + "type": "Attributes", + "description": "Defines the schedule for activating DNS policies. Settable only for `dns` and `dns_resolver` rules.", + "children": [ + { + "name": "fri", + "type": "String", + "description": "Specify the time intervals when the rule is active on Fridays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Fridays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "mon", + "type": "String", + "description": "Specify the time intervals when the rule is active on Mondays, in the increasing order from 00:00-24:00(capped at maximum of 6 time splits). If this parameter omitted, the rule is deactivated on Mondays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "sat", + "type": "String", + "description": "Specify the time intervals when the rule is active on Saturdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Saturdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "sun", + "type": "String", + "description": "Specify the time intervals when the rule is active on Sundays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Sundays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "thu", + "type": "String", + "description": "Specify the time intervals when the rule is active on Thursdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Thursdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "time_zone", + "type": "String", + "description": "Specify the time zone for rule evaluation. When a [valid time zone city name](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List) is provided, Gateway always uses the current time for that time zone. When this parameter is omitted, Gateway uses the time zone determined from the user's IP address. Colo time zone is used when the user's IP address does not resolve to a location." + }, + { + "name": "tue", + "type": "String", + "description": "Specify the time intervals when the rule is active on Tuesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Tuesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + }, + { + "name": "wed", + "type": "String", + "description": "Specify the time intervals when the rule is active on Wednesdays, in the increasing order from 00:00-24:00. If this parameter omitted, the rule is deactivated on Wednesdays. API returns a formatted version of this string, which may cause Terraform drift if a unformatted value is used." + } + ] + }, + { + "name": "traffic", + "type": "String", + "description": "Specify the wirefilter expression used for traffic matching. The API automatically formats and sanitizes expressions before storing them. To prevent Terraform state drift, use the formatted expression returned in the API response." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "deleted_at", + "type": "String", + "description": "Indicate the date of deletion, if any." + }, + { + "name": "id", + "type": "String", + "description": "Identify the API resource with a UUID." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicate that this rule is shared via the Orgs API and read only." + }, + { + "name": "sharable", + "type": "Boolean", + "description": "Indicate that this rule is sharable via the Orgs API." + }, + { + "name": "source_account", + "type": "String", + "description": "Provide the account tag of the account that created the rule." + }, + { + "name": "updated_at", + "type": "String" + }, + { + "name": "version", + "type": "Number", + "description": "Indicate the version number of the rule(read-only)." + }, + { + "name": "warning_status", + "type": "String", + "description": "Indicate a warning for a misconfigured rule, if any." + } + ] + }, + "data-source:cloudflare_zero_trust_gateway_proxy_endpoint": { + "kind": "data-source", + "name": "cloudflare_zero_trust_gateway_proxy_endpoint", + "example": "data \"cloudflare_zero_trust_gateway_proxy_endpoint\" \"example_zero_trust_gateway_proxy_endpoint\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n proxy_endpoint_id = \"ed35569b41ce4d1facfe683550f54086\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned proxy endpoints by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (an endpoint must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the endpoint name.\n * `id` — substring match on the endpoint ID (UUID), with or without dashes.\n * `kind` — exact match on the endpoint kind. The value must be `ip` or `identity`; any other value returns `400`.\n\nEach entry must match one of the per-field patterns below: the field\nmust be one of `name`, `id`, or `kind`; `name`/`id` accept any value,\nwhile `kind` only accepts `ip` or `identity`." + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned endpoints by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by endpoint name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\nAvailable values: \"name\", \"created_at\", \"updated_at\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring match on the endpoint name. When combined\nwith `filter`, both must match (logical AND)." + } + ] + }, + { + "name": "proxy_endpoint_id", + "type": "String" + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "ips", + "type": "List of String", + "description": "Specify the list of CIDRs to restrict ingress connections." + }, + { + "name": "kind", + "type": "String", + "description": "The proxy endpoint kind\nAvailable values: \"ip\", \"identity\"." + }, + { + "name": "name", + "type": "String", + "description": "Specify the name of the proxy endpoint." + }, + { + "name": "subdomain", + "type": "String", + "description": "Specify the subdomain to use as the destination in the proxy client." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_gateway_proxy_endpoint": { + "kind": "resource", + "name": "cloudflare_zero_trust_gateway_proxy_endpoint", + "example": "resource \"cloudflare_zero_trust_gateway_proxy_endpoint\" \"example_zero_trust_gateway_proxy_endpoint\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Devops team\"\n kind = \"ip\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_gateway_proxy_endpoint.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "name", + "type": "String", + "description": "Specify the name of the proxy endpoint." + } + ], + "optional": [ + { + "name": "ips", + "type": "List of String", + "description": "Specify the list of CIDRs to restrict ingress connections." + }, + { + "name": "kind", + "type": "String", + "description": "The proxy endpoint kind\nAvailable values: \"ip\", \"identity\"." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "subdomain", + "type": "String", + "description": "Specify the subdomain to use as the destination in the proxy client." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_gateway_proxy_endpoints": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_gateway_proxy_endpoints", + "example": "data \"cloudflare_zero_trust_gateway_proxy_endpoints\" \"example_zero_trust_gateway_proxy_endpoints\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "direction", + "type": "String", + "description": "Sort direction. Only takes effect when `order_by` is also provided; it\nis ignored otherwise. When `direction` is omitted the effective\ndirection is field-specific: `created_at` and `updated_at` default to\ndescending (newest first); `name` defaults to ascending.\n * `asc` — ascending.\n * `desc` — descending.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned proxy endpoints by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (an endpoint must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the endpoint name.\n * `id` — substring match on the endpoint ID (UUID), with or without dashes.\n * `kind` — exact match on the endpoint kind. The value must be `ip` or `identity`; any other value returns `400`.\n\nEach entry must match one of the per-field patterns below: the field\nmust be one of `name`, `id`, or `kind`; `name`/`id` accept any value,\nwhile `kind` only accepts `ip` or `identity`." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned endpoints by. When omitted, the order of\nresults is unspecified. Supported values:\n * `name` — sort alphabetically by endpoint name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\nAvailable values: \"name\", \"created_at\", \"updated_at\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring match on the endpoint name. When combined\nwith `filter`, both must match (logical AND)." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String" + }, + { + "name": "ips", + "type": "List of String", + "description": "Specify the list of CIDRs to restrict ingress connections." + }, + { + "name": "kind", + "type": "String", + "description": "The proxy endpoint kind\nAvailable values: \"ip\", \"identity\"." + }, + { + "name": "name", + "type": "String", + "description": "Specify the name of the proxy endpoint." + }, + { + "name": "subdomain", + "type": "String", + "description": "Specify the subdomain to use as the destination in the proxy client." + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_gateway_settings": { + "kind": "data-source", + "name": "cloudflare_zero_trust_gateway_settings", + "example": "data \"cloudflare_zero_trust_gateway_settings\" \"example_zero_trust_gateway_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "settings", + "type": "Attributes", + "description": "Specify account settings.", + "children": [ + { + "name": "activity_log", + "type": "Attributes", + "description": "Specify activity log settings.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to log activity." + } + ] + }, + { + "name": "antivirus", + "type": "Attributes", + "description": "Specify anti-virus settings.", + "children": [ + { + "name": "enabled_download_phase", + "type": "Boolean", + "description": "Specify whether to enable anti-virus scanning on downloads." + }, + { + "name": "enabled_upload_phase", + "type": "Boolean", + "description": "Specify whether to enable anti-virus scanning on uploads." + }, + { + "name": "fail_closed", + "type": "Boolean", + "description": "Specify whether to block requests for unscannable files." + }, + { + "name": "notification_settings", + "type": "Attributes", + "description": "Configure the message the user's device shows during an antivirus scan.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable notifications." + }, + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to include context information as query parameters." + }, + { + "name": "msg", + "type": "String", + "description": "Specify the message to show in the notification." + }, + { + "name": "support_url", + "type": "String", + "description": "Specify a URL that directs users to more information. If unset, the notification opens a block page." + } + ] + } + ] + }, + { + "name": "block_page", + "type": "Attributes", + "description": "Specify block page layout settings.", + "children": [ + { + "name": "background_color", + "type": "String", + "description": "Specify the block page background color in `#rrggbb` format when the mode is customized_block_page." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable the custom block page." + }, + { + "name": "footer_text", + "type": "String", + "description": "Specify the block page footer text when the mode is customized_block_page." + }, + { + "name": "header_text", + "type": "String", + "description": "Specify the block page header text when the mode is customized_block_page." + }, + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to append context to target_uri as query parameters. This applies only when the mode is redirect_uri." + }, + { + "name": "logo_path", + "type": "String", + "description": "Specify the full URL to the logo file when the mode is customized_block_page." + }, + { + "name": "mailto_address", + "type": "String", + "description": "Specify the admin email for users to contact when the mode is customized_block_page." + }, + { + "name": "mailto_subject", + "type": "String", + "description": "Specify the subject line for emails created from the block page when the mode is customized_block_page." + }, + { + "name": "mode", + "type": "String", + "description": "Specify whether to redirect users to a Cloudflare-hosted block page or a customer-provided URI.\nAvailable values: \"\", \"customized_block_page\", \"redirect_uri\"." + }, + { + "name": "name", + "type": "String", + "description": "Specify the block page title when the mode is customized_block_page." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicate that this setting was shared via the Orgs API and read only for the current account." + }, + { + "name": "source_account", + "type": "String", + "description": "Indicate the account tag of the account that shared this setting." + }, + { + "name": "suppress_footer", + "type": "Boolean", + "description": "Specify whether to suppress detailed information at the bottom of the block page when the mode is customized_block_page." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to redirect users to when the mode is redirect_uri." + }, + { + "name": "version", + "type": "Number", + "description": "Indicate the version number of the setting." + } + ] + }, + { + "name": "body_scanning", + "type": "Attributes", + "description": "Specify the DLP inspection mode.", + "children": [ + { + "name": "inspection_mode", + "type": "String", + "description": "Specify the inspection mode as either `deep` or `shallow`.\nAvailable values: \"deep\", \"shallow\"." + } + ] + }, + { + "name": "browser_isolation", + "type": "Attributes", + "description": "Specify Clientless Browser Isolation settings.", + "children": [ + { + "name": "non_identity_enabled", + "type": "Boolean", + "description": "Specify whether to enable non-identity onramp support for Browser Isolation." + }, + { + "name": "url_browser_isolation_enabled", + "type": "Boolean", + "description": "Specify whether to enable Clientless Browser Isolation." + } + ] + }, + { + "name": "certificate", + "type": "Attributes", + "description": "Specify certificate settings for Gateway TLS interception. If unset, the Cloudflare Root CA handles interception.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Specify the UUID of the certificate used for interception. Ensure the certificate is available at the edge(previously called 'active'). A nil UUID directs Cloudflare to use the Root CA." + } + ] + }, + { + "name": "custom_certificate", + "type": "Attributes", + "description": "Specify custom certificate settings for BYO-PKI. This field is deprecated; use `certificate` instead.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "binding_status", + "type": "String", + "description": "Indicate the internal certificate status." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable a custom certificate authority for signing Gateway traffic." + }, + { + "name": "id", + "type": "String", + "description": "Specify the UUID of the certificate (ID from MTLS certificate store)." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "extended_email_matching", + "type": "Attributes", + "description": "Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses `.` or `+` modifiers.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to match all variants of user emails (with + or . modifiers) used as criteria in Firewall policies." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicate that this setting was shared via the Orgs API and read only for the current account." + }, + { + "name": "source_account", + "type": "String", + "description": "Indicate the account tag of the account that shared this setting." + }, + { + "name": "version", + "type": "Number", + "description": "Indicate the version number of the setting." + } + ] + }, + { + "name": "fips", + "type": "Attributes", + "description": "Specify FIPS settings.", + "children": [ + { + "name": "tls", + "type": "Boolean", + "description": "Enforce cipher suites and TLS versions compliant with FIPS 140-2." + } + ] + }, + { + "name": "host_selector", + "type": "Attributes", + "description": "Enable host selection in egress policies.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable filtering via hosts for egress policies." + } + ] + }, + { + "name": "inspection", + "type": "Attributes", + "description": "Define the proxy inspection mode.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Define the proxy inspection mode. 1. static: Gateway applies static inspection to HTTP on TCP(80). With TLS decryption on, Gateway inspects HTTPS traffic on TCP(443) and UDP(443). 2. dynamic: Gateway applies protocol detection to inspect HTTP and HTTPS traffic on any port. TLS decryption must remain on to inspect HTTPS traffic.\nAvailable values: \"static\", \"dynamic\"." + } + ] + }, + { + "name": "max_ttl_secs", + "type": "Number", + "description": "Account-level cap on DNS response TTLs, in seconds. Gateway rewrites DNS responses so returned record TTLs do not exceed this value. Null means no cap. Each DNS location can inherit, override, or disable it through the location `max_ttl` setting." + }, + { + "name": "protocol_detection", + "type": "Attributes", + "description": "Specify whether to detect protocols from the initial bytes of client traffic.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to detect protocols from the initial bytes of client traffic." + } + ] + }, + { + "name": "sandbox", + "type": "Attributes", + "description": "Specify whether to enable the sandbox.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable the sandbox." + }, + { + "name": "fallback_action", + "type": "String", + "description": "Specify the action to take when the system cannot scan the file.\nAvailable values: \"allow\", \"block\"." + } + ] + }, + { + "name": "tls_decrypt", + "type": "Attributes", + "description": "Specify whether to inspect encrypted HTTP traffic.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to inspect encrypted HTTP traffic." + } + ] + } + ] + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_gateway_settings": { + "kind": "resource", + "name": "cloudflare_zero_trust_gateway_settings", + "example": "resource \"cloudflare_zero_trust_gateway_settings\" \"example_zero_trust_gateway_settings\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n settings = {\n activity_log = {\n enabled = true\n }\n antivirus = {\n enabled_download_phase = false\n enabled_upload_phase = false\n fail_closed = false\n notification_settings = {\n enabled = true\n include_context = true\n msg = \"msg\"\n support_url = \"support_url\"\n }\n }\n block_page = {\n background_color = \"background_color\"\n enabled = true\n footer_text = \"--footer--\"\n header_text = \"--header--\"\n include_context = true\n logo_path = \"https://logos.com/a.png\"\n mailto_address = \"admin@example.com\"\n mailto_subject = \"Blocked User Inquiry\"\n mode = \"\"\n name = \"Cloudflare\"\n suppress_footer = false\n target_uri = \"https://example.com\"\n }\n body_scanning = {\n inspection_mode = \"deep\"\n }\n browser_isolation = {\n non_identity_enabled = true\n url_browser_isolation_enabled = true\n }\n certificate = {\n id = \"d1b364c5-1311-466e-a194-f0e943e0799f\"\n }\n custom_certificate = {\n enabled = true\n id = \"d1b364c5-1311-466e-a194-f0e943e0799f\"\n }\n extended_email_matching = {\n enabled = true\n }\n fips = {\n tls = true\n }\n host_selector = {\n enabled = false\n }\n inspection = {\n mode = \"static\"\n }\n max_ttl_secs = 3600\n protocol_detection = {\n enabled = true\n }\n sandbox = {\n enabled = true\n fallback_action = \"allow\"\n }\n tls_decrypt = {\n enabled = true\n }\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_gateway_settings.example ''", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + } + ], + "optional": [ + { + "name": "settings", + "type": "Attributes", + "description": "Specify account settings.", + "children": [ + { + "name": "activity_log", + "type": "Attributes", + "description": "Specify activity log settings.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to log activity." + } + ] + }, + { + "name": "antivirus", + "type": "Attributes", + "description": "Specify anti-virus settings.", + "children": [ + { + "name": "enabled_download_phase", + "type": "Boolean", + "description": "Specify whether to enable anti-virus scanning on downloads." + }, + { + "name": "enabled_upload_phase", + "type": "Boolean", + "description": "Specify whether to enable anti-virus scanning on uploads." + }, + { + "name": "fail_closed", + "type": "Boolean", + "description": "Specify whether to block requests for unscannable files." + }, + { + "name": "notification_settings", + "type": "Attributes", + "description": "Configure the message the user's device shows during an antivirus scan.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable notifications." + }, + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to include context information as query parameters." + }, + { + "name": "msg", + "type": "String", + "description": "Specify the message to show in the notification." + }, + { + "name": "support_url", + "type": "String", + "description": "Specify a URL that directs users to more information. If unset, the notification opens a block page." + } + ] + } + ] + }, + { + "name": "block_page", + "type": "Attributes", + "description": "Specify block page layout settings.", + "children": [ + { + "name": "background_color", + "type": "String", + "description": "Specify the block page background color in `#rrggbb` format when the mode is customized_block_page." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable the custom block page." + }, + { + "name": "footer_text", + "type": "String", + "description": "Specify the block page footer text when the mode is customized_block_page." + }, + { + "name": "header_text", + "type": "String", + "description": "Specify the block page header text when the mode is customized_block_page." + }, + { + "name": "include_context", + "type": "Boolean", + "description": "Specify whether to append context to target_uri as query parameters. This applies only when the mode is redirect_uri." + }, + { + "name": "logo_path", + "type": "String", + "description": "Specify the full URL to the logo file when the mode is customized_block_page." + }, + { + "name": "mailto_address", + "type": "String", + "description": "Specify the admin email for users to contact when the mode is customized_block_page." + }, + { + "name": "mailto_subject", + "type": "String", + "description": "Specify the subject line for emails created from the block page when the mode is customized_block_page." + }, + { + "name": "mode", + "type": "String", + "description": "Specify whether to redirect users to a Cloudflare-hosted block page or a customer-provided URI.\nAvailable values: \"\", \"customized_block_page\", \"redirect_uri\"." + }, + { + "name": "name", + "type": "String", + "description": "Specify the block page title when the mode is customized_block_page." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicate that this setting was shared via the Orgs API and read only for the current account." + }, + { + "name": "source_account", + "type": "String", + "description": "Indicate the account tag of the account that shared this setting." + }, + { + "name": "suppress_footer", + "type": "Boolean", + "description": "Specify whether to suppress detailed information at the bottom of the block page when the mode is customized_block_page." + }, + { + "name": "target_uri", + "type": "String", + "description": "Specify the URI to redirect users to when the mode is redirect_uri." + }, + { + "name": "version", + "type": "Number", + "description": "Indicate the version number of the setting." + } + ] + }, + { + "name": "body_scanning", + "type": "Attributes", + "description": "Specify the DLP inspection mode.", + "children": [ + { + "name": "inspection_mode", + "type": "String", + "description": "Specify the inspection mode as either `deep` or `shallow`.\nAvailable values: \"deep\", \"shallow\"." + } + ] + }, + { + "name": "browser_isolation", + "type": "Attributes", + "description": "Specify Clientless Browser Isolation settings.", + "children": [ + { + "name": "non_identity_enabled", + "type": "Boolean", + "description": "Specify whether to enable non-identity onramp support for Browser Isolation." + }, + { + "name": "url_browser_isolation_enabled", + "type": "Boolean", + "description": "Specify whether to enable Clientless Browser Isolation." + } + ] + }, + { + "name": "certificate", + "type": "Attributes", + "description": "Specify certificate settings for Gateway TLS interception. If unset, the Cloudflare Root CA handles interception.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Specify the UUID of the certificate used for interception. Ensure the certificate is available at the edge(previously called 'active'). A nil UUID directs Cloudflare to use the Root CA." + } + ] + }, + { + "name": "custom_certificate", + "type": "Attributes", + "description": "Specify custom certificate settings for BYO-PKI. This field is deprecated; use `certificate` instead.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "binding_status", + "type": "String", + "description": "Indicate the internal certificate status." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable a custom certificate authority for signing Gateway traffic." + }, + { + "name": "id", + "type": "String", + "description": "Specify the UUID of the certificate (ID from MTLS certificate store)." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + { + "name": "extended_email_matching", + "type": "Attributes", + "description": "Configures user email settings for firewall policies. When you enable this, the system standardizes email addresses in the identity portion of the rule to match extended email variants in firewall policies. When you disable this setting, the system matches email addresses exactly as you provide them. Enable this setting if your email uses `.` or `+` modifiers.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to match all variants of user emails (with + or . modifiers) used as criteria in Firewall policies." + }, + { + "name": "read_only", + "type": "Boolean", + "description": "Indicate that this setting was shared via the Orgs API and read only for the current account." + }, + { + "name": "source_account", + "type": "String", + "description": "Indicate the account tag of the account that shared this setting." + }, + { + "name": "version", + "type": "Number", + "description": "Indicate the version number of the setting." + } + ] + }, + { + "name": "fips", + "type": "Attributes", + "description": "Specify FIPS settings.", + "children": [ + { + "name": "tls", + "type": "Boolean", + "description": "Enforce cipher suites and TLS versions compliant with FIPS 140-2." + } + ] + }, + { + "name": "host_selector", + "type": "Attributes", + "description": "Enable host selection in egress policies.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable filtering via hosts for egress policies." + } + ] + }, + { + "name": "inspection", + "type": "Attributes", + "description": "Define the proxy inspection mode.", + "children": [ + { + "name": "mode", + "type": "String", + "description": "Define the proxy inspection mode. 1. static: Gateway applies static inspection to HTTP on TCP(80). With TLS decryption on, Gateway inspects HTTPS traffic on TCP(443) and UDP(443). 2. dynamic: Gateway applies protocol detection to inspect HTTP and HTTPS traffic on any port. TLS decryption must remain on to inspect HTTPS traffic.\nAvailable values: \"static\", \"dynamic\"." + } + ] + }, + { + "name": "max_ttl_secs", + "type": "Number", + "description": "Account-level cap on DNS response TTLs, in seconds. Gateway rewrites DNS responses so returned record TTLs do not exceed this value. Null means no cap. Each DNS location can inherit, override, or disable it through the location `max_ttl` setting." + }, + { + "name": "protocol_detection", + "type": "Attributes", + "description": "Specify whether to detect protocols from the initial bytes of client traffic.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to detect protocols from the initial bytes of client traffic." + } + ] + }, + { + "name": "sandbox", + "type": "Attributes", + "description": "Specify whether to enable the sandbox.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to enable the sandbox." + }, + { + "name": "fallback_action", + "type": "String", + "description": "Specify the action to take when the system cannot scan the file.\nAvailable values: \"allow\", \"block\"." + } + ] + }, + { + "name": "tls_decrypt", + "type": "Attributes", + "description": "Specify whether to inspect encrypted HTTP traffic.", + "children": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Specify whether to inspect encrypted HTTP traffic." + } + ] + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "data-source:cloudflare_zero_trust_list": { + "kind": "data-source", + "name": "cloudflare_zero_trust_list", + "example": "data \"cloudflare_zero_trust_list\" \"example_zero_trust_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n list_id = \"f174e90a-fafe-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "direction", + "type": "String", + "description": "Sort direction. Applies to the field named in `order_by`; when `order_by`\nis omitted it applies to the default `created_at` ordering. When\n`direction` is omitted the default is field-specific: explicitly choosing\n`created_at` or `updated_at` defaults to descending (newest first); `name`\nand `item_count` default to ascending; and the default `created_at`\nordering used when `order_by` is omitted is ascending (for backwards\ncompatibility).\n * `asc` — ascending.\n * `desc` — descending.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned lists by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a list must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the list name.\n * `id` — substring match on the list ID (UUID), with or without dashes.\n * `type` — exact match on the list type. Supersedes the legacy `type` query\n parameter when both are supplied. Must be one of the valid type values.\n * `item_count` — exact integer match on the number of items in the list.\n\nEach entry must match one of the per-field patterns below: the field must be\none of `name`, `id`, `type`, or `item_count`; `name`/`id` accept any value,\n`type` is restricted to the valid list type values, and `item_count` must be\na non-negative integer." + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned lists by. When omitted, results are ordered by\n`created_at` in ascending order (i.e. creation order) for backwards\ncompatibility. Supported values:\n * `name` — sort alphabetically by list name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\n * `item_count` — sort by number of items in the list.\nAvailable values: \"name\", \"created_at\", \"updated_at\", \"item_count\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring match on the list name or description. When\ncombined with `filter`, both must match (logical AND)." + }, + { + "name": "type", + "type": "String", + "description": "Specify the list type.\nAvailable values: \"SERIAL\", \"URL\", \"DOMAIN\", \"EMAIL\", \"IP\", \"CATEGORY\", \"LOCATION\", \"DEVICE\", \"AAGUID\"." + } + ] + }, + { + "name": "list_id", + "type": "String", + "description": "Identify the API resource with a UUID." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Provide the list description." + }, + { + "name": "id", + "type": "String", + "description": "Identify the API resource with a UUID." + }, + { + "name": "items", + "type": "Attributes Set", + "description": "Provide the list items.", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Provide the list item description (optional)." + }, + { + "name": "value", + "type": "String", + "description": "Specify the item value." + } + ] + }, + { + "name": "list_count", + "type": "Number", + "description": "Indicate the number of items in the list." + }, + { + "name": "name", + "type": "String", + "description": "Specify the list name." + }, + { + "name": "type", + "type": "String", + "description": "Specify the list type.\nAvailable values: \"SERIAL\", \"URL\", \"DOMAIN\", \"EMAIL\", \"IP\", \"CATEGORY\", \"LOCATION\", \"DEVICE\", \"AAGUID\"." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "resource:cloudflare_zero_trust_list": { + "kind": "resource", + "name": "cloudflare_zero_trust_list", + "example": "resource \"cloudflare_zero_trust_list\" \"example_zero_trust_list\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"Admin Serial Numbers\"\n type = \"SERIAL\"\n description = \"The serial numbers for administrators\"\n items = [{\n description = \"Austin office IP\"\n value = \"8GE8721REF\"\n }]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_list.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "name", + "type": "String", + "description": "Specify the list name." + }, + { + "name": "type", + "type": "String", + "description": "Specify the list type.\nAvailable values: \"SERIAL\", \"URL\", \"DOMAIN\", \"EMAIL\", \"IP\", \"CATEGORY\", \"LOCATION\", \"DEVICE\", \"AAGUID\"." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "Provide the list description." + }, + { + "name": "items", + "type": "Attributes Set", + "description": "Add items to the list.", + "children": [ + { + "name": "description", + "type": "String", + "description": "Provide the list item description (optional)." + }, + { + "name": "value", + "type": "String", + "description": "Specify the item value." + } + ] + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identify the API resource with a UUID." + }, + { + "name": "list_count", + "type": "Number", + "description": "Indicate the number of items in the list." + }, + { + "name": "updated_at", + "type": "String" + } + ] + }, + "list-data-source:cloudflare_zero_trust_lists": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_lists", + "example": "data \"cloudflare_zero_trust_lists\" \"example_zero_trust_lists\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n direction = \"asc\"\n filter = [\"string\"]\n order_by = \"name\"\n search = \"search\"\n type = \"SERIAL\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Specify the Cloudflare account identifier." + }, + { + "name": "direction", + "type": "String", + "description": "Sort direction. Applies to the field named in `order_by`; when `order_by`\nis omitted it applies to the default `created_at` ordering. When\n`direction` is omitted the default is field-specific: explicitly choosing\n`created_at` or `updated_at` defaults to descending (newest first); `name`\nand `item_count` default to ascending; and the default `created_at`\nordering used when `order_by` is omitted is ascending (for backwards\ncompatibility).\n * `asc` — ascending.\n * `desc` — descending.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "filter", + "type": "List of String", + "description": "Filter the returned lists by one or more `field:value` pairs.\nRepeat the parameter to apply multiple filters; they are combined with\nlogical AND (a list must satisfy every filter to be returned).\n\nSupported fields and their matching behaviour:\n * `name` — case-insensitive substring match on the list name.\n * `id` — substring match on the list ID (UUID), with or without dashes.\n * `type` — exact match on the list type. Supersedes the legacy `type` query\n parameter when both are supplied. Must be one of the valid type values.\n * `item_count` — exact integer match on the number of items in the list.\n\nEach entry must match one of the per-field patterns below: the field must be\none of `name`, `id`, `type`, or `item_count`; `name`/`id` accept any value,\n`type` is restricted to the valid list type values, and `item_count` must be\na non-negative integer." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "order_by", + "type": "String", + "description": "Field to sort the returned lists by. When omitted, results are ordered by\n`created_at` in ascending order (i.e. creation order) for backwards\ncompatibility. Supported values:\n * `name` — sort alphabetically by list name.\n * `created_at` — sort by creation time; defaults to descending unless `direction` is set.\n * `updated_at` — sort by last-modified time; defaults to descending unless `direction` is set.\n * `item_count` — sort by number of items in the list.\nAvailable values: \"name\", \"created_at\", \"updated_at\", \"item_count\"." + }, + { + "name": "search", + "type": "String", + "description": "Case-insensitive substring match on the list name or description. When\ncombined with `filter`, both must match (logical AND)." + }, + { + "name": "type", + "type": "String", + "description": "Specify the list type.\nAvailable values: \"SERIAL\", \"URL\", \"DOMAIN\", \"EMAIL\", \"IP\", \"CATEGORY\", \"LOCATION\", \"DEVICE\", \"AAGUID\"." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Provide the list description." + }, + { + "name": "id", + "type": "String", + "description": "Identify the API resource with a UUID." + }, + { + "name": "items", + "type": "Attributes Set", + "description": "Provide the list items.", + "children": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "description", + "type": "String", + "description": "Provide the list item description (optional)." + }, + { + "name": "value", + "type": "String", + "description": "Specify the item value." + } + ] + }, + { + "name": "list_count", + "type": "Number", + "description": "Indicate the number of items in the list." + }, + { + "name": "name", + "type": "String", + "description": "Specify the list name." + }, + { + "name": "type", + "type": "String", + "description": "Specify the list type.\nAvailable values: \"SERIAL\", \"URL\", \"DOMAIN\", \"EMAIL\", \"IP\", \"CATEGORY\", \"LOCATION\", \"DEVICE\", \"AAGUID\"." + }, + { + "name": "updated_at", + "type": "String" + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_network_hostname_route": { + "kind": "data-source", + "name": "cloudflare_zero_trust_network_hostname_route", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_network_hostname_route\" \"example_zero_trust_network_hostname_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n hostname_route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "comment", + "type": "String", + "description": "If set, only list hostname routes with the given comment." + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "hostname", + "type": "String", + "description": "If set, only list hostname routes that contain a substring of the given value, the filter is case-insensitive." + }, + { + "name": "id", + "type": "String", + "description": "The hostname route ID." + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only return deleted hostname routes. If `false`, exclude deleted hostname routes." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "If set, only list hostname routes that point to a specific tunnel." + } + ] + }, + { + "name": "hostname_route_id", + "type": "String", + "description": "The hostname route ID." + } + ], + "computed": [ + { + "name": "comment", + "type": "String", + "description": "An optional description of the hostname route." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname of the route." + }, + { + "name": "id", + "type": "String", + "description": "The hostname route ID." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "tunnel_name", + "type": "String", + "description": "A user-friendly name for a tunnel." + } + ] + }, + "resource:cloudflare_zero_trust_network_hostname_route": { + "kind": "resource", + "name": "cloudflare_zero_trust_network_hostname_route", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "resource \"cloudflare_zero_trust_network_hostname_route\" \"example_zero_trust_network_hostname_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n comment = \"example comment\"\n hostname = \"office-1.local\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_network_hostname_route.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + } + ], + "optional": [ + { + "name": "comment", + "type": "String", + "description": "An optional description of the hostname route." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname of the route." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "The hostname route ID." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + }, + { + "name": "tunnel_name", + "type": "String", + "description": "A user-friendly name for a tunnel." + } + ] + }, + "list-data-source:cloudflare_zero_trust_network_hostname_routes": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_network_hostname_routes", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_network_hostname_routes\" \"example_zero_trust_network_hostname_routes\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n comment = \"example%20comment\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n hostname = \"office-1.local\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "comment", + "type": "String", + "description": "If set, only list hostname routes with the given comment." + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "hostname", + "type": "String", + "description": "If set, only list hostname routes that contain a substring of the given value, the filter is case-insensitive." + }, + { + "name": "id", + "type": "String", + "description": "The hostname route ID." + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only return deleted hostname routes. If `false`, exclude deleted hostname routes." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "tunnel_id", + "type": "String", + "description": "If set, only list hostname routes that point to a specific tunnel." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comment", + "type": "String", + "description": "An optional description of the hostname route." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "hostname", + "type": "String", + "description": "The hostname of the route." + }, + { + "name": "id", + "type": "String", + "description": "The hostname route ID." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "tunnel_name", + "type": "String", + "description": "A user-friendly name for a tunnel." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_organization": { + "kind": "data-source", + "name": "cloudflare_zero_trust_organization", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Revoke`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "data \"cloudflare_zero_trust_organization\" \"example_zero_trust_organization\" {\n account_id = \"account_id\"\n zone_id = \"zone_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "allow_authenticate_via_warp", + "type": "Boolean", + "description": "When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value." + }, + { + "name": "auth_domain", + "type": "String", + "description": "The unique subdomain assigned to your Zero Trust organization." + }, + { + "name": "auto_redirect_to_identity", + "type": "Boolean", + "description": "When set to `true`, users skip the identity provider selection step during login." + }, + { + "name": "custom_pages", + "type": "Attributes", + "children": [ + { + "name": "forbidden", + "type": "String", + "description": "The uid of the custom page to use when a user is denied access after failing a non-identity rule." + }, + { + "name": "identity_denied", + "type": "String", + "description": "The uid of the custom page to use when a user is denied access." + } + ] + }, + { + "name": "deny_unmatched_requests", + "type": "Boolean", + "description": "Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the `deny_unmatched_requests_exempted_zone_names` array." + }, + { + "name": "deny_unmatched_requests_exempted_zone_names", + "type": "List of String", + "description": "Contains zone names to exempt from the `deny_unmatched_requests` feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request." + }, + { + "name": "is_ui_read_only", + "type": "Boolean", + "description": "Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled." + }, + { + "name": "login_design", + "type": "Attributes", + "children": [ + { + "name": "background_color", + "type": "String", + "description": "The background color on your login page." + }, + { + "name": "footer_text", + "type": "String", + "description": "The text at the bottom of your login page." + }, + { + "name": "header_text", + "type": "String", + "description": "The text at the top of your login page." + }, + { + "name": "logo_path", + "type": "String", + "description": "The URL of the logo on your login page." + }, + { + "name": "text_color", + "type": "String", + "description": "The text color on your login page." + } + ] + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for an organization.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "Lists the MFA methods that users can authenticate with. The `piv_key` and `ssh_fido2_key` values are supported only for infrastructure applications." + }, + { + "name": "amr_matching_session_duration", + "type": "String", + "description": "Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains \"mfa\". Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days)." + }, + { + "name": "required_aaguids", + "type": "String", + "description": "Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs." + }, + { + "name": "session_duration", + "type": "String", + "description": "Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`." + } + ] + }, + { + "name": "mfa_required_for_all_apps", + "type": "Boolean", + "description": "Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: 'allowed_authenticators' cannot contain only the infrastructure SSH authenticators ('piv_key' and 'ssh_fido2_key') if the organization has any non-infrastructure applications." + }, + { + "name": "mfa_ssh_piv_key_requirements", + "type": "Attributes", + "description": "Configures SSH PIV key requirements for MFA using hardware security keys.", + "children": [ + { + "name": "pin_policy", + "type": "String", + "description": "Defines when a PIN is required to use the SSH key. Valid values: `never` (no PIN required), `once` (PIN required once per session), `always` (PIN required for each use).\nAvailable values: \"never\", \"once\", \"always\"." + }, + { + "name": "require_fips_device", + "type": "Boolean", + "description": "Requires the SSH PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device." + }, + { + "name": "ssh_key_size", + "type": "List of Number", + "description": "Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter." + }, + { + "name": "ssh_key_type", + "type": "List of String", + "description": "Specifies the allowed SSH key types. Valid values are `ecdsa`, `ed25519`, and `rsa`." + }, + { + "name": "touch_policy", + "type": "String", + "description": "Defines when physical touch is required to use the SSH key. Valid values: `never` (no touch required), `always` (touch required for each use), `cached` (touch cached for 15 seconds).\nAvailable values: \"never\", \"always\", \"cached\"." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of your Zero Trust organization." + }, + { + "name": "service_token_inactivity", + "type": "Attributes", + "description": "Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action applied to an inactive service token.\nAvailable values: \"disable\", \"delete\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether automatic enforcement for inactive service tokens is enabled." + }, + { + "name": "inactivity_threshold_days", + "type": "Number", + "description": "The number of days a service token must be inactive before the configured action is applied." + } + ] + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for applications will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h." + }, + { + "name": "strict_service_token_auth", + "type": "Boolean", + "description": "Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it." + }, + { + "name": "trusted_accounts", + "type": "List of String", + "description": "The account tags of organizations trusted by this organization for policy and device posture sharing." + }, + { + "name": "ui_read_only_toggle_reason", + "type": "String", + "description": "A description of the reason why the UI read only field is being toggled." + }, + { + "name": "user_seat_expiration_inactive_time", + "type": "String", + "description": "The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format `300ms` or `2h45m`. Valid time units are: `ns`, `us` (or `µs`), `ms`, `s`, `m`, `h`." + }, + { + "name": "warp_auth_non_browser_401", + "type": "Boolean", + "description": "When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page." + }, + { + "name": "warp_auth_session_duration", + "type": "String", + "description": "The amount of time that tokens issued for applications will be valid. Must be in the format `30m` or `2h45m`. Valid time units are: m, h." + } + ] + }, + "resource:cloudflare_zero_trust_organization": { + "kind": "resource", + "name": "cloudflare_zero_trust_organization", + "description": "Accepted Permissions\n\n- `Access: Organizations, Identity Providers, and Groups Read`\n- `Access: Organizations, Identity Providers, and Groups Revoke`\n- `Access: Organizations, Identity Providers, and Groups Write`", + "example": "resource \"cloudflare_zero_trust_organization\" \"example_zero_trust_organization\" {\n zone_id = \"zone_id\"\n allow_authenticate_via_warp = true\n auth_domain = \"test.cloudflareaccess.com\"\n auto_redirect_to_identity = true\n custom_pages = {\n forbidden = \"699d98642c564d2e855e9661899b7252\"\n identity_denied = \"699d98642c564d2e855e9661899b7252\"\n }\n deny_unmatched_requests = true\n deny_unmatched_requests_exempted_zone_names = [\"example.com\"]\n is_ui_read_only = true\n login_design = {\n background_color = \"#c5ed1b\"\n footer_text = \"This is an example description.\"\n header_text = \"This is an example description.\"\n logo_path = \"https://example.com/logo.png\"\n text_color = \"#c5ed1b\"\n }\n mfa_config = {\n allowed_authenticators = [\"totp\", \"biometrics\", \"security_key\"]\n amr_matching_session_duration = \"12h\"\n required_aaguids = \"2fc0579f-8113-47ea-b116-bb5a8db9202a\"\n session_duration = \"24h\"\n }\n mfa_piv_key_requirements = {\n pin_policy = \"always\"\n require_fips_device = true\n ssh_key_size = [256, 2048]\n ssh_key_type = [\"ecdsa\", \"rsa\"]\n touch_policy = \"always\"\n }\n mfa_required_for_all_apps = false\n name = \"Widget Corps Internal Applications\"\n service_token_inactivity = {\n action = \"disable\"\n enabled = true\n inactivity_threshold_days = 30\n }\n session_duration = \"24h\"\n strict_service_token_auth = true\n ui_read_only_toggle_reason = \"Temporarily turn off the UI read only lock to make a change via the UI\"\n user_seat_expiration_inactive_time = \"730h\"\n warp_auth_non_browser_401 = false\n warp_auth_session_duration = \"24h\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_organization.example ''", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "The Account ID to use for this endpoint. Mutually exclusive with the Zone ID." + }, + { + "name": "allow_authenticate_via_warp", + "type": "Boolean", + "description": "When set to true, users can authenticate via WARP for any application in your organization. Application settings will take precedence over this value." + }, + { + "name": "auth_domain", + "type": "String", + "description": "The unique subdomain assigned to your Zero Trust organization." + }, + { + "name": "auto_redirect_to_identity", + "type": "Boolean", + "description": "When set to `true`, users skip the identity provider selection step during login." + }, + { + "name": "custom_pages", + "type": "Attributes", + "children": [ + { + "name": "forbidden", + "type": "String", + "description": "The uid of the custom page to use when a user is denied access after failing a non-identity rule." + }, + { + "name": "identity_denied", + "type": "String", + "description": "The uid of the custom page to use when a user is denied access." + } + ] + }, + { + "name": "deny_unmatched_requests", + "type": "Boolean", + "description": "Determines whether to deny all requests to Cloudflare-protected resources that lack an associated Access application. If enabled, you must explicitly configure an Access application and policy to allow traffic to your Cloudflare-protected resources. For domains you want to be public across all subdomains, add the domain to the `deny_unmatched_requests_exempted_zone_names` array." + }, + { + "name": "deny_unmatched_requests_exempted_zone_names", + "type": "List of String", + "description": "Contains zone names to exempt from the `deny_unmatched_requests` feature. Requests to a subdomain in an exempted zone will block unauthenticated traffic by default if there is a configured Access application and policy that matches the request." + }, + { + "name": "is_ui_read_only", + "type": "Boolean", + "description": "Lock all settings as Read-Only in the Dashboard, regardless of user permission. Updates may only be made via the API or Terraform for this account when enabled." + }, + { + "name": "login_design", + "type": "Attributes", + "children": [ + { + "name": "background_color", + "type": "String", + "description": "The background color on your login page." + }, + { + "name": "footer_text", + "type": "String", + "description": "The text at the bottom of your login page." + }, + { + "name": "header_text", + "type": "String", + "description": "The text at the top of your login page." + }, + { + "name": "logo_path", + "type": "String", + "description": "The URL of the logo on your login page." + }, + { + "name": "text_color", + "type": "String", + "description": "The text color on your login page." + } + ] + }, + { + "name": "mfa_config", + "type": "Attributes", + "description": "Configures multi-factor authentication (MFA) settings for an organization.", + "children": [ + { + "name": "allowed_authenticators", + "type": "List of String", + "description": "Lists the MFA methods that users can authenticate with. The `piv_key` and `ssh_fido2_key` values are supported only for infrastructure applications." + }, + { + "name": "amr_matching_session_duration", + "type": "String", + "description": "Allows a user to skip MFA via Authentication Method Reference (AMR) matching when the AMR claim provided by the IdP the user used to authenticate contains \"mfa\". Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days)." + }, + { + "name": "required_aaguids", + "type": "String", + "description": "Specifies a Cloudflare List of required FIDO2 authenticator device AAGUIDs." + }, + { + "name": "session_duration", + "type": "String", + "description": "Defines the duration of an MFA session. Must be in minutes (m) or hours (h). Minimum: 0m. Maximum: 720h (30 days). Examples:`5m` or `24h`." + } + ] + }, + { + "name": "mfa_configuration_allowed", + "type": "Boolean", + "description": "Indicates if this organization can enforce multi-factor authentication (MFA) requirements at the application and policy level." + }, + { + "name": "mfa_required_for_all_apps", + "type": "Boolean", + "description": "Determines whether global MFA settings apply to applications by default. The organization must have MFA enabled with at least one authentication method and a session duration configured. Note: 'allowed_authenticators' cannot contain only the infrastructure SSH authenticators ('piv_key' and 'ssh_fido2_key') if the organization has any non-infrastructure applications." + }, + { + "name": "mfa_ssh_piv_key_requirements", + "type": "Attributes", + "description": "Configures SSH PIV key requirements for MFA using hardware security keys.", + "children": [ + { + "name": "pin_policy", + "type": "String", + "description": "Defines when a PIN is required to use the SSH key. Valid values: `never` (no PIN required), `once` (PIN required once per session), `always` (PIN required for each use).\nAvailable values: \"never\", \"once\", \"always\"." + }, + { + "name": "require_fips_device", + "type": "Boolean", + "description": "Requires the SSH PIV key to be stored on a FIPS 140-2 Level 1 or higher validated device." + }, + { + "name": "ssh_key_size", + "type": "List of Number", + "description": "Specifies the allowed SSH key sizes in bits. Valid sizes depend on key type. Ed25519 has a fixed key size and does not accept this parameter." + }, + { + "name": "ssh_key_type", + "type": "List of String", + "description": "Specifies the allowed SSH key types. Valid values are `ecdsa`, `ed25519`, and `rsa`." + }, + { + "name": "touch_policy", + "type": "String", + "description": "Defines when physical touch is required to use the SSH key. Valid values: `never` (no touch required), `always` (touch required for each use), `cached` (touch cached for 15 seconds).\nAvailable values: \"never\", \"always\", \"cached\"." + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The name of your Zero Trust organization." + }, + { + "name": "service_token_inactivity", + "type": "Attributes", + "description": "Configures automatic enforcement for inactive service tokens. A service token is inactive if no policy references it, and it has not successfully authenticated with an Access application during the selected inactivity period. This setting applies to every service token in your Zero Trust account.", + "children": [ + { + "name": "action", + "type": "String", + "description": "The action applied to an inactive service token.\nAvailable values: \"disable\", \"delete\"." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether automatic enforcement for inactive service tokens is enabled." + }, + { + "name": "inactivity_threshold_days", + "type": "Number", + "description": "The number of days a service token must be inactive before the configured action is applied." + } + ] + }, + { + "name": "session_duration", + "type": "String", + "description": "The amount of time that tokens issued for applications will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h." + }, + { + "name": "strict_service_token_auth", + "type": "Boolean", + "description": "Enables new behaviors for requests made with Access service tokens. Unauthorized requests emit audit logs, and return a 401 or 403 status code in the response instead of redirecting to the login page. Successful requests no longer receive a CF_Authorization cookie in the response. Zero Trust organizations created on or after October 5, 2026 will have this setting enabled by default, and cannot disable it." + }, + { + "name": "ui_read_only_toggle_reason", + "type": "String", + "description": "A description of the reason why the UI read only field is being toggled." + }, + { + "name": "user_seat_expiration_inactive_time", + "type": "String", + "description": "The amount of time a user seat is inactive before it expires. When the user seat exceeds the set time of inactivity, the user is removed as an active seat and no longer counts against your Teams seat count. Minimum value for this setting is 1 month (730h). Must be in the format `300ms` or `2h45m`. Valid time units are: `ns`, `us` (or `µs`), `ms`, `s`, `m`, `h`." + }, + { + "name": "warp_auth_non_browser_401", + "type": "Boolean", + "description": "When enabled, unsuccessful WARP authentication requests with a non-HTML Accept header return a 401 response instead of redirecting to the login page." + }, + { + "name": "warp_auth_session_duration", + "type": "String", + "description": "The amount of time that tokens issued for applications will be valid. Must be in the format `30m` or `2h45m`. Valid time units are: m, h." + }, + { + "name": "zone_id", + "type": "String", + "description": "The Zone ID to use for this endpoint. Mutually exclusive with the Account ID." + } + ], + "computed": [ + { + "name": "trusted_accounts", + "type": "List of String", + "description": "The account tags of organizations trusted by this organization for policy and device posture sharing." + } + ] + }, + "data-source:cloudflare_zero_trust_resource_library_application": { + "kind": "data-source", + "name": "cloudflare_zero_trust_resource_library_application", + "example": "data \"cloudflare_zero_trust_resource_library_application\" \"example_zero_trust_resource_library_application\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = 498\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "fields", + "type": "String", + "description": "Return only the listed properties on each application, as a comma-separated list.\nUse this to keep responses small when you only need part of each application — for\nexample populating a picker with `fields=id,name` instead of downloading every\nhostname and IP subnet.\n\nOmit this parameter to receive the full application object.\n\n`id` is always returned.\n\nSelectable properties: `id`, `name`, `human_id`, `version`, `hostnames`,\n`support_domains`, `ip_subnets`, `port_protocols`, `supported`, `gen_ai_score`,\n`application_confidence_score`, `created_at`, `updated_at`, `review_status`.\n\nUnknown or empty property names return `400`." + }, + { + "name": "filter", + "type": "String", + "description": "Filter applications using key:value format. Supported filter keys:\n- name: Filter by application name (e.g., name:HR)\n- id: Filter by application ID (e.g., id:498)\n- human_id: Filter by human-readable ID (e.g., human_id:HR)\n- hostname: Filter by hostname or support domain (e.g., hostname:portal.example.com)\n- source: Filter by application source name (e.g., source:cloudflare)\n- ip_subnet: Filter by IP subnet using CIDR containment — returns applications where any stored subnet contains the search value (e.g., ip_subnet:10.0.1.5/32 matches apps with 10.0.0.0/16)\n- category_id: Filter by category ID (e.g., category_id:12).\n- category_name: Filter by category name (e.g., category_name:HR).\n- supported: Filter by supported Cloudflare product (e.g., supported:ACCESS). Values: GATEWAY, ACCESS, CASB.\n- review_status: Filter by the account's Gateway review status. Values: approved, unapproved, in_review, unreviewed.\n." + }, + { + "name": "limit", + "type": "Number", + "description": "Limit of number of results to return (max 250)." + }, + { + "name": "offset", + "type": "Number", + "description": "Offset of results to return." + }, + { + "name": "order_by", + "type": "String", + "description": "Order results using field:direction format. Supported fields are name, id, human_id,\ncategory_id, application_type, application_confidence_score, and gen_ai_score.\nSupported directions are asc and desc. Ignored when search is provided; results are\nranked by relevance instead." + }, + { + "name": "search", + "type": "String", + "description": "Fuzzy search across application name and hostnames. Results are ranked by relevance. Must be between 2 and 200 characters. Can be combined with filter parameters." + } + ] + }, + { + "name": "id", + "type": "Number", + "description": "Returns the application ID." + } + ], + "computed": [ + { + "name": "application_confidence_score", + "type": "Number", + "description": "Confidence score for the application. Returns -1 when no score is available." + }, + { + "name": "application_score_composition", + "type": "String", + "description": "Returns the score composition breakdown for the application." + }, + { + "name": "application_source", + "type": "String", + "description": "Returns the application source." + }, + { + "name": "application_type", + "type": "String", + "description": "Returns the application type." + }, + { + "name": "application_type_description", + "type": "String", + "description": "Returns the application type description." + }, + { + "name": "category_id", + "type": "Number", + "description": "Returns the category ID." + }, + { + "name": "created_at", + "type": "String", + "description": "Returns the application creation time." + }, + { + "name": "gen_ai_score", + "type": "Number", + "description": "GenAI score for the application. Returns -1 when no score is available." + }, + { + "name": "hostnames", + "type": "Set of String", + "description": "Hostnames matched by the application." + }, + { + "name": "human_id", + "type": "String", + "description": "Returns the human readable ID." + }, + { + "name": "ip_subnets", + "type": "Set of String", + "description": "IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128." + }, + { + "name": "name", + "type": "String", + "description": "Returns the application name." + }, + { + "name": "port_protocols", + "type": "Set of String", + "description": "Port and protocol pairs matched by the application." + }, + { + "name": "support_domains", + "type": "Set of String", + "description": "Support domains matched by the application." + }, + { + "name": "supported", + "type": "Set of String", + "description": "Cloudflare products that support this application." + }, + { + "name": "updated_at", + "type": "String", + "description": "Returns the application update time." + }, + { + "name": "version", + "type": "String", + "description": "Returns the application version." + } + ] + }, + "resource:cloudflare_zero_trust_resource_library_application": { + "kind": "resource", + "name": "cloudflare_zero_trust_resource_library_application", + "example": "resource \"cloudflare_zero_trust_resource_library_application\" \"example_zero_trust_resource_library_application\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n hostnames = [\"example.com\", \"foo.com\"]\n category_id = 12\n human_id = \"HR\"\n ip_subnets = [\"192.168.1.0/24\", \"2001:db8::/48\"]\n name = \"HR\"\n port_protocols = [\"tcp/80\", \"tcp/443\"]\n support_domains = [\"example.com\", \"foo.com\"]\n}", + "importExample": "$ terraform import cloudflare_zero_trust_resource_library_application.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "category_id", + "type": "Number", + "description": "Returns the category ID." + }, + { + "name": "hostnames", + "type": "Set of String", + "description": "Hostnames matched by the application." + }, + { + "name": "human_id", + "type": "String", + "description": "Returns the human readable ID." + }, + { + "name": "ip_subnets", + "type": "Set of String", + "description": "IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128." + }, + { + "name": "name", + "type": "String", + "description": "Returns the application name." + }, + { + "name": "port_protocols", + "type": "Set of String", + "description": "Port and protocol pairs matched by the application." + }, + { + "name": "support_domains", + "type": "Set of String", + "description": "Support domains matched by the application." + } + ], + "computed": [ + { + "name": "application_confidence_score", + "type": "Number", + "description": "Confidence score for the application. Returns -1 when no score is available." + }, + { + "name": "application_score_composition", + "type": "String", + "description": "Returns the score composition breakdown for the application." + }, + { + "name": "application_source", + "type": "String", + "description": "Returns the application source." + }, + { + "name": "application_type", + "type": "String", + "description": "Returns the application type." + }, + { + "name": "application_type_description", + "type": "String", + "description": "Returns the application type description." + }, + { + "name": "created_at", + "type": "String", + "description": "Returns the application creation time." + }, + { + "name": "gen_ai_score", + "type": "Number", + "description": "GenAI score for the application. Returns -1 when no score is available." + }, + { + "name": "id", + "type": "Number", + "description": "Returns the application ID." + }, + { + "name": "supported", + "type": "Set of String", + "description": "Cloudflare products that support this application." + }, + { + "name": "updated_at", + "type": "String", + "description": "Returns the application update time." + }, + { + "name": "version", + "type": "String", + "description": "Returns the application version." + } + ] + }, + "list-data-source:cloudflare_zero_trust_resource_library_applications": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_resource_library_applications", + "example": "data \"cloudflare_zero_trust_resource_library_applications\" \"example_zero_trust_resource_library_applications\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n fields = \"fields\"\n filter = \"filter\"\n order_by = \"order_by\"\n search = \"xx\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "fields", + "type": "String", + "description": "Return only the listed properties on each application, as a comma-separated list.\nUse this to keep responses small when you only need part of each application — for\nexample populating a picker with `fields=id,name` instead of downloading every\nhostname and IP subnet.\n\nOmit this parameter to receive the full application object.\n\n`id` is always returned.\n\nSelectable properties: `id`, `name`, `human_id`, `version`, `hostnames`,\n`support_domains`, `ip_subnets`, `port_protocols`, `supported`, `gen_ai_score`,\n`application_confidence_score`, `created_at`, `updated_at`, `review_status`.\n\nUnknown or empty property names return `400`." + }, + { + "name": "filter", + "type": "String", + "description": "Filter applications using key:value format. Supported filter keys:\n- name: Filter by application name (e.g., name:HR)\n- id: Filter by application ID (e.g., id:498)\n- human_id: Filter by human-readable ID (e.g., human_id:HR)\n- hostname: Filter by hostname or support domain (e.g., hostname:portal.example.com)\n- source: Filter by application source name (e.g., source:cloudflare)\n- ip_subnet: Filter by IP subnet using CIDR containment — returns applications where any stored subnet contains the search value (e.g., ip_subnet:10.0.1.5/32 matches apps with 10.0.0.0/16)\n- category_id: Filter by category ID (e.g., category_id:12).\n- category_name: Filter by category name (e.g., category_name:HR).\n- supported: Filter by supported Cloudflare product (e.g., supported:ACCESS). Values: GATEWAY, ACCESS, CASB.\n- review_status: Filter by the account's Gateway review status. Values: approved, unapproved, in_review, unreviewed.\n." + }, + { + "name": "limit", + "type": "Number", + "description": "Limit of number of results to return (max 250)." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "offset", + "type": "Number", + "description": "Offset of results to return." + }, + { + "name": "order_by", + "type": "String", + "description": "Order results using field:direction format. Supported fields are name, id, human_id,\ncategory_id, application_type, application_confidence_score, and gen_ai_score.\nSupported directions are asc and desc. Ignored when search is provided; results are\nranked by relevance instead." + }, + { + "name": "search", + "type": "String", + "description": "Fuzzy search across application name and hostnames. Results are ranked by relevance. Must be between 2 and 200 characters. Can be combined with filter parameters." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "application_confidence_score", + "type": "Number", + "description": "Confidence score for the application. Returns -1 when no score is available." + }, + { + "name": "application_score_composition", + "type": "String", + "description": "Returns the score composition breakdown for the application." + }, + { + "name": "application_source", + "type": "String", + "description": "Returns the application source." + }, + { + "name": "application_type", + "type": "String", + "description": "Returns the application type." + }, + { + "name": "application_type_description", + "type": "String", + "description": "Returns the application type description." + }, + { + "name": "category_id", + "type": "Number", + "description": "Returns the category ID." + }, + { + "name": "created_at", + "type": "String", + "description": "Returns the application creation time." + }, + { + "name": "gen_ai_score", + "type": "Number", + "description": "GenAI score for the application. Returns -1 when no score is available." + }, + { + "name": "hostnames", + "type": "Set of String", + "description": "Hostnames matched by the application." + }, + { + "name": "human_id", + "type": "String", + "description": "Returns the human readable ID." + }, + { + "name": "id", + "type": "Number", + "description": "Returns the application ID." + }, + { + "name": "ip_subnets", + "type": "Set of String", + "description": "IP subnets for this application. Custom application create and update requests accept IPv4 prefix lengths /8 through /32 and IPv6 prefix lengths /32 through /128." + }, + { + "name": "name", + "type": "String", + "description": "Returns the application name." + }, + { + "name": "port_protocols", + "type": "Set of String", + "description": "Port and protocol pairs matched by the application." + }, + { + "name": "review_status", + "type": "String", + "description": "The account-specific Gateway review status. Applications with no assigned review status are returned as `unreviewed`.\nAvailable values: \"approved\", \"unapproved\", \"in_review\", \"unreviewed\"." + }, + { + "name": "support_domains", + "type": "Set of String", + "description": "Support domains matched by the application." + }, + { + "name": "supported", + "type": "Set of String", + "description": "Cloudflare products that support this application." + }, + { + "name": "updated_at", + "type": "String", + "description": "Returns the application update time." + }, + { + "name": "version", + "type": "String", + "description": "Returns the application version." + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_resource_library_categories": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_resource_library_categories", + "example": "data \"cloudflare_zero_trust_resource_library_categories\" \"example_zero_trust_resource_library_categories\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "account_id", + "type": "String" + } + ], + "optional": [ + { + "name": "limit", + "type": "Number", + "description": "Limit of number of results to return." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "offset", + "type": "Number", + "description": "Offset of results to return." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "created_at", + "type": "String", + "description": "Returns the category creation time." + }, + { + "name": "description", + "type": "String", + "description": "Returns the category description." + }, + { + "name": "id", + "type": "Number", + "description": "Returns the category ID." + }, + { + "name": "name", + "type": "String", + "description": "Returns the category name." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_resource_library_category": { + "kind": "data-source", + "name": "cloudflare_zero_trust_resource_library_category", + "example": "data \"cloudflare_zero_trust_resource_library_category\" \"example_zero_trust_resource_library_category\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n id = 12\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "id", + "type": "Number", + "description": "Returns the category ID." + } + ], + "optional": [], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Returns the category creation time." + }, + { + "name": "description", + "type": "String", + "description": "Returns the category description." + }, + { + "name": "name", + "type": "String", + "description": "Returns the category name." + } + ] + }, + "data-source:cloudflare_zero_trust_risk_behavior": { + "kind": "data-source", + "name": "cloudflare_zero_trust_risk_behavior", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_risk_behavior\" \"example_zero_trust_risk_behavior\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "behaviors", + "type": "Attributes Map", + "children": [ + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "name", + "type": "String" + }, + { + "name": "risk_level", + "type": "String", + "description": "Available values: \"low\", \"medium\", \"high\"." + } + ] + } + ] + }, + "resource:cloudflare_zero_trust_risk_behavior": { + "kind": "resource", + "name": "cloudflare_zero_trust_risk_behavior", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_risk_behavior\" \"example_zero_trust_risk_behavior\" {\n account_id = \"account_id\"\n behaviors = {\n foo = {\n enabled = true\n risk_level = \"low\"\n }\n }\n}", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "behaviors", + "type": "Attributes Map", + "children": [ + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "risk_level", + "type": "String", + "description": "Available values: \"low\", \"medium\", \"high\"." + } + ] + } + ], + "optional": [], + "computed": [] + }, + "data-source:cloudflare_zero_trust_risk_scoring_integration": { + "kind": "data-source", + "name": "cloudflare_zero_trust_risk_scoring_integration", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_risk_scoring_integration\" \"example_zero_trust_risk_scoring_integration\" {\n account_id = \"account_id\"\n integration_id = \"182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e\"\n}", + "required": [ + { + "name": "integration_id", + "type": "String" + } + ], + "optional": [ + { + "name": "account_id", + "type": "String" + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "The Cloudflare account tag." + }, + { + "name": "active", + "type": "Boolean", + "description": "Whether this integration is enabled and should export changes in risk score." + }, + { + "name": "created_at", + "type": "String", + "description": "When the integration was created in RFC3339 format." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "integration_type", + "type": "String", + "description": "Available values: \"Okta\"." + }, + { + "name": "reference_id", + "type": "String", + "description": "A reference ID defined by the client.\nShould be set to the Access-Okta IDP integration ID.\nUseful when the risk-score integration needs to be associated with a secondary asset and recalled using that ID." + }, + { + "name": "tenant_url", + "type": "String", + "description": "The base URL for the tenant. E.g. \"https://tenant.okta.com\"." + }, + { + "name": "well_known_url", + "type": "String", + "description": "The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1." + } + ] + }, + "resource:cloudflare_zero_trust_risk_scoring_integration": { + "kind": "resource", + "name": "cloudflare_zero_trust_risk_scoring_integration", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "resource \"cloudflare_zero_trust_risk_scoring_integration\" \"example_zero_trust_risk_scoring_integration\" {\n account_id = \"account_id\"\n integration_type = \"Okta\"\n tenant_url = \"https://example.com\"\n reference_id = \"reference_id\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_risk_scoring_integration.example '/'", + "required": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "integration_type", + "type": "String", + "description": "Available values: \"Okta\"." + }, + { + "name": "tenant_url", + "type": "String", + "description": "The base url of the tenant, e.g. \"https://tenant.okta.com\"." + } + ], + "optional": [ + { + "name": "active", + "type": "Boolean", + "description": "Whether this integration is enabled. If disabled, no risk changes will be exported to the third-party." + }, + { + "name": "reference_id", + "type": "String", + "description": "A reference id that can be supplied by the client. Currently this should be set to the Access-Okta IDP ID (a UUIDv4).\nhttps://developers.cloudflare.com/api/operations/access-identity-providers-get-an-access-identity-provider" + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "The Cloudflare account tag." + }, + { + "name": "created_at", + "type": "String", + "description": "When the integration was created in RFC3339 format." + }, + { + "name": "id", + "type": "String", + "description": "The id of the integration, a UUIDv4." + }, + { + "name": "well_known_url", + "type": "String", + "description": "The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1." + } + ] + }, + "list-data-source:cloudflare_zero_trust_risk_scoring_integrations": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_risk_scoring_integrations", + "description": "Accepted Permissions\n\n- `Zero Trust Read`\n- `Zero Trust Write`", + "example": "data \"cloudflare_zero_trust_risk_scoring_integrations\" \"example_zero_trust_risk_scoring_integrations\" {\n account_id = \"account_id\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String" + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_tag", + "type": "String", + "description": "The Cloudflare account tag." + }, + { + "name": "active", + "type": "Boolean", + "description": "Whether this integration is enabled and should export changes in risk score." + }, + { + "name": "created_at", + "type": "String", + "description": "When the integration was created in RFC3339 format." + }, + { + "name": "id", + "type": "String", + "description": "The id of the integration, a UUIDv4." + }, + { + "name": "integration_type", + "type": "String", + "description": "Available values: \"Okta\"." + }, + { + "name": "reference_id", + "type": "String", + "description": "A reference ID defined by the client.\nShould be set to the Access-Okta IDP integration ID.\nUseful when the risk-score integration needs to be associated with a secondary asset and recalled using that ID." + }, + { + "name": "tenant_url", + "type": "String", + "description": "The base URL for the tenant. E.g. \"https://tenant.okta.com\"." + }, + { + "name": "well_known_url", + "type": "String", + "description": "The URL for the Shared Signals Framework configuration, e.g. \"/.well-known/sse-configuration/{integration_uuid}/\". https://openid.net/specs/openid-sse-framework-1_0.html#rfc.section.6.2.1." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_cloudflared": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflared", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: cloudflared Read`\n- `Cloudflare One Connector: cloudflared Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflared\" \"example_zero_trust_tunnel_cloudflared\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "exclude_prefix", + "type": "String" + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "include_prefix", + "type": "String" + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "was_active_at", + "type": "String" + }, + { + "name": "was_inactive_at", + "type": "String" + } + ] + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "config_src", + "type": "String", + "description": "Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard.\nAvailable values: \"local\", \"cloudflare\"." + }, + { + "name": "connections", + "type": "Attributes List", + "description": "The Cloudflare Tunnel connections between your origin and Cloudflare's edge.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "client_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connector." + }, + { + "name": "client_version", + "type": "String", + "description": "The cloudflared version used to establish this connection." + }, + { + "name": "colo_name", + "type": "String", + "description": "The Cloudflare data center used for this connection." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + }, + { + "name": "is_pending_reconnect", + "type": "Boolean", + "description": "Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.", + "deprecated": "Deprecated." + }, + { + "name": "opened_at", + "type": "String", + "description": "Timestamp of when the connection was established." + }, + { + "name": "origin_ip", + "type": "String", + "description": "The public IP address of the host running cloudflared." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + } + ] + }, + { + "name": "conns_active_at", + "type": "String", + "description": "Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive." + }, + { + "name": "conns_inactive_at", + "type": "String", + "description": "Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "metadata", + "type": "String", + "description": "Metadata associated with the tunnel." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + }, + { + "name": "remote_config", + "type": "Boolean", + "description": "If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.", + "deprecated": "Deprecated." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + } + ] + }, + "resource:cloudflare_zero_trust_tunnel_cloudflared": { + "kind": "resource", + "name": "cloudflare_zero_trust_tunnel_cloudflared", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: cloudflared Read`\n- `Cloudflare One Connector: cloudflared Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "resource \"cloudflare_zero_trust_tunnel_cloudflared\" \"example_zero_trust_tunnel_cloudflared\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"blog\"\n config_src = \"cloudflare\"\n tunnel_secret = \"AQIDBAUGBwgBAgMEBQYHCAECAwQFBgcIAQIDBAUGBwg=\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_tunnel_cloudflared.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + } + ], + "optional": [ + { + "name": "config_src", + "type": "String", + "description": "Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard.\nAvailable values: \"local\", \"cloudflare\"." + }, + { + "name": "tunnel_secret", + "type": "String", + "description": "Sets the password required to run a locally-managed tunnel. Must be at least 32 bytes and encoded as a base64 string.", + "sensitive": true + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "connections", + "type": "Attributes List", + "description": "The Cloudflare Tunnel connections between your origin and Cloudflare's edge.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "client_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connector." + }, + { + "name": "client_version", + "type": "String", + "description": "The cloudflared version used to establish this connection." + }, + { + "name": "colo_name", + "type": "String", + "description": "The Cloudflare data center used for this connection." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + }, + { + "name": "opened_at", + "type": "String", + "description": "Timestamp of when the connection was established." + }, + { + "name": "origin_ip", + "type": "String", + "description": "The public IP address of the host running cloudflared." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + } + ] + }, + { + "name": "conns_active_at", + "type": "String", + "description": "Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive." + }, + { + "name": "conns_inactive_at", + "type": "String", + "description": "Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "metadata", + "type": "String", + "description": "Metadata associated with the tunnel." + }, + { + "name": "remote_config", + "type": "Boolean", + "description": "If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.", + "deprecated": "Deprecated." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_cloudflared_config": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflared_config", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: cloudflared Read`\n- `Cloudflare One Connector: cloudflared Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflared_config\" \"example_zero_trust_tunnel_cloudflared_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "optional": [], + "computed": [ + { + "name": "config", + "type": "Attributes", + "description": "The tunnel configuration and ingress rules.", + "children": [ + { + "name": "ingress", + "type": "Attributes List", + "description": "List of public hostname definitions. At least one ingress rule needs to be defined for the tunnel.", + "children": [ + { + "name": "hostname", + "type": "String", + "description": "Public hostname for this service." + }, + { + "name": "origin_request", + "type": "Attributes", + "description": "Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.", + "children": [ + { + "name": "access", + "type": "Attributes", + "description": "For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.", + "children": [ + { + "name": "aud_tag", + "type": "List of String", + "description": "Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API." + }, + { + "name": "required", + "type": "Boolean", + "description": "Deny traffic that has not fulfilled Access authorization." + }, + { + "name": "team_name", + "type": "String" + } + ] + }, + { + "name": "ca_pool", + "type": "String", + "description": "Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare." + }, + { + "name": "connect_timeout", + "type": "Number", + "description": "Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout." + }, + { + "name": "disable_chunked_encoding", + "type": "Boolean", + "description": "Disables chunked transfer encoding. Useful if you are running a WSGI server." + }, + { + "name": "http_host_header", + "type": "String", + "description": "Sets the HTTP Host header on requests sent to the local service." + }, + { + "name": "http2_origin", + "type": "Boolean", + "description": "Attempt to connect to origin using HTTP2. Origin must be configured as https." + }, + { + "name": "keep_alive_connections", + "type": "Number", + "description": "Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections." + }, + { + "name": "keep_alive_timeout", + "type": "Number", + "description": "Timeout after which an idle keepalive connection can be discarded." + }, + { + "name": "match_sn_ito_host", + "type": "Boolean", + "description": "Auto configure the Hostname on the origin server certificate." + }, + { + "name": "no_happy_eyeballs", + "type": "Boolean", + "description": "Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols." + }, + { + "name": "no_tls_verify", + "type": "Boolean", + "description": "Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted." + }, + { + "name": "origin_server_name", + "type": "String", + "description": "Hostname that cloudflared should expect from your origin server certificate." + }, + { + "name": "proxy_type", + "type": "String", + "description": "cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy." + }, + { + "name": "tcp_keep_alive", + "type": "Number", + "description": "The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server." + }, + { + "name": "tls_timeout", + "type": "Number", + "description": "Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server." + } + ] + }, + { + "name": "path", + "type": "String", + "description": "Requests with this path route to this public hostname." + }, + { + "name": "service", + "type": "String", + "description": "Protocol and address of destination server. Supported protocols: http://, https://, unix://, tcp://, ssh://, rdp://, unix+tls://, smb://. Alternatively can return a HTTP status code http_status:[code] e.g. 'http_status:404'." + } + ] + }, + { + "name": "origin_request", + "type": "Attributes", + "description": "Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.", + "children": [ + { + "name": "access", + "type": "Attributes", + "description": "For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.", + "children": [ + { + "name": "aud_tag", + "type": "List of String", + "description": "Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API." + }, + { + "name": "required", + "type": "Boolean", + "description": "Deny traffic that has not fulfilled Access authorization." + }, + { + "name": "team_name", + "type": "String" + } + ] + }, + { + "name": "ca_pool", + "type": "String", + "description": "Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare." + }, + { + "name": "connect_timeout", + "type": "Number", + "description": "Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout." + }, + { + "name": "disable_chunked_encoding", + "type": "Boolean", + "description": "Disables chunked transfer encoding. Useful if you are running a WSGI server." + }, + { + "name": "http_host_header", + "type": "String", + "description": "Sets the HTTP Host header on requests sent to the local service." + }, + { + "name": "http2_origin", + "type": "Boolean", + "description": "Attempt to connect to origin using HTTP2. Origin must be configured as https." + }, + { + "name": "keep_alive_connections", + "type": "Number", + "description": "Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections." + }, + { + "name": "keep_alive_timeout", + "type": "Number", + "description": "Timeout after which an idle keepalive connection can be discarded." + }, + { + "name": "match_sn_ito_host", + "type": "Boolean", + "description": "Auto configure the Hostname on the origin server certificate." + }, + { + "name": "no_happy_eyeballs", + "type": "Boolean", + "description": "Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols." + }, + { + "name": "no_tls_verify", + "type": "Boolean", + "description": "Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted." + }, + { + "name": "origin_server_name", + "type": "String", + "description": "Hostname that cloudflared should expect from your origin server certificate." + }, + { + "name": "proxy_type", + "type": "String", + "description": "cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy." + }, + { + "name": "tcp_keep_alive", + "type": "Number", + "description": "The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server." + }, + { + "name": "tls_timeout", + "type": "Number", + "description": "Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server." + } + ] + } + ] + }, + { + "name": "created_at", + "type": "String" + }, + { + "name": "source", + "type": "String", + "description": "Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel's configuration on the Zero Trust dashboard.\nAvailable values: \"local\", \"cloudflare\"." + }, + { + "name": "version", + "type": "Number", + "description": "The version of the Tunnel Configuration." + } + ] + }, + "resource:cloudflare_zero_trust_tunnel_cloudflared_config": { + "kind": "resource", + "name": "cloudflare_zero_trust_tunnel_cloudflared_config", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: cloudflared Read`\n- `Cloudflare One Connector: cloudflared Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "resource \"cloudflare_zero_trust_tunnel_cloudflared_config\" \"example_zero_trust_tunnel_cloudflared_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n config = {\n ingress = [{\n hostname = \"tunnel.example.com\"\n service = \"https://localhost:8001\"\n origin_request = {\n access = {\n aud_tag = [\"string\"]\n team_name = \"zero-trust-organization-name\"\n required = false\n }\n ca_pool = \"caPool\"\n connect_timeout = 10\n disable_chunked_encoding = true\n http2_origin = true\n http_host_header = \"httpHostHeader\"\n keep_alive_connections = 100\n keep_alive_timeout = 90\n match_sn_ito_host = false\n no_happy_eyeballs = false\n no_tls_verify = false\n origin_server_name = \"originServerName\"\n proxy_type = \"proxyType\"\n tcp_keep_alive = 30\n tls_timeout = 10\n }\n path = \"subpath\"\n }]\n origin_request = {\n access = {\n aud_tag = [\"string\"]\n team_name = \"zero-trust-organization-name\"\n required = false\n }\n ca_pool = \"caPool\"\n connect_timeout = 10\n disable_chunked_encoding = true\n http2_origin = true\n http_host_header = \"httpHostHeader\"\n keep_alive_connections = 100\n keep_alive_timeout = 90\n match_sn_ito_host = false\n no_happy_eyeballs = false\n no_tls_verify = false\n origin_server_name = \"originServerName\"\n proxy_type = \"proxyType\"\n tcp_keep_alive = 30\n tls_timeout = 10\n }\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_tunnel_cloudflared_config.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "optional": [ + { + "name": "config", + "type": "Attributes", + "description": "The tunnel configuration and ingress rules.", + "children": [ + { + "name": "ingress", + "type": "Attributes List", + "description": "List of public hostname definitions. At least one ingress rule needs to be defined for the tunnel.", + "children": [ + { + "name": "hostname", + "type": "String", + "description": "Public hostname for this service." + }, + { + "name": "origin_request", + "type": "Attributes", + "description": "Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.", + "children": [ + { + "name": "access", + "type": "Attributes", + "description": "For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.", + "children": [ + { + "name": "aud_tag", + "type": "List of String", + "description": "Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API." + }, + { + "name": "required", + "type": "Boolean", + "description": "Deny traffic that has not fulfilled Access authorization." + }, + { + "name": "team_name", + "type": "String" + } + ] + }, + { + "name": "ca_pool", + "type": "String", + "description": "Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare." + }, + { + "name": "connect_timeout", + "type": "Number", + "description": "Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout." + }, + { + "name": "disable_chunked_encoding", + "type": "Boolean", + "description": "Disables chunked transfer encoding. Useful if you are running a WSGI server." + }, + { + "name": "http_host_header", + "type": "String", + "description": "Sets the HTTP Host header on requests sent to the local service." + }, + { + "name": "http2_origin", + "type": "Boolean", + "description": "Attempt to connect to origin using HTTP2. Origin must be configured as https." + }, + { + "name": "keep_alive_connections", + "type": "Number", + "description": "Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections." + }, + { + "name": "keep_alive_timeout", + "type": "Number", + "description": "Timeout after which an idle keepalive connection can be discarded." + }, + { + "name": "match_sn_ito_host", + "type": "Boolean", + "description": "Auto configure the Hostname on the origin server certificate." + }, + { + "name": "no_happy_eyeballs", + "type": "Boolean", + "description": "Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols." + }, + { + "name": "no_tls_verify", + "type": "Boolean", + "description": "Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted." + }, + { + "name": "origin_server_name", + "type": "String", + "description": "Hostname that cloudflared should expect from your origin server certificate." + }, + { + "name": "proxy_type", + "type": "String", + "description": "cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy." + }, + { + "name": "tcp_keep_alive", + "type": "Number", + "description": "The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server." + }, + { + "name": "tls_timeout", + "type": "Number", + "description": "Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server." + } + ] + }, + { + "name": "path", + "type": "String", + "description": "Requests with this path route to this public hostname." + }, + { + "name": "service", + "type": "String", + "description": "Protocol and address of destination server. Supported protocols: http://, https://, unix://, tcp://, ssh://, rdp://, unix+tls://, smb://. Alternatively can return a HTTP status code http_status:[code] e.g. 'http_status:404'." + } + ] + }, + { + "name": "origin_request", + "type": "Attributes", + "description": "Configuration parameters for the public hostname specific connection settings between cloudflared and origin server.", + "children": [ + { + "name": "access", + "type": "Attributes", + "description": "For all L7 requests to this hostname, cloudflared will validate each request's Cf-Access-Jwt-Assertion request header.", + "children": [ + { + "name": "aud_tag", + "type": "List of String", + "description": "Access applications that are allowed to reach this hostname for this Tunnel. Audience tags can be identified in the dashboard or via the List Access policies API." + }, + { + "name": "required", + "type": "Boolean", + "description": "Deny traffic that has not fulfilled Access authorization." + }, + { + "name": "team_name", + "type": "String" + } + ] + }, + { + "name": "ca_pool", + "type": "String", + "description": "Path to the certificate authority (CA) for the certificate of your origin. This option should be used only if your certificate is not signed by Cloudflare." + }, + { + "name": "connect_timeout", + "type": "Number", + "description": "Timeout for establishing a new TCP connection to your origin server. This excludes the time taken to establish TLS, which is controlled by tlsTimeout." + }, + { + "name": "disable_chunked_encoding", + "type": "Boolean", + "description": "Disables chunked transfer encoding. Useful if you are running a WSGI server." + }, + { + "name": "http_host_header", + "type": "String", + "description": "Sets the HTTP Host header on requests sent to the local service." + }, + { + "name": "http2_origin", + "type": "Boolean", + "description": "Attempt to connect to origin using HTTP2. Origin must be configured as https." + }, + { + "name": "keep_alive_connections", + "type": "Number", + "description": "Maximum number of idle keepalive connections between Tunnel and your origin. This does not restrict the total number of concurrent connections." + }, + { + "name": "keep_alive_timeout", + "type": "Number", + "description": "Timeout after which an idle keepalive connection can be discarded." + }, + { + "name": "match_sn_ito_host", + "type": "Boolean", + "description": "Auto configure the Hostname on the origin server certificate." + }, + { + "name": "no_happy_eyeballs", + "type": "Boolean", + "description": "Disable the “happy eyeballs” algorithm for IPv4/IPv6 fallback if your local network has misconfigured one of the protocols." + }, + { + "name": "no_tls_verify", + "type": "Boolean", + "description": "Disables TLS verification of the certificate presented by your origin. Will allow any certificate from the origin to be accepted." + }, + { + "name": "origin_server_name", + "type": "String", + "description": "Hostname that cloudflared should expect from your origin server certificate." + }, + { + "name": "proxy_type", + "type": "String", + "description": "cloudflared starts a proxy server to translate HTTP traffic into TCP when proxying, for example, SSH or RDP. This configures what type of proxy will be started. Valid options are: \"\" for the regular proxy and \"socks\" for a SOCKS5 proxy." + }, + { + "name": "tcp_keep_alive", + "type": "Number", + "description": "The timeout after which a TCP keepalive packet is sent on a connection between Tunnel and the origin server." + }, + { + "name": "tls_timeout", + "type": "Number", + "description": "Timeout for completing a TLS handshake to your origin server, if you have chosen to connect Tunnel to an HTTPS server." + } + ] + } + ] + }, + { + "name": "source", + "type": "String", + "description": "Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel's configuration on the Zero Trust dashboard.\nAvailable values: \"local\", \"cloudflare\"." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "version", + "type": "Number", + "description": "The version of the Tunnel Configuration." + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_cloudflared_route": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflared_route", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflared_route\" \"example_zero_trust_tunnel_cloudflared_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the route." + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted routes. If `false`, exclude deleted routes. If empty, all routes will be included." + }, + { + "name": "network_subset", + "type": "String", + "description": "If set, only list routes that are contained within this IP range." + }, + { + "name": "network_superset", + "type": "String", + "description": "If set, only list routes that contain this IP range." + }, + { + "name": "tun_types", + "type": "List of String", + "description": "The types of tunnels to filter by, separated by commas." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "UUID of the virtual network." + } + ] + }, + { + "name": "route_id", + "type": "String", + "description": "UUID of the route." + } + ], + "computed": [ + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the route." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the route." + }, + { + "name": "network", + "type": "String", + "description": "The private IPv4 or IPv6 range connected by the route, in CIDR notation." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "UUID of the virtual network." + } + ] + }, + "resource:cloudflare_zero_trust_tunnel_cloudflared_route": { + "kind": "resource", + "name": "cloudflare_zero_trust_tunnel_cloudflared_route", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Write`", + "example": "resource \"cloudflare_zero_trust_tunnel_cloudflared_route\" \"example_zero_trust_tunnel_cloudflared_route\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n network = \"172.16.0.0/16\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n comment = \"Example comment for this route.\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "importExample": "$ terraform import cloudflare_zero_trust_tunnel_cloudflared_route.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "network", + "type": "String", + "description": "The private IPv4 or IPv6 range connected by the route, in CIDR notation." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "optional": [ + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the route." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "UUID of the virtual network." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the route." + } + ] + }, + "list-data-source:cloudflare_zero_trust_tunnel_cloudflared_routes": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflared_routes", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflared_routes\" \"example_zero_trust_tunnel_cloudflared_routes\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n is_deleted = true\n network_subset = \"172.16.0.0/16\"\n network_superset = \"172.16.0.0/16\"\n route_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n tun_types = [\"cfd_tunnel\"]\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the route." + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted routes. If `false`, exclude deleted routes. If empty, all routes will be included." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "network_subset", + "type": "String", + "description": "If set, only list routes that are contained within this IP range." + }, + { + "name": "network_superset", + "type": "String", + "description": "If set, only list routes that contain this IP range." + }, + { + "name": "route_id", + "type": "String", + "description": "UUID of the route." + }, + { + "name": "tun_types", + "type": "List of String", + "description": "The types of tunnels to filter by, separated by commas." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "UUID of the virtual network." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the route." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the route." + }, + { + "name": "network", + "type": "String", + "description": "The private IPv4 or IPv6 range connected by the route, in CIDR notation." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "tunnel_name", + "type": "String", + "description": "A user-friendly name for a tunnel." + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "UUID of the virtual network." + }, + { + "name": "virtual_network_name", + "type": "String", + "description": "A user-friendly name for the virtual network." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_cloudflared_token": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflared_token", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: cloudflared Write`\n- `Cloudflare One Connectors Write`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflared_token\" \"example_zero_trust_tunnel_cloudflared_token\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "optional": [], + "computed": [ + { + "name": "token", + "type": "String", + "description": "The Tunnel Token is used as a mechanism to authenticate the operation of a tunnel.", + "sensitive": true + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_cloudflared_virtual_network": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflared_virtual_network\" \"example_zero_trust_tunnel_cloudflared_virtual_network\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n virtual_network_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "UUID of the virtual network." + }, + { + "name": "is_default", + "type": "Boolean", + "description": "If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included." + }, + { + "name": "is_default_network", + "type": "Boolean", + "description": "If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included." + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted virtual networks. If `false`, exclude deleted virtual networks. If empty, all virtual networks will be included." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the virtual network." + } + ] + }, + { + "name": "virtual_network_id", + "type": "String", + "description": "UUID of the virtual network." + } + ], + "computed": [ + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the virtual network." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the virtual network." + }, + { + "name": "is_default_network", + "type": "Boolean", + "description": "If `true`, this virtual network is the default for the account." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the virtual network." + } + ] + }, + "resource:cloudflare_zero_trust_tunnel_cloudflared_virtual_network": { + "kind": "resource", + "name": "cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Write`", + "example": "resource \"cloudflare_zero_trust_tunnel_cloudflared_virtual_network\" \"example_zero_trust_tunnel_cloudflared_virtual_network\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"us-east-1-vpc\"\n comment = \"Staging VPC for data science\"\n is_default = true\n is_default_network = false\n}", + "importExample": "$ terraform import cloudflare_zero_trust_tunnel_cloudflared_virtual_network.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the virtual network." + } + ], + "optional": [ + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the virtual network." + }, + { + "name": "is_default", + "type": "Boolean", + "description": "If `true`, this virtual network is the default for the account.", + "deprecated": "Deprecated." + }, + { + "name": "is_default_network", + "type": "Boolean", + "description": "If `true`, this virtual network is the default for the account." + } + ], + "computed": [ + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the virtual network." + } + ] + }, + "list-data-source:cloudflare_zero_trust_tunnel_cloudflared_virtual_networks": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflared_virtual_networks", + "description": "Accepted Permissions\n\n- `Cloudflare One Networks Read`\n- `Cloudflare One Networks Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflared_virtual_networks\" \"example_zero_trust_tunnel_cloudflared_virtual_networks\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n is_default = true\n is_default_network = true\n is_deleted = true\n name = \"us-east-1-vpc\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "id", + "type": "String", + "description": "UUID of the virtual network." + }, + { + "name": "is_default", + "type": "Boolean", + "description": "If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included." + }, + { + "name": "is_default_network", + "type": "Boolean", + "description": "If `true`, only include the default virtual network. If `false`, exclude the default virtual network. If empty, all virtual networks will be included." + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted virtual networks. If `false`, exclude deleted virtual networks. If empty, all virtual networks will be included." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the virtual network." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "comment", + "type": "String", + "description": "Optional remark describing the virtual network." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the virtual network." + }, + { + "name": "is_default_network", + "type": "Boolean", + "description": "If `true`, this virtual network is the default for the account." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the virtual network." + } + ] + } + ] + }, + "list-data-source:cloudflare_zero_trust_tunnel_cloudflareds": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_tunnel_cloudflareds", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: cloudflared Read`\n- `Cloudflare One Connector: cloudflared Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`\n- `Cloudflare Tunnel Read`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_cloudflareds\" \"example_zero_trust_tunnel_cloudflareds\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n exclude_prefix = \"vpc1-\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n include_prefix = \"vpc1-\"\n is_deleted = true\n name = \"blog\"\n status = \"healthy\"\n uuid = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n was_active_at = \"2009-11-10T23:00:00Z\"\n was_inactive_at = \"2009-11-10T23:00:00Z\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "exclude_prefix", + "type": "String" + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "include_prefix", + "type": "String" + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "was_active_at", + "type": "String" + }, + { + "name": "was_inactive_at", + "type": "String" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_tag", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "config_src", + "type": "String", + "description": "Indicates if this is a locally or remotely configured tunnel. If `local`, manage the tunnel using a YAML file on the origin machine. If `cloudflare`, manage the tunnel on the Zero Trust dashboard.\nAvailable values: \"local\", \"cloudflare\"." + }, + { + "name": "connections", + "type": "Attributes List", + "description": "The Cloudflare Tunnel connections between your origin and Cloudflare's edge.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "client_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connector." + }, + { + "name": "client_version", + "type": "String", + "description": "The cloudflared version used to establish this connection." + }, + { + "name": "colo_name", + "type": "String", + "description": "The Cloudflare data center used for this connection." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + }, + { + "name": "is_pending_reconnect", + "type": "Boolean", + "description": "Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.", + "deprecated": "Deprecated." + }, + { + "name": "opened_at", + "type": "String", + "description": "Timestamp of when the connection was established." + }, + { + "name": "origin_ip", + "type": "String", + "description": "The public IP address of the host running cloudflared." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + } + ] + }, + { + "name": "conns_active_at", + "type": "String", + "description": "Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive." + }, + { + "name": "conns_inactive_at", + "type": "String", + "description": "Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "metadata", + "type": "String", + "description": "Metadata associated with the tunnel." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + }, + { + "name": "remote_config", + "type": "Boolean", + "description": "If `true`, the tunnel can be configured remotely from the Zero Trust dashboard. If `false`, the tunnel must be configured locally on the origin machine.", + "deprecated": "Deprecated." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + } + ] + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_warp_connector": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_warp_connector", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: WARP Read`\n- `Cloudflare One Connector: WARP Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`", + "example": "data \"cloudflare_zero_trust_tunnel_warp_connector\" \"example_zero_trust_tunnel_warp_connector\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "exclude_prefix", + "type": "String" + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "include_prefix", + "type": "String" + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the tunnel." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "was_active_at", + "type": "String" + }, + { + "name": "was_inactive_at", + "type": "String" + } + ] + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "connections", + "type": "Attributes List", + "description": "The Cloudflare Tunnel connections between your origin and Cloudflare's edge.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "client_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connector." + }, + { + "name": "client_version", + "type": "String", + "description": "The cloudflared version used to establish this connection." + }, + { + "name": "colo_name", + "type": "String", + "description": "The Cloudflare data center used for this connection." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + }, + { + "name": "is_pending_reconnect", + "type": "Boolean", + "description": "Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.", + "deprecated": "Deprecated." + }, + { + "name": "opened_at", + "type": "String", + "description": "Timestamp of when the connection was established." + }, + { + "name": "origin_ip", + "type": "String", + "description": "The public IP address of the host running cloudflared." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + } + ] + }, + { + "name": "conns_active_at", + "type": "String", + "description": "Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive." + }, + { + "name": "conns_inactive_at", + "type": "String", + "description": "Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "metadata", + "type": "String", + "description": "Metadata associated with the tunnel." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + } + ] + }, + "resource:cloudflare_zero_trust_tunnel_warp_connector": { + "kind": "resource", + "name": "cloudflare_zero_trust_tunnel_warp_connector", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: WARP Read`\n- `Cloudflare One Connector: WARP Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`", + "example": "resource \"cloudflare_zero_trust_tunnel_warp_connector\" \"example_zero_trust_tunnel_warp_connector\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n name = \"blog\"\n ha = true\n}", + "importExample": "$ terraform import cloudflare_zero_trust_tunnel_warp_connector.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + } + ], + "optional": [ + { + "name": "ha", + "type": "Boolean", + "description": "Indicates that the tunnel will be created to be highly available. If omitted, defaults to false." + }, + { + "name": "tunnel_secret", + "type": "String", + "description": "Sets the password required to run a locally-managed tunnel. Must be at least 32 bytes and encoded as a base64 string.", + "sensitive": true + } + ], + "computed": [ + { + "name": "account_tag", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "connections", + "type": "Attributes List", + "description": "The Cloudflare Tunnel connections between your origin and Cloudflare's edge.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "client_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connector." + }, + { + "name": "client_version", + "type": "String", + "description": "The cloudflared version used to establish this connection." + }, + { + "name": "colo_name", + "type": "String", + "description": "The Cloudflare data center used for this connection." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + }, + { + "name": "is_pending_reconnect", + "type": "Boolean", + "description": "Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.", + "deprecated": "Deprecated." + }, + { + "name": "opened_at", + "type": "String", + "description": "Timestamp of when the connection was established." + }, + { + "name": "origin_ip", + "type": "String", + "description": "The public IP address of the host running cloudflared." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + } + ] + }, + { + "name": "conns_active_at", + "type": "String", + "description": "Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive." + }, + { + "name": "conns_inactive_at", + "type": "String", + "description": "Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "metadata", + "type": "String", + "description": "Metadata associated with the tunnel." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_warp_connector_config": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_warp_connector_config", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: WARP Read`\n- `Cloudflare One Connector: WARP Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`", + "example": "data \"cloudflare_zero_trust_tunnel_warp_connector_config\" \"example_zero_trust_tunnel_warp_connector_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "optional": [], + "computed": [ + { + "name": "config", + "type": "Attributes", + "description": "Provider-specific configuration. Present for `aws` and `local` modes.", + "children": [ + { + "name": "fnr_id", + "type": "String", + "description": "Floating Network Resource ID — the secondary ENI that is moved between nodes on failover." + }, + { + "name": "vips", + "type": "Attributes List", + "description": "VIPs to assign on the CloudflareWARP interface.", + "children": [ + { + "name": "address", + "type": "String", + "description": "Virtual IP address (IPv4 or IPv6)." + } + ] + }, + { + "name": "vips_previous", + "type": "Attributes List", + "description": "VIPs to clean up on demotion or version drift.", + "children": [ + { + "name": "address", + "type": "String", + "description": "Virtual IP address (IPv4 or IPv6)." + } + ] + } + ] + }, + { + "name": "configuration_version", + "type": "Number", + "description": "Monotonically increasing configuration version, incremented on each PUT." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "ha_mode", + "type": "String", + "description": "High-availability mode for the WARP Connector tunnel. `none` means HA is enabled but no provider is configured yet (newly created tunnels default to this). `disabled` means HA is explicitly turned off. `aws` uses AWS ENI move for failover. `local` uses virtual IPs (VIPs) on the local interface.\nAvailable values: \"none\", \"disabled\", \"aws\", \"local\"." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp of the last update. Null if never updated." + } + ] + }, + "resource:cloudflare_zero_trust_tunnel_warp_connector_config": { + "kind": "resource", + "name": "cloudflare_zero_trust_tunnel_warp_connector_config", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: WARP Read`\n- `Cloudflare One Connector: WARP Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`", + "example": "resource \"cloudflare_zero_trust_tunnel_warp_connector_config\" \"example_zero_trust_tunnel_warp_connector_config\" {\n account_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n ha_mode = \"aws\"\n config = {\n fnr_id = \"eni-0123456789abcdef0\"\n }\n}", + "importExample": "$ terraform import cloudflare_zero_trust_tunnel_warp_connector_config.example '/'", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Identifier." + }, + { + "name": "ha_mode", + "type": "String", + "description": "High-availability mode for the WARP Connector tunnel. `none` means HA is enabled but no provider is configured yet (newly created tunnels default to this). `disabled` means HA is explicitly turned off. `aws` uses AWS ENI move for failover. `local` uses virtual IPs (VIPs) on the local interface.\nAvailable values: \"none\", \"disabled\", \"aws\", \"local\"." + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "optional": [ + { + "name": "config", + "type": "Attributes", + "description": "Provider-specific configuration. Required shape depends on ha_mode. For `aws`, must contain `fnr_id`. For `local`, must contain `vips`. For `none` and `disabled`, must be empty or omitted.", + "children": [ + { + "name": "fnr_id", + "type": "String", + "description": "Floating Network Resource ID — the secondary ENI that is moved between nodes on failover." + }, + { + "name": "vips", + "type": "Attributes List", + "description": "VIPs to assign on the CloudflareWARP interface.", + "children": [ + { + "name": "address", + "type": "String", + "description": "Virtual IP address (IPv4 or IPv6)." + } + ] + }, + { + "name": "vips_previous", + "type": "Attributes List", + "description": "VIPs to clean up on demotion or version drift.", + "children": [ + { + "name": "address", + "type": "String", + "description": "Virtual IP address (IPv4 or IPv6)." + } + ] + } + ] + } + ], + "computed": [ + { + "name": "configuration_version", + "type": "Number", + "description": "Monotonically increasing configuration version, incremented on each PUT." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "updated_at", + "type": "String", + "description": "Timestamp of the last update. Null if never updated." + } + ] + }, + "data-source:cloudflare_zero_trust_tunnel_warp_connector_token": { + "kind": "data-source", + "name": "cloudflare_zero_trust_tunnel_warp_connector_token", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: cloudflared Write`\n- `Cloudflare One Connectors Write`\n- `Cloudflare Tunnel Write`", + "example": "data \"cloudflare_zero_trust_tunnel_warp_connector_token\" \"example_zero_trust_tunnel_warp_connector_token\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n tunnel_id = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n}", + "required": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "tunnel_id", + "type": "String", + "description": "UUID of the tunnel." + } + ], + "optional": [], + "computed": [ + { + "name": "token", + "type": "String", + "description": "The Tunnel Token is used as a mechanism to authenticate the operation of a tunnel.", + "sensitive": true + } + ] + }, + "list-data-source:cloudflare_zero_trust_tunnel_warp_connectors": { + "kind": "list-data-source", + "name": "cloudflare_zero_trust_tunnel_warp_connectors", + "description": "Accepted Permissions\n\n- `Cloudflare One Connector: WARP Read`\n- `Cloudflare One Connector: WARP Write`\n- `Cloudflare One Connectors Read`\n- `Cloudflare One Connectors Write`", + "example": "data \"cloudflare_zero_trust_tunnel_warp_connectors\" \"example_zero_trust_tunnel_warp_connectors\" {\n account_id = \"699d98642c564d2e855e9661899b7252\"\n exclude_prefix = \"vpc1-\"\n existed_at = \"2019-10-12T07%3A20%3A50.52Z\"\n include_prefix = \"vpc1-\"\n is_deleted = true\n name = \"blog\"\n status = \"healthy\"\n uuid = \"f70ff985-a4ef-4643-bbbc-4a0ed4fc8415\"\n was_active_at = \"2009-11-10T23:00:00Z\"\n was_inactive_at = \"2009-11-10T23:00:00Z\"\n}", + "required": [], + "optional": [ + { + "name": "account_id", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "exclude_prefix", + "type": "String" + }, + { + "name": "existed_at", + "type": "String", + "description": "If provided, include only resources that were created (and not deleted) before this time. URL encoded." + }, + { + "name": "include_prefix", + "type": "String" + }, + { + "name": "is_deleted", + "type": "Boolean", + "description": "If `true`, only include deleted tunnels. If `false`, exclude deleted tunnels. If empty, all tunnels will be included." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for the tunnel." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "was_active_at", + "type": "String" + }, + { + "name": "was_inactive_at", + "type": "String" + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account_tag", + "type": "String", + "description": "Cloudflare account ID" + }, + { + "name": "connections", + "type": "Attributes List", + "description": "The Cloudflare Tunnel connections between your origin and Cloudflare's edge.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "client_id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connector." + }, + { + "name": "client_version", + "type": "String", + "description": "The cloudflared version used to establish this connection." + }, + { + "name": "colo_name", + "type": "String", + "description": "The Cloudflare data center used for this connection." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + }, + { + "name": "is_pending_reconnect", + "type": "Boolean", + "description": "Cloudflare continues to track connections for several minutes after they disconnect. This is an optimization to improve latency and reliability of reconnecting. If `true`, the connection has disconnected but is still being tracked. If `false`, the connection is actively serving traffic.", + "deprecated": "Deprecated." + }, + { + "name": "opened_at", + "type": "String", + "description": "Timestamp of when the connection was established." + }, + { + "name": "origin_ip", + "type": "String", + "description": "The public IP address of the host running cloudflared." + }, + { + "name": "uuid", + "type": "String", + "description": "UUID of the Cloudflare Tunnel connection." + } + ] + }, + { + "name": "conns_active_at", + "type": "String", + "description": "Timestamp of when the tunnel established at least one connection to Cloudflare's edge. If `null`, the tunnel is inactive." + }, + { + "name": "conns_inactive_at", + "type": "String", + "description": "Timestamp of when the tunnel became inactive (no connections to Cloudflare's edge). If `null`, the tunnel is active." + }, + { + "name": "created_at", + "type": "String", + "description": "Timestamp of when the resource was created." + }, + { + "name": "deleted_at", + "type": "String", + "description": "Timestamp of when the resource was deleted. If `null`, the resource has not been deleted." + }, + { + "name": "id", + "type": "String", + "description": "UUID of the tunnel." + }, + { + "name": "metadata", + "type": "String", + "description": "Metadata associated with the tunnel." + }, + { + "name": "name", + "type": "String", + "description": "A user-friendly name for a tunnel." + }, + { + "name": "status", + "type": "String", + "description": "The status of the tunnel. Valid values are `inactive` (tunnel has never been run), `degraded` (tunnel is active and able to serve traffic but in an unhealthy state), `healthy` (tunnel is active and able to serve traffic), or `down` (tunnel can not serve traffic as it has no connections to the Cloudflare Edge).\nAvailable values: \"inactive\", \"degraded\", \"healthy\", \"down\"." + }, + { + "name": "tun_type", + "type": "String", + "description": "The type of tunnel.\nAvailable values: \"cfd_tunnel\", \"warp_connector\", \"warp\", \"magic\", \"ip_sec\", \"gre\", \"cni\"." + } + ] + } + ] + }, + "data-source:cloudflare_zone": { + "kind": "data-source", + "name": "cloudflare_zone", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`\n- `Zone Zone Read`", + "example": "data \"cloudflare_zone\" \"example_zone\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "account", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "Filter by an account ID." + }, + { + "name": "name", + "type": "String", + "description": "An account Name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`" + } + ] + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order zones.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any).\nAvailable values: \"any\", \"all\"." + }, + { + "name": "name", + "type": "String", + "description": "A domain name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`" + }, + { + "name": "order", + "type": "String", + "description": "Field to order zones by.\nAvailable values: \"name\", \"status\", \"account.id\", \"account.name\", \"plan.id\"." + }, + { + "name": "status", + "type": "String", + "description": "Specify a zone status to filter by.\nAvailable values: \"initializing\", \"pending\", \"active\", \"moved\"." + }, + { + "name": "type", + "type": "List of String", + "description": "Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type \"internal\" are excluded from the results." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "account", + "type": "Attributes", + "description": "The account the zone belongs to.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "The name of the account." + } + ] + }, + { + "name": "activated_on", + "type": "String", + "description": "The last time proof of ownership was detected and the zone was made\nactive." + }, + { + "name": "cname_suffix", + "type": "String", + "description": "Allows the customer to use a custom apex.\n*Tenants Only Configuration*." + }, + { + "name": "created_on", + "type": "String", + "description": "When the zone was created." + }, + { + "name": "development_mode", + "type": "Number", + "description": "The interval (in seconds) from when development mode expires\n(positive integer) or last expired (negative integer) for the\ndomain. If development mode has never been enabled, this value is 0." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "meta", + "type": "Attributes", + "description": "Metadata about the zone.", + "children": [ + { + "name": "cdn_only", + "type": "Boolean", + "description": "The zone is only configured for CDN." + }, + { + "name": "custom_certificate_quota", + "type": "Number", + "description": "Number of Custom Certificates the zone can have." + }, + { + "name": "dns_only", + "type": "Boolean", + "description": "The zone is only configured for DNS." + }, + { + "name": "foundation_dns", + "type": "Boolean", + "description": "The zone is setup with Foundation DNS." + }, + { + "name": "page_rule_quota", + "type": "Number", + "description": "Number of Page Rules a zone can have." + }, + { + "name": "phishing_detected", + "type": "Boolean", + "description": "The zone has been flagged for phishing." + }, + { + "name": "step", + "type": "Number" + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the zone was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment (\"label\") not exceeding 63 characters." + }, + { + "name": "name_servers", + "type": "List of String", + "description": "The name servers Cloudflare assigns to a zone." + }, + { + "name": "original_dnshost", + "type": "String", + "description": "DNS host at the time of switching to Cloudflare." + }, + { + "name": "original_name_servers", + "type": "List of String", + "description": "Original name servers before moving to Cloudflare." + }, + { + "name": "original_registrar", + "type": "String", + "description": "Registrar for the domain at the time of switching to Cloudflare." + }, + { + "name": "owner", + "type": "Attributes", + "description": "The owner of the zone.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "Name of the owner." + }, + { + "name": "type", + "type": "String", + "description": "The type of owner." + } + ] + }, + { + "name": "paused", + "type": "Boolean", + "description": "Indicates whether the zone is only using Cloudflare DNS services. A\ntrue value means the zone will not receive security or performance\nbenefits." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Legacy permissions based on legacy user membership information.", + "deprecated": "Deprecated." + }, + { + "name": "plan", + "type": "Attributes", + "description": "A Zones subscription information.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "can_subscribe", + "type": "Boolean", + "description": "States if the subscription can be activated." + }, + { + "name": "currency", + "type": "String", + "description": "The denomination of the customer." + }, + { + "name": "externally_managed", + "type": "Boolean", + "description": "If this Zone is managed by another company." + }, + { + "name": "frequency", + "type": "String", + "description": "How often the customer is billed." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "is_subscribed", + "type": "Boolean", + "description": "States if the subscription active." + }, + { + "name": "legacy_discount", + "type": "Boolean", + "description": "If the legacy discount applies to this Zone." + }, + { + "name": "legacy_id", + "type": "String", + "description": "The legacy name of the plan." + }, + { + "name": "name", + "type": "String", + "description": "Name of the owner." + }, + { + "name": "price", + "type": "Number", + "description": "How much the customer is paying." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "The zone status on Cloudflare.\nAvailable values: \"initializing\", \"pending\", \"active\", \"moved\"." + }, + { + "name": "tenant", + "type": "Attributes", + "description": "The root organizational unit that this zone belongs to (such as a tenant or organization).", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "The name of the Tenant account." + } + ] + }, + { + "name": "tenant_unit", + "type": "Attributes", + "description": "The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization).", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "A full zone implies that DNS is hosted with Cloudflare. A partial zone is\ntypically a partner-hosted zone or a CNAME setup.\nAvailable values: \"full\", \"partial\", \"secondary\", \"internal\"." + }, + { + "name": "vanity_name_servers", + "type": "List of String", + "description": "An array of domains used for custom name servers. This is only available for Business and Enterprise plans." + }, + { + "name": "verification_key", + "type": "String", + "description": "Verification key for partial zone setup." + } + ] + }, + "resource:cloudflare_zone": { + "kind": "resource", + "name": "cloudflare_zone", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone DNS Edit`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`\n- `Zone Zone Edit`\n\n-> If you are attempting to sign up a subdomain of a zone you must first have Subdomain Support entitlement for your account.", + "example": "resource \"cloudflare_zone\" \"example_zone\" {\n account = {\n id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n }\n name = \"example.com\"\n type = \"full\"\n}", + "importExample": "$ terraform import cloudflare_zone.example ''", + "required": [ + { + "name": "account", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + { + "name": "name", + "type": "String", + "description": "The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment (\"label\") not exceeding 63 characters." + } + ], + "optional": [ + { + "name": "paused", + "type": "Boolean", + "description": "Indicates whether the zone is only using Cloudflare DNS services. A\ntrue value means the zone will not receive security or performance\nbenefits." + }, + { + "name": "type", + "type": "String", + "description": "A full zone implies that DNS is hosted with Cloudflare. A partial zone is\ntypically a partner-hosted zone or a CNAME setup.\nAvailable values: \"full\", \"partial\", \"secondary\", \"internal\"." + }, + { + "name": "vanity_name_servers", + "type": "List of String", + "description": "An array of domains used for custom name servers. This is only\navailable for Business and Enterprise plans." + } + ], + "computed": [ + { + "name": "activated_on", + "type": "String", + "description": "The last time proof of ownership was detected and the zone was made\nactive." + }, + { + "name": "cname_suffix", + "type": "String", + "description": "Allows the customer to use a custom apex.\n*Tenants Only Configuration*." + }, + { + "name": "created_on", + "type": "String", + "description": "When the zone was created." + }, + { + "name": "development_mode", + "type": "Number", + "description": "The interval (in seconds) from when development mode expires\n(positive integer) or last expired (negative integer) for the\ndomain. If development mode has never been enabled, this value is 0." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "meta", + "type": "Attributes", + "description": "Metadata about the zone.", + "children": [ + { + "name": "cdn_only", + "type": "Boolean", + "description": "The zone is only configured for CDN." + }, + { + "name": "custom_certificate_quota", + "type": "Number", + "description": "Number of Custom Certificates the zone can have." + }, + { + "name": "dns_only", + "type": "Boolean", + "description": "The zone is only configured for DNS." + }, + { + "name": "foundation_dns", + "type": "Boolean", + "description": "The zone is setup with Foundation DNS." + }, + { + "name": "page_rule_quota", + "type": "Number", + "description": "Number of Page Rules a zone can have." + }, + { + "name": "phishing_detected", + "type": "Boolean", + "description": "The zone has been flagged for phishing." + }, + { + "name": "step", + "type": "Number" + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the zone was last modified." + }, + { + "name": "name_servers", + "type": "List of String", + "description": "The name servers Cloudflare assigns to a zone." + }, + { + "name": "original_dnshost", + "type": "String", + "description": "DNS host at the time of switching to Cloudflare." + }, + { + "name": "original_name_servers", + "type": "List of String", + "description": "Original name servers before moving to Cloudflare." + }, + { + "name": "original_registrar", + "type": "String", + "description": "Registrar for the domain at the time of switching to Cloudflare." + }, + { + "name": "owner", + "type": "Attributes", + "description": "The owner of the zone.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "Name of the owner." + }, + { + "name": "type", + "type": "String", + "description": "The type of owner." + } + ] + }, + { + "name": "permissions", + "type": "List of String", + "description": "Legacy permissions based on legacy user membership information.", + "deprecated": "Deprecated." + }, + { + "name": "plan", + "type": "Attributes", + "description": "A Zones subscription information.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "can_subscribe", + "type": "Boolean", + "description": "States if the subscription can be activated." + }, + { + "name": "currency", + "type": "String", + "description": "The denomination of the customer." + }, + { + "name": "externally_managed", + "type": "Boolean", + "description": "If this Zone is managed by another company." + }, + { + "name": "frequency", + "type": "String", + "description": "How often the customer is billed." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "is_subscribed", + "type": "Boolean", + "description": "States if the subscription active." + }, + { + "name": "legacy_discount", + "type": "Boolean", + "description": "If the legacy discount applies to this Zone." + }, + { + "name": "legacy_id", + "type": "String", + "description": "The legacy name of the plan." + }, + { + "name": "name", + "type": "String", + "description": "Name of the owner." + }, + { + "name": "price", + "type": "Number", + "description": "How much the customer is paying." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "The zone status on Cloudflare.\nAvailable values: \"initializing\", \"pending\", \"active\", \"moved\"." + }, + { + "name": "tenant", + "type": "Attributes", + "description": "The root organizational unit that this zone belongs to (such as a tenant or organization).", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "The name of the Tenant account." + } + ] + }, + { + "name": "tenant_unit", + "type": "Attributes", + "description": "The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization).", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + { + "name": "verification_key", + "type": "String", + "description": "Verification key for partial zone setup." + } + ] + }, + "data-source:cloudflare_zone_auto_origin_tls_kex": { + "kind": "data-source", + "name": "cloudflare_zone_auto_origin_tls_kex", + "example": "data \"cloudflare_zone_auto_origin_tls_kex\" \"example_zone_auto_origin_tls_kex\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Auto-Origin TLS KEX selection is enabled for the zone." + }, + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "resource:cloudflare_zone_auto_origin_tls_kex": { + "kind": "resource", + "name": "cloudflare_zone_auto_origin_tls_kex", + "example": "resource \"cloudflare_zone_auto_origin_tls_kex\" \"example_zone_auto_origin_tls_kex\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n enabled = true\n}", + "importExample": "$ terraform import cloudflare_zone_auto_origin_tls_kex.example ''", + "required": [ + { + "name": "enabled", + "type": "Boolean", + "description": "Controls enablement of Auto-Origin TLS KEX selection for the zone." + }, + { + "name": "zone_id", + "type": "String" + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "The ID of this resource." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "data-source:cloudflare_zone_cache_reserve": { + "kind": "data-source", + "name": "cloudflare_zone_cache_reserve", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_zone_cache_reserve\" \"example_zone_cache_reserve\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + }, + { + "name": "value", + "type": "String", + "description": "Value of the Cache Reserve zone setting.\nAvailable values: \"on\", \"off\"." + } + ] + }, + "resource:cloudflare_zone_cache_reserve": { + "kind": "resource", + "name": "cloudflare_zone_cache_reserve", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_zone_cache_reserve\" \"example_zone_cache_reserve\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = \"on\"\n}", + "importExample": "$ terraform import cloudflare_zone_cache_reserve.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "value", + "type": "String", + "description": "Value of the Cache Reserve zone setting.\nAvailable values: \"on\", \"off\"." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "data-source:cloudflare_zone_cache_variants": { + "kind": "data-source", + "name": "cloudflare_zone_cache_variants", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_zone_cache_variants\" \"example_zone_cache_variants\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + }, + { + "name": "value", + "type": "Attributes", + "description": "Value of the zone setting.", + "children": [ + { + "name": "avif", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for avif." + }, + { + "name": "bmp", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for bmp." + }, + { + "name": "gif", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for gif." + }, + { + "name": "jp2", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jp2." + }, + { + "name": "jpeg", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jpeg." + }, + { + "name": "jpg", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jpg." + }, + { + "name": "jpg2", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jpg2." + }, + { + "name": "png", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for png." + }, + { + "name": "tif", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for tif." + }, + { + "name": "tiff", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for tiff." + }, + { + "name": "webp", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for webp." + } + ] + } + ] + }, + "resource:cloudflare_zone_cache_variants": { + "kind": "resource", + "name": "cloudflare_zone_cache_variants", + "description": "Accepted Permissions\n\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_zone_cache_variants\" \"example_zone_cache_variants\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n value = {\n avif = [\"image/webp\", \"image/jpeg\"]\n bmp = [\"image/webp\", \"image/jpeg\"]\n gif = [\"image/webp\", \"image/jpeg\"]\n jp2 = [\"image/webp\", \"image/avif\"]\n jpeg = [\"image/webp\", \"image/avif\"]\n jpg = [\"image/webp\", \"image/avif\"]\n jpg2 = [\"image/webp\", \"image/avif\"]\n png = [\"image/webp\", \"image/avif\"]\n tif = [\"image/webp\", \"image/avif\"]\n tiff = [\"image/webp\", \"image/avif\"]\n webp = [\"image/jpeg\", \"image/avif\"]\n }\n}", + "importExample": "$ terraform import cloudflare_zone_cache_variants.example ''", + "required": [ + { + "name": "value", + "type": "Attributes", + "description": "Value of the zone setting.", + "children": [ + { + "name": "avif", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for avif." + }, + { + "name": "bmp", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for bmp." + }, + { + "name": "gif", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for gif." + }, + { + "name": "jp2", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jp2." + }, + { + "name": "jpeg", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jpeg." + }, + { + "name": "jpg", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jpg." + }, + { + "name": "jpg2", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for jpg2." + }, + { + "name": "png", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for png." + }, + { + "name": "tif", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for tif." + }, + { + "name": "tiff", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for tiff." + }, + { + "name": "webp", + "type": "List of String", + "description": "List of strings with the MIME types of all the variants that should be served for webp." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether the setting is editable." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "modified_on", + "type": "String", + "description": "Last time this setting was modified." + } + ] + }, + "data-source:cloudflare_zone_dns_settings": { + "kind": "data-source", + "name": "cloudflare_zone_dns_settings", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`\n- `Zone DNS Settings Read`\n- `Zone DNS Settings Write`", + "example": "data \"cloudflare_zone_dns_settings\" \"example_zone_dns_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "flatten_all_cnames", + "type": "Boolean", + "description": "Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened." + }, + { + "name": "foundation_dns", + "type": "Boolean", + "description": "Deprecated. Use nameservers.type to configure Advanced Nameservers.", + "deprecated": "Deprecated." + }, + { + "name": "internal_dns", + "type": "Attributes", + "description": "Settings for this internal zone.", + "children": [ + { + "name": "reference_zone_id", + "type": "String", + "description": "The ID of the zone to fallback to." + } + ] + }, + { + "name": "multi_provider", + "type": "Boolean", + "description": "Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers." + }, + { + "name": "nameservers", + "type": "Attributes", + "description": "Controls the nameservers through which the zone is available.", + "children": [ + { + "name": "nameserver_set_id", + "type": "String", + "description": "Identifier of the account-owned Custom Nameserver Set to use for this zone." + }, + { + "name": "ns_set", + "type": "Number", + "description": "Configured nameserver set number to use for this zone." + }, + { + "name": "type", + "type": "String", + "description": "Nameserver type.\nAvailable values: \"cloudflare.standard\", \"custom.account\", \"custom.tenant\", \"custom.zone\", \"custom\"." + } + ] + }, + { + "name": "ns_ttl", + "type": "Number", + "description": "The time to live (TTL) of the zone's nameserver (NS) records." + }, + { + "name": "secondary_overrides", + "type": "Boolean", + "description": "Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex." + }, + { + "name": "soa", + "type": "Attributes", + "description": "Components of the zone's SOA record.", + "children": [ + { + "name": "expire", + "type": "Number", + "description": "Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone." + }, + { + "name": "min_ttl", + "type": "Number", + "description": "The time to live (TTL) for negative caching of records within the zone." + }, + { + "name": "mname", + "type": "String", + "description": "The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used." + }, + { + "name": "refresh", + "type": "Number", + "description": "Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated." + }, + { + "name": "retry", + "type": "Number", + "description": "Time in seconds after which secondary servers should retry queries after the primary server was unresponsive." + }, + { + "name": "rname", + "type": "String", + "description": "The email address of the zone administrator, with the first label representing the local part of the email address." + }, + { + "name": "ttl", + "type": "Number", + "description": "The time to live (TTL) of the SOA record itself." + } + ] + }, + { + "name": "zone_mode", + "type": "String", + "description": "Whether the zone mode is a regular or CDN/DNS only zone.\nAvailable values: \"standard\", \"cdn_only\", \"dns_only\"." + } + ] + }, + "resource:cloudflare_zone_dns_settings": { + "kind": "resource", + "name": "cloudflare_zone_dns_settings", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`\n- `Zone DNS Settings Read`\n- `Zone DNS Settings Write`", + "example": "resource \"cloudflare_zone_dns_settings\" \"example_zone_dns_settings\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n flatten_all_cnames = false\n foundation_dns = false\n internal_dns = {\n reference_zone_id = \"reference_zone_id\"\n }\n multi_provider = false\n nameservers = {\n type = \"cloudflare.standard\"\n }\n ns_ttl = 86400\n secondary_overrides = false\n soa = {\n expire = 604800\n min_ttl = 1800\n mname = \"kristina.ns.cloudflare.com\"\n refresh = 10000\n retry = 2400\n rname = \"admin.example.com\"\n ttl = 3600\n }\n zone_mode = \"dns_only\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "flatten_all_cnames", + "type": "Boolean", + "description": "Whether to flatten all CNAME records in the zone. Note that, due to DNS limitations, a CNAME record at the zone apex will always be flattened." + }, + { + "name": "foundation_dns", + "type": "Boolean", + "description": "Deprecated. Use nameservers.type to configure Advanced Nameservers.", + "deprecated": "Deprecated." + }, + { + "name": "internal_dns", + "type": "Attributes", + "description": "Settings for this internal zone.", + "children": [ + { + "name": "reference_zone_id", + "type": "String", + "description": "The ID of the zone to fallback to." + } + ] + }, + { + "name": "multi_provider", + "type": "Boolean", + "description": "Whether to enable multi-provider DNS, which causes Cloudflare to activate the zone even when non-Cloudflare NS records exist, and to respect NS records at the zone apex during outbound zone transfers." + }, + { + "name": "nameservers", + "type": "Attributes", + "description": "Controls the nameservers through which the zone is available.", + "children": [ + { + "name": "nameserver_set_id", + "type": "String", + "description": "Identifier of the account-owned Custom Nameserver Set to use for this zone." + }, + { + "name": "ns_set", + "type": "Number", + "description": "Configured nameserver set number to use for this zone." + }, + { + "name": "type", + "type": "String", + "description": "Nameserver type.\nAvailable values: \"cloudflare.standard\", \"cloudflare.advanced\", \"custom.account\", \"custom.tenant\", \"custom.zone\", \"custom\"." + } + ] + }, + { + "name": "ns_ttl", + "type": "Number", + "description": "The time to live (TTL) of the zone's nameserver (NS) records." + }, + { + "name": "secondary_overrides", + "type": "Boolean", + "description": "Allows a Secondary DNS zone to use (proxied) override records and CNAME flattening at the zone apex." + }, + { + "name": "soa", + "type": "Attributes", + "description": "Components of the zone's SOA record.", + "children": [ + { + "name": "expire", + "type": "Number", + "description": "Time in seconds of being unable to query the primary server after which secondary servers should stop serving the zone." + }, + { + "name": "min_ttl", + "type": "Number", + "description": "The time to live (TTL) for negative caching of records within the zone." + }, + { + "name": "mname", + "type": "String", + "description": "The primary nameserver, which may be used for outbound zone transfers. If null, a Cloudflare-assigned value will be used." + }, + { + "name": "refresh", + "type": "Number", + "description": "Time in seconds after which secondary servers should re-check the SOA record to see if the zone has been updated." + }, + { + "name": "retry", + "type": "Number", + "description": "Time in seconds after which secondary servers should retry queries after the primary server was unresponsive." + }, + { + "name": "rname", + "type": "String", + "description": "The email address of the zone administrator, with the first label representing the local part of the email address." + }, + { + "name": "ttl", + "type": "Number", + "description": "The time to live (TTL) of the SOA record itself." + } + ] + }, + { + "name": "zone_mode", + "type": "String", + "description": "Whether the zone mode is a regular or CDN/DNS only zone.\nAvailable values: \"standard\", \"cdn_only\", \"dns_only\"." + } + ], + "computed": [] + }, + "data-source:cloudflare_zone_dnssec": { + "kind": "data-source", + "name": "cloudflare_zone_dnssec", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "data \"cloudflare_zone_dnssec\" \"example_zone_dnssec\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "algorithm", + "type": "String", + "description": "Algorithm key code." + }, + { + "name": "digest", + "type": "String", + "description": "Digest hash." + }, + { + "name": "digest_algorithm", + "type": "String", + "description": "Type of digest algorithm." + }, + { + "name": "digest_type", + "type": "String", + "description": "Coded type for digest algorithm." + }, + { + "name": "dnssec_multi_signer", + "type": "Boolean", + "description": "If true, multi-signer DNSSEC is enabled on the zone, allowing multiple\nproviders to serve a DNSSEC-signed zone at the same time.\nThis is required for DNSKEY records (except those automatically\ngenerated by Cloudflare) to be added to the zone.\n\nSee [Multi-signer DNSSEC](https://developers.cloudflare.com/dns/dnssec/multi-signer-dnssec/) for details." + }, + { + "name": "dnssec_presigned", + "type": "Boolean", + "description": "If true, allows Cloudflare to transfer in a DNSSEC-signed zone\nincluding signatures from an external provider, without requiring\nCloudflare to sign any records on the fly.\n\nNote that this feature has some limitations.\nSee [Cloudflare as Secondary](https://developers.cloudflare.com/dns/zone-setups/zone-transfers/cloudflare-as-secondary/setup/#dnssec) for details." + }, + { + "name": "dnssec_use_nsec3", + "type": "Boolean", + "description": "If true, enables the use of NSEC3 together with DNSSEC on the zone.\nCombined with setting dnssec_presigned to true, this enables the use of\nNSEC3 records when transferring in from an external provider.\nIf dnssec_presigned is instead set to false (default), NSEC3 records will be\ngenerated and signed at request time.\n\nSee [DNSSEC with NSEC3](https://developers.cloudflare.com/dns/dnssec/enable-nsec3/) for details." + }, + { + "name": "ds", + "type": "String", + "description": "Full DS record." + }, + { + "name": "flags", + "type": "Number", + "description": "Flag for DNSSEC record." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "key_tag", + "type": "Number", + "description": "Code for key tag." + }, + { + "name": "key_type", + "type": "String", + "description": "Algorithm key type." + }, + { + "name": "modified_on", + "type": "String", + "description": "When DNSSEC was last modified." + }, + { + "name": "public_key", + "type": "String", + "description": "Public key for DS record." + }, + { + "name": "status", + "type": "String", + "description": "Status of DNSSEC, based on user-desired state and presence of necessary records.\nAvailable values: \"active\", \"pending\", \"disabled\", \"pending-disabled\", \"error\"." + } + ] + }, + "resource:cloudflare_zone_dnssec": { + "kind": "resource", + "name": "cloudflare_zone_dnssec", + "description": "Accepted Permissions\n\n- `DNS Read`\n- `DNS Write`", + "example": "resource \"cloudflare_zone_dnssec\" \"example_zone_dnssec\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n dnssec_multi_signer = false\n dnssec_presigned = true\n dnssec_use_nsec3 = false\n status = \"active\"\n}", + "importExample": "$ terraform import cloudflare_zone_dnssec.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "dnssec_multi_signer", + "type": "Boolean", + "description": "If true, multi-signer DNSSEC is enabled on the zone, allowing multiple\nproviders to serve a DNSSEC-signed zone at the same time.\nThis is required for DNSKEY records (except those automatically\ngenerated by Cloudflare) to be added to the zone.\n\nSee [Multi-signer DNSSEC](https://developers.cloudflare.com/dns/dnssec/multi-signer-dnssec/) for details." + }, + { + "name": "dnssec_presigned", + "type": "Boolean", + "description": "If true, allows Cloudflare to transfer in a DNSSEC-signed zone\nincluding signatures from an external provider, without requiring\nCloudflare to sign any records on the fly.\n\nNote that this feature has some limitations.\nSee [Cloudflare as Secondary](https://developers.cloudflare.com/dns/zone-setups/zone-transfers/cloudflare-as-secondary/setup/#dnssec) for details." + }, + { + "name": "dnssec_use_nsec3", + "type": "Boolean", + "description": "If true, enables the use of NSEC3 together with DNSSEC on the zone.\nCombined with setting dnssec_presigned to true, this enables the use of\nNSEC3 records when transferring in from an external provider.\nIf dnssec_presigned is instead set to false (default), NSEC3 records will be\ngenerated and signed at request time.\n\nSee [DNSSEC with NSEC3](https://developers.cloudflare.com/dns/dnssec/enable-nsec3/) for details." + }, + { + "name": "status", + "type": "String", + "description": "Status of DNSSEC, based on user-desired state and presence of necessary records.\nAvailable values: \"active\", \"disabled\"." + } + ], + "computed": [ + { + "name": "algorithm", + "type": "String", + "description": "Algorithm key code." + }, + { + "name": "digest", + "type": "String", + "description": "Digest hash." + }, + { + "name": "digest_algorithm", + "type": "String", + "description": "Type of digest algorithm." + }, + { + "name": "digest_type", + "type": "String", + "description": "Coded type for digest algorithm." + }, + { + "name": "ds", + "type": "String", + "description": "Full DS record." + }, + { + "name": "flags", + "type": "Number", + "description": "Flag for DNSSEC record." + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "key_tag", + "type": "Number", + "description": "Code for key tag." + }, + { + "name": "key_type", + "type": "String", + "description": "Algorithm key type." + }, + { + "name": "modified_on", + "type": "String", + "description": "When DNSSEC was last modified." + }, + { + "name": "public_key", + "type": "String", + "description": "Public key for DS record." + } + ] + }, + "data-source:cloudflare_zone_hold": { + "kind": "data-source", + "name": "cloudflare_zone_hold", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "data \"cloudflare_zone_hold\" \"example_zone_hold\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "computed": [ + { + "name": "hold", + "type": "Boolean" + }, + { + "name": "hold_after", + "type": "String" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + }, + { + "name": "include_subdomains", + "type": "String" + } + ] + }, + "resource:cloudflare_zone_hold": { + "kind": "resource", + "name": "cloudflare_zone_hold", + "description": "Accepted Permissions\n\n- `Access: Apps and Policies Read`\n- `Access: Apps and Policies Revoke`\n- `Access: Apps and Policies Write`\n- `Access: Mutual TLS Certificates Write`\n- `Access: Organizations, Identity Providers, and Groups Write`\n- `Analytics Read`\n- `Apps Write`\n- `Cache Purge`\n- `DNS Read`\n- `DNS Write`\n- `Firewall Services Read`\n- `Firewall Services Write`\n- `Load Balancers Read`\n- `Load Balancers Write`\n- `Logs Read`\n- `Logs Write`\n- `Page Rules Read`\n- `Page Rules Write`\n- `SSL and Certificates Read`\n- `SSL and Certificates Write`\n- `Stream Read`\n- `Stream Write`\n- `Trust and Safety Read`\n- `Trust and Safety Write`\n- `Workers Routes Read`\n- `Workers Routes Write`\n- `Workers Scripts Read`\n- `Workers Scripts Write`\n- `Zaraz Admin`\n- `Zaraz Edit`\n- `Zaraz Read`\n- `Zero Trust: PII Read`\n- `Zone Read`\n- `Zone Settings Read`\n- `Zone Settings Write`\n- `Zone Write`", + "example": "resource \"cloudflare_zone_hold\" \"example_zone_hold\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "importExample": "$ terraform import cloudflare_zone_hold.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier." + } + ], + "optional": [ + { + "name": "hold_after", + "type": "String", + "description": "If `hold_after` is provided and future-dated, the hold will be temporarily disabled,\nthen automatically re-enabled by the system at the time specified\nin this RFC3339-formatted timestamp. A past-dated `hold_after` value will have\nno effect on an existing, enabled hold. Providing an empty string will set its value\nto the current time. Providing `null` will disable the hold indefinitely." + }, + { + "name": "include_subdomains", + "type": "Boolean", + "description": "If `true`, the zone hold will extend to block any subdomain of the given zone, as well\nas SSL4SaaS Custom Hostnames. For example, a zone hold on a zone with the hostname\n'example.com' and include_subdomains=true will block 'example.com',\n'staging.example.com', 'api.staging.example.com', etc." + } + ], + "computed": [ + { + "name": "hold", + "type": "Boolean" + }, + { + "name": "id", + "type": "String", + "description": "Identifier." + } + ] + }, + "data-source:cloudflare_zone_lockdown": { + "kind": "data-source", + "name": "cloudflare_zone_lockdown", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_zone_lockdown\" \"example_zone_lockdown\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n lock_downs_id = \"372e67954025e0ba6aaa6d586b9e0b59\"\n}", + "required": [], + "optional": [ + { + "name": "filter", + "type": "Attributes", + "children": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "description", + "type": "String", + "description": "A string to search for in the description of existing rules." + }, + { + "name": "description_search", + "type": "String", + "description": "A string to search for in the description of existing rules." + }, + { + "name": "ip", + "type": "String", + "description": "A single IP address to search for in existing rules." + }, + { + "name": "ip_range_search", + "type": "String", + "description": "A single IP address range to search for in existing rules." + }, + { + "name": "ip_search", + "type": "String", + "description": "A single IP address to search for in existing rules." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + }, + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority." + }, + { + "name": "uri_search", + "type": "String", + "description": "A single URI to search for in the list of URLs of existing rules." + } + ] + }, + { + "name": "lock_downs_id", + "type": "String", + "description": "The unique identifier of the Zone Lockdown rule." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "configurations", + "type": "Attributes List", + "description": "A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule.\nAvailable values: \"ip\", \"ip_range\"." + }, + { + "name": "value", + "type": "String", + "description": "The IP address to match. This address will be compared to the IP address of incoming requests." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the Zone Lockdown rule." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + }, + { + "name": "urls", + "type": "Set of String", + "description": "The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns." + } + ] + }, + "resource:cloudflare_zone_lockdown": { + "kind": "resource", + "name": "cloudflare_zone_lockdown", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "resource \"cloudflare_zone_lockdown\" \"example_zone_lockdown\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n configurations = [{\n target = \"ip\"\n value = \"198.51.100.4\"\n }]\n urls = [\"shop.example.com/*\"]\n description = \"Prevent multiple login failures to mitigate brute force attacks\"\n paused = false\n priority = 5\n}", + "importExample": "$ terraform import cloudflare_zone_lockdown.example '/'", + "required": [ + { + "name": "configurations", + "type": "Attributes List", + "description": "A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule.\nAvailable values: \"ip\", \"ip_range\"." + }, + { + "name": "value", + "type": "String", + "description": "The IP address to match. This address will be compared to the IP address of incoming requests." + } + ] + }, + { + "name": "urls", + "type": "Set of String", + "description": "The URLs to include in the current WAF override. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "optional": [ + { + "name": "description", + "type": "String", + "description": "An informative summary of the rule. This value is sanitized and any tags will be removed." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + }, + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority." + } + ], + "computed": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the Zone Lockdown rule." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + } + ] + }, + "list-data-source:cloudflare_zone_lockdowns": { + "kind": "list-data-source", + "name": "cloudflare_zone_lockdowns", + "description": "Accepted Permissions\n\n- `Firewall Services Read`\n- `Firewall Services Write`", + "example": "data \"cloudflare_zone_lockdowns\" \"example_zone_lockdowns\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n created_on = \"2014-01-01T05:20:00.12345Z\"\n description = \"endpoints\"\n description_search = \"endpoints\"\n ip = \"1.2.3.4\"\n ip_range_search = \"1.2.3.0/16\"\n ip_search = \"1.2.3.4\"\n modified_on = \"2014-01-01T05:20:00.12345Z\"\n priority = 5\n uri_search = \"/some/path\"\n}", + "required": [], + "optional": [ + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "description", + "type": "String", + "description": "A string to search for in the description of existing rules." + }, + { + "name": "description_search", + "type": "String", + "description": "A string to search for in the description of existing rules." + }, + { + "name": "ip", + "type": "String", + "description": "A single IP address to search for in existing rules." + }, + { + "name": "ip_range_search", + "type": "String", + "description": "A single IP address range to search for in existing rules." + }, + { + "name": "ip_search", + "type": "String", + "description": "A single IP address to search for in existing rules." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + }, + { + "name": "priority", + "type": "Number", + "description": "The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority." + }, + { + "name": "uri_search", + "type": "String", + "description": "A single URI to search for in the list of URLs of existing rules." + }, + { + "name": "zone_id", + "type": "String", + "description": "Defines an identifier." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "configurations", + "type": "Attributes List", + "description": "A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of `ip` or `ip_range` configurations.", + "children": [ + { + "name": "target", + "type": "String", + "description": "The configuration target. You must set the target to `ip` when specifying an IP address in the Zone Lockdown rule.\nAvailable values: \"ip\", \"ip_range\"." + }, + { + "name": "value", + "type": "String", + "description": "The IP address to match. This address will be compared to the IP address of incoming requests." + } + ] + }, + { + "name": "created_on", + "type": "String", + "description": "The timestamp of when the rule was created." + }, + { + "name": "description", + "type": "String", + "description": "An informative summary of the rule." + }, + { + "name": "id", + "type": "String", + "description": "The unique identifier of the Zone Lockdown rule." + }, + { + "name": "modified_on", + "type": "String", + "description": "The timestamp of when the rule was last modified." + }, + { + "name": "paused", + "type": "Boolean", + "description": "When true, indicates that the rule is currently paused." + }, + { + "name": "urls", + "type": "Set of String", + "description": "The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns." + } + ] + } + ] + }, + "data-source:cloudflare_zone_setting": { + "kind": "data-source", + "name": "cloudflare_zone_setting", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`", + "example": "data \"cloudflare_zone_setting\" \"example_zone_setting\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"always_online\"\n}", + "required": [ + { + "name": "setting_id", + "type": "String", + "description": "Setting name" + } + ], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "ssl-recommender enrollment setting." + }, + { + "name": "id", + "type": "String", + "description": "Setting name" + }, + { + "name": "modified_on", + "type": "String", + "description": "last time this setting was modified." + }, + { + "name": "time_remaining", + "type": "Number", + "description": "Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false." + }, + { + "name": "value", + "type": "String", + "description": "Current value of the zone setting.\nAvailable values: \"on\", \"off\"." + } + ] + }, + "resource:cloudflare_zone_setting": { + "kind": "resource", + "name": "cloudflare_zone_setting", + "description": "Accepted Permissions\n\n- `Zone Settings Read`\n- `Zone Settings Write`\n\n-> If using the `ssl_recommender` zone setting, use the `enabled` attribute instead of `value`.", + "example": "# Basic on/off setting\nresource \"cloudflare_zone_setting\" \"always_online\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"always_online\"\n value = \"on\"\n}\n\n# String value with specific choices\nresource \"cloudflare_zone_setting\" \"min_tls_version\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"min_tls_version\"\n value = \"1.2\"\n}\n\n# Numeric value\nresource \"cloudflare_zone_setting\" \"browser_cache_ttl\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"browser_cache_ttl\"\n value = 14400 # 4 hours in seconds\n}\n\n# Array/List value\nresource \"cloudflare_zone_setting\" \"ciphers\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ciphers\"\n value = [\n \"ECDHE-ECDSA-AES128-GCM-SHA256\",\n \"ECDHE-ECDSA-CHACHA20-POLY1305\"\n ]\n}\n\n# Nested object value\nresource \"cloudflare_zone_setting\" \"security_header\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"security_header\"\n value = {\n strict_transport_security = {\n enabled = true\n include_subdomains = true\n max_age = 86400\n nosniff = true\n preload = false\n }\n }\n}\n\n# Special case: ssl_recommender uses 'enabled' instead of 'value'\nresource \"cloudflare_zone_setting\" \"ssl_recommender\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n setting_id = \"ssl_recommender\"\n enabled = true\n}", + "importExample": "$ terraform import cloudflare_zone_setting.example '/'", + "required": [ + { + "name": "setting_id", + "type": "String", + "description": "Setting name" + }, + { + "name": "value", + "type": "Dynamic", + "description": "Current value of the zone setting." + }, + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "enabled", + "type": "Boolean", + "description": "ssl-recommender enrollment setting." + } + ], + "computed": [ + { + "name": "editable", + "type": "Boolean", + "description": "Whether or not this setting can be modified for this zone (based on your Cloudflare plan level)." + }, + { + "name": "id", + "type": "String", + "description": "Setting name" + }, + { + "name": "modified_on", + "type": "String", + "description": "last time this setting was modified." + }, + { + "name": "time_remaining", + "type": "Number", + "description": "Value of the zone setting.\nNotes: The interval (in seconds) from when development mode expires (positive integer) or last expired (negative integer) for the domain. If development mode has never been enabled, this value is false." + } + ] + }, + "data-source:cloudflare_zone_subscription": { + "kind": "data-source", + "name": "cloudflare_zone_subscription", + "description": "Accepted Permissions\n\n- `Billing Read`\n- `Billing Write`", + "example": "data \"cloudflare_zone_subscription\" \"example_zone_subscription\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n}", + "required": [], + "optional": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "computed": [ + { + "name": "currency", + "type": "String", + "description": "The monetary unit in which pricing information is displayed." + }, + { + "name": "current_period_end", + "type": "String", + "description": "The end of the current period and also when the next billing is due." + }, + { + "name": "current_period_start", + "type": "String", + "description": "When the current billing period started. May match initial_period_start if this is the first period." + }, + { + "name": "frequency", + "type": "String", + "description": "How often the subscription is renewed automatically.\nAvailable values: \"weekly\", \"monthly\", \"quarterly\", \"yearly\", \"not-applicable\"." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "price", + "type": "Number", + "description": "The price of the subscription that will be billed, in US dollars." + }, + { + "name": "rate_plan", + "type": "Attributes", + "description": "The rate plan applied to the subscription.", + "children": [ + { + "name": "currency", + "type": "String", + "description": "The currency applied to the rate plan subscription." + }, + { + "name": "externally_managed", + "type": "Boolean", + "description": "Whether this rate plan is managed externally from Cloudflare." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the rate plan.\nAvailable values: \"free\", \"lite\", \"pro\", \"pro_plus\", \"business\", \"enterprise\", \"partners_free\", \"partners_pro\", \"partners_business\", \"partners_enterprise\", \"partners_ent\"." + }, + { + "name": "is_contract", + "type": "Boolean", + "description": "Whether a rate plan is enterprise-based (or newly adopted term contract)." + }, + { + "name": "public_name", + "type": "String", + "description": "The full name of the rate plan." + }, + { + "name": "scope", + "type": "String", + "description": "The scope that this rate plan applies to." + }, + { + "name": "sets", + "type": "List of String", + "description": "The list of sets this rate plan applies to. Returns array of strings." + } + ] + }, + { + "name": "state", + "type": "String", + "description": "The state that the subscription is in.\nAvailable values: \"Trial\", \"Provisioned\", \"Paid\", \"AwaitingPayment\", \"Cancelled\", \"Failed\", \"Expired\"." + } + ] + }, + "resource:cloudflare_zone_subscription": { + "kind": "resource", + "name": "cloudflare_zone_subscription", + "description": "Accepted Permissions\n\n- `Billing Read`\n- `Billing Write`", + "example": "resource \"cloudflare_zone_subscription\" \"example_zone_subscription\" {\n zone_id = \"023e105f4ecef8ad9ca31a8372d0c353\"\n frequency = \"monthly\"\n rate_plan = {\n id = \"free\"\n currency = \"USD\"\n externally_managed = false\n is_contract = false\n public_name = \"Business Plan\"\n scope = \"zone\"\n sets = [\"string\"]\n }\n}", + "importExample": "$ terraform import cloudflare_zone_subscription.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Identifier" + } + ], + "optional": [ + { + "name": "frequency", + "type": "String", + "description": "How often the subscription is renewed automatically.\nAvailable values: \"weekly\", \"monthly\", \"quarterly\", \"yearly\".\nNote: Some plans may not support frequency configuration and will return \"not-applicable\"." + }, + { + "name": "rate_plan", + "type": "Attributes", + "description": "The rate plan applied to the subscription.", + "children": [ + { + "name": "currency", + "type": "String", + "description": "The currency applied to the rate plan subscription." + }, + { + "name": "externally_managed", + "type": "Boolean", + "description": "Whether this rate plan is managed externally from Cloudflare." + }, + { + "name": "id", + "type": "String", + "description": "The ID of the rate plan.\nAvailable values: \"free\", \"lite\", \"pro\", \"pro_plus\", \"business\", \"enterprise\", \"partners_free\", \"partners_pro\", \"partners_business\", \"partners_enterprise\", \"partners_ent\"." + }, + { + "name": "is_contract", + "type": "Boolean", + "description": "Whether a rate plan is enterprise-based (or newly adopted term contract)." + }, + { + "name": "public_name", + "type": "String", + "description": "The full name of the rate plan." + }, + { + "name": "scope", + "type": "String", + "description": "The scope that this rate plan applies to." + }, + { + "name": "sets", + "type": "List of String", + "description": "The list of sets this rate plan applies to. Returns array of strings." + } + ] + } + ], + "computed": [ + { + "name": "currency", + "type": "String", + "description": "The monetary unit in which pricing information is displayed." + }, + { + "name": "current_period_end", + "type": "String", + "description": "The end of the current period and also when the next billing is due." + }, + { + "name": "current_period_start", + "type": "String", + "description": "When the current billing period started. May match initial_period_start if this is the first period." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "price", + "type": "Number", + "description": "The price of the subscription that will be billed, in US dollars." + }, + { + "name": "state", + "type": "String", + "description": "The state that the subscription is in.\nAvailable values: \"Trial\", \"Provisioned\", \"Paid\", \"AwaitingPayment\", \"Cancelled\", \"Failed\", \"Expired\"." + } + ] + }, + "data-source:cloudflare_zone_tracing": { + "kind": "data-source", + "name": "cloudflare_zone_tracing", + "example": "data \"cloudflare_zone_tracing\" \"example_zone_tracing\" {\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Specify the zone ID." + } + ], + "optional": [], + "computed": [ + { + "name": "destinations", + "type": "List of String", + "description": "Up to 100 OpenTelemetry destination identifiers that receive traces." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Cloudflare Traces is enabled for the zone." + }, + { + "name": "forward_context", + "type": "Boolean", + "description": "Whether trace context is sent externally or across a zone boundary." + }, + { + "name": "id", + "type": "String", + "description": "Specify the zone ID." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether traces are persisted in Cloudflare." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "When inbound trace context may be continued. Authenticated propagation is not supported yet.\nAvailable values: \"accept\", \"authenticated\", \"reject\"." + }, + { + "name": "sampling_ratio", + "type": "Number", + "description": "The ratio of requests sampled for tracing, from 0 to 1." + } + ] + }, + "resource:cloudflare_zone_tracing": { + "kind": "resource", + "name": "cloudflare_zone_tracing", + "example": "resource \"cloudflare_zone_tracing\" \"example_zone_tracing\" {\n zone_id = \"zone_id\"\n destinations = [\"x\"]\n enabled = true\n forward_context = true\n persist = true\n propagation_policy = \"accept\"\n sampling_ratio = 0\n}", + "importExample": "$ terraform import cloudflare_zone_tracing.example ''", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Specify the zone ID." + } + ], + "optional": [ + { + "name": "destinations", + "type": "List of String", + "description": "Up to 100 OpenTelemetry destination identifiers that receive traces." + }, + { + "name": "enabled", + "type": "Boolean", + "description": "Whether Cloudflare Traces is enabled for the zone." + }, + { + "name": "forward_context", + "type": "Boolean", + "description": "Whether trace context is sent externally or across a zone boundary." + }, + { + "name": "persist", + "type": "Boolean", + "description": "Whether traces are persisted in Cloudflare." + }, + { + "name": "propagation_policy", + "type": "String", + "description": "When inbound trace context may be continued. Authenticated propagation is not supported yet.\nAvailable values: \"accept\", \"authenticated\", \"reject\"." + }, + { + "name": "sampling_ratio", + "type": "Number", + "description": "The ratio of requests sampled for tracing, from 0 to 1." + } + ], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Specify the zone ID." + } + ] + }, + "data-source:cloudflare_zone_tracing_rules": { + "kind": "data-source", + "name": "cloudflare_zone_tracing_rules", + "example": "data \"cloudflare_zone_tracing_rules\" \"example_zone_tracing_rules\" {\n zone_id = \"zone_id\"\n}", + "required": [ + { + "name": "zone_id", + "type": "String", + "description": "Specify the zone ID." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Specify the zone ID." + }, + { + "name": "rules", + "type": "Attributes List", + "description": "Trace rules in evaluation order.", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"set_trace_settings\"." + }, + { + "name": "action_parameters", + "type": "Attributes", + "children": [ + { + "name": "sampling_ratio", + "type": "Number", + "description": "The ratio of requests sampled for tracing, from 0 to 1." + } + ] + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "expression", + "type": "String", + "description": "A Rules language expression that selects requests." + } + ] + } + ] + }, + "resource:cloudflare_zone_tracing_rules": { + "kind": "resource", + "name": "cloudflare_zone_tracing_rules", + "example": "resource \"cloudflare_zone_tracing_rules\" \"example_zone_tracing_rules\" {\n zone_id = \"zone_id\"\n rules = [{\n action = \"set_trace_settings\"\n action_parameters = {\n sampling_ratio = 0\n }\n description = \"description\"\n enabled = true\n expression = \"x\"\n }]\n}", + "importExample": "$ terraform import cloudflare_zone_tracing_rules.example ''", + "required": [ + { + "name": "rules", + "type": "Attributes List", + "description": "Trace rules in evaluation order.", + "children": [ + { + "name": "action", + "type": "String", + "description": "Available values: \"set_trace_settings\"." + }, + { + "name": "action_parameters", + "type": "Attributes", + "children": [ + { + "name": "sampling_ratio", + "type": "Number", + "description": "The ratio of requests sampled for tracing, from 0 to 1." + } + ] + }, + { + "name": "description", + "type": "String" + }, + { + "name": "enabled", + "type": "Boolean" + }, + { + "name": "expression", + "type": "String", + "description": "A Rules language expression that selects requests." + } + ] + }, + { + "name": "zone_id", + "type": "String", + "description": "Specify the zone ID." + } + ], + "optional": [], + "computed": [ + { + "name": "id", + "type": "String", + "description": "Specify the zone ID." + } + ] + }, + "list-data-source:cloudflare_zones": { + "kind": "list-data-source", + "name": "cloudflare_zones", + "description": "Accepted Permissions\n\n- `Zone Zone Read`", + "example": "data \"cloudflare_zones\" \"example_zones\" {\n account = {\n id = \"id\"\n name = \"name\"\n }\n direction = \"desc\"\n name = \"name\"\n order = \"status\"\n status = \"initializing\"\n type = [\"full\"]\n}", + "required": [], + "optional": [ + { + "name": "account", + "type": "Attributes", + "children": [ + { + "name": "id", + "type": "String", + "description": "Filter by an account ID." + }, + { + "name": "name", + "type": "String", + "description": "An account Name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`" + } + ] + }, + { + "name": "direction", + "type": "String", + "description": "Direction to order zones.\nAvailable values: \"asc\", \"desc\"." + }, + { + "name": "match", + "type": "String", + "description": "Whether to match all search requirements or at least one (any).\nAvailable values: \"any\", \"all\"." + }, + { + "name": "max_items", + "type": "Number", + "description": "Max items to fetch, default: 1000" + }, + { + "name": "name", + "type": "String", + "description": "A domain name. Optional filter operators can be provided to extend refine the search:\n * `equal` (default)\n * `not_equal`\n * `starts_with`\n * `ends_with`\n * `contains`\n * `starts_with_case_sensitive`\n * `ends_with_case_sensitive`\n * `contains_case_sensitive`" + }, + { + "name": "order", + "type": "String", + "description": "Field to order zones by.\nAvailable values: \"name\", \"status\", \"account.id\", \"account.name\", \"plan.id\"." + }, + { + "name": "status", + "type": "String", + "description": "Specify a zone status to filter by.\nAvailable values: \"initializing\", \"pending\", \"active\", \"moved\"." + }, + { + "name": "type", + "type": "List of String", + "description": "Zone types to filter by. Multiple types can be specified as a comma-separated list (e.g., ?type=full,partial,secondary). When this parameter is not provided, zones with type \"internal\" are excluded from the results." + } + ], + "computed": [ + { + "name": "result", + "type": "Attributes List", + "description": "The items returned by the data source", + "children": [ + { + "name": "account", + "type": "Attributes", + "description": "The account the zone belongs to.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "The name of the account." + } + ] + }, + { + "name": "activated_on", + "type": "String", + "description": "The last time proof of ownership was detected and the zone was made\nactive." + }, + { + "name": "cname_suffix", + "type": "String", + "description": "Allows the customer to use a custom apex.\n*Tenants Only Configuration*." + }, + { + "name": "created_on", + "type": "String", + "description": "When the zone was created." + }, + { + "name": "development_mode", + "type": "Number", + "description": "The interval (in seconds) from when development mode expires\n(positive integer) or last expired (negative integer) for the\ndomain. If development mode has never been enabled, this value is 0." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "meta", + "type": "Attributes", + "description": "Metadata about the zone.", + "children": [ + { + "name": "cdn_only", + "type": "Boolean", + "description": "The zone is only configured for CDN." + }, + { + "name": "custom_certificate_quota", + "type": "Number", + "description": "Number of Custom Certificates the zone can have." + }, + { + "name": "dns_only", + "type": "Boolean", + "description": "The zone is only configured for DNS." + }, + { + "name": "foundation_dns", + "type": "Boolean", + "description": "The zone is setup with Foundation DNS." + }, + { + "name": "page_rule_quota", + "type": "Number", + "description": "Number of Page Rules a zone can have." + }, + { + "name": "phishing_detected", + "type": "Boolean", + "description": "The zone has been flagged for phishing." + }, + { + "name": "step", + "type": "Number" + } + ] + }, + { + "name": "modified_on", + "type": "String", + "description": "When the zone was last modified." + }, + { + "name": "name", + "type": "String", + "description": "The domain name. Per [RFC 1035](https://datatracker.ietf.org/doc/html/rfc1035#section-2.3.4) the overall zone name can be up to 253 characters, with each segment (\"label\") not exceeding 63 characters." + }, + { + "name": "name_servers", + "type": "List of String", + "description": "The name servers Cloudflare assigns to a zone." + }, + { + "name": "original_dnshost", + "type": "String", + "description": "DNS host at the time of switching to Cloudflare." + }, + { + "name": "original_name_servers", + "type": "List of String", + "description": "Original name servers before moving to Cloudflare." + }, + { + "name": "original_registrar", + "type": "String", + "description": "Registrar for the domain at the time of switching to Cloudflare." + }, + { + "name": "owner", + "type": "Attributes", + "description": "The owner of the zone.", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "Name of the owner." + }, + { + "name": "type", + "type": "String", + "description": "The type of owner." + } + ] + }, + { + "name": "paused", + "type": "Boolean", + "description": "Indicates whether the zone is only using Cloudflare DNS services. A\ntrue value means the zone will not receive security or performance\nbenefits." + }, + { + "name": "permissions", + "type": "List of String", + "description": "Legacy permissions based on legacy user membership information.", + "deprecated": "Deprecated." + }, + { + "name": "plan", + "type": "Attributes", + "description": "A Zones subscription information.", + "deprecated": "Deprecated.", + "children": [ + { + "name": "can_subscribe", + "type": "Boolean", + "description": "States if the subscription can be activated." + }, + { + "name": "currency", + "type": "String", + "description": "The denomination of the customer." + }, + { + "name": "externally_managed", + "type": "Boolean", + "description": "If this Zone is managed by another company." + }, + { + "name": "frequency", + "type": "String", + "description": "How often the customer is billed." + }, + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "is_subscribed", + "type": "Boolean", + "description": "States if the subscription active." + }, + { + "name": "legacy_discount", + "type": "Boolean", + "description": "If the legacy discount applies to this Zone." + }, + { + "name": "legacy_id", + "type": "String", + "description": "The legacy name of the plan." + }, + { + "name": "name", + "type": "String", + "description": "Name of the owner." + }, + { + "name": "price", + "type": "Number", + "description": "How much the customer is paying." + } + ] + }, + { + "name": "status", + "type": "String", + "description": "The zone status on Cloudflare.\nAvailable values: \"initializing\", \"pending\", \"active\", \"moved\"." + }, + { + "name": "tenant", + "type": "Attributes", + "description": "The root organizational unit that this zone belongs to (such as a tenant or organization).", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + }, + { + "name": "name", + "type": "String", + "description": "The name of the Tenant account." + } + ] + }, + { + "name": "tenant_unit", + "type": "Attributes", + "description": "The immediate parent organizational unit that this zone belongs to (such as under a tenant or sub-organization).", + "children": [ + { + "name": "id", + "type": "String", + "description": "Identifier" + } + ] + }, + { + "name": "type", + "type": "String", + "description": "A full zone implies that DNS is hosted with Cloudflare. A partial zone is\ntypically a partner-hosted zone or a CNAME setup.\nAvailable values: \"full\", \"partial\", \"secondary\", \"internal\"." + }, + { + "name": "vanity_name_servers", + "type": "List of String", + "description": "An array of domains used for custom name servers. This is only available for Business and Enterprise plans." + }, + { + "name": "verification_key", + "type": "String", + "description": "Verification key for partial zone setup." + } + ] + } + ] + } + }, + "endpoints": { + "delete /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_application", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}/ca": [ + { + "declaration": "resource:cloudflare_zero_trust_access_short_lived_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/access/certificates/{certificate_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_mtls_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/access/groups/{group_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_group", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers/{identity_provider_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_identity_provider", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens/{service_token_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_service_token", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/custom_csrs/{custom_csr_id}": [ + { + "declaration": "resource:cloudflare_custom_csr", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets/{asset_name}": [ + { + "declaration": "resource:cloudflare_custom_page_asset", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_access_rule", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/load_balancers/{load_balancer_id}": [ + { + "declaration": "resource:cloudflare_load_balancer", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs/{job_id}": [ + { + "declaration": "resource:cloudflare_logpush_job", + "roles": [ + "delete" + ] + } + ], + "delete /{accounts_or_zones}/{account_or_zone_id}/rulesets/{ruleset_id}": [ + { + "declaration": "resource:cloudflare_ruleset", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}": [ + { + "declaration": "resource:cloudflare_account", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/access/ai-controls/mcp/portals/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_portal", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/access/ai-controls/mcp/servers/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_server", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/access/custom_pages/{custom_page_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_custom_page", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/access/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_policy", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/access/tags/{tag_name}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_tag", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/addressing/address_maps/{address_map_id}": [ + { + "declaration": "resource:cloudflare_address_map", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/addressing/prefixes/{prefix_id}": [ + { + "declaration": "resource:cloudflare_byo_ip_prefix", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/ai-gateway/gateways/{gateway_id}/routes/{id}": [ + { + "declaration": "resource:cloudflare_ai_gateway_dynamic_routing", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/ai-gateway/gateways/{id}": [ + { + "declaration": "resource:cloudflare_ai_gateway", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/ai-search/instances/{id}": [ + { + "declaration": "resource:cloudflare_ai_search_instance", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/ai-search/namespaces/{name}": [ + { + "declaration": "resource:cloudflare_ai_search_namespace", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/ai-search/tokens/{id}": [ + { + "declaration": "resource:cloudflare_ai_search_token", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/alerting/v3/destinations/webhooks/{webhook_id}": [ + { + "declaration": "resource:cloudflare_notification_policy_webhooks", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/alerting/v3/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_notification_policy", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/calls/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_calls_sfu_app", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/calls/turn_keys/{key_id}": [ + { + "declaration": "resource:cloudflare_calls_turn_app", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/cfd_tunnel/{tunnel_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/challenges/widgets/{sitekey}": [ + { + "declaration": "resource:cloudflare_turnstile_widget", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/cloudforce-one/requests/{request_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/cloudforce-one/requests/{request_id}/asset/{asset_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_asset", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/cloudforce-one/requests/{request_id}/message/{message_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_message", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/cloudforce-one/requests/priority/{priority_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_priority", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/connectivity/directory/services/{service_id}": [ + { + "declaration": "resource:cloudflare_connectivity_directory_service", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/d1/database/{database_id}": [ + { + "declaration": "resource:cloudflare_d1_database", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/data-security/posture/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_policy", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/data-security/posture/webhooks/{webhook_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_webhook", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/devices/deployment-groups/{group_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_deployment_groups", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/devices/ip-profiles/{profile_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_ip_profile", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/devices/networks/{network_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_managed_networks", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/devices/policy/{policy_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_custom_profile", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/devices/posture/{rule_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_posture_rule", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/devices/posture/integration/{integration_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_posture_integration", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/devices/settings": [ + { + "declaration": "resource:cloudflare_zero_trust_device_settings", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dex/devices/dex_tests/{dex_test_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dex_test", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dex/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dex_rule", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/data_classes/{data_class_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_class", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/data_tag_categories/{category_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag_category", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/data_tag_categories/{category_id}/data_tags/{tag_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/datasets/{dataset_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_dataset", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/entries/{entry_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_entry", + "roles": [ + "delete" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_entry", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/entries/integration/{entry_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_integration_entry", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/entries/predefined/{entry_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_predefined_entry", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/profiles/custom/{profile_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_profile", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/profiles/predefined/{profile_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_predefined_profile", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_group", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}/levels/{sensitivity_level_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_level", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dlp/settings": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_settings", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dls/regional_services/prefix_bindings/{binding_id}": [ + { + "declaration": "resource:cloudflare_dls_prefix_binding", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dns_firewall/{dns_firewall_id}": [ + { + "declaration": "resource:cloudflare_dns_firewall", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/dns_settings/views/{view_id}": [ + { + "declaration": "resource:cloudflare_account_dns_settings_internal_view", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/email-security/settings/allow_policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_email_security_allow_policy", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/email-security/settings/block_senders/{pattern_id}": [ + { + "declaration": "resource:cloudflare_email_security_block_sender", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/email-security/settings/domains/{domain_id}": [ + { + "declaration": "resource:cloudflare_email_security_domain", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/email-security/settings/impersonation_registry/{impersonation_registry_id}": [ + { + "declaration": "resource:cloudflare_email_security_impersonation_registry", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/email-security/settings/trusted_domains/{trusted_domain_id}": [ + { + "declaration": "resource:cloudflare_email_security_trusted_domains", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/email/routing/addresses/{destination_address_identifier}": [ + { + "declaration": "resource:cloudflare_email_routing_address", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/event_notifications/r2/{bucket_name}/configuration/queues/{queue_id}": [ + { + "declaration": "resource:cloudflare_r2_bucket_event_notification", + "roles": [ + "update", + "delete" + ] + } + ], + "delete /accounts/{account_id}/field_extractors/{extractor}": [ + { + "declaration": "resource:cloudflare_field_extractor", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/flagship/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_flagship_app", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/flagship/apps/{app_id}/flags/{flag_key}": [ + { + "declaration": "resource:cloudflare_flagship_flag", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/gateway/certificates/{certificate_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/gateway/lists/{list_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_list", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/gateway/locations/{location_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dns_location", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/gateway/pacfiles/{pacfile_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_pacfile", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/gateway/proxy_endpoints/{proxy_endpoint_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_proxy_endpoint", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/gateway/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_policy", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/hyperdrive/configs/{hyperdrive_id}": [ + { + "declaration": "resource:cloudflare_hyperdrive_config", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/iam/user_groups/{user_group_id}": [ + { + "declaration": "resource:cloudflare_user_group", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/images/v1/{image_id}": [ + { + "declaration": "resource:cloudflare_image", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/images/v1/variants/{variant_id}": [ + { + "declaration": "resource:cloudflare_image_variant", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/infrastructure/targets/{target_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_infrastructure_target", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/load_balancers/monitor_groups/{monitor_group_id}": [ + { + "declaration": "resource:cloudflare_load_balancer_monitor_group", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/load_balancers/monitors/{monitor_id}": [ + { + "declaration": "resource:cloudflare_load_balancer_monitor", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/load_balancers/pools/{pool_id}": [ + { + "declaration": "resource:cloudflare_load_balancer_pool", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/bgp/filter_profiles/{profile_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_bgp_filter_profile", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/cf1_sites/{cf1_site_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_cf1_site", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/connectors/{connector_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_connector", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/gre_tunnels/{gre_tunnel_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_gre_tunnel", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_ipsec_tunnel", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/routes/{route_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_static_route", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/sites/{site_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/sites/{site_id}/acls/{acl_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site_acl", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/sites/{site_id}/lans/{lan_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site_lan", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/magic/sites/{site_id}/wans/{wan_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site_wan", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/members/{member_id}": [ + { + "declaration": "resource:cloudflare_account_member", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/mnm/config": [ + { + "declaration": "resource:cloudflare_magic_network_monitoring_configuration", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/mnm/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_magic_network_monitoring_rule", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/moq/relays/{relay_id}": [ + { + "declaration": "resource:cloudflare_moq_relay", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/mtls_certificates/{mtls_certificate_id}": [ + { + "declaration": "resource:cloudflare_mtls_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/oauth_clients/{oauth_client_id}": [ + { + "declaration": "resource:cloudflare_oauth_client", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/one/integrations/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_integration", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/pages/projects/{project_name}": [ + { + "declaration": "resource:cloudflare_pages_project", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/pages/projects/{project_name}/domains/{domain_name}": [ + { + "declaration": "resource:cloudflare_pages_domain", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/pipelines/v1/pipelines/{pipeline_id}": [ + { + "declaration": "resource:cloudflare_pipeline", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/pipelines/v1/sinks/{sink_id}": [ + { + "declaration": "resource:cloudflare_pipeline_sink", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/pipelines/v1/streams/{stream_id}": [ + { + "declaration": "resource:cloudflare_pipeline_stream", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/queues/{queue_id}": [ + { + "declaration": "resource:cloudflare_queue", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/queues/{queue_id}/consumers/{consumer_id}": [ + { + "declaration": "resource:cloudflare_queue_consumer", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/r2/buckets/{bucket_name}": [ + { + "declaration": "resource:cloudflare_r2_bucket", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/r2/buckets/{bucket_name}/cors": [ + { + "declaration": "resource:cloudflare_r2_bucket_cors", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom/{domain}": [ + { + "declaration": "resource:cloudflare_r2_custom_domain", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/r2/buckets/{bucket_name}/sippy": [ + { + "declaration": "resource:cloudflare_r2_bucket_sippy", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/resource-library/applications/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_resource_library_application", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/rules/lists/{list_id}": [ + { + "declaration": "resource:cloudflare_list", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/rules/lists/{list_id}/items": [ + { + "declaration": "resource:cloudflare_list_item", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/rum/site_info/{site_id}": [ + { + "declaration": "resource:cloudflare_web_analytics_site", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/rum/v2/{ruleset_id}/rule/{rule_id}": [ + { + "declaration": "resource:cloudflare_web_analytics_rule", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/secondary_dns/acls/{acl_id}": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_acl", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/secondary_dns/peers/{peer_id}": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_peer", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/secondary_dns/tsigs/{tsig_id}": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_tsig", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/secrets_store/stores/{store_id}": [ + { + "declaration": "resource:cloudflare_secrets_store", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/secrets_store/stores/{store_id}/secrets/{secret_id}": [ + { + "declaration": "resource:cloudflare_secrets_store_secret", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/shares/{share_id}": [ + { + "declaration": "resource:cloudflare_share", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/shares/{share_id}/recipients/{recipient_id}": [ + { + "declaration": "resource:cloudflare_share_recipient", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/shares/{share_id}/resources/{share_resource_id}": [ + { + "declaration": "resource:cloudflare_share_resource", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/sso_connectors/{sso_connector_id}": [ + { + "declaration": "resource:cloudflare_sso_connector", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/storage/kv/namespaces/{namespace_id}": [ + { + "declaration": "resource:cloudflare_workers_kv_namespace", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name}": [ + { + "declaration": "resource:cloudflare_workers_kv", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/{identifier}": [ + { + "declaration": "resource:cloudflare_stream", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/{identifier}/audio/{audio_identifier}": [ + { + "declaration": "resource:cloudflare_stream_audio_track", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/{identifier}/captions/{language}": [ + { + "declaration": "resource:cloudflare_stream_caption_language", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/{identifier}/downloads": [ + { + "declaration": "resource:cloudflare_stream_download", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/keys/{identifier}": [ + { + "declaration": "resource:cloudflare_stream_key", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/live_inputs/{live_input_identifier}": [ + { + "declaration": "resource:cloudflare_stream_live_input", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/watermarks/{identifier}": [ + { + "declaration": "resource:cloudflare_stream_watermark", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/stream/webhook": [ + { + "declaration": "resource:cloudflare_stream_webhook", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/subscriptions/{subscription_identifier}": [ + { + "declaration": "resource:cloudflare_account_subscription", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/teamnet/routes/{route_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_route", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/teamnet/virtual_networks/{virtual_network_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/tokens/{token_id}": [ + { + "declaration": "resource:cloudflare_account_token", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential_set", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}/credentials/{credential_id}": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/vuln_scanner/target_environments/{target_environment_id}": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_target_environment", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/warp_connector/{tunnel_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_warp_connector", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}": [ + { + "declaration": "resource:cloudflare_workers_for_platforms_dispatch_namespace", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/workers/domains/{domain_id}": [ + { + "declaration": "resource:cloudflare_workers_custom_domain", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/workers/scripts/{script_name}": [ + { + "declaration": "resource:cloudflare_workers_script", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/workers/scripts/{script_name}/subdomain": [ + { + "declaration": "resource:cloudflare_workers_script_subdomain", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/workers/workers/{worker_id}": [ + { + "declaration": "resource:cloudflare_worker", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/workflows/{workflow_name}": [ + { + "declaration": "resource:cloudflare_workflow", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/zerotrust/routes/hostname/{hostname_route_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_network_hostname_route", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/zerotrust/subnets/warp/{subnet_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_subnet", + "roles": [ + "delete" + ] + } + ], + "delete /accounts/{account_id}/zt_risk_scoring/integrations/{integration_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_risk_scoring_integration", + "roles": [ + "delete" + ] + } + ], + "delete /certificates/{certificate_id}": [ + { + "declaration": "resource:cloudflare_origin_ca_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /organizations/{organization_id}": [ + { + "declaration": "resource:cloudflare_organization", + "roles": [ + "delete" + ] + } + ], + "delete /user/tokens/{token_id}": [ + { + "declaration": "resource:cloudflare_api_token", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}": [ + { + "declaration": "resource:cloudflare_zone", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/acm/custom_trust_store/{custom_origin_trust_store_id}": [ + { + "declaration": "resource:cloudflare_custom_origin_trust_store", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/addressing/regional_hostnames/{hostname}": [ + { + "declaration": "resource:cloudflare_regional_hostname", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/api_gateway/operations/{operation_id}": [ + { + "declaration": "resource:cloudflare_api_shield_operation", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/api_gateway/user_schemas/{schema_id}": [ + { + "declaration": "resource:cloudflare_api_shield_schema", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/cache/tiered_cache_smart_topology_enable": [ + { + "declaration": "resource:cloudflare_tiered_cache", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/cache/variants": [ + { + "declaration": "resource:cloudflare_zone_cache_variants", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/client_certificates/{client_certificate_id}": [ + { + "declaration": "resource:cloudflare_client_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/content-upload-scan/payloads/{expression_id}": [ + { + "declaration": "resource:cloudflare_content_scanning_expression", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/custom_certificates/{custom_certificate_id}": [ + { + "declaration": "resource:cloudflare_custom_ssl", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/custom_hostnames/{custom_hostname_id}": [ + { + "declaration": "resource:cloudflare_custom_hostname", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/custom_hostnames/fallback_origin": [ + { + "declaration": "resource:cloudflare_custom_hostname_fallback_origin", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/dns_records/{dns_record_id}": [ + { + "declaration": "resource:cloudflare_dns_record", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/dnssec": [ + { + "declaration": "resource:cloudflare_zone_dnssec", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/email/routing/dns": [ + { + "declaration": "resource:cloudflare_email_routing_dns", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/email/routing/rules/{rule_identifier}": [ + { + "declaration": "resource:cloudflare_email_routing_rule", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/email/sending/subdomains/{subdomain_id}": [ + { + "declaration": "resource:cloudflare_email_sending_subdomain", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/filters/{filter_id}": [ + { + "declaration": "resource:cloudflare_filter", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/firewall/lockdowns/{lock_downs_id}": [ + { + "declaration": "resource:cloudflare_zone_lockdown", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/firewall/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_firewall_rule", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/firewall/ua_rules/{ua_rule_id}": [ + { + "declaration": "resource:cloudflare_user_agent_blocking_rule", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/healthchecks/{healthcheck_id}": [ + { + "declaration": "resource:cloudflare_healthcheck", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/hold": [ + { + "declaration": "resource:cloudflare_zone_hold", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/hostnames/settings/{setting_id}/{hostname}": [ + { + "declaration": "resource:cloudflare_hostname_tls_setting", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/keyless_certificates/{keyless_certificate_id}": [ + { + "declaration": "resource:cloudflare_keyless_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/leaked-credential-checks/detections/{detection_id}": [ + { + "declaration": "resource:cloudflare_leaked_credential_check_rule", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/managed_headers": [ + { + "declaration": "resource:cloudflare_managed_transforms", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/observability/tracing/rules": [ + { + "declaration": "resource:cloudflare_zone_tracing_rules", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/observability/tracing/settings": [ + { + "declaration": "resource:cloudflare_zone_tracing", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/origin_tls_client_auth/{certificate_id}": [ + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/origin_tls_client_auth/hostnames/certificates/{certificate_id}": [ + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_hostname_certificate", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/origin/cloud_regions/{origin_ip}": [ + { + "declaration": "resource:cloudflare_origin_cloud_region", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/page_shield/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_page_shield_policy", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/pagerules/{pagerule_id}": [ + { + "declaration": "resource:cloudflare_page_rule", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/rate_limits/{rate_limit_id}": [ + { + "declaration": "resource:cloudflare_rate_limit", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/schema_validation/schemas/{schema_id}": [ + { + "declaration": "resource:cloudflare_schema_validation_schemas", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/schema_validation/settings/operations/{operation_id}": [ + { + "declaration": "resource:cloudflare_schema_validation_operation_settings", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/secondary_dns/incoming": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_incoming", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/secondary_dns/outgoing": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_outgoing", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/settings/origin_tls_compliance_modes": [ + { + "declaration": "resource:cloudflare_origin_tls_compliance_modes", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/snippets/{snippet_name}": [ + { + "declaration": "resource:cloudflare_snippet", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/snippets/snippet_rules": [ + { + "declaration": "resource:cloudflare_snippet_rules", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/spectrum/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_spectrum_application", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/speed_api/schedule/{url}": [ + { + "declaration": "resource:cloudflare_observatory_scheduled_test", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/ssl/certificate_packs/{certificate_pack_id}": [ + { + "declaration": "resource:cloudflare_certificate_pack", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/token_validation/config/{config_id}": [ + { + "declaration": "resource:cloudflare_token_validation_config", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/token_validation/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_token_validation_rules", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/url_normalization": [ + { + "declaration": "resource:cloudflare_url_normalization_settings", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/waiting_rooms/{waiting_room_id}": [ + { + "declaration": "resource:cloudflare_waiting_room", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/waiting_rooms/{waiting_room_id}/events/{event_id}": [ + { + "declaration": "resource:cloudflare_waiting_room_event", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/web3/hostnames/{identifier}": [ + { + "declaration": "resource:cloudflare_web3_hostname", + "roles": [ + "delete" + ] + } + ], + "delete /zones/{zone_id}/workers/routes/{route_id}": [ + { + "declaration": "resource:cloudflare_workers_route", + "roles": [ + "delete" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/apps": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_application", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_access_applications", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_application", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_application", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}/ca": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_short_lived_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_short_lived_certificate", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/apps/ca": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_access_short_lived_certificates", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/certificates": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_access_mtls_certificates", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/certificates/{certificate_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_mtls_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_mtls_certificate", + "roles": [ + "read", + "delete", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/certificates/settings": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_mtls_hostname_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_mtls_hostname_settings", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/groups": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_group", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_access_groups", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/groups/{group_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_group", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_group", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_identity_provider", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_access_identity_providers", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers/{identity_provider_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_identity_provider", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_identity_provider", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/organizations": [ + { + "declaration": "data-source:cloudflare_zero_trust_organization", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_organization", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_service_token", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_access_service_tokens", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens/{service_token_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_service_token", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_service_token", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/custom_csrs": [ + { + "declaration": "data-source:cloudflare_custom_csr", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_custom_csrs", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/custom_csrs/{custom_csr_id}": [ + { + "declaration": "data-source:cloudflare_custom_csr", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_custom_csr", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/custom_pages": [ + { + "declaration": "list-data-source:cloudflare_custom_pages_list", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/{identifier}": [ + { + "declaration": "data-source:cloudflare_custom_pages", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_custom_pages", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets": [ + { + "declaration": "list-data-source:cloudflare_custom_page_assets", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets/{asset_name}": [ + { + "declaration": "data-source:cloudflare_custom_page_asset", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_custom_page_asset", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/email/routing/rules": [ + { + "declaration": "data-source:cloudflare_email_routing_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_email_routing_rules", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules": [ + { + "declaration": "data-source:cloudflare_access_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_access_rules", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules/{rule_id}": [ + { + "declaration": "data-source:cloudflare_access_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_access_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/load_balancers": [ + { + "declaration": "list-data-source:cloudflare_load_balancers", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/load_balancers/{load_balancer_id}": [ + { + "declaration": "data-source:cloudflare_load_balancer", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_load_balancer", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/logpush/datasets/{dataset_id}/fields": [ + { + "declaration": "data-source:cloudflare_logpush_dataset_field", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/logpush/datasets/{dataset_id}/jobs": [ + { + "declaration": "data-source:cloudflare_logpush_dataset_job", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs": [ + { + "declaration": "list-data-source:cloudflare_logpush_jobs", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs/{job_id}": [ + { + "declaration": "data-source:cloudflare_logpush_job", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_logpush_job", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/rulesets": [ + { + "declaration": "list-data-source:cloudflare_rulesets", + "roles": [ + "read" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/rulesets/{ruleset_id}": [ + { + "declaration": "data-source:cloudflare_ruleset", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_ruleset", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/subscriptions": [ + { + "declaration": "data-source:cloudflare_account_subscription", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_account_subscription", + "roles": [ + "read", + "import" + ] + } + ], + "get /{accounts_or_zones}/{account_or_zone_id}/waiting_rooms": [ + { + "declaration": "list-data-source:cloudflare_waiting_rooms", + "roles": [ + "read" + ] + } + ], + "get /accounts": [ + { + "declaration": "data-source:cloudflare_account", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_accounts", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}": [ + { + "declaration": "data-source:cloudflare_account", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_account", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/access/ai-controls/mcp/portals": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_ai_controls_mcp_portal", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_access_ai_controls_mcp_portals", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/access/ai-controls/mcp/portals/{id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_ai_controls_mcp_portal", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_portal", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/access/ai-controls/mcp/servers": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_ai_controls_mcp_server", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_access_ai_controls_mcp_servers", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/access/ai-controls/mcp/servers/{id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_ai_controls_mcp_server", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_server", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/access/custom_pages": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_access_custom_pages", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/access/custom_pages/{custom_page_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_custom_page", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_custom_page", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/access/keys": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_key_configuration", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_key_configuration", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/access/policies": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_access_policies", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/access/policies/{policy_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_policy", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/access/tags": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_access_tags", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/access/tags/{tag_name}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_tag", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_tag", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/addressing/address_maps": [ + { + "declaration": "list-data-source:cloudflare_address_maps", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/addressing/address_maps/{address_map_id}": [ + { + "declaration": "data-source:cloudflare_address_map", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_address_map", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/addressing/prefixes": [ + { + "declaration": "list-data-source:cloudflare_byo_ip_prefixes", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/addressing/prefixes/{prefix_id}": [ + { + "declaration": "data-source:cloudflare_byo_ip_prefix", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_byo_ip_prefix", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/ai-gateway/gateways": [ + { + "declaration": "data-source:cloudflare_ai_gateway", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_ai_gateways", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/ai-gateway/gateways/{gateway_id}/routes/{id}": [ + { + "declaration": "data-source:cloudflare_ai_gateway_dynamic_routing", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_ai_gateway_dynamic_routing", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/ai-gateway/gateways/{id}": [ + { + "declaration": "data-source:cloudflare_ai_gateway", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_ai_gateway", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/ai-search/instances": [ + { + "declaration": "data-source:cloudflare_ai_search_instance", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_ai_search_instances", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/ai-search/instances/{id}": [ + { + "declaration": "data-source:cloudflare_ai_search_instance", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_ai_search_instance", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/ai-search/namespaces": [ + { + "declaration": "list-data-source:cloudflare_ai_search_namespaces", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/ai-search/namespaces/{name}": [ + { + "declaration": "data-source:cloudflare_ai_search_namespace", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_ai_search_namespace", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/ai-search/tokens": [ + { + "declaration": "data-source:cloudflare_ai_search_token", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_ai_search_tokens", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/ai-search/tokens/{id}": [ + { + "declaration": "data-source:cloudflare_ai_search_token", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_ai_search_token", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/alerting/v3/destinations/webhooks": [ + { + "declaration": "list-data-source:cloudflare_notification_policy_webhooks_list", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/alerting/v3/destinations/webhooks/{webhook_id}": [ + { + "declaration": "data-source:cloudflare_notification_policy_webhooks", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_notification_policy_webhooks", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/alerting/v3/policies": [ + { + "declaration": "list-data-source:cloudflare_notification_policies", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/alerting/v3/policies/{policy_id}": [ + { + "declaration": "data-source:cloudflare_notification_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_notification_policy", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/botnet_feed/configs/asn": [ + { + "declaration": "data-source:cloudflare_botnet_feed_config_asn", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/calls/apps": [ + { + "declaration": "list-data-source:cloudflare_calls_sfu_apps", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/calls/apps/{app_id}": [ + { + "declaration": "data-source:cloudflare_calls_sfu_app", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_calls_sfu_app", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/calls/turn_keys": [ + { + "declaration": "list-data-source:cloudflare_calls_turn_apps", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/calls/turn_keys/{key_id}": [ + { + "declaration": "data-source:cloudflare_calls_turn_app", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_calls_turn_app", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/cfd_tunnel": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_tunnel_cloudflareds", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/cfd_tunnel/{tunnel_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/cfd_tunnel/{tunnel_id}/configurations": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared_config", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_config", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/cfd_tunnel/{tunnel_id}/token": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared_token", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/challenges/widgets": [ + { + "declaration": "data-source:cloudflare_turnstile_widget", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_turnstile_widgets", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/challenges/widgets/{sitekey}": [ + { + "declaration": "data-source:cloudflare_turnstile_widget", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_turnstile_widget", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/cloudforce-one/requests/{request_id}": [ + { + "declaration": "data-source:cloudflare_cloudforce_one_request", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_cloudforce_one_request", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/cloudforce-one/requests/{request_id}/asset/{asset_id}": [ + { + "declaration": "data-source:cloudflare_cloudforce_one_request_asset", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_cloudforce_one_request_asset", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/cloudforce-one/requests/priority/{priority_id}": [ + { + "declaration": "data-source:cloudflare_cloudforce_one_request_priority", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_cloudforce_one_request_priority", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/connectivity/directory/services": [ + { + "declaration": "data-source:cloudflare_connectivity_directory_service", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_connectivity_directory_services", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/connectivity/directory/services/{service_id}": [ + { + "declaration": "data-source:cloudflare_connectivity_directory_service", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_connectivity_directory_service", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/d1/database": [ + { + "declaration": "data-source:cloudflare_d1_database", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_d1_databases", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/d1/database/{database_id}": [ + { + "declaration": "data-source:cloudflare_d1_database", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_d1_database", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/data-security/posture/policies": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_casb_policies", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/data-security/posture/policies/{policy_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_casb_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_casb_policy", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/data-security/posture/webhooks": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_casb_webhooks", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/data-security/posture/webhooks/{webhook_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_casb_webhook", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_casb_webhook", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/deployment-groups": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_device_deployment_groups_list", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/devices/deployment-groups/{group_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_deployment_groups", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_deployment_groups", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/ip-profiles": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_ip_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_device_ip_profiles", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/devices/ip-profiles/{profile_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_ip_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_ip_profile", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/networks": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_device_managed_networks_list", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/devices/networks/{network_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_managed_networks", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_managed_networks", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/policies": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_custom_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_device_custom_profiles", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/devices/policy": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_default_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_default_profile", + "roles": [ + "read", + "update", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/policy/{policy_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_custom_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_custom_profile", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/policy/{policy_id}/fallback_domains": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_custom_profile_local_domain_fallback", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_custom_profile_local_domain_fallback", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/policy/fallback_domains": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_default_profile_local_domain_fallback", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_default_profile_local_domain_fallback", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/posture": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_device_posture_rules", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/devices/posture/{rule_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_posture_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_posture_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/posture/integration": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_device_posture_integrations", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/devices/posture/integration/{integration_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_posture_integration", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_posture_integration", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/devices/settings": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_settings", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dex/devices/dex_tests": [ + { + "declaration": "data-source:cloudflare_zero_trust_dex_test", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_dex_tests", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dex/devices/dex_tests/{dex_test_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dex_test", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dex_test", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dex/rules": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dex_rules", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dex/rules/{rule_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dex_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dex_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/custom_prompt_topics": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_custom_prompt_topics", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/custom_prompt_topics/{entry_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_custom_prompt_topic", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/data_classes": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_data_classes", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/data_classes/{data_class_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_data_class", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_class", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/data_tag_categories": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_data_tag_categories", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/data_tag_categories/{category_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_data_tag_category", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag_category", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/data_tag_categories/{category_id}/data_tags": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_data_tags", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/data_tag_categories/{category_id}/data_tags/{tag_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_data_tag", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/datasets": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_datasets", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/datasets/{dataset_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_dataset", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_dataset", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/entries": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_custom_entries", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_entries", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_integration_entries", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_predefined_entries", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/entries/{entry_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_custom_entry", + "roles": [ + "read" + ] + }, + { + "declaration": "data-source:cloudflare_zero_trust_dlp_entry", + "roles": [ + "read" + ] + }, + { + "declaration": "data-source:cloudflare_zero_trust_dlp_integration_entry", + "roles": [ + "read" + ] + }, + { + "declaration": "data-source:cloudflare_zero_trust_dlp_predefined_entry", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_entry", + "roles": [ + "read", + "import" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_entry", + "roles": [ + "read", + "import" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_integration_entry", + "roles": [ + "read", + "import" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_predefined_entry", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/profiles/custom/{profile_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_custom_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_profile", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/profiles/predefined/{profile_id}/config": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_predefined_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_predefined_profile", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/sensitivity_groups": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_sensitivity_groups", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_sensitivity_group", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_group", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}/level_order": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_sensitivity_level_order", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_level_order", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}/levels": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_dlp_sensitivity_levels", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}/levels/{sensitivity_level_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_sensitivity_level", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_level", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dlp/settings": [ + { + "declaration": "data-source:cloudflare_zero_trust_dlp_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dls/regional_services/prefix_bindings": [ + { + "declaration": "list-data-source:cloudflare_dls_prefix_bindings", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dls/regional_services/prefix_bindings/{binding_id}": [ + { + "declaration": "data-source:cloudflare_dls_prefix_binding", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dls_prefix_binding", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dns_firewall": [ + { + "declaration": "list-data-source:cloudflare_dns_firewalls", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dns_firewall/{dns_firewall_id}": [ + { + "declaration": "data-source:cloudflare_dns_firewall", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dns_firewall", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/dns_settings": [ + { + "declaration": "data-source:cloudflare_account_dns_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_account_dns_settings", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dns_settings/views": [ + { + "declaration": "data-source:cloudflare_account_dns_settings_internal_view", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_account_dns_settings_internal_views", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/dns_settings/views/{view_id}": [ + { + "declaration": "data-source:cloudflare_account_dns_settings_internal_view", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_account_dns_settings_internal_view", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/allow_policies": [ + { + "declaration": "data-source:cloudflare_email_security_allow_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_email_security_allow_policies", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/allow_policies/{policy_id}": [ + { + "declaration": "data-source:cloudflare_email_security_allow_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_security_allow_policy", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/block_senders": [ + { + "declaration": "data-source:cloudflare_email_security_block_sender", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_email_security_block_senders", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/block_senders/{pattern_id}": [ + { + "declaration": "data-source:cloudflare_email_security_block_sender", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_security_block_sender", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/domains": [ + { + "declaration": "data-source:cloudflare_email_security_domain", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_email_security_domains", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/domains/{domain_id}": [ + { + "declaration": "data-source:cloudflare_email_security_domain", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_security_domain", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/impersonation_registry": [ + { + "declaration": "data-source:cloudflare_email_security_impersonation_registry", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_email_security_impersonation_registries", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/impersonation_registry/{impersonation_registry_id}": [ + { + "declaration": "data-source:cloudflare_email_security_impersonation_registry", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_security_impersonation_registry", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/trusted_domains": [ + { + "declaration": "data-source:cloudflare_email_security_trusted_domains", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_email_security_trusted_domains_list", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/email-security/settings/trusted_domains/{trusted_domain_id}": [ + { + "declaration": "data-source:cloudflare_email_security_trusted_domains", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_security_trusted_domains", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/email/routing/addresses": [ + { + "declaration": "data-source:cloudflare_email_routing_address", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_email_routing_addresses", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/email/routing/addresses/{destination_address_identifier}": [ + { + "declaration": "data-source:cloudflare_email_routing_address", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_routing_address", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/event_notifications/r2/{bucket_name}/configuration/queues/{queue_id}": [ + { + "declaration": "data-source:cloudflare_r2_bucket_event_notification", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_bucket_event_notification", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/field_extractors/{extractor}": [ + { + "declaration": "data-source:cloudflare_field_extractor", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_field_extractor", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/flagship/apps": [ + { + "declaration": "list-data-source:cloudflare_flagship_apps", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/flagship/apps/{app_id}": [ + { + "declaration": "data-source:cloudflare_flagship_app", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_flagship_app", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/flagship/apps/{app_id}/flags": [ + { + "declaration": "data-source:cloudflare_flagship_flag", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_flagship_flags", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/flagship/apps/{app_id}/flags/{flag_key}": [ + { + "declaration": "data-source:cloudflare_flagship_flag", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_flagship_flag", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/app_types": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_gateway_app_types_list", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/categories": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_gateway_categories_list", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/certificates": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_gateway_certificates", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/certificates/{certificate_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_gateway_certificate", + "roles": [ + "create", + "read", + "update", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/configuration": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_gateway_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/lists": [ + { + "declaration": "data-source:cloudflare_zero_trust_list", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_lists", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/lists/{list_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_list", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_list", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/locations": [ + { + "declaration": "data-source:cloudflare_zero_trust_dns_location", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_dns_locations", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/locations/{location_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_dns_location", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dns_location", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/logging": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_logging", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_gateway_logging", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/pacfiles": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_gateway_pacfiles", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/pacfiles/{pacfile_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_pacfile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_gateway_pacfile", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/proxy_endpoints": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_proxy_endpoint", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_gateway_proxy_endpoints", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/proxy_endpoints/{proxy_endpoint_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_proxy_endpoint", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_gateway_proxy_endpoint", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/gateway/rules": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_gateway_policies", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/gateway/rules/{rule_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_gateway_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_gateway_policy", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/hyperdrive/configs": [ + { + "declaration": "list-data-source:cloudflare_hyperdrive_configs", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/hyperdrive/configs/{hyperdrive_id}": [ + { + "declaration": "data-source:cloudflare_hyperdrive_config", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_hyperdrive_config", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/iam/permission_groups": [ + { + "declaration": "list-data-source:cloudflare_account_permission_groups", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/iam/permission_groups/{permission_group_id}": [ + { + "declaration": "data-source:cloudflare_account_permission_group", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/iam/resource_groups": [ + { + "declaration": "list-data-source:cloudflare_resource_groups", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/iam/resource_groups/{resource_group_id}": [ + { + "declaration": "data-source:cloudflare_resource_group", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/iam/user_groups": [ + { + "declaration": "data-source:cloudflare_user_group", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_user_groups", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/iam/user_groups/{user_group_id}": [ + { + "declaration": "data-source:cloudflare_user_group", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_user_group", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/iam/user_groups/{user_group_id}/members": [ + { + "declaration": "data-source:cloudflare_user_group_members", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_user_group_members", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/images/v1": [ + { + "declaration": "list-data-source:cloudflare_images", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/images/v1/{image_id}": [ + { + "declaration": "data-source:cloudflare_image", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_image", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/images/v1/variants/{variant_id}": [ + { + "declaration": "data-source:cloudflare_image_variant", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_image_variant", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/infrastructure/targets": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_infrastructure_target", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_access_infrastructure_targets", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/infrastructure/targets/{target_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_access_infrastructure_target", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_access_infrastructure_target", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/load_balancers/monitor_groups": [ + { + "declaration": "list-data-source:cloudflare_load_balancer_monitor_groups", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/load_balancers/monitor_groups/{monitor_group_id}": [ + { + "declaration": "data-source:cloudflare_load_balancer_monitor_group", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_load_balancer_monitor_group", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/load_balancers/monitors": [ + { + "declaration": "list-data-source:cloudflare_load_balancer_monitors", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/load_balancers/monitors/{monitor_id}": [ + { + "declaration": "data-source:cloudflare_load_balancer_monitor", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_load_balancer_monitor", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/load_balancers/pools": [ + { + "declaration": "data-source:cloudflare_load_balancer_pool", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_load_balancer_pools", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/load_balancers/pools/{pool_id}": [ + { + "declaration": "data-source:cloudflare_load_balancer_pool", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_load_balancer_pool", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/bgp/filter_profiles": [ + { + "declaration": "list-data-source:cloudflare_magic_wan_bgp_filter_profiles", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/magic/bgp/filter_profiles/{profile_id}": [ + { + "declaration": "data-source:cloudflare_magic_wan_bgp_filter_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_wan_bgp_filter_profile", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/cf1_sites": [ + { + "declaration": "list-data-source:cloudflare_magic_transit_cf1_sites", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/magic/cf1_sites/{cf1_site_id}": [ + { + "declaration": "data-source:cloudflare_magic_transit_cf1_site", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_transit_cf1_site", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/connectors": [ + { + "declaration": "data-source:cloudflare_magic_transit_connector", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_magic_transit_connectors", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/magic/connectors/{connector_id}": [ + { + "declaration": "data-source:cloudflare_magic_transit_connector", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_transit_connector", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/gre_tunnels/{gre_tunnel_id}": [ + { + "declaration": "data-source:cloudflare_magic_wan_gre_tunnel", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_wan_gre_tunnel", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id}": [ + { + "declaration": "data-source:cloudflare_magic_wan_ipsec_tunnel", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_wan_ipsec_tunnel", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/routes/{route_id}": [ + { + "declaration": "data-source:cloudflare_magic_wan_static_route", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_wan_static_route", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/sites": [ + { + "declaration": "data-source:cloudflare_magic_transit_site", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_magic_transit_sites", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/magic/sites/{site_id}": [ + { + "declaration": "data-source:cloudflare_magic_transit_site", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_transit_site", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/sites/{site_id}/acls": [ + { + "declaration": "list-data-source:cloudflare_magic_transit_site_acls", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/magic/sites/{site_id}/acls/{acl_id}": [ + { + "declaration": "data-source:cloudflare_magic_transit_site_acl", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_transit_site_acl", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/sites/{site_id}/lans": [ + { + "declaration": "list-data-source:cloudflare_magic_transit_site_lans", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/magic/sites/{site_id}/lans/{lan_id}": [ + { + "declaration": "data-source:cloudflare_magic_transit_site_lan", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_transit_site_lan", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/magic/sites/{site_id}/wans": [ + { + "declaration": "list-data-source:cloudflare_magic_transit_site_wans", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/magic/sites/{site_id}/wans/{wan_id}": [ + { + "declaration": "data-source:cloudflare_magic_transit_site_wan", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_transit_site_wan", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/members": [ + { + "declaration": "data-source:cloudflare_account_member", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_account_members", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/members/{member_id}": [ + { + "declaration": "data-source:cloudflare_account_member", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_account_member", + "roles": [ + "create", + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/mnm/config": [ + { + "declaration": "data-source:cloudflare_magic_network_monitoring_configuration", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_network_monitoring_configuration", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/mnm/rules": [ + { + "declaration": "list-data-source:cloudflare_magic_network_monitoring_rules", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/mnm/rules/{rule_id}": [ + { + "declaration": "data-source:cloudflare_magic_network_monitoring_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_magic_network_monitoring_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/moq/relays": [ + { + "declaration": "data-source:cloudflare_moq_relay", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_moq_relays", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/moq/relays/{relay_id}": [ + { + "declaration": "data-source:cloudflare_moq_relay", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_moq_relay", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/mtls_certificates": [ + { + "declaration": "list-data-source:cloudflare_mtls_certificates", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/mtls_certificates/{mtls_certificate_id}": [ + { + "declaration": "data-source:cloudflare_mtls_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_mtls_certificate", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/mtls_certificates/{mtls_certificate_id}/associations": [ + { + "declaration": "data-source:cloudflare_mtls_certificate_associations", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/oauth_clients": [ + { + "declaration": "list-data-source:cloudflare_oauth_clients", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/oauth_clients/{oauth_client_id}": [ + { + "declaration": "data-source:cloudflare_oauth_client", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_oauth_client", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/one/integrations": [ + { + "declaration": "data-source:cloudflare_zero_trust_casb_integration", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_casb_integrations", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/one/integrations/{id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_casb_integration", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_casb_integration", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/pages/projects": [ + { + "declaration": "list-data-source:cloudflare_pages_projects", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/pages/projects/{project_name}": [ + { + "declaration": "data-source:cloudflare_pages_project", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_pages_project", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/pages/projects/{project_name}/domains": [ + { + "declaration": "list-data-source:cloudflare_pages_domains", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/pages/projects/{project_name}/domains/{domain_name}": [ + { + "declaration": "data-source:cloudflare_pages_domain", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_pages_domain", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/pipelines/v1/pipelines/{pipeline_id}": [ + { + "declaration": "data-source:cloudflare_pipeline", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_pipeline", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/pipelines/v1/sinks": [ + { + "declaration": "data-source:cloudflare_pipeline_sink", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_pipeline_sinks", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/pipelines/v1/sinks/{sink_id}": [ + { + "declaration": "data-source:cloudflare_pipeline_sink", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_pipeline_sink", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/pipelines/v1/streams": [ + { + "declaration": "data-source:cloudflare_pipeline_stream", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_pipeline_streams", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/pipelines/v1/streams/{stream_id}": [ + { + "declaration": "data-source:cloudflare_pipeline_stream", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_pipeline_stream", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/queues": [ + { + "declaration": "list-data-source:cloudflare_queues", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/queues/{queue_id}": [ + { + "declaration": "data-source:cloudflare_queue", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_queue", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/queues/{queue_id}/consumers": [ + { + "declaration": "list-data-source:cloudflare_queue_consumers", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/queues/{queue_id}/consumers/{consumer_id}": [ + { + "declaration": "data-source:cloudflare_queue_consumer", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_queue_consumer", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/r2-catalog/{bucket_name}": [ + { + "declaration": "data-source:cloudflare_r2_data_catalog", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_data_catalog", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/r2/buckets/{bucket_name}": [ + { + "declaration": "data-source:cloudflare_r2_bucket", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_bucket", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/r2/buckets/{bucket_name}/cors": [ + { + "declaration": "data-source:cloudflare_r2_bucket_cors", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_bucket_cors", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom/{domain}": [ + { + "declaration": "data-source:cloudflare_r2_custom_domain", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_custom_domain", + "roles": [ + "create", + "read", + "update" + ] + } + ], + "get /accounts/{account_id}/r2/buckets/{bucket_name}/lifecycle": [ + { + "declaration": "data-source:cloudflare_r2_bucket_lifecycle", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_bucket_lifecycle", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/r2/buckets/{bucket_name}/lock": [ + { + "declaration": "data-source:cloudflare_r2_bucket_lock", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_bucket_lock", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/r2/buckets/{bucket_name}/sippy": [ + { + "declaration": "data-source:cloudflare_r2_bucket_sippy", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_r2_bucket_sippy", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/registrar/domains": [ + { + "declaration": "list-data-source:cloudflare_registrar_domains", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/registrar/domains/{domain_name}": [ + { + "declaration": "data-source:cloudflare_registrar_domain", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_registrar_domain", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/resource-library/applications": [ + { + "declaration": "data-source:cloudflare_zero_trust_resource_library_application", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_resource_library_applications", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/resource-library/applications/{id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_resource_library_application", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_resource_library_application", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/resource-library/categories": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_resource_library_categories", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/resource-library/categories/{id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_resource_library_category", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/roles": [ + { + "declaration": "list-data-source:cloudflare_account_roles", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/roles/{role_id}": [ + { + "declaration": "data-source:cloudflare_account_role", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/rules/lists": [ + { + "declaration": "list-data-source:cloudflare_lists", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/rules/lists/{list_id}": [ + { + "declaration": "data-source:cloudflare_list", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_list", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/rules/lists/{list_id}/items": [ + { + "declaration": "list-data-source:cloudflare_list_items", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_list_item", + "roles": [ + "create" + ] + } + ], + "get /accounts/{account_id}/rules/lists/{list_id}/items/{item_id}": [ + { + "declaration": "data-source:cloudflare_list_item", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_list_item", + "roles": [ + "create", + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/rum/site_info/{site_id}": [ + { + "declaration": "data-source:cloudflare_web_analytics_site", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_web_analytics_site", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/rum/site_info/list": [ + { + "declaration": "data-source:cloudflare_web_analytics_site", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_web_analytics_sites", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/secondary_dns/acls": [ + { + "declaration": "list-data-source:cloudflare_dns_zone_transfers_acls", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/secondary_dns/acls/{acl_id}": [ + { + "declaration": "data-source:cloudflare_dns_zone_transfers_acl", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dns_zone_transfers_acl", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/secondary_dns/peers": [ + { + "declaration": "list-data-source:cloudflare_dns_zone_transfers_peers", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/secondary_dns/peers/{peer_id}": [ + { + "declaration": "data-source:cloudflare_dns_zone_transfers_peer", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dns_zone_transfers_peer", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/secondary_dns/tsigs": [ + { + "declaration": "list-data-source:cloudflare_dns_zone_transfers_tsigs", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/secondary_dns/tsigs/{tsig_id}": [ + { + "declaration": "data-source:cloudflare_dns_zone_transfers_tsig", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dns_zone_transfers_tsig", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/secrets_store/stores": [ + { + "declaration": "data-source:cloudflare_secrets_store", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_secrets_stores", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/secrets_store/stores/{store_id}": [ + { + "declaration": "data-source:cloudflare_secrets_store", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_secrets_store", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/secrets_store/stores/{store_id}/secrets": [ + { + "declaration": "data-source:cloudflare_secrets_store_secret", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_secrets_store_secrets", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/secrets_store/stores/{store_id}/secrets/{secret_id}": [ + { + "declaration": "data-source:cloudflare_secrets_store_secret", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_secrets_store_secret", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/shares": [ + { + "declaration": "data-source:cloudflare_share", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_shares", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/shares/{share_id}": [ + { + "declaration": "data-source:cloudflare_share", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_share", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/shares/{share_id}/recipients": [ + { + "declaration": "list-data-source:cloudflare_share_recipients", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/shares/{share_id}/recipients/{recipient_id}": [ + { + "declaration": "data-source:cloudflare_share_recipient", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_share_recipient", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/shares/{share_id}/resources": [ + { + "declaration": "data-source:cloudflare_share_resource", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_share_resources", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/shares/{share_id}/resources/{share_resource_id}": [ + { + "declaration": "data-source:cloudflare_share_resource", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_share_resource", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/sso_connectors": [ + { + "declaration": "list-data-source:cloudflare_sso_connectors", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/sso_connectors/{sso_connector_id}": [ + { + "declaration": "data-source:cloudflare_sso_connector", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_sso_connector", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/storage/kv/namespaces": [ + { + "declaration": "data-source:cloudflare_workers_kv_namespace", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_workers_kv_namespaces", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/storage/kv/namespaces/{namespace_id}": [ + { + "declaration": "data-source:cloudflare_workers_kv_namespace", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_kv_namespace", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/metadata/{key_name}": [ + { + "declaration": "resource:cloudflare_workers_kv", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name}": [ + { + "declaration": "data-source:cloudflare_workers_kv", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_kv", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/stream": [ + { + "declaration": "list-data-source:cloudflare_streams", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/{identifier}": [ + { + "declaration": "data-source:cloudflare_stream", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/{identifier}/audio": [ + { + "declaration": "data-source:cloudflare_stream_audio_track", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream_audio_track", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/{identifier}/captions/{language}": [ + { + "declaration": "data-source:cloudflare_stream_caption_language", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream_caption_language", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/{identifier}/downloads": [ + { + "declaration": "data-source:cloudflare_stream_download", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream_download", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/keys": [ + { + "declaration": "data-source:cloudflare_stream_key", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream_key", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/stream/live_inputs/{live_input_identifier}": [ + { + "declaration": "data-source:cloudflare_stream_live_input", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream_live_input", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/watermarks": [ + { + "declaration": "list-data-source:cloudflare_stream_watermarks", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/watermarks/{identifier}": [ + { + "declaration": "data-source:cloudflare_stream_watermark", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream_watermark", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/stream/webhook": [ + { + "declaration": "data-source:cloudflare_stream_webhook", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_stream_webhook", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/teamnet/routes": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared_route", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_tunnel_cloudflared_routes", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_route", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/teamnet/routes/{route_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared_route", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_route", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/teamnet/virtual_networks": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_tunnel_cloudflared_virtual_networks", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/teamnet/virtual_networks/{virtual_network_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/tokens": [ + { + "declaration": "data-source:cloudflare_account_token", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_account_tokens", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/tokens/{token_id}": [ + { + "declaration": "data-source:cloudflare_account_token", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_account_token", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/tokens/permission_groups": [ + { + "declaration": "data-source:cloudflare_account_api_token_permission_groups", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_account_api_token_permission_groups_list", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/vuln_scanner/credential_sets": [ + { + "declaration": "list-data-source:cloudflare_vulnerability_scanner_credential_sets", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}": [ + { + "declaration": "data-source:cloudflare_vulnerability_scanner_credential_set", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential_set", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}/credentials": [ + { + "declaration": "list-data-source:cloudflare_vulnerability_scanner_credentials", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}/credentials/{credential_id}": [ + { + "declaration": "data-source:cloudflare_vulnerability_scanner_credential", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/vuln_scanner/target_environments": [ + { + "declaration": "list-data-source:cloudflare_vulnerability_scanner_target_environments", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/vuln_scanner/target_environments/{target_environment_id}": [ + { + "declaration": "data-source:cloudflare_vulnerability_scanner_target_environment", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_vulnerability_scanner_target_environment", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/warp_connector": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_warp_connector", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_tunnel_warp_connectors", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/warp_connector/{tunnel_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_warp_connector", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_tunnel_warp_connector", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/warp_connector/{tunnel_id}/configurations": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_warp_connector_config", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_tunnel_warp_connector_config", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/warp_connector/{tunnel_id}/token": [ + { + "declaration": "data-source:cloudflare_zero_trust_tunnel_warp_connector_token", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/dispatch/namespaces": [ + { + "declaration": "list-data-source:cloudflare_workers_for_platforms_dispatch_namespaces", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}": [ + { + "declaration": "data-source:cloudflare_workers_for_platforms_dispatch_namespace", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_for_platforms_dispatch_namespace", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/workers/domains": [ + { + "declaration": "data-source:cloudflare_workers_custom_domain", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_workers_custom_domains", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/domains/{domain_id}": [ + { + "declaration": "data-source:cloudflare_workers_custom_domain", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_custom_domain", + "roles": [ + "create", + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/workers/scripts": [ + { + "declaration": "data-source:cloudflare_workers_script", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_workers_scripts", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/scripts/{script_name}": [ + { + "declaration": "data-source:cloudflare_workers_script", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_script", + "roles": [ + "import" + ] + } + ], + "get /accounts/{account_id}/workers/scripts/{script_name}/content/v2": [ + { + "declaration": "resource:cloudflare_workers_script", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/scripts/{script_name}/deployments": [ + { + "declaration": "list-data-source:cloudflare_workers_deployments", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/scripts/{script_name}/deployments/{deployment_id}": [ + { + "declaration": "data-source:cloudflare_workers_deployment", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_deployment", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/workers/scripts/{script_name}/schedules": [ + { + "declaration": "data-source:cloudflare_workers_cron_trigger", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_cron_trigger", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/workers/scripts/{script_name}/subdomain": [ + { + "declaration": "data-source:cloudflare_workers_script_subdomain", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_script_subdomain", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/workers/workers": [ + { + "declaration": "data-source:cloudflare_worker", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_workers", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/workers/{worker_id}": [ + { + "declaration": "data-source:cloudflare_worker", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_worker", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/workers/workers/{worker_id}/versions": [ + { + "declaration": "list-data-source:cloudflare_worker_versions", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workers/workers/{worker_id}/versions/{version_id}": [ + { + "declaration": "data-source:cloudflare_worker_version", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_worker_version", + "roles": [ + "create", + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/workflows": [ + { + "declaration": "data-source:cloudflare_workflow", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_workflows", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/workflows/{workflow_name}": [ + { + "declaration": "data-source:cloudflare_workflow", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workflow", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/zerotrust/connectivity_settings": [ + { + "declaration": "data-source:cloudflare_zero_trust_connectivity_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_connectivity_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/zerotrust/routes/hostname": [ + { + "declaration": "data-source:cloudflare_zero_trust_network_hostname_route", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zero_trust_network_hostname_routes", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/zerotrust/routes/hostname/{hostname_route_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_network_hostname_route", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_network_hostname_route", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/zerotrust/subnets/warp/{subnet_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_subnet", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_subnet", + "roles": [ + "read", + "import" + ] + } + ], + "get /accounts/{account_id}/zt_risk_scoring/behaviors": [ + { + "declaration": "data-source:cloudflare_zero_trust_risk_behavior", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_risk_behavior", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/zt_risk_scoring/integrations": [ + { + "declaration": "list-data-source:cloudflare_zero_trust_risk_scoring_integrations", + "roles": [ + "read" + ] + } + ], + "get /accounts/{account_id}/zt_risk_scoring/integrations/{integration_id}": [ + { + "declaration": "data-source:cloudflare_zero_trust_risk_scoring_integration", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_risk_scoring_integration", + "roles": [ + "read", + "import" + ] + } + ], + "get /certificates": [ + { + "declaration": "data-source:cloudflare_origin_ca_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_origin_ca_certificates", + "roles": [ + "read" + ] + } + ], + "get /certificates/{certificate_id}": [ + { + "declaration": "data-source:cloudflare_origin_ca_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_origin_ca_certificate", + "roles": [ + "read", + "import" + ] + } + ], + "get /ips": [ + { + "declaration": "data-source:cloudflare_ip_ranges", + "roles": [ + "read" + ] + } + ], + "get /oauth/scopes": [ + { + "declaration": "list-data-source:cloudflare_oauth_scopes", + "roles": [ + "read" + ] + } + ], + "get /organizations": [ + { + "declaration": "data-source:cloudflare_organization", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_organizations", + "roles": [ + "read" + ] + } + ], + "get /organizations/{organization_id}": [ + { + "declaration": "data-source:cloudflare_organization", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_organization", + "roles": [ + "read", + "import" + ] + } + ], + "get /organizations/{organization_id}/profile": [ + { + "declaration": "data-source:cloudflare_organization_profile", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_organization_profile", + "roles": [ + "read" + ] + } + ], + "get /user": [ + { + "declaration": "data-source:cloudflare_user", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_user", + "roles": [ + "read" + ] + } + ], + "get /user/tokens": [ + { + "declaration": "data-source:cloudflare_api_token", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_api_tokens", + "roles": [ + "read" + ] + } + ], + "get /user/tokens/{token_id}": [ + { + "declaration": "data-source:cloudflare_api_token", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_api_token", + "roles": [ + "read", + "import" + ] + } + ], + "get /user/tokens/permission_groups": [ + { + "declaration": "list-data-source:cloudflare_api_token_permission_groups_list", + "roles": [ + "read" + ] + } + ], + "get /zones": [ + { + "declaration": "data-source:cloudflare_zone", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zones", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}": [ + { + "declaration": "data-source:cloudflare_zone", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/acm/custom_trust_store": [ + { + "declaration": "data-source:cloudflare_custom_origin_trust_store", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_custom_origin_trust_stores", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/acm/custom_trust_store/{custom_origin_trust_store_id}": [ + { + "declaration": "data-source:cloudflare_custom_origin_trust_store", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_custom_origin_trust_store", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/acm/total_tls": [ + { + "declaration": "data-source:cloudflare_total_tls", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_total_tls", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/addressing/regional_hostnames": [ + { + "declaration": "list-data-source:cloudflare_regional_hostnames", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/addressing/regional_hostnames/{hostname}": [ + { + "declaration": "data-source:cloudflare_regional_hostname", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_regional_hostname", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/api_gateway/configuration": [ + { + "declaration": "data-source:cloudflare_api_shield", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_api_shield", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/api_gateway/discovery/operations": [ + { + "declaration": "list-data-source:cloudflare_api_shield_discovery_operations", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/api_gateway/operations": [ + { + "declaration": "data-source:cloudflare_api_shield_operation", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_api_shield_operations", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/api_gateway/operations/{operation_id}": [ + { + "declaration": "data-source:cloudflare_api_shield_operation", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_api_shield_operation", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/api_gateway/operations/{operation_id}/schema_validation": [ + { + "declaration": "data-source:cloudflare_api_shield_operation_schema_validation_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_api_shield_operation_schema_validation_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/api_gateway/settings/schema_validation": [ + { + "declaration": "data-source:cloudflare_api_shield_schema_validation_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_api_shield_schema_validation_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/api_gateway/user_schemas": [ + { + "declaration": "list-data-source:cloudflare_api_shield_schemas", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/api_gateway/user_schemas/{schema_id}": [ + { + "declaration": "data-source:cloudflare_api_shield_schema", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_api_shield_schema", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/argo/smart_routing": [ + { + "declaration": "data-source:cloudflare_argo_smart_routing", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_argo_smart_routing", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/argo/tiered_caching": [ + { + "declaration": "data-source:cloudflare_argo_tiered_caching", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_argo_tiered_caching", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/bot_management": [ + { + "declaration": "data-source:cloudflare_bot_management", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_bot_management", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/cache/cache_reserve": [ + { + "declaration": "data-source:cloudflare_zone_cache_reserve", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_cache_reserve", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/cache/regional_tiered_cache": [ + { + "declaration": "data-source:cloudflare_regional_tiered_cache", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_regional_tiered_cache", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/cache/tiered_cache_smart_topology_enable": [ + { + "declaration": "data-source:cloudflare_tiered_cache", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_tiered_cache", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/cache/variants": [ + { + "declaration": "data-source:cloudflare_zone_cache_variants", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_cache_variants", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/certificate_authorities/hostname_associations": [ + { + "declaration": "data-source:cloudflare_certificate_authorities_hostname_associations", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_certificate_authorities_hostname_associations", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/client_certificates": [ + { + "declaration": "data-source:cloudflare_client_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_client_certificates", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/client_certificates/{client_certificate_id}": [ + { + "declaration": "data-source:cloudflare_client_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_client_certificate", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/cloud_connector/rules": [ + { + "declaration": "data-source:cloudflare_cloud_connector_rules", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_cloud_connector_rules", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/content-upload-scan/payloads": [ + { + "declaration": "list-data-source:cloudflare_content_scanning_expressions", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/content-upload-scan/settings": [ + { + "declaration": "data-source:cloudflare_content_scanning", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_content_scanning", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/ct/alerting": [ + { + "declaration": "data-source:cloudflare_ct_alerting", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_ct_alerting", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/custom_certificates": [ + { + "declaration": "data-source:cloudflare_custom_ssl", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_custom_ssls", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/custom_certificates/{custom_certificate_id}": [ + { + "declaration": "data-source:cloudflare_custom_ssl", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_custom_ssl", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/custom_hostnames": [ + { + "declaration": "data-source:cloudflare_custom_hostname", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_custom_hostnames", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/custom_hostnames/{custom_hostname_id}": [ + { + "declaration": "data-source:cloudflare_custom_hostname", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_custom_hostname", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/custom_hostnames/fallback_origin": [ + { + "declaration": "data-source:cloudflare_custom_hostname_fallback_origin", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_custom_hostname_fallback_origin", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/dcv_delegation/uuid": [ + { + "declaration": "data-source:cloudflare_dcv_delegation", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/devices/policy/certificates": [ + { + "declaration": "data-source:cloudflare_zero_trust_device_default_profile_certificates", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_device_default_profile_certificates", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/dns_records": [ + { + "declaration": "data-source:cloudflare_dns_record", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_dns_records", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/dns_records/{dns_record_id}": [ + { + "declaration": "data-source:cloudflare_dns_record", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dns_record", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/dns_settings": [ + { + "declaration": "data-source:cloudflare_zone_dns_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_dns_settings", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/dnssec": [ + { + "declaration": "data-source:cloudflare_zone_dnssec", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_dnssec", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/email/routing": [ + { + "declaration": "data-source:cloudflare_email_routing_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_routing_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/email/routing/dns": [ + { + "declaration": "data-source:cloudflare_email_routing_dns", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_routing_dns", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/email/routing/rules/{rule_identifier}": [ + { + "declaration": "data-source:cloudflare_email_routing_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_routing_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/email/routing/rules/catch_all": [ + { + "declaration": "data-source:cloudflare_email_routing_catch_all", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_routing_catch_all", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/email/sending/subdomains": [ + { + "declaration": "list-data-source:cloudflare_email_sending_subdomains", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/email/sending/subdomains/{subdomain_id}": [ + { + "declaration": "data-source:cloudflare_email_sending_subdomain", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_email_sending_subdomain", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/filters": [ + { + "declaration": "data-source:cloudflare_filter", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_filters", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/filters/{filter_id}": [ + { + "declaration": "data-source:cloudflare_filter", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_filter", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/firewall/lockdowns": [ + { + "declaration": "data-source:cloudflare_zone_lockdown", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_zone_lockdowns", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/firewall/lockdowns/{lock_downs_id}": [ + { + "declaration": "data-source:cloudflare_zone_lockdown", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_lockdown", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/firewall/rules": [ + { + "declaration": "list-data-source:cloudflare_firewall_rules", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/firewall/rules/{rule_id}": [ + { + "declaration": "data-source:cloudflare_firewall_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_firewall_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/firewall/ua_rules": [ + { + "declaration": "data-source:cloudflare_user_agent_blocking_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_user_agent_blocking_rules", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/firewall/ua_rules/{ua_rule_id}": [ + { + "declaration": "data-source:cloudflare_user_agent_blocking_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_user_agent_blocking_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/healthchecks": [ + { + "declaration": "list-data-source:cloudflare_healthchecks", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/healthchecks/{healthcheck_id}": [ + { + "declaration": "data-source:cloudflare_healthcheck", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_healthcheck", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/hold": [ + { + "declaration": "data-source:cloudflare_zone_hold", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_hold", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/hostnames/settings/{setting_id}": [ + { + "declaration": "list-data-source:cloudflare_hostname_tls_settings", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/hostnames/settings/{setting_id}/{hostname}": [ + { + "declaration": "data-source:cloudflare_hostname_tls_setting", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_hostname_tls_setting", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/keyless_certificates": [ + { + "declaration": "list-data-source:cloudflare_keyless_certificates", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/keyless_certificates/{keyless_certificate_id}": [ + { + "declaration": "data-source:cloudflare_keyless_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_keyless_certificate", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/leaked-credential-checks": [ + { + "declaration": "data-source:cloudflare_leaked_credential_check", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_leaked_credential_check", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/leaked-credential-checks/detections": [ + { + "declaration": "list-data-source:cloudflare_leaked_credential_check_rules", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/leaked-credential-checks/detections/{detection_id}": [ + { + "declaration": "data-source:cloudflare_leaked_credential_check_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_leaked_credential_check_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/logs/control/retention/flag": [ + { + "declaration": "data-source:cloudflare_logpull_retention", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_logpull_retention", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/managed_headers": [ + { + "declaration": "data-source:cloudflare_managed_transforms", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_managed_transforms", + "roles": [ + "read", + "import", + "other" + ] + } + ], + "get /zones/{zone_id}/observability/tracing/rules": [ + { + "declaration": "data-source:cloudflare_zone_tracing_rules", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_tracing_rules", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/observability/tracing/settings": [ + { + "declaration": "data-source:cloudflare_zone_tracing", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_tracing", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/origin_tls_client_auth": [ + { + "declaration": "list-data-source:cloudflare_authenticated_origin_pulls_certificates", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/origin_tls_client_auth/{certificate_id}": [ + { + "declaration": "data-source:cloudflare_authenticated_origin_pulls_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_certificate", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/origin_tls_client_auth/hostnames/{hostname}": [ + { + "declaration": "data-source:cloudflare_authenticated_origin_pulls", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_authenticated_origin_pulls", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/origin_tls_client_auth/hostnames/certificates": [ + { + "declaration": "list-data-source:cloudflare_authenticated_origin_pulls_hostname_certificates", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/origin_tls_client_auth/hostnames/certificates/{certificate_id}": [ + { + "declaration": "data-source:cloudflare_authenticated_origin_pulls_hostname_certificate", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_hostname_certificate", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/origin_tls_client_auth/settings": [ + { + "declaration": "data-source:cloudflare_authenticated_origin_pulls_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/origin/cloud_regions": [ + { + "declaration": "list-data-source:cloudflare_origin_cloud_regions", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/origin/cloud_regions/{origin_ip}": [ + { + "declaration": "data-source:cloudflare_origin_cloud_region", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_origin_cloud_region", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/page_shield/connections": [ + { + "declaration": "list-data-source:cloudflare_page_shield_connections_list", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/page_shield/connections/{connection_id}": [ + { + "declaration": "data-source:cloudflare_page_shield_connections", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/page_shield/cookies": [ + { + "declaration": "list-data-source:cloudflare_page_shield_cookies_list", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/page_shield/cookies/{cookie_id}": [ + { + "declaration": "data-source:cloudflare_page_shield_cookies", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/page_shield/policies": [ + { + "declaration": "list-data-source:cloudflare_page_shield_policies", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/page_shield/policies/{policy_id}": [ + { + "declaration": "data-source:cloudflare_page_shield_policy", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_page_shield_policy", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/page_shield/scripts": [ + { + "declaration": "list-data-source:cloudflare_page_shield_scripts_list", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/page_shield/scripts/{script_id}": [ + { + "declaration": "data-source:cloudflare_page_shield_scripts", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/pagerules/{pagerule_id}": [ + { + "declaration": "data-source:cloudflare_page_rule", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_page_rule", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/precursor": [ + { + "declaration": "data-source:cloudflare_precursor", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_precursor", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/rate_limits/{rate_limit_id}": [ + { + "declaration": "data-source:cloudflare_rate_limit", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_rate_limit", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/schema_validation/schemas": [ + { + "declaration": "data-source:cloudflare_schema_validation_schemas", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_schema_validation_schemas_list", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/schema_validation/schemas/{schema_id}": [ + { + "declaration": "data-source:cloudflare_schema_validation_schemas", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_schema_validation_schemas", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/schema_validation/settings": [ + { + "declaration": "data-source:cloudflare_schema_validation_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_schema_validation_settings", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/schema_validation/settings/operations": [ + { + "declaration": "list-data-source:cloudflare_schema_validation_operation_settings_list", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/schema_validation/settings/operations/{operation_id}": [ + { + "declaration": "data-source:cloudflare_schema_validation_operation_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_schema_validation_operation_settings", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/secondary_dns/incoming": [ + { + "declaration": "data-source:cloudflare_dns_zone_transfers_incoming", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dns_zone_transfers_incoming", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/secondary_dns/outgoing": [ + { + "declaration": "data-source:cloudflare_dns_zone_transfers_outgoing", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_dns_zone_transfers_outgoing", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/settings/{setting_id}": [ + { + "declaration": "data-source:cloudflare_zone_setting", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_setting", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/settings/auto_origin_tls_kex": [ + { + "declaration": "data-source:cloudflare_zone_auto_origin_tls_kex", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_auto_origin_tls_kex", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/settings/google-tag-gateway/config": [ + { + "declaration": "data-source:cloudflare_google_tag_gateway", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_google_tag_gateway", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/settings/nel": [ + { + "declaration": "data-source:cloudflare_nel_setting", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_nel_setting", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/settings/origin_tls_compliance_modes": [ + { + "declaration": "data-source:cloudflare_origin_tls_compliance_modes", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_origin_tls_compliance_modes", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/snippets": [ + { + "declaration": "list-data-source:cloudflare_snippet_list", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_snippets_list", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/snippets/{snippet_name}": [ + { + "declaration": "data-source:cloudflare_snippet", + "roles": [ + "read" + ] + }, + { + "declaration": "data-source:cloudflare_snippets", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_snippet", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/snippets/{snippet_name}/content": [ + { + "declaration": "resource:cloudflare_snippet", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/snippets/snippet_rules": [ + { + "declaration": "data-source:cloudflare_snippet_rules", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_snippet_rules_list", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_snippet_rules", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/spectrum/apps": [ + { + "declaration": "data-source:cloudflare_spectrum_application", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_spectrum_applications", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/spectrum/apps/{app_id}": [ + { + "declaration": "data-source:cloudflare_spectrum_application", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_spectrum_application", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/spectrum/protocols": [ + { + "declaration": "list-data-source:cloudflare_spectrum_protocols", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/speed_api/schedule/{url}": [ + { + "declaration": "data-source:cloudflare_observatory_scheduled_test", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_observatory_scheduled_test", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/ssl/certificate_packs": [ + { + "declaration": "data-source:cloudflare_certificate_pack", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_certificate_packs", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/ssl/certificate_packs/{certificate_pack_id}": [ + { + "declaration": "data-source:cloudflare_certificate_pack", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_certificate_pack", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/ssl/universal/settings": [ + { + "declaration": "data-source:cloudflare_universal_ssl_setting", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_universal_ssl_setting", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/subscription": [ + { + "declaration": "data-source:cloudflare_zone_subscription", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_zone_subscription", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/token_validation/config": [ + { + "declaration": "list-data-source:cloudflare_token_validation_configs", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/token_validation/config/{config_id}": [ + { + "declaration": "data-source:cloudflare_token_validation_config", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_token_validation_config", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/token_validation/rules": [ + { + "declaration": "data-source:cloudflare_token_validation_rules", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_token_validation_rules_list", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/token_validation/rules/{rule_id}": [ + { + "declaration": "data-source:cloudflare_token_validation_rules", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_token_validation_rules", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/url_normalization": [ + { + "declaration": "data-source:cloudflare_url_normalization_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_url_normalization_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/waiting_rooms/{waiting_room_id}": [ + { + "declaration": "data-source:cloudflare_waiting_room", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_waiting_room", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/waiting_rooms/{waiting_room_id}/events": [ + { + "declaration": "list-data-source:cloudflare_waiting_room_events", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/waiting_rooms/{waiting_room_id}/events/{event_id}": [ + { + "declaration": "data-source:cloudflare_waiting_room_event", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_waiting_room_event", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/waiting_rooms/{waiting_room_id}/rules": [ + { + "declaration": "data-source:cloudflare_waiting_room_rules", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_waiting_room_rules", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/waiting_rooms/settings": [ + { + "declaration": "data-source:cloudflare_waiting_room_settings", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_waiting_room_settings", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/web3/hostnames": [ + { + "declaration": "list-data-source:cloudflare_web3_hostnames", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/web3/hostnames/{identifier}": [ + { + "declaration": "data-source:cloudflare_web3_hostname", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_web3_hostname", + "roles": [ + "read", + "import" + ] + } + ], + "get /zones/{zone_id}/workers/routes": [ + { + "declaration": "list-data-source:cloudflare_workers_routes", + "roles": [ + "read" + ] + } + ], + "get /zones/{zone_id}/workers/routes/{route_id}": [ + { + "declaration": "data-source:cloudflare_workers_route", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_workers_route", + "roles": [ + "read", + "import" + ] + } + ], + "patch /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_access_rule", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/addressing/address_maps/{address_map_id}": [ + { + "declaration": "resource:cloudflare_address_map", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/addressing/prefixes/{prefix_id}": [ + { + "declaration": "resource:cloudflare_byo_ip_prefix", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/ai-gateway/gateways/{gateway_id}/routes/{id}": [ + { + "declaration": "resource:cloudflare_ai_gateway_dynamic_routing", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/cfd_tunnel/{tunnel_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/devices/deployment-groups/{group_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_deployment_groups", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/devices/ip-profiles/{profile_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_ip_profile", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/devices/policy": [ + { + "declaration": "resource:cloudflare_zero_trust_device_default_profile", + "roles": [ + "create", + "update" + ] + } + ], + "patch /accounts/{account_id}/devices/policy/{policy_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_custom_profile", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/devices/posture/integration/{integration_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_posture_integration", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/dex/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dex_rule", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/dls/regional_services/prefix_bindings/{binding_id}": [ + { + "declaration": "resource:cloudflare_dls_prefix_binding", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/dns_firewall/{dns_firewall_id}": [ + { + "declaration": "resource:cloudflare_dns_firewall", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/dns_settings": [ + { + "declaration": "resource:cloudflare_account_dns_settings", + "roles": [ + "create", + "update" + ] + } + ], + "patch /accounts/{account_id}/dns_settings/views/{view_id}": [ + { + "declaration": "resource:cloudflare_account_dns_settings_internal_view", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/email-security/settings/allow_policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_email_security_allow_policy", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/email-security/settings/block_senders/{pattern_id}": [ + { + "declaration": "resource:cloudflare_email_security_block_sender", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/email-security/settings/impersonation_registry/{impersonation_registry_id}": [ + { + "declaration": "resource:cloudflare_email_security_impersonation_registry", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/email-security/settings/trusted_domains/{trusted_domain_id}": [ + { + "declaration": "resource:cloudflare_email_security_trusted_domains", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/email/routing/addresses/{destination_address_identifier}": [ + { + "declaration": "resource:cloudflare_email_routing_address", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/gateway/proxy_endpoints/{proxy_endpoint_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_proxy_endpoint", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/images/v1/{image_id}": [ + { + "declaration": "resource:cloudflare_image", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/images/v1/variants/{variant_id}": [ + { + "declaration": "resource:cloudflare_image_variant", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/magic/cf1_sites/{cf1_site_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_cf1_site", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/magic/connectors/{connector_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_connector", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/oauth_clients/{oauth_client_id}": [ + { + "declaration": "resource:cloudflare_oauth_client", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/one/integrations/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_integration", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/pages/projects/{project_name}": [ + { + "declaration": "resource:cloudflare_pages_project", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/pages/projects/{project_name}/domains/{domain_name}": [ + { + "declaration": "resource:cloudflare_pages_domain", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/pipelines/v1/streams/{stream_id}": [ + { + "declaration": "resource:cloudflare_pipeline_stream", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/r2/buckets/{bucket_name}": [ + { + "declaration": "resource:cloudflare_r2_bucket", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/resource-library/applications/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_resource_library_application", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/secrets_store/stores/{store_id}/secrets/{secret_id}": [ + { + "declaration": "resource:cloudflare_secrets_store_secret", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/sso_connectors/{sso_connector_id}": [ + { + "declaration": "resource:cloudflare_sso_connector", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/stream/{identifier}/audio/{audio_identifier}": [ + { + "declaration": "resource:cloudflare_stream_audio_track", + "roles": [ + "create", + "update" + ] + } + ], + "patch /accounts/{account_id}/teamnet/routes/{route_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_route", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/teamnet/virtual_networks/{virtual_network_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/warp_connector/{tunnel_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_warp_connector", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/zerotrust/connectivity_settings": [ + { + "declaration": "resource:cloudflare_zero_trust_connectivity_settings", + "roles": [ + "create", + "update" + ] + } + ], + "patch /accounts/{account_id}/zerotrust/routes/hostname/{hostname_route_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_network_hostname_route", + "roles": [ + "update" + ] + } + ], + "patch /accounts/{account_id}/zerotrust/subnets/warp/{subnet_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_subnet", + "roles": [ + "update" + ] + } + ], + "patch /user": [ + { + "declaration": "resource:cloudflare_user", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}": [ + { + "declaration": "resource:cloudflare_zone", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/addressing/regional_hostnames/{hostname}": [ + { + "declaration": "resource:cloudflare_regional_hostname", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/api_gateway/discovery/operations/{operation_id}": [ + { + "declaration": "resource:cloudflare_api_shield_discovery_operation", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/api_gateway/user_schemas/{schema_id}": [ + { + "declaration": "resource:cloudflare_api_shield_schema", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/argo/smart_routing": [ + { + "declaration": "resource:cloudflare_argo_smart_routing", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/argo/tiered_caching": [ + { + "declaration": "resource:cloudflare_argo_tiered_caching", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/cache/cache_reserve": [ + { + "declaration": "resource:cloudflare_zone_cache_reserve", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/cache/regional_tiered_cache": [ + { + "declaration": "resource:cloudflare_regional_tiered_cache", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/cache/tiered_cache_smart_topology_enable": [ + { + "declaration": "resource:cloudflare_tiered_cache", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/cache/variants": [ + { + "declaration": "resource:cloudflare_zone_cache_variants", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/client_certificates/{client_certificate_id}": [ + { + "declaration": "resource:cloudflare_client_certificate", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/content-upload-scan/payloads/{expression_id}": [ + { + "declaration": "resource:cloudflare_content_scanning_expression", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/ct/alerting": [ + { + "declaration": "resource:cloudflare_ct_alerting", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/custom_certificates/{custom_certificate_id}": [ + { + "declaration": "resource:cloudflare_custom_ssl", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/custom_hostnames/{custom_hostname_id}": [ + { + "declaration": "resource:cloudflare_custom_hostname", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/devices/policy/certificates": [ + { + "declaration": "resource:cloudflare_zero_trust_device_default_profile_certificates", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/dns_settings": [ + { + "declaration": "resource:cloudflare_zone_dns_settings", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/dnssec": [ + { + "declaration": "resource:cloudflare_zone_dnssec", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/email/routing/dns": [ + { + "declaration": "resource:cloudflare_email_routing_dns", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/email/sending/subdomains/{subdomain_id}": [ + { + "declaration": "resource:cloudflare_email_sending_subdomain", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/hold": [ + { + "declaration": "resource:cloudflare_zone_hold", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/keyless_certificates/{keyless_certificate_id}": [ + { + "declaration": "resource:cloudflare_keyless_certificate", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/managed_headers": [ + { + "declaration": "resource:cloudflare_managed_transforms", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/observability/tracing/settings": [ + { + "declaration": "resource:cloudflare_zone_tracing", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/schema_validation/schemas/{schema_id}": [ + { + "declaration": "resource:cloudflare_schema_validation_schemas", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/settings/{setting_id}": [ + { + "declaration": "resource:cloudflare_zone_setting", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/settings/auto_origin_tls_kex": [ + { + "declaration": "resource:cloudflare_zone_auto_origin_tls_kex", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/settings/nel": [ + { + "declaration": "resource:cloudflare_nel_setting", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/ssl/universal/settings": [ + { + "declaration": "resource:cloudflare_universal_ssl_setting", + "roles": [ + "create", + "update" + ] + } + ], + "patch /zones/{zone_id}/token_validation/config/{config_id}": [ + { + "declaration": "resource:cloudflare_token_validation_config", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/token_validation/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_token_validation_rules", + "roles": [ + "update" + ] + } + ], + "patch /zones/{zone_id}/web3/hostnames/{identifier}": [ + { + "declaration": "resource:cloudflare_web3_hostname", + "roles": [ + "update" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/access/apps": [ + { + "declaration": "resource:cloudflare_zero_trust_access_application", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}/ca": [ + { + "declaration": "resource:cloudflare_zero_trust_access_short_lived_certificate", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/access/certificates": [ + { + "declaration": "resource:cloudflare_zero_trust_access_mtls_certificate", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/access/groups": [ + { + "declaration": "resource:cloudflare_zero_trust_access_group", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers": [ + { + "declaration": "resource:cloudflare_zero_trust_access_identity_provider", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens": [ + { + "declaration": "resource:cloudflare_zero_trust_access_service_token", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/custom_csrs": [ + { + "declaration": "resource:cloudflare_custom_csr", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets": [ + { + "declaration": "resource:cloudflare_custom_page_asset", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/firewall/access_rules/rules": [ + { + "declaration": "resource:cloudflare_access_rule", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/load_balancers": [ + { + "declaration": "resource:cloudflare_load_balancer", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs": [ + { + "declaration": "resource:cloudflare_logpush_job", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/logpush/ownership": [ + { + "declaration": "resource:cloudflare_logpush_ownership_challenge", + "roles": [ + "create" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/rulesets": [ + { + "declaration": "resource:cloudflare_ruleset", + "roles": [ + "create", + "other" + ] + } + ], + "post /{accounts_or_zones}/{account_or_zone_id}/subscriptions": [ + { + "declaration": "resource:cloudflare_account_subscription", + "roles": [ + "create" + ] + } + ], + "post /accounts": [ + { + "declaration": "resource:cloudflare_account", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/access/ai-controls/mcp/portals": [ + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_portal", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/access/ai-controls/mcp/servers": [ + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_server", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/access/custom_pages": [ + { + "declaration": "resource:cloudflare_zero_trust_access_custom_page", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/access/policies": [ + { + "declaration": "resource:cloudflare_zero_trust_access_policy", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/access/tags": [ + { + "declaration": "resource:cloudflare_zero_trust_access_tag", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/addressing/address_maps": [ + { + "declaration": "resource:cloudflare_address_map", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/addressing/prefixes": [ + { + "declaration": "resource:cloudflare_byo_ip_prefix", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/ai-gateway/gateways": [ + { + "declaration": "resource:cloudflare_ai_gateway", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/ai-gateway/gateways/{gateway_id}/routes": [ + { + "declaration": "resource:cloudflare_ai_gateway_dynamic_routing", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/ai-search/instances": [ + { + "declaration": "resource:cloudflare_ai_search_instance", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/ai-search/namespaces": [ + { + "declaration": "resource:cloudflare_ai_search_namespace", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/ai-search/tokens": [ + { + "declaration": "resource:cloudflare_ai_search_token", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/alerting/v3/destinations/webhooks": [ + { + "declaration": "resource:cloudflare_notification_policy_webhooks", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/alerting/v3/policies": [ + { + "declaration": "resource:cloudflare_notification_policy", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/calls/apps": [ + { + "declaration": "resource:cloudflare_calls_sfu_app", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/calls/turn_keys": [ + { + "declaration": "resource:cloudflare_calls_turn_app", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/cfd_tunnel": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/challenges/widgets": [ + { + "declaration": "resource:cloudflare_turnstile_widget", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/cloudforce-one/requests": [ + { + "declaration": "data-source:cloudflare_cloudforce_one_request", + "roles": [ + "read" + ] + }, + { + "declaration": "list-data-source:cloudflare_cloudforce_one_requests", + "roles": [ + "read" + ] + } + ], + "post /accounts/{account_id}/cloudforce-one/requests/{request_id}/asset": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_asset", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/cloudforce-one/requests/{request_id}/message": [ + { + "declaration": "data-source:cloudflare_cloudforce_one_request_message", + "roles": [ + "read" + ] + }, + { + "declaration": "resource:cloudflare_cloudforce_one_request_message", + "roles": [ + "read", + "import" + ] + } + ], + "post /accounts/{account_id}/cloudforce-one/requests/{request_id}/message/new": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_message", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/cloudforce-one/requests/new": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/cloudforce-one/requests/priority/new": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_priority", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/connectivity/directory/services": [ + { + "declaration": "resource:cloudflare_connectivity_directory_service", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/d1/database": [ + { + "declaration": "resource:cloudflare_d1_database", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/data-security/posture/policies": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_policy", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/data-security/posture/webhooks": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_webhook", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/devices/deployment-groups": [ + { + "declaration": "resource:cloudflare_zero_trust_device_deployment_groups", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/devices/ip-profiles": [ + { + "declaration": "resource:cloudflare_zero_trust_device_ip_profile", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/devices/networks": [ + { + "declaration": "resource:cloudflare_zero_trust_device_managed_networks", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/devices/policy": [ + { + "declaration": "resource:cloudflare_zero_trust_device_custom_profile", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/devices/posture": [ + { + "declaration": "resource:cloudflare_zero_trust_device_posture_rule", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/devices/posture/integration": [ + { + "declaration": "resource:cloudflare_zero_trust_device_posture_integration", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dex/devices/dex_tests": [ + { + "declaration": "resource:cloudflare_zero_trust_dex_test", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dex/rules": [ + { + "declaration": "resource:cloudflare_zero_trust_dex_rule", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/data_classes": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_class", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/data_tag_categories": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag_category", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/data_tag_categories/{category_id}/data_tags": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/datasets": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_dataset", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/entries": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_entry", + "roles": [ + "create" + ] + }, + { + "declaration": "resource:cloudflare_zero_trust_dlp_entry", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/entries/integration": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_integration_entry", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/entries/predefined": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_predefined_entry", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/profiles/custom": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_profile", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/sensitivity_groups": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_group", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}/levels": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_level", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dls/regional_services/prefix_bindings": [ + { + "declaration": "resource:cloudflare_dls_prefix_binding", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dns_firewall": [ + { + "declaration": "resource:cloudflare_dns_firewall", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/dns_settings/views": [ + { + "declaration": "resource:cloudflare_account_dns_settings_internal_view", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/email-security/settings/allow_policies": [ + { + "declaration": "resource:cloudflare_email_security_allow_policy", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/email-security/settings/block_senders": [ + { + "declaration": "resource:cloudflare_email_security_block_sender", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/email-security/settings/domains": [ + { + "declaration": "resource:cloudflare_email_security_domain", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/email-security/settings/impersonation_registry": [ + { + "declaration": "resource:cloudflare_email_security_impersonation_registry", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/email-security/settings/trusted_domains": [ + { + "declaration": "resource:cloudflare_email_security_trusted_domains", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/email/routing/addresses": [ + { + "declaration": "resource:cloudflare_email_routing_address", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/flagship/apps": [ + { + "declaration": "resource:cloudflare_flagship_app", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/flagship/apps/{app_id}/flags": [ + { + "declaration": "resource:cloudflare_flagship_flag", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/gateway/certificates": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_certificate", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/gateway/certificates/{certificate_id}/activate": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_certificate", + "roles": [ + "create", + "update" + ] + } + ], + "post /accounts/{account_id}/gateway/certificates/{certificate_id}/deactivate": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_certificate", + "roles": [ + "update" + ] + } + ], + "post /accounts/{account_id}/gateway/lists": [ + { + "declaration": "resource:cloudflare_zero_trust_list", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/gateway/locations": [ + { + "declaration": "resource:cloudflare_zero_trust_dns_location", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/gateway/pacfiles": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_pacfile", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/gateway/proxy_endpoints": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_proxy_endpoint", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/gateway/rules": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_policy", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/hyperdrive/configs": [ + { + "declaration": "resource:cloudflare_hyperdrive_config", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/iam/user_groups": [ + { + "declaration": "resource:cloudflare_user_group", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/iam/user_groups/{user_group_id}/members": [ + { + "declaration": "resource:cloudflare_user_group_members", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/images/v1": [ + { + "declaration": "resource:cloudflare_image", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/images/v1/variants": [ + { + "declaration": "resource:cloudflare_image_variant", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/infrastructure/targets": [ + { + "declaration": "resource:cloudflare_zero_trust_access_infrastructure_target", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/load_balancers/monitor_groups": [ + { + "declaration": "resource:cloudflare_load_balancer_monitor_group", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/load_balancers/monitors": [ + { + "declaration": "resource:cloudflare_load_balancer_monitor", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/load_balancers/pools": [ + { + "declaration": "resource:cloudflare_load_balancer_pool", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/bgp/filter_profiles": [ + { + "declaration": "resource:cloudflare_magic_wan_bgp_filter_profile", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/cf1_sites": [ + { + "declaration": "resource:cloudflare_magic_transit_cf1_site", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/connectors": [ + { + "declaration": "resource:cloudflare_magic_transit_connector", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/gre_tunnels": [ + { + "declaration": "resource:cloudflare_magic_wan_gre_tunnel", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/ipsec_tunnels": [ + { + "declaration": "resource:cloudflare_magic_wan_ipsec_tunnel", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/routes": [ + { + "declaration": "resource:cloudflare_magic_wan_static_route", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/sites": [ + { + "declaration": "resource:cloudflare_magic_transit_site", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/sites/{site_id}/acls": [ + { + "declaration": "resource:cloudflare_magic_transit_site_acl", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/sites/{site_id}/lans": [ + { + "declaration": "resource:cloudflare_magic_transit_site_lan", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/magic/sites/{site_id}/wans": [ + { + "declaration": "resource:cloudflare_magic_transit_site_wan", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/members": [ + { + "declaration": "resource:cloudflare_account_member", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/mnm/config": [ + { + "declaration": "resource:cloudflare_magic_network_monitoring_configuration", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/mnm/rules": [ + { + "declaration": "resource:cloudflare_magic_network_monitoring_rule", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/moq/relays": [ + { + "declaration": "resource:cloudflare_moq_relay", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/mtls_certificates": [ + { + "declaration": "resource:cloudflare_mtls_certificate", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/oauth_clients": [ + { + "declaration": "resource:cloudflare_oauth_client", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/one/integrations": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_integration", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/one/integrations/{id}/pause": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_integration", + "roles": [ + "other" + ] + } + ], + "post /accounts/{account_id}/one/integrations/{id}/resume": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_integration", + "roles": [ + "other" + ] + } + ], + "post /accounts/{account_id}/pages/projects": [ + { + "declaration": "resource:cloudflare_pages_project", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/pages/projects/{project_name}/domains": [ + { + "declaration": "resource:cloudflare_pages_domain", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/pipelines/v1/pipelines": [ + { + "declaration": "resource:cloudflare_pipeline", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/pipelines/v1/sinks": [ + { + "declaration": "resource:cloudflare_pipeline_sink", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/pipelines/v1/streams": [ + { + "declaration": "resource:cloudflare_pipeline_stream", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/queues": [ + { + "declaration": "resource:cloudflare_queue", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/queues/{queue_id}/consumers": [ + { + "declaration": "resource:cloudflare_queue_consumer", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/r2-catalog/{bucket_name}/disable": [ + { + "declaration": "resource:cloudflare_r2_data_catalog", + "roles": [ + "delete" + ] + } + ], + "post /accounts/{account_id}/r2-catalog/{bucket_name}/enable": [ + { + "declaration": "resource:cloudflare_r2_data_catalog", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/r2/buckets": [ + { + "declaration": "resource:cloudflare_r2_bucket", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom": [ + { + "declaration": "resource:cloudflare_r2_custom_domain", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/resource-library/applications": [ + { + "declaration": "resource:cloudflare_zero_trust_resource_library_application", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/rules/lists": [ + { + "declaration": "resource:cloudflare_list", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/rules/lists/{list_id}/items": [ + { + "declaration": "resource:cloudflare_list_item", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/rum/site_info": [ + { + "declaration": "resource:cloudflare_web_analytics_site", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/rum/v2/{ruleset_id}/rule": [ + { + "declaration": "resource:cloudflare_web_analytics_rule", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/secondary_dns/acls": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_acl", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/secondary_dns/peers": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_peer", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/secondary_dns/tsigs": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_tsig", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/secrets_store/stores": [ + { + "declaration": "resource:cloudflare_secrets_store", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/secrets_store/stores/{store_id}/secrets": [ + { + "declaration": "resource:cloudflare_secrets_store_secret", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/shares": [ + { + "declaration": "resource:cloudflare_share", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/shares/{share_id}/recipients": [ + { + "declaration": "resource:cloudflare_share_recipient", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/shares/{share_id}/resources": [ + { + "declaration": "resource:cloudflare_share_resource", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/sso_connectors": [ + { + "declaration": "resource:cloudflare_sso_connector", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/storage/kv/namespaces": [ + { + "declaration": "resource:cloudflare_workers_kv_namespace", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/stream": [ + { + "declaration": "resource:cloudflare_stream", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/stream/{identifier}": [ + { + "declaration": "resource:cloudflare_stream", + "roles": [ + "update" + ] + } + ], + "post /accounts/{account_id}/stream/{identifier}/captions/{language}/generate": [ + { + "declaration": "resource:cloudflare_stream_caption_language", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/stream/{identifier}/downloads": [ + { + "declaration": "resource:cloudflare_stream_download", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/stream/keys": [ + { + "declaration": "resource:cloudflare_stream_key", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/stream/live_inputs": [ + { + "declaration": "resource:cloudflare_stream_live_input", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/stream/watermarks": [ + { + "declaration": "resource:cloudflare_stream_watermark", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/teamnet/routes": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_route", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/teamnet/virtual_networks": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_virtual_network", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/tokens": [ + { + "declaration": "resource:cloudflare_account_token", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/vuln_scanner/credential_sets": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential_set", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}/credentials": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/vuln_scanner/target_environments": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_target_environment", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/warp_connector": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_warp_connector", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/workers/dispatch/namespaces": [ + { + "declaration": "resource:cloudflare_workers_for_platforms_dispatch_namespace", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/workers/scripts/{script_name}/deployments": [ + { + "declaration": "resource:cloudflare_workers_deployment", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/workers/scripts/{script_name}/subdomain": [ + { + "declaration": "resource:cloudflare_workers_script_subdomain", + "roles": [ + "create", + "update" + ] + } + ], + "post /accounts/{account_id}/workers/workers": [ + { + "declaration": "resource:cloudflare_worker", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/workers/workers/{worker_id}/versions": [ + { + "declaration": "resource:cloudflare_worker_version", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/zerotrust/routes/hostname": [ + { + "declaration": "resource:cloudflare_zero_trust_network_hostname_route", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/zerotrust/subnets/warp": [ + { + "declaration": "resource:cloudflare_zero_trust_device_subnet", + "roles": [ + "create" + ] + } + ], + "post /accounts/{account_id}/zt_risk_scoring/integrations": [ + { + "declaration": "resource:cloudflare_zero_trust_risk_scoring_integration", + "roles": [ + "create" + ] + } + ], + "post /certificates": [ + { + "declaration": "resource:cloudflare_origin_ca_certificate", + "roles": [ + "create" + ] + } + ], + "post /organizations": [ + { + "declaration": "resource:cloudflare_organization", + "roles": [ + "create" + ] + } + ], + "post /user/tokens": [ + { + "declaration": "resource:cloudflare_api_token", + "roles": [ + "create" + ] + } + ], + "post /zones": [ + { + "declaration": "resource:cloudflare_zone", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/acm/custom_trust_store": [ + { + "declaration": "resource:cloudflare_custom_origin_trust_store", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/acm/total_tls": [ + { + "declaration": "resource:cloudflare_total_tls", + "roles": [ + "create", + "update" + ] + } + ], + "post /zones/{zone_id}/addressing/regional_hostnames": [ + { + "declaration": "resource:cloudflare_regional_hostname", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/api_gateway/operations/item": [ + { + "declaration": "resource:cloudflare_api_shield_operation", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/api_gateway/user_schemas": [ + { + "declaration": "resource:cloudflare_api_shield_schema", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/cache/tiered_cache_smart_topology_enable": [ + { + "declaration": "resource:cloudflare_tiered_cache", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/client_certificates": [ + { + "declaration": "resource:cloudflare_client_certificate", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/content-upload-scan/payloads": [ + { + "declaration": "resource:cloudflare_content_scanning_expression", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/custom_certificates": [ + { + "declaration": "resource:cloudflare_custom_ssl", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/custom_hostnames": [ + { + "declaration": "resource:cloudflare_custom_hostname", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/dns_records": [ + { + "declaration": "resource:cloudflare_dns_record", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/email/routing/disable": [ + { + "declaration": "resource:cloudflare_email_routing_settings", + "roles": [ + "delete" + ] + } + ], + "post /zones/{zone_id}/email/routing/dns": [ + { + "declaration": "resource:cloudflare_email_routing_dns", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/email/routing/enable": [ + { + "declaration": "resource:cloudflare_email_routing_settings", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/email/routing/rules": [ + { + "declaration": "resource:cloudflare_email_routing_rule", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/email/sending/subdomains": [ + { + "declaration": "resource:cloudflare_email_sending_subdomain", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/filters": [ + { + "declaration": "resource:cloudflare_filter", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/firewall/lockdowns": [ + { + "declaration": "resource:cloudflare_zone_lockdown", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/firewall/rules": [ + { + "declaration": "resource:cloudflare_firewall_rule", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/firewall/ua_rules": [ + { + "declaration": "resource:cloudflare_user_agent_blocking_rule", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/healthchecks": [ + { + "declaration": "resource:cloudflare_healthcheck", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/hold": [ + { + "declaration": "resource:cloudflare_zone_hold", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/keyless_certificates": [ + { + "declaration": "resource:cloudflare_keyless_certificate", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/leaked-credential-checks": [ + { + "declaration": "resource:cloudflare_leaked_credential_check", + "roles": [ + "create", + "update" + ] + } + ], + "post /zones/{zone_id}/leaked-credential-checks/detections": [ + { + "declaration": "resource:cloudflare_leaked_credential_check_rule", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/logs/control/retention/flag": [ + { + "declaration": "resource:cloudflare_logpull_retention", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/origin_tls_client_auth": [ + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_certificate", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/origin_tls_client_auth/hostnames/certificates": [ + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_hostname_certificate", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/page_shield/policies": [ + { + "declaration": "resource:cloudflare_page_shield_policy", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/pagerules": [ + { + "declaration": "resource:cloudflare_page_rule", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/rate_limits": [ + { + "declaration": "resource:cloudflare_rate_limit", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/schema_validation/schemas": [ + { + "declaration": "resource:cloudflare_schema_validation_schemas", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/secondary_dns/incoming": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_incoming", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/secondary_dns/outgoing": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_outgoing", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/spectrum/apps": [ + { + "declaration": "resource:cloudflare_spectrum_application", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/speed_api/schedule/{url}": [ + { + "declaration": "resource:cloudflare_observatory_scheduled_test", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/ssl/certificate_packs/order": [ + { + "declaration": "resource:cloudflare_certificate_pack", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/subscription": [ + { + "declaration": "resource:cloudflare_zone_subscription", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/token_validation/config": [ + { + "declaration": "resource:cloudflare_token_validation_config", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/token_validation/rules": [ + { + "declaration": "resource:cloudflare_token_validation_rules", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/waiting_rooms": [ + { + "declaration": "resource:cloudflare_waiting_room", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/waiting_rooms/{waiting_room_id}/events": [ + { + "declaration": "resource:cloudflare_waiting_room_event", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/web3/hostnames": [ + { + "declaration": "resource:cloudflare_web3_hostname", + "roles": [ + "create" + ] + } + ], + "post /zones/{zone_id}/workers/routes": [ + { + "declaration": "resource:cloudflare_workers_route", + "roles": [ + "create" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/access/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_application", + "roles": [ + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/access/certificates/{certificate_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_mtls_certificate", + "roles": [ + "update", + "delete" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/access/certificates/settings": [ + { + "declaration": "resource:cloudflare_zero_trust_access_mtls_hostname_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/access/groups/{group_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_group", + "roles": [ + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/access/identity_providers/{identity_provider_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_identity_provider", + "roles": [ + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/access/organizations": [ + { + "declaration": "resource:cloudflare_zero_trust_organization", + "roles": [ + "create", + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/access/service_tokens/{service_token_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_service_token", + "roles": [ + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/custom_pages/{identifier}": [ + { + "declaration": "resource:cloudflare_custom_pages", + "roles": [ + "create", + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/custom_pages/assets/{asset_name}": [ + { + "declaration": "resource:cloudflare_custom_page_asset", + "roles": [ + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/load_balancers/{load_balancer_id}": [ + { + "declaration": "resource:cloudflare_load_balancer", + "roles": [ + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/logpush/jobs/{job_id}": [ + { + "declaration": "resource:cloudflare_logpush_job", + "roles": [ + "update" + ] + } + ], + "put /{accounts_or_zones}/{account_or_zone_id}/rulesets/{ruleset_id}": [ + { + "declaration": "resource:cloudflare_ruleset", + "roles": [ + "update", + "other" + ] + } + ], + "put /accounts/{account_id}": [ + { + "declaration": "resource:cloudflare_account", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/access/ai-controls/mcp/portals/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_portal", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/access/ai-controls/mcp/servers/{id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_ai_controls_mcp_server", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/access/custom_pages/{custom_page_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_custom_page", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/access/keys": [ + { + "declaration": "resource:cloudflare_zero_trust_access_key_configuration", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/access/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_policy", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/access/tags/{tag_name}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_tag", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/ai-gateway/gateways/{id}": [ + { + "declaration": "resource:cloudflare_ai_gateway", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/ai-search/instances/{id}": [ + { + "declaration": "resource:cloudflare_ai_search_instance", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/ai-search/namespaces/{name}": [ + { + "declaration": "resource:cloudflare_ai_search_namespace", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/ai-search/tokens/{id}": [ + { + "declaration": "resource:cloudflare_ai_search_token", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/alerting/v3/destinations/webhooks/{webhook_id}": [ + { + "declaration": "resource:cloudflare_notification_policy_webhooks", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/alerting/v3/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_notification_policy", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/calls/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_calls_sfu_app", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/calls/turn_keys/{key_id}": [ + { + "declaration": "resource:cloudflare_calls_turn_app", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/cfd_tunnel/{tunnel_id}/configurations": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_cloudflared_config", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/challenges/widgets/{sitekey}": [ + { + "declaration": "resource:cloudflare_turnstile_widget", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/cloudforce-one/requests/{request_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/cloudforce-one/requests/{request_id}/asset/{asset_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_asset", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/cloudforce-one/requests/{request_id}/message/{message_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_message", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/cloudforce-one/requests/priority/{priority_id}": [ + { + "declaration": "resource:cloudflare_cloudforce_one_request_priority", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/connectivity/directory/services/{service_id}": [ + { + "declaration": "resource:cloudflare_connectivity_directory_service", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/d1/database/{database_id}": [ + { + "declaration": "resource:cloudflare_d1_database", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/data-security/posture/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_policy", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/data-security/posture/webhooks/{webhook_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_casb_webhook", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/devices/networks/{network_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_managed_networks", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/devices/policy/{policy_id}/fallback_domains": [ + { + "declaration": "resource:cloudflare_zero_trust_device_custom_profile_local_domain_fallback", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/devices/policy/fallback_domains": [ + { + "declaration": "resource:cloudflare_zero_trust_device_default_profile_local_domain_fallback", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/devices/posture/{rule_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_device_posture_rule", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/devices/settings": [ + { + "declaration": "resource:cloudflare_zero_trust_device_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/dex/devices/dex_tests/{dex_test_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dex_test", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/data_classes/{data_class_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_class", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/data_tag_categories/{category_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag_category", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/data_tag_categories/{category_id}/data_tags/{tag_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_data_tag", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/datasets/{dataset_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_dataset", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/entries/{entry_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_entry", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/entries/custom/{entry_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_entry", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/entries/integration/{entry_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_integration_entry", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/entries/predefined/{entry_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_predefined_entry", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/profiles/custom/{profile_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_custom_profile", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/profiles/predefined/{profile_id}/config": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_predefined_profile", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_group", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}/level_order": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_level_order", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/sensitivity_groups/{sensitivity_group_id}/levels/{sensitivity_level_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_sensitivity_level", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/dlp/settings": [ + { + "declaration": "resource:cloudflare_zero_trust_dlp_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/email-security/settings/domains/{domain_id}": [ + { + "declaration": "resource:cloudflare_email_security_domain", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/event_notifications/r2/{bucket_name}/configuration/queues/{queue_id}": [ + { + "declaration": "resource:cloudflare_r2_bucket_event_notification", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/field_extractors/{extractor}": [ + { + "declaration": "resource:cloudflare_field_extractor", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/flagship/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_flagship_app", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/flagship/apps/{app_id}/flags/{flag_key}": [ + { + "declaration": "resource:cloudflare_flagship_flag", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/gateway/configuration": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/gateway/lists/{list_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_list", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/gateway/locations/{location_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_dns_location", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/gateway/logging": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_logging", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/gateway/pacfiles/{pacfile_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_pacfile", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/gateway/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_gateway_policy", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/hyperdrive/configs/{hyperdrive_id}": [ + { + "declaration": "resource:cloudflare_hyperdrive_config", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/iam/user_groups/{user_group_id}": [ + { + "declaration": "resource:cloudflare_user_group", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/iam/user_groups/{user_group_id}/members": [ + { + "declaration": "resource:cloudflare_user_group_members", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/infrastructure/targets/{target_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_access_infrastructure_target", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/load_balancers/monitor_groups/{monitor_group_id}": [ + { + "declaration": "resource:cloudflare_load_balancer_monitor_group", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/load_balancers/monitors/{monitor_id}": [ + { + "declaration": "resource:cloudflare_load_balancer_monitor", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/load_balancers/pools/{pool_id}": [ + { + "declaration": "resource:cloudflare_load_balancer_pool", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/bgp/filter_profiles/{profile_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_bgp_filter_profile", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/gre_tunnels/{gre_tunnel_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_gre_tunnel", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_ipsec_tunnel", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/routes/{route_id}": [ + { + "declaration": "resource:cloudflare_magic_wan_static_route", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/sites/{site_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/sites/{site_id}/acls/{acl_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site_acl", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/sites/{site_id}/lans/{lan_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site_lan", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/magic/sites/{site_id}/wans/{wan_id}": [ + { + "declaration": "resource:cloudflare_magic_transit_site_wan", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/members/{member_id}": [ + { + "declaration": "resource:cloudflare_account_member", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/mnm/config": [ + { + "declaration": "resource:cloudflare_magic_network_monitoring_configuration", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/mnm/rules": [ + { + "declaration": "resource:cloudflare_magic_network_monitoring_rule", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/moq/relays/{relay_id}": [ + { + "declaration": "resource:cloudflare_moq_relay", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/queues/{queue_id}": [ + { + "declaration": "resource:cloudflare_queue", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/queues/{queue_id}/consumers/{consumer_id}": [ + { + "declaration": "resource:cloudflare_queue_consumer", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/r2/buckets/{bucket_name}/cors": [ + { + "declaration": "resource:cloudflare_r2_bucket_cors", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom/{domain}": [ + { + "declaration": "resource:cloudflare_r2_custom_domain", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/r2/buckets/{bucket_name}/domains/managed": [ + { + "declaration": "resource:cloudflare_r2_managed_domain", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/r2/buckets/{bucket_name}/lifecycle": [ + { + "declaration": "resource:cloudflare_r2_bucket_lifecycle", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/r2/buckets/{bucket_name}/lock": [ + { + "declaration": "resource:cloudflare_r2_bucket_lock", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/r2/buckets/{bucket_name}/sippy": [ + { + "declaration": "resource:cloudflare_r2_bucket_sippy", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/registrar/domains/{domain_name}": [ + { + "declaration": "resource:cloudflare_registrar_domain", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/rules/lists/{list_id}": [ + { + "declaration": "resource:cloudflare_list", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/rum/site_info/{site_id}": [ + { + "declaration": "resource:cloudflare_web_analytics_site", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/rum/v2/{ruleset_id}/rule/{rule_id}": [ + { + "declaration": "resource:cloudflare_web_analytics_rule", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/secondary_dns/acls/{acl_id}": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_acl", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/secondary_dns/peers/{peer_id}": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_peer", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/secondary_dns/tsigs/{tsig_id}": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_tsig", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/shares/{share_id}": [ + { + "declaration": "resource:cloudflare_share", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/shares/{share_id}/resources/{share_resource_id}": [ + { + "declaration": "resource:cloudflare_share_resource", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/storage/kv/namespaces/{namespace_id}": [ + { + "declaration": "resource:cloudflare_workers_kv_namespace", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name}": [ + { + "declaration": "resource:cloudflare_workers_kv", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/stream/{identifier}/captions/{language}": [ + { + "declaration": "resource:cloudflare_stream_caption_language", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/stream/live_inputs/{live_input_identifier}": [ + { + "declaration": "resource:cloudflare_stream_live_input", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/stream/webhook": [ + { + "declaration": "resource:cloudflare_stream_webhook", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/subscriptions/{subscription_identifier}": [ + { + "declaration": "resource:cloudflare_account_subscription", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/tokens/{token_id}": [ + { + "declaration": "resource:cloudflare_account_token", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential_set", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/vuln_scanner/credential_sets/{credential_set_id}/credentials/{credential_id}": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_credential", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/vuln_scanner/target_environments/{target_environment_id}": [ + { + "declaration": "resource:cloudflare_vulnerability_scanner_target_environment", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/warp_connector/{tunnel_id}/configurations": [ + { + "declaration": "resource:cloudflare_zero_trust_tunnel_warp_connector_config", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/workers/domains": [ + { + "declaration": "resource:cloudflare_workers_custom_domain", + "roles": [ + "create" + ] + } + ], + "put /accounts/{account_id}/workers/scripts/{script_name}": [ + { + "declaration": "resource:cloudflare_workers_script", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/workers/scripts/{script_name}/schedules": [ + { + "declaration": "resource:cloudflare_workers_cron_trigger", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/workers/workers/{worker_id}": [ + { + "declaration": "resource:cloudflare_worker", + "roles": [ + "update" + ] + } + ], + "put /accounts/{account_id}/workflows/{workflow_name}": [ + { + "declaration": "resource:cloudflare_workflow", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/zt_risk_scoring/behaviors": [ + { + "declaration": "resource:cloudflare_zero_trust_risk_behavior", + "roles": [ + "create", + "update" + ] + } + ], + "put /accounts/{account_id}/zt_risk_scoring/integrations/{integration_id}": [ + { + "declaration": "resource:cloudflare_zero_trust_risk_scoring_integration", + "roles": [ + "update" + ] + } + ], + "put /organizations/{organization_id}": [ + { + "declaration": "resource:cloudflare_organization", + "roles": [ + "update" + ] + } + ], + "put /organizations/{organization_id}/profile": [ + { + "declaration": "resource:cloudflare_organization_profile", + "roles": [ + "create", + "update" + ] + } + ], + "put /user/tokens/{token_id}": [ + { + "declaration": "resource:cloudflare_api_token", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/api_gateway/configuration": [ + { + "declaration": "resource:cloudflare_api_shield", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/api_gateway/operations/{operation_id}/schema_validation": [ + { + "declaration": "resource:cloudflare_api_shield_operation_schema_validation_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/api_gateway/settings/schema_validation": [ + { + "declaration": "resource:cloudflare_api_shield_schema_validation_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/bot_management": [ + { + "declaration": "resource:cloudflare_bot_management", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/certificate_authorities/hostname_associations": [ + { + "declaration": "resource:cloudflare_certificate_authorities_hostname_associations", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/cloud_connector/rules": [ + { + "declaration": "resource:cloudflare_cloud_connector_rules", + "roles": [ + "create", + "update", + "delete" + ] + } + ], + "put /zones/{zone_id}/content-upload-scan/settings": [ + { + "declaration": "resource:cloudflare_content_scanning", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/custom_hostnames/fallback_origin": [ + { + "declaration": "resource:cloudflare_custom_hostname_fallback_origin", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/dns_records/{dns_record_id}": [ + { + "declaration": "resource:cloudflare_dns_record", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/email/routing/rules/{rule_identifier}": [ + { + "declaration": "resource:cloudflare_email_routing_rule", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/email/routing/rules/catch_all": [ + { + "declaration": "resource:cloudflare_email_routing_catch_all", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/filters/{filter_id}": [ + { + "declaration": "resource:cloudflare_filter", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/firewall/lockdowns/{lock_downs_id}": [ + { + "declaration": "resource:cloudflare_zone_lockdown", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/firewall/rules/{rule_id}": [ + { + "declaration": "resource:cloudflare_firewall_rule", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/firewall/ua_rules/{ua_rule_id}": [ + { + "declaration": "resource:cloudflare_user_agent_blocking_rule", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/healthchecks/{healthcheck_id}": [ + { + "declaration": "resource:cloudflare_healthcheck", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/hostnames/settings/{setting_id}/{hostname}": [ + { + "declaration": "resource:cloudflare_hostname_tls_setting", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/leaked-credential-checks/detections/{detection_id}": [ + { + "declaration": "resource:cloudflare_leaked_credential_check_rule", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/observability/tracing/rules": [ + { + "declaration": "resource:cloudflare_zone_tracing_rules", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/origin_tls_client_auth/hostnames": [ + { + "declaration": "resource:cloudflare_authenticated_origin_pulls", + "roles": [ + "create", + "update", + "delete" + ] + } + ], + "put /zones/{zone_id}/origin_tls_client_auth/settings": [ + { + "declaration": "resource:cloudflare_authenticated_origin_pulls_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/origin/cloud_regions/{origin_ip}": [ + { + "declaration": "resource:cloudflare_origin_cloud_region", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/page_shield/policies/{policy_id}": [ + { + "declaration": "resource:cloudflare_page_shield_policy", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/pagerules/{pagerule_id}": [ + { + "declaration": "resource:cloudflare_page_rule", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/precursor": [ + { + "declaration": "resource:cloudflare_precursor", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/rate_limits/{rate_limit_id}": [ + { + "declaration": "resource:cloudflare_rate_limit", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/schema_validation/settings": [ + { + "declaration": "resource:cloudflare_schema_validation_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/schema_validation/settings/operations/{operation_id}": [ + { + "declaration": "resource:cloudflare_schema_validation_operation_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/secondary_dns/incoming": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_incoming", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/secondary_dns/outgoing": [ + { + "declaration": "resource:cloudflare_dns_zone_transfers_outgoing", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/settings/google-tag-gateway/config": [ + { + "declaration": "resource:cloudflare_google_tag_gateway", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/settings/origin_tls_compliance_modes": [ + { + "declaration": "resource:cloudflare_origin_tls_compliance_modes", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/snippets/{snippet_name}": [ + { + "declaration": "resource:cloudflare_snippet", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/snippets/snippet_rules": [ + { + "declaration": "resource:cloudflare_snippet_rules", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/spectrum/apps/{app_id}": [ + { + "declaration": "resource:cloudflare_spectrum_application", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/subscription": [ + { + "declaration": "resource:cloudflare_zone_subscription", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/url_normalization": [ + { + "declaration": "resource:cloudflare_url_normalization_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/waiting_rooms/{waiting_room_id}": [ + { + "declaration": "resource:cloudflare_waiting_room", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/waiting_rooms/{waiting_room_id}/events/{event_id}": [ + { + "declaration": "resource:cloudflare_waiting_room_event", + "roles": [ + "update" + ] + } + ], + "put /zones/{zone_id}/waiting_rooms/{waiting_room_id}/rules": [ + { + "declaration": "resource:cloudflare_waiting_room_rules", + "roles": [ + "create", + "update", + "delete" + ] + } + ], + "put /zones/{zone_id}/waiting_rooms/settings": [ + { + "declaration": "resource:cloudflare_waiting_room_settings", + "roles": [ + "create", + "update" + ] + } + ], + "put /zones/{zone_id}/workers/routes/{route_id}": [ + { + "declaration": "resource:cloudflare_workers_route", + "roles": [ + "update" + ] + } + ] + } +} diff --git a/packages/docs-site/src/terraform-extension.ts b/packages/docs-site/src/terraform-extension.ts index 564fd5975..49329da63 100644 --- a/packages/docs-site/src/terraform-extension.ts +++ b/packages/docs-site/src/terraform-extension.ts @@ -3,35 +3,58 @@ import { defineFernExtension } from 'astro-fern'; import { canonicalTerraformEndpoint, generatedTerraformDocsSchema, + indexTerraformDocs, TERRAFORM_EXTENSION_NAME, terraformOperationDataSchema, - type GeneratedTerraformDocs, + type TerraformDeclaration, type TerraformOperationData, } from './terraform.ts'; -function loadTerraformDocs(): GeneratedTerraformDocs { +const HTTP_METHODS = ['get', 'post', 'put', 'patch', 'delete', 'head', 'options', 'trace'] as const; + +function loadTerraformIndex(): Map { const file = new URL('./generated/terraform-docs.json', import.meta.url); - return generatedTerraformDocsSchema.parse(JSON.parse(readFileSync(file, 'utf8'))); + return indexTerraformDocs(generatedTerraformDocsSchema.parse(JSON.parse(readFileSync(file, 'utf8')))); } -const terraformDocs = loadTerraformDocs(); - -/** Build-only bridge from Stainless's Terraform model into operation artifacts. */ +/** Build-only bridge from the released Terraform provider into operation artifacts. */ export const cloudflareTerraformExtension = defineFernExtension< TerraformOperationData, - GeneratedTerraformDocs['operations'] + Map >({ name: TERRAFORM_EXTENSION_NAME, schema: terraformOperationDataSchema, - prepare: () => terraformDocs.operations, - operation: ({ method, path, operation }, operations) => { - const entry = operations[canonicalTerraformEndpoint(method, path)]; - if (!entry) return undefined; - if (entry.operationId !== operation.operationId) { - throw new Error( - `generated Terraform mapping expected operationId "${entry.operationId}" for ${method.toUpperCase()} ${path}, received "${operation.operationId ?? ''}"`, + prepare: (document, { logger }) => { + const index = loadTerraformIndex(); + // Report provider endpoints the current OpenAPI no longer has, so drift is visible in builds. + const known = new Set(); + for (const [endpointPath, pathItem] of Object.entries(document.paths ?? {})) { + for (const method of HTTP_METHODS) { + if ((pathItem as Record | undefined)?.[method]) + known.add(canonicalTerraformEndpoint(method, endpointPath)); + } + } + const missing = [...index.keys()].filter((key) => !known.has(key)); + const orphaned = new Set( + [...index] + .filter(([key]) => missing.includes(key)) + .flatMap(([, declarations]) => declarations.map(({ kind, name }) => `${kind}:${name}`)), + ); + const matched = new Set( + [...index] + .filter(([key]) => known.has(key)) + .flatMap(([, declarations]) => declarations.map(({ kind, name }) => `${kind}:${name}`)), + ); + const unmatched = [...orphaned].filter((declaration) => !matched.has(declaration)); + if (unmatched.length > 0) { + logger.warn( + `${unmatched.length} Terraform declarations match no OpenAPI operation: ${unmatched.slice(0, 10).join(', ')}${unmatched.length > 10 ? ', …' : ''}`, ); } - return { data: { declarations: entry.declarations } }; + return index; + }, + operation: ({ method, path }, index) => { + const declarations = index.get(canonicalTerraformEndpoint(method, path)); + return declarations?.length ? { data: { declarations } } : undefined; }, }); diff --git a/packages/docs-site/src/terraform.test.ts b/packages/docs-site/src/terraform.test.ts index abdae23b2..42737d825 100644 --- a/packages/docs-site/src/terraform.test.ts +++ b/packages/docs-site/src/terraform.test.ts @@ -6,8 +6,12 @@ import { canonicalTerraformEndpoint, generatedTerraformDocsSchema, getTerraformOperationData, + indexTerraformDocs, TERRAFORM_EXTENSION_NAME, terraformDeclarationLabel, + terraformEndpointKeys, + terraformRolesSummary, + type GeneratedTerraformDocs, type TerraformDeclaration, withTerraformTarget, } from './terraform.ts'; @@ -15,9 +19,8 @@ import { const resource: TerraformDeclaration = { kind: 'resource', name: 'cloudflare_widget', - stainlessResource: 'widgets', - methodName: 'create', - snippet: 'resource "cloudflare_widget" "example" {}\n', + roles: ['create'], + example: 'resource "cloudflare_widget" "example" {}\n', required: [], optional: [], computed: [], @@ -27,7 +30,8 @@ const dataSource: TerraformDeclaration = { ...resource, kind: 'data-source', name: 'cloudflare_widget_data', - snippet: 'data "cloudflare_widget" "example" {}\n', + roles: ['read'], + example: 'data "cloudflare_widget" "example" {}\n', }; function pageWith(declarations?: TerraformDeclaration[]): FernPageSchema { @@ -49,13 +53,84 @@ test('canonical Terraform endpoints ignore parameter naming differences', () => ); }); +test('SDK endpoints match both concrete and merged scope paths', () => { + assert.deepEqual(terraformEndpointKeys('post /{accounts_or_zones}/{account_or_zone_id}/rules'), [ + 'post /accounts/{}/rules', + 'post /zones/{}/rules', + 'post /{}/{}/rules', + ]); + assert.deepEqual(terraformEndpointKeys('get /accounts/{account_id}/dns_settings'), [ + 'get /accounts/{}/dns_settings', + 'get /{}/{}/dns_settings', + ]); + assert.deepEqual(terraformEndpointKeys('get /user/tokens'), ['get /user/tokens']); +}); + +test('indexTerraformDocs merges roles across endpoint variants and orders declarations', () => { + const base = { required: [], optional: [], computed: [] }; + const docs: GeneratedTerraformDocs = { + format: 2, + source: { provider: { repository: 'https://example.com/provider', version: '1.0.0' }, sdks: [] }, + stats: { declarations: 2, linkedDeclarations: 2, endpoints: 2, unresolvedCalls: 0 }, + unlinked: [], + undocumented: [], + unresolvedCalls: [], + declarations: { + 'resource:cloudflare_widget': { kind: 'resource', name: 'cloudflare_widget', ...base }, + 'data-source:cloudflare_widget': { kind: 'data-source', name: 'cloudflare_widget', ...base }, + }, + endpoints: { + 'get /accounts/{account_id}/widgets/{id}': [ + { declaration: 'data-source:cloudflare_widget', roles: ['read'] }, + { declaration: 'resource:cloudflare_widget', roles: ['read', 'import'] }, + ], + 'get /{accounts_or_zones}/{account_or_zone_id}/widgets/{id}': [ + { declaration: 'resource:cloudflare_widget', roles: ['read'] }, + ], + }, + }; + const index = indexTerraformDocs(docs); + const merged = index.get('get /accounts/{}/widgets/{}'); + assert.deepEqual( + merged?.map(({ kind, roles }) => [kind, roles]), + [ + ['resource', ['read', 'import']], + ['data-source', ['read']], + ], + ); + assert.deepEqual( + index.get('get /zones/{}/widgets/{}')?.map(({ kind }) => kind), + ['resource'], + ); +}); + +test('the generated file schema rejects links to unknown declarations', () => { + const result = generatedTerraformDocsSchema.safeParse({ + format: 2, + source: { provider: { repository: 'https://example.com/provider', version: '1.0.0' }, sdks: [] }, + stats: { declarations: 0, linkedDeclarations: 0, endpoints: 1, unresolvedCalls: 0 }, + unlinked: [], + undocumented: [], + unresolvedCalls: [], + declarations: {}, + endpoints: { 'get /x': [{ declaration: 'resource:missing', roles: ['read'] }] }, + }); + assert.equal(result.success, false); + assert.deepEqual(result.error?.issues[0]?.path, ['endpoints', 'get /x', 0, 'declaration']); +}); + test('Terraform operation data remains namespaced on the operation', () => { assert.deepEqual(getTerraformOperationData(pageWith([resource]).operation)?.declarations, [resource]); assert.equal(terraformDeclarationLabel(resource), 'resource cloudflare_widget'); assert.equal(terraformDeclarationLabel(dataSource), 'data cloudflare_widget_data'); + assert.equal( + terraformRolesSummary({ ...resource, roles: ['read', 'import'] }), + 'Called by this resource to read and import.', + ); + assert.equal(terraformRolesSummary(dataSource), 'Called by this data source to read.'); }); -test('withTerraformTarget preserves all declaration snippets for agent Markdown', () => { +test('withTerraformTarget preserves all declaration examples for agent Markdown', () => { const page = pageWith([resource, dataSource]); const decorated = withTerraformTarget(page); const code = decorated.targets.find((target) => target.id === 'terraform')?.code; @@ -64,19 +139,17 @@ test('withTerraformTarget preserves all declaration snippets for agent Markdown' assert.equal(page.targets.find((target) => target.id === 'terraform')?.code, null); }); -test('the generated index retains every declaration for shared DLP endpoints', async () => { +test('the generated index links every CRUD operation of a resource', async () => { const source = await readFile(new URL('./generated/terraform-docs.json', import.meta.url), 'utf8'); - const generated = generatedTerraformDocsSchema.parse(JSON.parse(source)); - const dlp = generated.operations['get /accounts/{}/dlp/entries']; - assert.ok(dlp); - assert.equal(dlp.declarations.length, 4); - assert.deepEqual( - dlp.declarations.map((declaration) => declaration.name), - [ - 'cloudflare_zero_trust_dlp_custom_entries', - 'cloudflare_zero_trust_dlp_entries', - 'cloudflare_zero_trust_dlp_integration_entries', - 'cloudflare_zero_trust_dlp_predefined_entries', - ], + const index = indexTerraformDocs(generatedTerraformDocsSchema.parse(JSON.parse(source))); + const roles = (key: string) => + index.get(key)?.find(({ kind, name }) => kind === 'resource' && name === 'cloudflare_dns_record')?.roles; + assert.deepEqual(roles('post /zones/{}/dns_records'), ['create']); + assert.deepEqual(roles('get /zones/{}/dns_records/{}'), ['read', 'import']); + assert.deepEqual(roles('put /zones/{}/dns_records/{}'), ['update']); + assert.deepEqual(roles('delete /zones/{}/dns_records/{}'), ['delete']); + // Scope-polymorphic SDK paths resolve to Forge's merged `/{account_or_zone}/…` path. + assert.ok( + index.get('post /{}/{}/firewall/access_rules/rules')?.some(({ name }) => name === 'cloudflare_access_rule'), ); }); diff --git a/packages/docs-site/src/terraform.ts b/packages/docs-site/src/terraform.ts index 8b9ad58dd..3c0aab901 100644 --- a/packages/docs-site/src/terraform.ts +++ b/packages/docs-site/src/terraform.ts @@ -7,7 +7,6 @@ export interface TerraformAttribute { description?: string; deprecated?: string; sensitive?: boolean; - requiresReplace?: boolean; children?: TerraformAttribute[]; } @@ -18,21 +17,33 @@ export const terraformAttributeSchema: z.ZodType = z.lazy(() description: z.string().optional(), deprecated: z.string().optional(), sensitive: z.boolean().optional(), - requiresReplace: z.boolean().optional(), children: z.array(terraformAttributeSchema).optional(), }), ); -export const terraformDeclarationSchema = z.object({ - kind: z.enum(['resource', 'data-source', 'list-data-source']), +export const terraformRoleSchema = z.enum(['create', 'read', 'update', 'delete', 'import', 'other']); +export type TerraformRole = z.infer; + +export const terraformDeclarationKindSchema = z.enum(['resource', 'data-source', 'list-data-source']); +export type TerraformDeclarationKind = z.infer; + +/** A declaration as stored once in the generated file. */ +export const generatedTerraformDeclarationSchema = z.object({ + kind: terraformDeclarationKindSchema, name: z.string().min(1), - stainlessResource: z.string().min(1), - methodName: z.string().min(1), - snippet: z.string().min(1).optional(), + description: z.string().optional(), + example: z.string().min(1).optional(), + importExample: z.string().min(1).optional(), required: z.array(terraformAttributeSchema), optional: z.array(terraformAttributeSchema), computed: z.array(terraformAttributeSchema), }); +export type GeneratedTerraformDeclaration = z.infer; + +/** A declaration as attached to one operation, with the lifecycle roles that use it. */ +export const terraformDeclarationSchema = generatedTerraformDeclarationSchema.extend({ + roles: z.array(terraformRoleSchema).min(1), +}); export type TerraformDeclaration = z.infer; export const terraformOperationDataSchema = z.object({ @@ -40,38 +51,153 @@ export const terraformOperationDataSchema = z.object({ }); export type TerraformOperationData = z.infer; -export const generatedTerraformDocsSchema = z.object({ - format: z.literal(1), - operations: z.record( - z.string(), - z.object({ - operationId: z.string().min(1), - declarations: z.array(terraformDeclarationSchema).min(1), - }), - ), +export const terraformEndpointLinkSchema = z.object({ + /** Key into `declarations`. */ + declaration: z.string().min(1), + roles: z.array(terraformRoleSchema).min(1), }); +export type TerraformEndpointLink = z.infer; + +const commitSchema = z.string().regex(/^[0-9a-f]{40}$/, 'expected a full git commit SHA'); + +/** + * Shape of `src/generated/terraform-docs.json`. `scripts/generate-terraform-docs.ts` validates + * its output against this schema, and the build reads the file with it. + */ +export const generatedTerraformDocsSchema = z + .object({ + format: z.literal(2), + source: z.object({ + provider: z.object({ + repository: z.url(), + version: z.string().regex(/^\d+\.\d+\.\d+/), + /** Commit of the provider checkout, when it was a git checkout. */ + commit: commitSchema.optional(), + }), + sdks: z.array( + z.object({ module: z.string().min(1), version: z.string().min(1), commit: commitSchema.optional() }), + ), + }), + stats: z.object({ + declarations: z.number().int().nonnegative(), + linkedDeclarations: z.number().int().nonnegative(), + endpoints: z.number().int().nonnegative(), + unresolvedCalls: z.number().int().nonnegative(), + }), + /** Declarations that make no recognised SDK call (custom or stub implementations). */ + unlinked: z.array(z.string()), + /** SDK calls for which no endpoint was found in cloudflare-go `api.md`. */ + /** Service code without a tfplugindocs page, i.e. not registered by the released provider. */ + undocumented: z.array(z.string()), + unresolvedCalls: z.array(z.object({ declaration: z.string(), call: z.string() })), + declarations: z.record(z.string(), generatedTerraformDeclarationSchema), + /** Keyed by the SDK endpoint exactly as cloudflare-go documents it, e.g. `post /zones/{zone_id}/dns_records`. */ + endpoints: z.record(z.string(), z.array(terraformEndpointLinkSchema)), + }) + .superRefine((docs, context) => { + for (const [endpoint, links] of Object.entries(docs.endpoints)) { + links.forEach((link, index) => { + if (!docs.declarations[link.declaration]) { + context.addIssue({ + code: 'custom', + path: ['endpoints', endpoint, index, 'declaration'], + message: `references unknown declaration ${link.declaration}`, + }); + } + }); + } + }); export type GeneratedTerraformDocs = z.infer; export const TERRAFORM_EXTENSION_NAME = 'cloudflare-terraform'; -export function getTerraformOperationData( - operation: FernPageSchema['operation'], -): TerraformOperationData | undefined { +export function getTerraformOperationData(operation: FernPageSchema['operation']): TerraformOperationData | undefined { const value = operation.extensions[TERRAFORM_EXTENSION_NAME]; return value === undefined ? undefined : terraformOperationDataSchema.parse(value); } +const SCOPE_PREFIX = /^\/(?:accounts|zones|\{\})\/\{\}(?=\/|$)/; + +/** Normalizes an endpoint so path parameter names do not matter: `get /zones/{zone_id}` -> `get /zones/{}`. */ export function canonicalTerraformEndpoint(method: string, endpointPath: string): string { return `${method.toLowerCase()} ${endpointPath.replaceAll(/\{[^}]+\}/g, '{}')}`; } -export function terraformDeclarationLabel(declaration: TerraformDeclaration): string { +/** + * Keys under which an SDK endpoint should be found in the OpenAPI document. + * + * cloudflare-go and the Forge OpenAPI disagree on scope-polymorphic paths: the SDK may + * document `/{accounts_or_zones}/{account_or_zone_id}/…` where Forge has `/{account_or_zone}/…`, + * or the SDK may document `/accounts/{account_id}/…` for an operation Forge merged into + * `/{account_or_zone}/…`. Concrete scopes match the merged path; merged scopes match both. + */ +export function terraformEndpointKeys(endpoint: string): string[] { + const separator = endpoint.indexOf(' '); + if (separator < 1) throw new Error(`Invalid Terraform endpoint ${endpoint}`); + const key = canonicalTerraformEndpoint(endpoint.slice(0, separator), endpoint.slice(separator + 1)); + const [method, endpointPath] = [key.slice(0, separator), key.slice(separator + 1)]; + const scope = endpointPath.match(SCOPE_PREFIX)?.[0]; + if (!scope) return [key]; + const rest = endpointPath.slice(scope.length); + const variants = scope === '/{}/{}' ? ['/accounts/{}', '/zones/{}', '/{}/{}'] : [scope, '/{}/{}']; + return variants.map((prefix) => `${method} ${prefix}${rest}`); +} + +/** Indexes generated endpoint links by OpenAPI lookup key. */ +export function indexTerraformDocs(docs: GeneratedTerraformDocs): Map { + const index = new Map>(); + for (const [endpoint, links] of Object.entries(docs.endpoints)) { + for (const key of terraformEndpointKeys(endpoint)) { + const declarations = index.get(key) ?? new Map(); + for (const { declaration: id, roles } of links) { + const declaration = docs.declarations[id]; + if (!declaration) throw new Error(`Terraform endpoint ${endpoint} references unknown declaration ${id}`); + const previous = declarations.get(id); + const merged = previous ? [...new Set([...previous.roles, ...roles])] : roles; + declarations.set(id, { + ...declaration, + roles: terraformRoleSchema.options.filter((role) => merged.includes(role)), + }); + } + index.set(key, declarations); + } + } + const kindOrder = { resource: 0, 'data-source': 1, 'list-data-source': 2 }; + return new Map( + [...index].map(([key, declarations]) => [ + key, + [...declarations.values()].sort( + (left, right) => kindOrder[left.kind] - kindOrder[right.kind] || left.name.localeCompare(right.name), + ), + ]), + ); +} + +export function terraformDeclarationLabel(declaration: Pick): string { return `${declaration.kind === 'resource' ? 'resource' : 'data'} ${declaration.name}`; } +const ROLE_LABELS: Record = { + create: 'create', + read: 'read', + update: 'update', + delete: 'delete', + import: 'import', + other: 'other', +}; + +/** e.g. "Used by this resource to create and import." */ +export function terraformRolesSummary(declaration: TerraformDeclaration): string { + const roles = declaration.roles.filter((role) => role !== 'other').map((role) => ROLE_LABELS[role]); + const subject = declaration.kind === 'resource' ? 'resource' : 'data source'; + if (roles.length === 0) return `Called by this ${subject}.`; + const list = roles.length === 1 ? roles[0] : `${roles.slice(0, -1).join(', ')} and ${roles.at(-1)}`; + return `Called by this ${subject} to ${list}.`; +} + function combinedTerraformSnippet(data: TerraformOperationData): string | undefined { const snippets = data.declarations.flatMap((declaration) => - declaration.snippet ? [{ label: terraformDeclarationLabel(declaration), code: declaration.snippet.trimEnd() }] : [], + declaration.example ? [{ label: terraformDeclarationLabel(declaration), code: declaration.example.trimEnd() }] : [], ); if (snippets.length === 0) return undefined; if (snippets.length === 1) return snippets[0]?.code; @@ -86,8 +212,6 @@ export function withTerraformTarget(page: FernPageSchema): FernPageSchema { if (!code) return page; return { ...page, - targets: page.targets.map((target) => - target.id === 'terraform' ? { ...target, code, syntax: 'hcl' } : target, - ), + targets: page.targets.map((target) => (target.id === 'terraform' ? { ...target, code, syntax: 'hcl' } : target)), }; }